Abu Dhabi: Two experts in corporate work and law have warned of the spread of the ‘shadow AI’ phenomenon in the workplace, as employees are no longer content with bringing their personal devices to the offices, but are now bringing their own artificial intelligence tools and applications into the workplace without prior permission.
They emphasised that while this new digital trend saves employees long working hours and speeds up the pace of achievement, it presents institutions with a real security dilemma known as ‘shadow AI’, where these unregulated tools could turn into open windows for leaking sensitive data.
The Microsoft and LinkedIn Work Trends Index, based on a study of 31,000 people in 31 countries, revealed that 78% of AI users were bringing their own AI tools to work, known as BYOAI or Bring Your Own AI.
Employees, on condition of anonymity, confirmed that artificial intelligence applications have become a key part of their daily tasks, noting that they use their personal accounts on these applications to speed up the pace of work, which saves them a lot of time and effort, and doubles their productivity.
They stated that the most prominent personal artificial intelligence tools they rely on have functions ranging from writing texts, summarising reports, programming, and generating presentations, in addition to analysing data, drafting contracts, and processing long and complex documents, as well as generating professional images, noting that the cost of paid subscriptions for these applications is low compared to their benefits, as their prices range between $10 (Dh36) and $20 (Dh72) per month.
According to a study conducted by KnowBe4 in the UAE and Saudi Arabia, and published by Business Wire last June, 41% of employees reported that they usually resort to acquiring self-operating artificial intelligence (Agentic AI) tools themselves in cases where official options are unavailable or restricted, which makes organisations vulnerable to cyberattacks.
More than half of cybersecurity leaders (54%) reported that mistakes made during day-to-day work had the greatest impact on their organisations’ cybersecurity over the past 12 months, while 44% of employees admitted that time pressures and distractions in the work environment actually push them to make serious security mistakes, even when they are aware of sound security protocols.
For its part, the Cyber Security Council of the UAE government warned against artificial intelligence tools that appear in search results, as not all of them are safe, and some of them aim to collect user data and information.
The Council stressed on the importance of using artificial intelligence tools only from trusted sources, not granting them access to the camera or other information, verifying the reliability of the site, and reviewing the permissions they request before approving them.
Spread of AI in workplaces
Corporate innovation consultant Ahmed Shahrouj said that the concept of shadow AI, or what can be called “artificial intelligence outside of governance,” is the use of artificial intelligence tools or applications by employees. Employees perform the work of the organisation without these tools being officially approved, or without their use being fully subject to the organisation’s controls related to data, privacy, security and risk management.
Shahrouj pointed out the danger of this type of use, as it often does not seem dangerous. The employee does not feel that he is sharing the organisation’s data with an external party. He simply wants to summarise a report, rephrase a letter, analyse an Excel file, review a contract, prepare a presentation, or extract recommendations from a long document.
But from a data governance perspective, copying information into a chat box or uploading a file to an external platform is ultimately a data sharing and processing operation, and this is where the challenge begins when employees get ahead of the organisation's policies.
He pointed out that the spread of artificial intelligence in workplaces is happening at a speed that is sometimes difficult for institutions to keep up with, and that indicators suggest that the use of artificial intelligence is no longer always an institutional decision that starts with the information technology department, but may start with the employee himself.
He said: “An employee discovers a new tool in the morning, creates a personal account, and hours later the tool becomes part of how he does his work. This is how shadow AI can be created before the organisation even knows it has shadow AI.”
Shahrouj pointed out that the risks are not limited to the data of clients, their names and personal numbers. The information that is entered may be a contract that has not yet been signed, a financial offer, supplier data, a feasibility study, an executive meeting record, an innovative idea that has not been recorded, a software code, or details about weaknesses in a system.
He continued: “Open-source AI is not synonymous with insecure AI. An organisation may use an open-source model and run it within its technical infrastructure and under its controls, so that the data remains within the corporate environment. In contrast, the risk may be greater when an employee uses a public online AI service or a personal account without sufficient knowledge of how the data is processed or stored or of the policies that govern its use. Therefore, the issue is not: Is the tool free or paid? Nor: Is the model open-source or closed? The most important issue is: Is this tool certified? Where does it process the data? What does the user allow to input into it? And who has the ability to monitor and manage this use?”
He noted that this issue is of particular importance in the UAE, not only because of the expansion in the use of artificial intelligence, but also because the country has already entered a more advanced stage in employing it in government work.
Shahrouj pointed out that when artificial intelligence reaches this level of integration with government operations, the governance of its use becomes an essential part of the success of the transformation itself. True foresight for the future does not mean just adopting the technology, but anticipating the new risks that arise with it. This is why the UAE government did not wait for artificial intelligence to reach this stage before it started thinking about governance.
Carefully planned solutions are necessary
In the face of the shadow AI phenomenon in workplaces, Shahrouj considered that the simplest solution might be to issue a circular saying: “The use of artificial intelligence tools is prohibited.” But it is not necessarily the best solution, as completely banning the technology may deprive the organisation of real opportunities to raise productivity, improve analysis, speed up reporting, develop services and support innovation. Worse still, banning without providing an alternative may push some uses to become more secretive in their use. Therefore, the innovative organisation does not fight artificial intelligence, but rather moves its use from unregulated individual effort to responsible institutional use.
