SophiaRobert

AI Risk Pricing Challenge for Companies

· fashion

Companies Cannot Price The Shadow AI Risk They Cannot See

The recent surge in data breaches attributed to “shadow AI” has left many in the industry scratching their heads. However, this phenomenon is not just a symptom of a larger problem; it’s a harbinger of a systemic issue that threatens even well-intentioned organizations.

According to an IBM report, 43% of security incidents last year involved unauthorized AI tools adopted by staff without management approval. The report might have us believe that the culprit lies with employees’ reckless adoption of unvetted tools. However, this narrative overlooks the elephant in the room: 68% of companies lack a policy governing AI use at all.

This laissez-faire approach is puzzling, given the risks involved. As Yakir Golan from Kovrr notes, “Companies should manage their AI usage risk as if it were 90 to 95% and model risk as if it were 5 to 10%.” This imbalance highlights our critical failure in managing AI-related risks.

The recent EU AI Act is a step towards transparency, mandating companies to disclose when staff interact with AI systems and marking synthetic content as artificially generated. However, this provision comes with its own set of challenges. As Golan notes, “Disclosure presumes an inventory,” implying that companies must first catalog their AI assets before they can manage them effectively.

Employees are often left to navigate the complex landscape of AI risks without guidelines or oversight. The UpGuard survey found that 81% of employees and 88% of security leaders admit to using unapproved AI tools, with 45% resorting to workarounds when applications are blocked. This paints a disturbing picture of a workforce operating in uncertainty.

The vendors who supply enterprise AI models also bear some responsibility for the lack of transparency. Their focus on large-scale deployments and regulatory compliance has created a blind spot, allowing shadow AI to thrive in the shadows.

Insurers have been ahead of the curve, with their underwriting practices reflecting an understanding that AI-related breaches are more costly and complex than traditional cyber attacks. The global average breach reached just under $5 million last year, with AI-facilitated breaches racking up an additional $1 million in damages. This should serve as a wake-up call for companies to reassess their risk management strategies.

The shadow AI phenomenon is merely a symptom of our systemic failure to adapt to the rapidly evolving landscape of AI risks. It’s time for companies to take ownership of their AI assets and usage patterns, to recognize that true transparency requires more than just regulatory compliance. The clock is ticking – December 2027 looms large on the horizon, when standalone high-risk obligations under Annex III come into effect.

Reader Views

  • TC
    The Closet Desk · editorial

    The elephant in the room remains an elephant because we're more focused on finger-pointing than systemic overhaul. We need to acknowledge that AI risk pricing is not just about management approval or inventory cataloging – it's also about accountability from vendors who supply models with unknown biases and vulnerabilities. If companies are being told to manage their AI usage risk like a 90% certainty, shouldn't we demand similar transparency from the models themselves?

  • TH
    Theo H. · menswear writer

    "The recent emphasis on AI risk pricing challenges companies to acknowledge what's lurking in the shadows: the employee factor. While vendors and policymakers focus on compliance and disclosure, it's essential to consider the incentives driving staff to adopt unapproved AI tools. Are we seeing a case of users exploiting vulnerabilities because they feel empowered by the absence of clear guidelines? The onus is not solely on companies to catalog their AI assets but also on employees to recognize the risks involved in circumventing security protocols."

  • NB
    Nina B. · stylist

    The article gets close to hitting the nail on the head, but I think we're still underestimating the scope of the problem here. The real challenge isn't just about managing AI usage risk, but also about understanding that AI is not a one-time cost, but an ongoing commitment. Companies need to recognize that their current systems and processes are woefully unprepared for the complexity of AI-driven operations. Until we acknowledge this reality, we're going to keep seeing companies caught off guard by these data breaches and wondering how they got there in the first place.

Related articles

More from SophiaRobert

View as Web Story →