Is it safe to enter company materials into an AI chatbot an individual subscribes to? [Photo: Reve AI]

[DigitalToday reporter Yoonseo Lee (이윤서)] Concerns have been raised that, in principle, people should avoid entering company information into AI services they personally subscribe to.

IT media outlet ITmedia reported on Aug. 27 (local time) that personal cloud-based AI services can use entered data for training and are difficult for companies to track and control, which can also create problems in responding to security incidents.

The key issue is how input information is handled. Cloud-based AI, including ChatGPT, can use user-entered data for model training. This means entering company secrets or internal materials could lead to a risk of information leakage. Such settings often remain the same even when users are on a paid personal plan.

The terms of service for personal ChatGPT state that the company may use "the content" to provide, maintain, develop and improve the service, and for legal compliance, policy enforcement and maintaining safety. Here, the content refers to user inputs and the AI's outputs. Because the terms specify the scope in which the service provider can handle input data, entering company documents into a personal account itself can be a risk factor.

By contrast, corporate plans can, depending on contract terms, in some cases be set not to use input information for training. Some personal services also offer settings to prevent input from being used for training, but that does not mean it is acceptable to enter company information into an AI an individual subscribes to.

The problem arises when a security incident occurs. AI officially adopted by a company is often operated in a way that allows usage to be monitored or traced to identify the cause, but that is not easy with services an individual subscribes to separately. From the company's standpoint, it is difficult to check who entered what information into an external service, and it can also negatively affect incident investigations.

For this reason, contracting and using external IT services without company approval is called "shadow IT" and, for AI services, "shadow AI". From a corporate security perspective, it is classified as behavior that should be restrained. Even if the goal is to improve work efficiency, company data leaving for an external cloud through an unmanaged route falls outside the scope of control.

As an alternative to reduce the risk of information transfer, "local AI" and "local LLM" are being discussed. This is a method of running AI directly on a user's device or manageable equipment. In the past it was assessed as having lower performance than cloud-based AI, but as the gap has narrowed over the past 1 to 2 years, many companies are reviewing adoption and use.

Ultimately, the standard that determines the safety of work AI is not whether an individual paid for it, but whether the company can control the data processing path. The report said employees should use company-approved corporate services and check what information may be entered, and companies should also prepare clear usage guidelines and training and secure alternatives such as local AI. As the use of AI expands, responding to "shadow AI" in management blind spots is expected to emerge as a key task for corporate security.

Keyword

#ChatGPT #Shadow AI #Shadow IT #local AI #local LLM
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.