That means that CISOs need to do a risk assessment of every genAI app employees are using, he said in an interview, and then set policies and procedures staff have to follow.
He warned CISOs and CEOs against following āthe Ostrich algorithmā ā pretending the danger doesnāt exist by ignoring, if not rewarding, the shadow use of AI by employees, either in the office or at home.
āThereās no question thereās a tremendous amount of use of generative AI apps being used in ways that are highly problematic for the organization,ā he said. āRemember, I can use a genAI app from my personal computer that my company has no control over, and still leak a tremendous amount of data just from what Iām asking ā and it may not be only what Iām asking, but what others are also asking, and the generative AI learns from the pattern of questions.

