Some organizations, concerned about exposing sensitive information to AI services like ChatGPT, opt to block them entirely on corporate networks, though this knee-jerk reaction proves ineffective. Employees can still access such services through personal devices.
Other businesses attempt to tailor AI security and governance strategies based on regulatory requirements, but with limited global regulatory guidance on AI, this often leads to chaotic and evolving governance policies that may not align with future mandates. It’s evident that enterprises must establish and enforce clear security and governance policies for AI services deployed internally, as these services can potentially access highly sensitive enterprise data, posing significant implications for data privacy and security.