AI Adoption in the Workplace: A Cybersecurity Expert’s Playbook

Is the use of artificial intelligence on the rise among employees? Absolutely. While still more prevalent in “knowledge-based industries,” such as education and finance, Gallup recently reported a sharp increase in overall workplace adoption, with nearly a third of U.S. employees saying they frequently use AI tools, particularly for tasks involving problem-solving, research and writing. 

But are all these workers using AI safely and securely? Unfortunately, no. According to IBM, shadow AI, the “unsanctioned use of any AI tool or application without formal approval or oversight,” is steadily increasing, particularly among small and mid-sized businesses. And, as the Society for Human Resource Management noted, it’s creating a “bevy of new risks that require HR and IT leaders to revamp their education and governance strategies.” 

So, how can companies set clear guardrails to protect their workplaces from potential cybersecurity threats while also enabling their team members to reap the benefits of AI? We turned to the experts at Sullivan Wright Technologies, who shared three questions organizations should consider when developing AI-related policies.

 

1. Is there a reasonably clear purpose or goal for using AI? Leadership must first ask themselves how, or if, AI could benefit their employees and operations. Having clarity on its application can help businesses pinpoint the right tools to test and prevent the all-too-common mistake of using AI by default. During this process, if companies determine AI is not useful or worth the associated risks and therefore not permitted, their corporate policies should explicitly state this and alert employees to the consequences of unauthorized use.

 

2. Are we using enterprise-grade AI tools? It’s frequently said in the cybersecurity field that if you’re not paying for the product, then you are the product. With free AI tools, user data is often the unstated cost of using the platforms. Generally, commercial accounts offer greater transparency and access to more rigorous security controls, enabling companies to monitor and restrict usage as needed. But Sullivan Wright Technologies is quick to point out it’s about more than investing in the proper tools. Businesses should also provide regular, relevant employee security training to their team members.

 

3. Would this share proprietary or confidential data? Companies should always set clear restrictions on data submission, specifying the input — if any — employees may use with AI platforms. For example, do employees have to use generic information in their queries, or can they upload redacted files? If team members must work with sensitive data, an experienced cybersecurity professional can help businesses establish and update AI-related protocols to ensure corporate information remains protected.

 

That said, one of the pros’ biggest pieces of advice? Avoid blanket adoption of workplace AI. Companies should start small, picking a platform or tool to pilot and documenting their progress to measure potential impact. In some cases, leadership may find the promised outcomes were AI hype. 

However, if implemented strategically and with detailed guidelines to mitigate possible risks, both businesses and their employees can see clear gains from AI, from enhanced efficiency to greater productivity. And that’s worth investing in.

 

Click here to sign up for the monthly e-newsletter:

Related Articles