Talk about Artificial Intelligence (AI) today cannot be avoided. I mean, I enjoy listening to sports radio and if the commercials aren’t addressing AI, then the hosts are in some capacity.
With sports, I think AI has infected the nature of how things have been traditionally played. I use the word infected because I think it’s done more to hinder progress than promote it. Analytics within baseball and the new Automate Ball-Strike (ABS) system introduced to Major League Baseball (MLB) this year have been comedic in some circumstances even allowing for a margin of error.
Okay, that rant is over, but the point is clear. AI is literally EVERYWHERE!
Some of the more common names are ChatGPT, Microsoft Copilot, Google Gemini and Claude. Many vendors even have their own AI tools.
What I want to focus on is its usage within the workplace. Its prevalence doesn’t just exist as a topic of discussion; it’s probably being used within your business in ways you are not only unaware of, but that could put your cybersecurity position at risk.
Like most things, I think we take more than we give. For example, I use Google constantly to inquire about problems I encounter in the IT space. Google gives me results others have seen fit to put on the web for my benefit. But how often am I contributing? How often am I giving back rather than taking in?
This is where things get risky for businesses using AI to enhance their day-to-day activities. They may be putting information into an ecosystem that doesn’t provide the level of privacy their business requires.
What if your users are entering Social Security Numbers (SSN), employee names and addresses, or phone numbers? That’s Personally Identifiable Information (PII).
Let’s take it a step further.
What if you work in healthcare or life sciences and utilize an AI tool to compile information? That could include trial data, patient information or patient names.
Where is that information now? Can you get it back? Can it be erased? Is it contributing to everyone else’s data? Is it co-mingled rather than siloed?
I recently had this kind of discussion with a client. However, the right question was asked at the outset: Can I use this tool and remain HIPAA compliant?
This exemplifies how communicating with IT and asking the right questions can help eliminate “ghost IT.”
But it still doesn’t address what technical controls your business or Managed Services Provider (MSP) has implemented to prohibit, educate or guide your business in its use of today’s AI tools.