Opens in a new tab
vmblog logo 2024 wht (updated)

How Network Observability Can Help Mitigate Shadow AI Risks

Share: 

network observability mitigate shadow ai risks

By Eileen Haggerty, Area Vice President, Product & Solutions Marketing, at NETSCOUT

For years, IT and security leaders have been locked in a high-stakes game of whack-a-mole with Shadow IT. It began with the bring-your-own-device (BYOD) movement, driven by employees who bypassed corporate policy to use the tools that made them the most productive. Today, that same relentless pursuit of efficiency has ushered in a new, far more complex challenge: unapproved AI.

With today’s rapid acceleration and rollout of AI, we are witnessing the rise of Shadow AI, where employees use AI without official company approval. According to Gallup data, nearly 40% of workers report that their workplaces have adopted AI technology. What is more alarming is Gartner’s finding that nearly 70% of cybersecurity leaders suspect, or have seen, employees using unapproved or prohibited AI tools.

Both data points indicate that Shadow AI represents a fundamental shift in workflows, often happening in the dark with little governance or oversight. The risks Shadow AI presents are formidable, but network observability that utilizes deep packet inspection (DPI) can provide the ground truth enterprises need to safely integrate AI.

The Risks of Shadow AI 

The main risk for enterprises associated with Shadow AI is the leakage of confidential information and intellectual property. Consumer-grade AI often uses user input to train its models, potentially exposing trade secrets or confidential information to the public. Take the 2023 Samsung data leak as an example. Employees utilized ChatGPT to help with work tasks but ended up leaking proprietary data to OpenAI servers.

Another risk Shadow AI poses is algorithmic bias. IT-approved AI tools typically undergo testing to ensure they do not produce biased outcomes based on race, gender, and age. For example, if an HR professional screens a job candidate’s resume using an unapproved AI tool, the company may be violating anti-discrimination laws.

Furthermore, a lack of central governance and the rise of specialized AI tools can result in different departments within an organization (from marketing to engineering) ending up with expensive and incompatible, siloed AI solutions. Having multiple AI models in use across departments heightens the risk of data leaks and makes tracking them more difficult. When IT teams must address these risks one silo at a time, they can quickly find themselves trapped in a painful and arduous cycle. It’s like patching a hole in a tire while continuing to run over nails; eventually, temporary fixes become ineffective.

The Truth Always Matters

The first reaction of many organizations is to attempt to implement an AI ban, which, as history shows, is counterproductive. A total ban typically drives more secretive use and exacerbates friction between IT teams and the affected departments. Fortunately, security products and protocols are evolving to address Shadow AI risks, for example, cloud access security brokers (CASBs) that block unauthorized queries. However, these specialized tools and policies, while effective, can only govern what they see.

One way companies gain visibility is through traditional Metrics, Events, Logs, and Traces (MELT) data, which helps show ‘what’ happened. When coupled with DPI, enterprises can see ‘why,’ ‘where,’ and ‘how’ it happened. For example, if an employee uses their personal account for a task or a browser extension, MELT data can provide some insight into individual systems, but not how application traffic behaves across the network path. This is the user experience. Network observability with DPI fills that gap, giving IT teams a real-world view of service behavior so they can truly understand what happened, where, and why.

In modern workplaces with hybrid and remote work, encrypted traffic, and dispersed cloud environments, policies and solutions are more easily bypassed. This is where leveraging network observability becomes crucial as the source of truth.

The Power of Network Observability

Technology and security leaders know the network doesn’t lie. Each time an AI tool is used, whether approved by IT or not, it must go through the network. For enterprises looking to mitigate Shadow AI risks, they must pivot away from autonomously blocking queries to intelligently observing them:

  • Without DPI, companies can miss AI activity happening through browser add-ons or plug-ins. With it, IT teams get a fuller picture of what’s being used on the network and enable ongoing observability for performance assurance and troubleshooting at the same level as other business-critical services.
  • The added context helps IT teams distinguish between normal AI use and a serious attempt to move sensitive data out of the company, enabling them to respond based on the level of risk and prevent escalation.
  • Better visibility helps organizations avoid duplicate spending on AI tools by showing when different departments are paying for similar solutions. 

Fearing or forbidding AI usage is not the smart path forward. Visibility can transform uncertainty into confidence, governance into enablement, and experimentation into measurable business value. The organizations that can see AI activity across their environments, understand the impact, and guide its responsible adoption will ultimately unlock AI’s greatest promise:  accelerating innovation while maintaining trust, resilience, and control.

##

ABOUT THE AUTHOR

Eileen Haggerty is an AVP of Product and Solutions Marketing at NETSCOUT, focusing on ensuring the company’s observability solutions meet the needs of enterprise customers. With a background in technical marketing at companies such as Motorola and Racal Data Group, she has extensive experience in product management and marketing and earned her MBA from Boston College Carroll School of Management.