Anton Chuvakin, security advisor at the Office of the CISO for Google Cloud, shed light on the nuanced differences between consumer and enterprise generative artificial intelligence (genAI) tools, the emerging phenomenon of shadow AI and the strategies organizations can take to mitigate the associated risks.
Chuvakin recounted some recent customer interactions regarding concerns about adopting consumer-grade AI chatbots for business purposes. He underscored the inherent risks of using tools designed for casual use in enterprise contexts, emphasizing that “the right [approach] is to use enterprise AI.”
“The volume and the amount of confusion was overwhelming. So ultimately it is shadow IT all over again, but with chatbots, and it's also complicated,” he told SDxCentral. “For a moment, there was only consumer-grade AI. There was no business genAI … so that created sort of a critical mess.”
Chuvakin delineated the differences between consumer and enterprise AI tools: Consumer-grade AI systems are expected to learn from prompts and improve over time, designed mainly for fun or personal use. Enterprise AI, on the other hand, often requires restrictions on learning from prompts to protect sensitive information, necessitating fine-grained control over the learning process. Enterprise AI should ideally learn from controlled and canonical sources rather than from any available data.
“Governance of training, data output filtering, learning from proms, it's much stronger [in enterprise AI] or sometimes it's the opposite on consumer-grade versus enterprise-grade AI,” he said. “It's less about safety, but it's more about the enterprise using the tool having control over what it learned from what it will say and what it can do.”
Potential shadow AI risks and safeguardsChuvakin said that the use of consumer-intended genAI tools in business situations will raise serious questions about data security, compliance and privacy for businesses.
Google Cloud found the types of potential shadow AI risks including sensitive data leakage, hallucinations and unauthorized data access, but noted banning the genAI tools in the workplace is not the solution.
“Ultimately, people are concerned with intellectual property leakage, people are concerned with incorrect results or systems learning from the incorrect, noncanonical sources,” Chuvakin said.
He recommended balancing educating the employees and raising awareness about genAI tool risks versus enforcing the genAI usage and safety rules and regulations. “Enforcement alone is either not gonna work, or it's gonna actually work for the opposite.”
In terms of security technologies for genAI safety and control, Chuvakin suggested leveraging existing network and cloud security tools such as cloud access security broker (CASB).
“I suspect that there are startups that have built like a layer of controls, maybe like a proxy with filter, for consumer-grade but ultimately enterprise-grade AI tools as well,” he said. “If some company wants even more granular control, this is what I expect to happen: some form of filtering in a proxy for AI access will probably be created.”
Looking to the future, Chuvakin anticipates greater clarity and differentiation between consumer and enterprise genAI tools, reducing confusion and aligning tool selection more closely with specific business needs.
“There will be additional tooling built by us and other providers and of course small startups to sort of clearly differentiate and maybe add an additional layer of controls, because admittedly, small business versus mid-sized business versus large regulated enterprise that's global will have different levels of controls, and we can satisfy probably all of them with the most stringent [tools], but sometimes not in the easiest manner.”
How Google Cloud deals with genAI risks and shadow AIChuvakin noted that Google treats its own consumer-grade and enterprise genAI tools with caution and guidance on how to handle certain types of corporate data.
“The advantage we have is that the access to the latest technology in a more controlled environment is a lot easier here because we built most of them,” he said. “We can always observe certain gaps and big problems, and we will write code to solve them. And we also are the first party for a lot of models, so we know we can always call somebody or message somebody and say, ‘Would the model do this?’”
But the philosophical challenges are the same such as using consumer-grade AI tools for enterprise use is risky, Chuvakin said.
Comments