During a quarterly security review, an IT admin at a consulting firm runs a DLP report on web traffic and discovers that 35 employees have been uploading client deliverables, internal strategy documents, and draft proposals to 'DocSummarize.ai' - a free AI document summarization service not listed in the company's approved vendor list and without a signed data processing agreement.
An IT admin discovers employees have been sharing sensitive internal documents with a vendor's AI summarization tool that is not approved by IT security. The tool's privacy policy says it retains documents for 90 days for quality assurance. What category of AI risk does this represent?
- A.Shadow AI and unauthorized data processing - unsanctioned use of an AI tool results in sensitive data being processed under unknown terms
- B.Adversarial ML - employees are unintentionally poisoning the vendor's model with internal data; ISO/IEC 42001 certifies this setup
- C.Model theft - employees are giving the vendor data that trains a model competitive with the company's own AI systems
- D.AI-powered phishing - the vendor may use documents to craft targeted phishing attacks