As we enter the AI era, business needs a combination of cultural change and strong controls to manage the potential risks of generative AI (GenAI). Unsanctioned GenAI usage presents a new manifestation of “shadow IT,”, as employees use unlicensed tools to jumpstart their endeavors or quicken monotonous tasks.
What IT leaders must do is create strong and clear governance that gives employees the confidence and enthusiasm to innovate with AI.
As Mary K. Pratt wrote on CIO.com: “Unauthorized AI is eating your corporate data, thanks to employees who are feeding legal documents, HR data, source code, and other sensitive corporate information into AI tools that IT hasn’t approved for use.”[1]
The danger isn’t simply that corporate data fed into these tools may surface in other places — though that’s a big enough concern. Shadow AI can also create compliance challenges, as regulated customer information is fed into unauthorized systems, based outside of geographic restrictions.
Users working without the appropriate skills and training may also be taking erroneous and poor-quality output and putting it into workflows where there may be serious consequences for the business.
What’s more, AI use brings further potential legal ramifications. As Willy Iglesias, CIO for New Zealand Clinical Research, wrote in a recent article for CIO.com: “Organizations leveraging AI tools like ChatGPT for customer service, employee support or decision-making could inadvertently expose sensitive data to legal discovery or government subpoenas.”[2]
Without the necessary governance frameworks, GenAI usage is a minefield.
Build out policies
Blocking GenAI isn’t the answer. Employees will find workarounds, and organizations may miss out on the technology’s transformative potential. Instead, businesses need clear processes and policies to monitor usage and manage risk, including an acceptable usage policy that clearly demonstrates what is allowed. Enterprises also need to provide effective AI usage training while ensuring employees are aware of its risks, including inadvertent data exfiltration and potential for reputational harm. Employees need to recognize that using AI safely requires significant cultural change managed through education and communication.
As Eva Zborowska, IDC Research Director, AI Europe, put it in a recent blog, “When people understand the reasoning behind restrictions, compliance rates soar. When they don’t, Shadow Everything thrives.”[3]
Beyond these safeguards, organizations also need to make deliberate choices about their infrastructure and how AI workloads run. In some cases, it can make more sense to keep specific AI tasks within the data center on hardware designed for AI. This could mean deploying AMD EPYC™ CPUs or AMD Instinct™ GPUs that deliver efficient performance for inferencing and scale across deep learning and training workloads. By running AI on optimized hardware in their own local environments, enterprises can gain greater control, performance consistency, and cost predictability, while ensuring their infrastructure is ready to support the next wave of AI innovation.
AI PCs may also contribute to the security solution. These systems are equipped with neural processing units (NPUs) to run artificial intelligence tasks efficiently. This can allow potentially sensitive AI workloads to run locally and securely on employee devices or enable hybrid configurations in which sensitive data remains on the device and is not transported elsewhere. Real-time guardrails, like those delivered by Styrk Portal, can use the NPU to filter AI prompts and responses automatically, protecting against malignant prompt injections and data leaks.
Such measures give businesses the scope to innovate, delivering AI-enhanced tools that are performant and support employee productivity, without relinquishing control of data to third parties or increasing legal or regulatory risks. What’s more, these devices can improve security elsewhere, leveraging emerging AI tools to detect anomalous behavior and battle malware, phishing, and other forms of cyberattack.
Combine these emerging AI tools with the enterprise-grade security and management features built into AMD Ryzen™ PRO processors, and AI PCs could actively support enterprises as they mitigate the risks of shadow AI and channel employees towards sanctioned tools and workflows.
The risks and requirements of proper AI adoption can be daunting, but it serves no one’s interests for the IT department to become the “department of no.” Appropriate hardware, services, and policies are critical to the long-term goal of delivering AI safely and effectively — and to reducing the allure of shadow AI.
Learn more about the power of AI PCs.
[1] CIO.com, 10 ways to prevent shadow AI disaster, July 2024, https://www.cio.com/article/2150142/10-ways-to-prevent-shadow-ai-disaster.html
[2] CIO.com, How safe is your AI conversation? What CIOs must know about privacy risks, August 2025, https://www.cio.com/article/4033630/how-safe-is-your-ai-conversation-what-cios-must-know-about-privacy-risks.html
[3] IDC Blog, Shadow AI: How stealth productivity is strangling enterprise AI adoption. And creating a security nightmare, July 2025, https://blog-idceurope.com/shadow-ai-how-stealth-productivity-is-strangling-enterprise-ai-adoption-and-creating-a-security-nightmare/
