Taiwanese Firms Address Shadow AI Security Risks in Enterprises

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Zyxel, a subsidiary of Unizyx, highlights rising cybersecurity and compliance risks from employees' unauthorized use of generative AI tools ('shadow AI') in Taiwan. With 44% of employees reportedly using AI without company approval, Zyxel and startup Lingji Technology launched AI security solutions to help businesses manage and mitigate these potential hazards.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves AI systems (generative AI tools and AI-powered cybersecurity solutions) and discusses the potential security risks (data leakage, vulnerabilities, compliance risks) from unmanaged AI use, which could plausibly lead to harm. However, no actual harm or incident has been reported; the article mainly presents a hazard scenario and a mitigation solution. Therefore, this qualifies as an AI Hazard because it concerns plausible future harm from AI use and the measures to prevent it, rather than an AI Incident or Complementary Information about a past incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Human or fundamental rightsEconomic/Property

Severity
AI hazard

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

愛用 AI 反成資安漏洞 合勤控旗下兆勤以AI防堵「影子 AI」資安危機 | 聯合新聞網

2026-05-19
UDN
Why's our monitor labelling this an incident or hazard?
The event involves AI systems (generative AI tools and AI-powered cybersecurity solutions) and discusses the potential security risks (data leakage, vulnerabilities, compliance risks) from unmanaged AI use, which could plausibly lead to harm. However, no actual harm or incident has been reported; the article mainly presents a hazard scenario and a mitigation solution. Therefore, this qualifies as an AI Hazard because it concerns plausible future harm from AI use and the measures to prevent it, rather than an AI Incident or Complementary Information about a past incident.
Thumbnail Image

企業導入生成式AI 合勤控:避免影子AI成資安隱患 | 產經 | 中央社 CNA

2026-05-19
Central News Agency
Why's our monitor labelling this an incident or hazard?
The event involves AI systems (generative AI and AI-based security tools) and concerns potential risks (data leakage, compliance issues) stemming from unauthorized AI use within companies. Since no actual harm or incident has occurred yet, but there is a plausible risk of harm due to shadow AI, this qualifies as an AI Hazard. The article mainly focuses on the potential for harm and the mitigation strategies, not on a realized incident or harm.
Thumbnail Image

應對影子AI風險,兆勤攜聆機科技推資安防護解方-MoneyDJ理財網

2026-05-19
MoneyDJ理財網
Why's our monitor labelling this an incident or hazard?
The event involves AI systems (generative AI and LLMs) and addresses risks related to their use, but no actual harm or incident has occurred. The article mainly discusses a new AI security product and collaboration aimed at mitigating potential AI risks, which fits the definition of Complementary Information. There is no direct or indirect harm reported, nor a plausible immediate hazard event. Hence, it is not an AI Incident or AI Hazard but a governance and risk management update.
Thumbnail Image

企業導入生成式AI 合勤控:避免影子AI成資安隱患 | 產業熱點 | 產業 | 經濟日報

2026-05-19
Udnemoney聯合理財網
Why's our monitor labelling this an incident or hazard?
The event involves AI systems (generative AI and large language models) and addresses the potential security and compliance risks (data leakage, regulatory non-compliance) arising from unauthorized or unmanaged AI use within enterprises. Although no specific harm has yet occurred, the article clearly identifies plausible future harms due to shadow AI usage and presents a solution to mitigate these risks. Therefore, this qualifies as an AI Hazard because it concerns credible potential harms stemming from AI system use in a corporate environment, but no actual incident of harm is reported.
Thumbnail Image

合勤控旗下兆勤推出「生成式AI 防護解決方案」 協助企業應對影子AI資安風險 | 鉅亨網 - 台股新聞

2026-05-19
Anue鉅亨
Why's our monitor labelling this an incident or hazard?
The event involves AI systems in the context of generative AI tools and cybersecurity, but it is about a newly introduced protective solution to manage potential risks rather than an incident or hazard where harm has occurred or is imminent. The article highlights the potential for harm if shadow AI is unmanaged but does not describe a concrete AI incident or a near-miss AI hazard. Therefore, this is best classified as Complementary Information, providing context and response to AI-related risks without reporting a direct or plausible harm event.