حذر المركز الوطني للأمن السيبراني في بريطانيا «NCSC» من مخاطر استخدام الموظفين أدوات وتطبيقات ذكاء اصطناعي غير معتمدة من جهات عملهم، مؤكداً أن هذه الممارسات قد تعرض بيانات الشركات والعملاء لمخاطر أمنية يصعب على المؤسسات اكتشافها وإدارتها.
ويُعرف استخدام تقنيات الذكاء الاصطناعي خارج الأنظمة والسياسات المعتمدة داخل المؤسسات باسم «الذكاء الاصطناعي الخفي» أو Shadow AI، وهو امتداد لمفهوم «تقنية المعلومات الخفية»، الذي يشير إلى استخدام الموظفين خدمات تقنية دون موافقة أقسام تقنية المعلومات أو الأمن السيبراني.
71% استخدموا أدوات غير معتمدة
واستشهد المركز بأبحاث أشارت إلى أن نحو 71% من الموظفين في بريطانيا استخدموا أدوات ذكاء اصطناعي لم تعتمدها جهات عملهم، ما يعكس اتساع استخدام هذه التقنيات بوتيرة أسرع من قدرة المؤسسات على تقييمها وتوفير بدائل رسمية لها.
وأشار المركز إلى أن إدخال بيانات الشركات أو العملاء في خدمات ذكاء اصطناعي غير معتمدة قد يزيد احتمالات تسرب البيانات وفقدان الملكية الفكرية وعدم الالتزام بالمتطلبات التنظيمية.
مخاطر تمتد إلى وكلاء الذكاء الاصطناعي
وحذر المركز أيضاً من المخاطر المرتبطة بوكلاء الذكاء الاصطناعي، موضحاً أن استغلال ثغرة أمنية في أحد الوكلاء قد يمنح المهاجم إمكانية الوصول إلى البيانات والخدمات والصلاحيات نفسها التي يستطيع الوكيل الوصول إليها بصورة مشروعة.
«الحظر الكامل» ليس الحل
وأكد المركز أن المؤسسات ينبغي أن تركز على تقليل مخاطر «الذكاء الاصطناعي الخفي» بدلاً من افتراض إمكانية القضاء عليه بالكامل، داعياً إلى وضع ضوابط واضحة للاستخدام الآمن، وتشجيع الموظفين على مناقشة احتياجاتهم التقنية مع فرق الأمن السيبراني.
وشدد على أن المؤسسات لا تستطيع عملياً حجب جميع أدوات الذكاء الاصطناعي المتاحة، ما يجعل توفير بدائل آمنة ومعتمدة وتعزيز ثقافة الأمن السيبراني من أبرز الوسائل للحد من المخاطر.
The UK National Cyber Security Centre (NCSC) has warned about the risks of employees using artificial intelligence tools and applications that are not approved by their organizations, emphasizing that these practices could expose company and customer data to security risks that are difficult for institutions to detect and manage.
Using artificial intelligence technologies outside the approved systems and policies within organizations is known as "Shadow AI," which is an extension of the concept of "shadow IT," referring to employees using technology services without the approval of IT or cybersecurity departments.
71% Used Unapproved Tools
The centre cited research indicating that about 71% of employees in the UK have used AI tools not approved by their organizations, reflecting the rapid expansion of the use of these technologies at a pace faster than organizations can assess and provide official alternatives.
The centre noted that entering company or customer data into unapproved AI services could increase the likelihood of data breaches, loss of intellectual property, and non-compliance with regulatory requirements.
Risks Extend to AI Agents
The centre also warned about the risks associated with AI agents, explaining that exploiting a security vulnerability in one of the agents could grant an attacker access to the same data, services, and permissions that the agent can legitimately access.
"Complete Ban" Is Not the Solution
The centre affirmed that organizations should focus on reducing the risks of "Shadow AI" rather than assuming it can be completely eradicated, calling for clear controls for safe usage and encouraging employees to discuss their technical needs with cybersecurity teams.
It stressed that organizations cannot practically block all available AI tools, making the provision of safe and approved alternatives and promoting a culture of cybersecurity among the most effective means to mitigate risks.