Lack of GenAI Training and Use of Unsanctioned Tools Pose Workplace Security Risks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Ivanti's research reveals that while 75% of office workers use generative AI, 81% lack formal training and 15% use unsanctioned AI tools. This widespread, unregulated use increases the risk of security breaches, data privacy violations, and legal issues, as employees bypass protocols for convenience.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article focuses on the potential risks and security concerns arising from the use of generative AI by employees without formal training, which could plausibly lead to harms such as data breaches or legal violations. However, no actual harm or incident is reported. Therefore, this qualifies as an AI Hazard because it describes circumstances where AI use could plausibly lead to harm, but no direct or indirect harm has yet materialized. It is not Complementary Information because it is not updating or responding to a previously reported incident, nor is it unrelated as it clearly involves AI systems and their use in the workplace.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityAccountabilityRespect of human rightsTransparency & explainabilitySafety

Industries
Business processes and support servicesDigital securityIT infrastructure and hosting

Affected stakeholders
BusinessConsumers

Harm types
Economic/PropertyReputationalHuman or fundamental rights

Business function:
ICT management and information securityCompliance and justice

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard