AAISM · Question #107
An organization has discovered that employees have started regularly utilizing open-source generative AI without formal guidance. Which of the following should be the CISO's GREATEST concern?
The correct answer is C. Data leakage. The greatest immediate risk from unsanctioned use of public or open-source generative AI tools is data leakage--employees may paste confidential or regulated information into third-party systems, resulting in loss of confidentiality, regulatory exposure, and loss of…
Question
An organization has discovered that employees have started regularly utilizing open-source generative AI without formal guidance. Which of the following should be the CISO's GREATEST concern?
Options
- ALack of monitoring
- BPolicy violations
- CData leakage
- DModel hallucinations
How the community answered
(38 responses)- A5% (2)
- B21% (8)
- C61% (23)
- D13% (5)
Explanation
The greatest immediate risk from unsanctioned use of public or open-source generative AI tools is data leakage--employees may paste confidential or regulated information into third-party systems, resulting in loss of confidentiality, regulatory exposure, and loss of intellectual property. AAISM emphasizes that when AI use occurs outside approved channels, the top control priority is preventing exfiltration of sensitive data via prompts, attachments, and context sharing. Monitoring and policy are necessary enablers, but leakage is the highest-impact failure mode in the short term; hallucinations primarily affect accuracy, not confidentiality.
Topics
Community Discussion
No community discussion yet for this question.