India’s Shadow AI Risk: Data Leaks & Governance Gaps

By Business DeskIndia’s Shadow AI Risk: Data Leaks & Governance Gaps

Indian companies face mounting data security risks from ‘shadow AI’ use. Employees’ unmonitored AI tool adoption leads to thousands of violations and potential IP leaks.

Indian companies are increasingly vulnerable to significant data security and governance risks. Employees are adopting ‘shadow AI,’ utilizing personal AI accounts and unauthorized tools alongside official enterprise platforms.

This widespread, unmonitored use exposes sensitive intellectual property, source code, and regulated data. Over 3,000 AI-related data policy violations occur monthly within Indian organizations, highlighting a critical security gap.

Uncontrolled AI Adoption Raises Stakes

A Netskope Threat Labs report indicates that 82% of Indian workers interact with AI applications directly. Furthermore, 97% use Software-as-a-Service (SaaS) applications with embedded AI features.

Another 92% use applications that leverage user data for model training. Cyber expert Amit Jaju noted that despite AI adoption being a priority, few Indian companies have established formal AI governance or ethics frameworks.

This creates a scenario where employee experimentation with AI tools outpaces security and compliance safeguards. Tarun Wig, co-founder and CEO of Innefu Labs, argues that restricting AI use is ineffective, as employees often seek productivity gains, not malicious intent.

Critical Data Exposures Detailed

The most significant exposure comes from source code, accounting for 49% of AI-related data policy violations in India over the past year. This includes developers using AI for debugging, code explanation, and function writing, inadvertently exposing proprietary information.

Regulated data contributes 23% of violations, mirroring the risk posed by intellectual property, which also accounts for 23%. Passwords and API keys make up another 5% of these breaches.

Sharing sensitive information with public AI tools through shadow AI creates immediate data security and compliance risks. Jaju warned this could lead to breaches and violations under India’s DPDP Act, particularly for regulated sectors.

Persistent Visibility Challenges

The problem extends beyond standalone AI chatbots to AI features embedded in everyday software, complicating monitoring efforts. Personal AI accounts exacerbate this by creating a visibility gap for IT teams.

While personal AI use at work decreased from 79% to 41%, and organization-managed AI tools increased from 30% to 77% over the past year, visibility issues persist. A notable 18% of users still switch between personal and enterprise accounts, often due to the speed and convenience of personal tools.

Home/business/Article