He suggested that this could begin by creating what could be called an “AI Safe Zone,” which is not necessarily a single platform, but rather an institutional system that defines the approved tools, the accounts that should be used, the types of data that are allowed to be entered, what is prohibited from being shared, when the identity of the data should be hidden, how new tools are approved, and who is responsible for monitoring risks.
He pointed out that the organisation also needs a clear classification of information. Public data is not the same as internal data, and internal information is not the same as confidential or highly sensitive information. What is permissible to enter into one system does not necessarily mean that it is permissible to enter into any other system.
He continued: “This can be summarised by a simple question that any employee can ask themselves before pressing the send button: If there was someone from outside the organisation sitting on the other end, would I give them this document or this information? If the answer is no, then it makes sense not to enter it into a general, unapproved artificial intelligence tool either.”
Shahrouj pointed out that the danger may come from the most eager employees to achieve results. In other words, the paradox that we should not overlook is that the employee who may expose information to danger is not necessarily a negligent employee. On the contrary, the person may be one of the most eager employees to achieve results, innovate, and increase productivity. He found a tool that reduces his three hours of work to 10 minutes, so he used it. Here, the question should not be: Why did he use it? Rather: Why did we not provide him with a safe and approved way to use it? Here, the issue turns from an individual responsibility only, to an institutional responsibility.
Shahrouj stressed that AI governance is no longer solely the responsibility of IT or cybersecurity management, but now requires the involvement of data management, legal affairs, human resources, risk management, innovation, and executive leadership, because Shadow AI is not just a technical challenge; it is a challenge to corporate culture, behaviour, governance, and the design of the business itself.
Legal risks
For his part, legal advisor Dr. Ammar Ali warned of the legal risks of employees using artificial intelligence tools that are not approved or subject to institutional control.
He pointed out that the danger arises when an employee enters into his personal account contracts, customer data, financial reports, health files, or internal correspondence and meetings, believing that he is only “copying and pasting” information, while this may legally constitute processing or disclosing data to a party outside the corporate environment.
He explained that the UAE legislation has set a clear legal framework around these practices. Article (5) of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data stipulates that the processing of data must be legitimate and for a specific purpose, that the data must be limited to the extent necessary for that purpose, and that it must be kept securely and surrounded by measures that protect it from hacking or illegal or unauthorised processing. Article (7) also obliges the controller to take appropriate technical and organisational measures to protect the confidentiality and privacy of the data.
Therefore, uploading customer or employee data to an unapproved artificial intelligence platform may not only be an internal violation, but may also place the organisation in legal obligations related to data security, and even reporting its breach or violation of confidentiality when the conditions of Article (9) of the law are met. The law also permits imposing administrative penalties when it is proven that the controller or processor has violated its provisions.
Dr. Ali pointed to the law on combating rumours and cybercrimes. Article (45) of Federal Decree-Law No. 34 of 2021 criminalises the disclosure of confidential information obtained by a person due to his work, job, or profession, using one of the means of information technology, without authorisation, and stipulates a penalty of imprisonment for a period of not less than six months, and a fine of Dh200,000 to Dh1 million, or one of these two penalties, with the use of information to achieve a benefit for the perpetrator or for others being considered an aggravating circumstance.
He explained that introducing work secrets into an external artificial intelligence platform falls under this text whenever the elements and circumstances of the crime are present.
He pointed out that with regard to the employment relationship, Article 16 of Federal Decree-Law No. 33 of 2021 on Regulating Employment Relations obliges the worker to maintain the confidentiality of information and data that he accesses by virtue of his work, not to disclose work secrets, and not to personally keep paper or electronic copies related to work secrets without the employer’s permission.
Dr. Ali also pointed out that the matter may reach the point of termination of service without warning, as Article 44 permits this, after fulfilling the legal procedures, if the worker discloses a secret of work related to industrial or intellectual property, and this results in harm to the employer or loss of an opportunity or achievement of a personal benefit for the worker.
Dr. Ali stressed that the responsibility should not be placed entirely on the employee. Article 13 of the Labor Law obliges the employer to establish regulations governing work instructions, penalties, and other matters, which supports the need for a clear institutional policy for the use of artificial intelligence. The Data Protection Law also places on the institution, as the data controller when the description applies to it, the responsibility to take the necessary technical and organisational measures to protect it.
He stressed that the solution is not to prevent artificial intelligence, but to govern it, through approved tools, classification of information that is prohibited from being entered, controls for personal accounts, employee training, and human oversight of the outputs.
Rules and guidelines
In May 2024, the Cabinet adopted a comprehensive guide to the controls and guidelines for the use of generative artificial intelligence technologies in the UAE government, with the aim of unifying best practices for the ethical, responsible and safe use of artificial intelligence. The guide clearly addresses the governance of artificial intelligence applications, government data, training data, user rights and risk management.
Since 2023, the Telecommunications and Digital Government Regulatory Authority (TDRA) has also launched a unified central interface for generative AI services for government entities via the Federal Digital Network (FedNet). The interface provides an approved mechanism for government entities to obtain generative AI services, supports their use in accordance with national regulations and policies, and protects the interests of entities while dealing with these technologies.