Brief IA

Ghost AI on Campuses: A Challenge for Data Security

💡 Use Cases·Tom Levy·

Ghost AI on Campuses: A Challenge for Data Security

Ghost AI on Campuses: A Challenge for Data Security
Key Takeaways
1Ghost AI is growing in universities, escaping the control of official IT services.
2Students and staff are using AI tools without approval, risking leaks of sensitive data.
3Technological and cultural measures are essential to identify and manage these unauthorized practices.
💡Why it mattersManaging ghost AI is crucial to protect sensitive data and ensure responsible use of technology on campuses.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

The Enthusiasm for AI in Higher Education

The enthusiasm surrounding artificial intelligence in higher education is palpable. Students, teachers, and administrative staff see these technologies as new opportunities to enhance teaching and research. However, this excitement can lead to the hasty adoption of AI tools, often without prior approval or assessment from IT services. This phenomenon, known as shadow AI, occurs when technological tools are used outside official channels.

Shadow AI manifests in various ways. For example, a student might input sensitive information into a public chatbot, while a researcher could use grant funds to deploy a cloud-based AI tool, discreetly connecting it to institutional data. Similarly, an administrator might experiment with a free tool promising productivity gains, unaware of the implications for data privacy.

The Origins of Shadow AI

Shadow AI primarily emerges from two sources: students and employees. Students, as digital natives, are inclined to use public language models to complete their tasks more efficiently. However, without clear guidelines from universities, they may overlook legal boundaries, particularly those imposed by the Family Educational Rights and Privacy Act (FERPA) or other regulations concerning sensitive data.

On the employee side, including teachers, researchers, and administrators, shadow AI is also developing. Senior researchers, often with their own budgets and grants, sometimes choose tools without consulting the IT department. They still utilize the university's networks, data, and intellectual property. Occasionally, these tools are integrated into workflows before the IT department is informed or solicited for support.

The Risks Associated with Shadow AI

One of the main risks associated with shadow AI is data leakage. When sensitive information, such as student records, health data, or proprietary research, is introduced into AI tools, it can be exposed to privacy breaches. Depending on the tool's policies, this data may be retained, used to train future models, or processed in ways that are incompatible with institutional obligations.

It is crucial to understand how data is used and what the privacy policies of AI tools are. Some providers may reserve the right to use queries and results to improve their models. For many public tools, the data sent becomes an integral part of their ecosystem, which may be acceptable for innocuous queries but not for sensitive data.

Identifying and Managing Shadow AI

To identify shadow AI, it is essential to combine technological and cultural approaches. On the technological front, perimeter security tools, firewall logs, data loss prevention systems, and web filters can help monitor the use of AI services. IT teams can thus track outgoing traffic to known AI services and limit access if necessary.

CDW works with security and observability partners to provide tools that monitor traffic to AI applications, identify the services used, and assist IT teams in assessing potential risks to sensitive data. These tools offer best practices for software implementation and configuration, enabling teams to make informed decisions.

From a cultural perspective, it is important for the IT department to be seen as a partner rather than just a control agent. If teachers and staff fear that contacting IT will only lead to refusals, they will seek alternative solutions. The IT department must be a trusted collaborator, ready to offer guidance from the outset of discussions.

To encourage compliance, it is effective to make approved tools more attractive than unofficial ones. If a sanctioned AI platform offers access to institutional knowledge in addition to general AI capabilities, it naturally becomes the preferred option. Enterprise tools that are fast, reliable, and more valuable will be chosen because they perform better.

For institutions where the use of AI is already out of control, the first step is not to lock everything down but to gain visibility into the situation. Understanding what is happening is essential for designing realistic policies and remediation solutions. Next, creating an AI Center of Excellence or a similar body, including IT staff, academic leadership, researchers, and administrators, can help co-create effective policies.

AI in higher education is not just a passing trend. Employers expect graduates to master the responsible use of AI tools. Universities that view AI as a threat to be suppressed risk inadequately preparing their students and pushing AI use underground, rather than framing it thoughtfully and securely.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.