Artificial intelligence (AI) is stomping into enterprises and reinventing business operations, but it brings a new set of challenges. Uncontrolled growth of AI applications – AI sprawl – can lead to significant issues for IT systems and the entire enterprise.
Imagine multiple teams independently developing similar AI solutions, unaware of each other's efforts. This redundancy wastes valuable resources and drives up infrastructure costs as IT struggles to support a growing number of disparate systems. Integrating these diverse AI tools into a cohesive ecosystem becomes a complex and costly endeavor. On another level, individual employees using their own AI and generative AI (genAI) services are deploying shadow IT that presents its own liabilities.
With AI sprawl, sensitive data is processed by multiple applications, greatly expanding the potential attack surface. Each new AI model introduces potential vulnerabilities that could be exploited to manipulate outcomes or introduce bias. A decentralized approach to AI deployment makes it increasingly difficult to maintain oversight and ensure robust security across the board.
This is already a serious real-world problem. Rick Caccia, founder and CEO of AI management software firm WitnessAI, told SDxCentral about some horror stories he's seen in this area.
“One company I spoke with had a developer upload their entire mobile app’s source code to an AI to optimize it,” Caccia said. “Another example is employees sharing sensitive financial data, like earnings reports, with AI platforms. These are common issues across many companies. The problem is, businesses often don’t know this is happening until it’s too late, leading to data breaches or compliance violations.”
Navigating the governance maze As AI applications proliferate, organizations face mounting challenges in maintaining compliance with regulations and ethical guidelines. Establishing accountability for AI-driven decisions becomes complex. Uncontrolled AI deployments risk perpetuating biases present in training data, potentially leading to unfair or discriminatory outcomes. Meeting data privacy and other regulatory requirements becomes increasingly difficult.
Unchecked growth of AI applications can strain IT infrastructure. Multiple AI systems competing for limited compute power, memory, and storage can create performance bottlenecks. Increased data flow from these applications can congest the network, leading to latency issues and impacting overall system performance.
IT departments often lack a full-scope view of all AI applications operating within the organization. This lack of visibility can cause shadow AI, where employees utilize unapproved tools, introducing security and compliance risks. Managing updates and patches for a sprawling AI landscape becomes a logistical nightmare. Optimizing resource allocation becomes nearly impossible without a clear understanding of AI usage patterns.
Addressing AI sprawl requires a proactive and strategic approach. Organizations need to establish clear AI governance frameworks, implement robust security measures, and leverage tools to monitor and manage AI usage across the enterprise. By taking these steps, businesses can harness the power of AI while mitigating the risks associated with its uncontrolled growth.
Q&A with Nutanix CIO Rami Mazid SDxCentral spoke with Nutanix CIO Rami Mazid to discuss the short- and long-term effects of AI sprawl on enterprise systems.
SDxCentral: How do you define AI sprawl?
Rami Mazid: AI sprawl refers to the uncontrolled proliferation of AI tools across an organization. Just like with cybersecurity, there are too many tools solving too many things without centralized oversight. This leads to inefficiencies, redundancies, and significant security risks. For instance, various departments, like sales and marketing, might independently adopt different AI solutions for similar problems, but these solutions don’t integrate or align with each other. This increases costs and operational inefficiencies. AI sprawl also raises governance challenges, making it difficult to ensure data quality, consistency, and security.
SDxCentral: Can you provide an example of inefficiency that AI sprawl can cause within a company?
RM: Let’s take a scenario where the marketing team adopts an AI tool to analyze customer behavior while the sales team uses a different AI tool to address a similar challenge from a sales perspective. Since these tools don’t communicate or integrate, you’re paying for two AI solutions doing almost the same thing. In addition, these isolated AI tools can cause inefficiencies because the data is siloed and the teams are not working from a single source of truth. This lack of integration causes increased costs and operational complexities.
SDxCentral: How can CIOs and CTOs prevent this? Who should take the lead on managing these tools?
RM: I believe the CIO should be responsible for managing AI strategy across the organization. CIOs are in a unique position because they oversee multiple functions while CTOs tend to focus more on the engineering side of the product. At Nutanix, we’re adopting a centralized AI governance approach. We’ve established a cross-functional committee to take inventory of all existing AI tools and develop a unified strategy. This includes creating policies, frameworks, and best practices that align with the company’s overall objectives. By standardizing AI usage across departments we can drive efficiency, reduce redundancy, and maintain security.
SDxCentral: What are some other key concerns?
RM: Data governance is a huge concern. With AI tools spread across an organization it’s difficult to ensure data quality and security. Each tool might store or process data in different ways, potentially exposing sensitive information and increasing the risk of compliance violations, such as GDPR breaches. Additionally, if AI is not deployed thoughtfully, you can end up with redundant solutions that don’t deliver the intended value. It’s crucial to define clear use cases and establish a strategic plan before implementing AI solutions.
SDxCentral: How does AI sprawl affect a company’s cybersecurity posture?
RM: When you have multiple, uncoordinated AI tools, you increase the attack surface for potential breaches. Each tool may expose data to different environments or systems, making it harder to track and secure. Without proper oversight, sensitive data could be at risk, leading to serious compliance and security issues. That’s why a unified approach to AI governance is critical – it ensures that all tools are integrated securely and adhere to the company’s data protection policies.
SDxCentral: How is your company using AI to improve your own operations?
RM: We’ve deployed AI to enhance several internal processes. One example is how we’ve improved our first contact resolution (FCR) for customer support. The industry average FCR is about 48%, meaning that less than half of issues are resolved on the first contact. By integrating AI-driven solutions, we’ve pushed our FCR to 98%. We’ve also reduced ticket volumes by 40%, thanks to automation that resolves common issues before they even reach human support teams. This has significantly boosted our Net Promoter Score (NPS), which is now over 90%.
SDxCentral: Who should enterprises consult to get the best guidance on maximizing efficiency?
RM: I recommend speaking with both CIOs and CTOs who have firsthand experience in managing AI at an enterprise level. CIOs are particularly important because they have a holistic view of how AI fits across the organization, from infrastructure to security to business operations.
Comments