How do we find the AI tools our staff are already using?
Discovering AI tools used by staff requires a multi-faceted approach combining technical detection, policy enforcement, and user engagement. Organisations should implement network monitoring, endpoint detection, and data loss prevention (DLP) solutions to identify unsanctioned AI application usage and data exfiltration. Concurrently, establishing clear acceptable use policies and conducting regular staff awareness training are crucial for fostering a culture of compliance and encouraging voluntary disclosure, aligning with ISO 42001's governance principles.
Practitioners often underestimate the prevalence of "shadow AI" – the use of AI tools by employees without official sanction or awareness from IT and security departments. This typically arises from staff seeking efficiency gains or leveraging readily available public AI services. To address this, organisations must move beyond passive policy statements. Active technical controls are essential, including monitoring network traffic for connections to known AI service domains, analysing DNS queries, and inspecting endpoint processes for unapproved applications. Implementing robust data loss prevention (DLP) solutions is also critical to detect attempts to input sensitive organisational data into external AI models, which poses significant intellectual property and confidentiality risks.
A common mistake is relying solely on technical enforcement without addressing the underlying user behaviour or providing approved alternatives. While technical controls can identify usage, they do not inherently prevent it or educate staff on the risks. Organisations should establish a clear process for evaluating and approving AI tools, making this process transparent and accessible. Furthermore, regular and mandatory staff training on acceptable AI use, data handling policies, and the specific risks associated with unsanctioned tools is vital. This training should explain *why* certain tools are restricted, not just *that* they are restricted, fostering a more informed and compliant workforce. This proactive engagement aligns with ISO 42001's emphasis on competence and awareness.
Sources
- ISO/IEC 42001:2023, Clause 6.1 (Actions to address risks and opportunities)
- ISO/IEC 42001:2023, Clause 7.3 (Awareness)
- ISO/IEC 27002:2022, Clause 5.10 (Acceptable use of information and other associated assets), referenced by ISO/IEC 42001:2023 Annex A