During a quarterly security review, an IT admin at a consulting firm runs a DLP report on web traffic and discovers that 35 employees have been uploading client deliverables, internal strategy documents, and draft proposals to 'DocSummarize.ai' - a free AI document summarization service not listed in the company's approved vendor list and without a signed data processing agreement.
An IT admin discovers employees have been sharing sensitive internal documents with a vendor's AI summarization tool that is not approved by IT security. The tool's privacy policy says it retains documents for 90 days for quality assurance. What category of AI risk does this represent?
- A.A. AI-powered phishing - the vendor may use documents to craft targeted phishing attacks
- B.C. Adversarial ML - employees are unintentionally poisoning the vendor's model with internal data
- C.B. Shadow AI and unauthorized data processing - unsanctioned use of an AI tool results in sensitive data being processed under unknown terms
- D.D. Model theft - employees are giving the vendor data that trains a model competitive with the company's own AI systems
Why C is correct
Shadow AI refers to employees using unapproved AI tools that process company data outside of IT governance controls. The risk is that sensitive data is sent to a third party under terms the company has not reviewed, consented to, or included in their data processing inventory. This can violate GDPR data processor obligations, breach client confidentiality commitments, and create regulatory exposure. Options A, C, and D are not the primary concern in this scenario.
Know someone studying for AI Security Fundamentals? Send them this one.