AI for Government
Aware · M23 · lesson 23 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Approved vs. Shadow AI
📖
now learning

Approved vs. Shadow AI

10 min

Learning Objectives

After completing this lecture, you will be able to:

  • Understand the key concepts of approved vs. shadow ai in a government context
  • Connect approved vs. shadow ai to your agency's AI initiatives
  • Identify next steps for applying these concepts in your role

Key Topics Covered

  • Risks of using unapproved AI tools
  • Why personal AI accounts are dangerous for government work
  • The shadow AI epidemic

Why This Matters for Government

Government agencies face unique challenges when it comes to AI adoption. This lecture addresses these challenges head-on by providing all government employees with the knowledge and frameworks needed to navigate AI in the public sector responsibly and effectively.

As part of the L1 (AI Aware) curriculum, this lecture builds on the foundational principle that every AI system in government ultimately serves citizens. Whether you are working with AI tools daily or setting strategy for your agency, understanding approved vs. shadow ai is essential for responsible, effective government AI adoption.

Lecture URL: https://skill.re/learn/govt/approved-vs-shadow-ai.php

======================================================================

TRANSCRIPT: Approved vs. Shadow AI

======================================================================

What you will learn: Risks of using unapproved AI tools. Why personal AI accounts are dangerous for government work.

Here's a scenario: You need to use AI for a project. Your agency has approved tools, but you find them slow or limited. You remember ChatGPT or another tool you use personally. You think, "I'll just quickly test something in my personal account."

This is one of the most common ways government data gets exposed. It's how the bright red lines get crossed.

This lecture is about understanding the difference between approved and unapproved (shadow) AI tools, and why that difference matters.

WHY THIS MATTERS FOR GOVERNMENT

Shadow AI—unapproved tools used for work—creates risks:

  • Data exposure: Your agency's data ends up on servers you don't control
  • Compliance violations: You're violating policy and possibly law
  • Security weakness: Unapproved tools haven't been security-vetted
  • Liability: Your agency is liable if data is exposed

Understanding the distinction and following the rules protects you and your agency.

APPROVED VS. SHADOW AI

Approved AI Tools:

  • Vetted by your agency's IT and security teams
  • Security assessment completed
  • Configuration for government use
  • Audit logging enabled
  • Data handling policies in place
  • Support and liability clear
  • Terms of service compliant with government requirements
  • Updates and security patches managed

Shadow AI Tools:

  • No vetting by your agency
  • No security assessment
  • Default consumer configuration
  • May or may not have audit logging
  • Data handling unclear
  • Support and liability unclear
  • Terms of service may violate government policy
  • Updates and patches managed by vendor (might break your work)

Key Difference:

Approved tools: Your agency knows what's happening with your data.

Shadow tools: Your agency has no visibility into what's happening with your data.

RISKS OF SHADOW AI

Risk 1: Data Exposure to Foreign Entities

When you use a personal account on a cloud service, your data goes to that service's servers. Those servers might be in other countries. Foreign governments might have access.

You upload data containing information about government operations, citizens, or systems. That data is now outside government control.

Risk 2: Data Retention and Reuse

When you use a cloud AI service, the service retains your data for training and improvement purposes.

You uploaded a spreadsheet with PII "just for testing." The service retains it. Months later, it's part of a dataset sold to a data broker. It's used to train a model sold to another company.

Risk 3: Compliance Violations

You violate your agency's security policies by using unapproved tools.

You might violate regulations (GDPR, HIPAA, etc.) by moving regulated data to unapproved systems.

You might violate laws about how government data can be handled.

Risk 4: Lack of Audit Trail

Approved tools log who accessed what data and when. Shadow tools don't.

If something goes wrong, you can't prove what happened. You can't demonstrate proper handling of data.

Risk 5: Vulnerability to Attacks

Shadow tools might not have the security updates and protections of approved tools. They're more vulnerable to hacking.

Risk 6: Personal Liability

If data is exposed through your use of a shadow tool, you might be personally liable. Your agency might pursue disciplinary action against you.

ANTI-PATTERNS / MISUSE RISKS

Anti-Pattern 1: "Just This Once"

You need something done quickly. Your agency's approved tools are slow. You think, "I'll just quickly use my personal ChatGPT. Just this once."

Risk: "Just this once" becomes a habit. Soon you're regularly using shadow AI. Data is exposed.

Anti-Pattern 2: "It's Not Sensitive"

You use shadow AI with data you think isn't sensitive. "It's just aggregate statistics. No one will care."

Risk: The data is more sensitive than you realize. It's exposed. Consequences ensue.

Anti-Pattern 3: "Everyone Does It"

You notice colleagues using shadow AI. You think, "If they're doing it, it must be okay."

Risk: Just because others are breaking policy doesn't make it okay. You're still liable.

Anti-Pattern 4: Assuming the Service Is Safe

A major commercial AI service. They have security. It must be safe for government data.

Risk: No commercial service is configured for government data handling requirements. Even if the service is secure, its terms of service don't comply with government regulations.

PRACTICE / REFLECTION PROMPTS

  • Do you use any AI tools for work that aren't on your agency's approved list? If so, what data are you using? What are the risks?
  • If your agency doesn't have approved AI tools you need, what's the process for approving new tools?
  • What would you do if you were under time pressure and your agency's approved tools were too slow?

KEY TAKEAWAYS

  • Never use unapproved AI tools for government work, even "just to test something."
  • Personal accounts for work are never okay. Use official accounts on approved tools.
  • Shadow AI exposes data to uncontrolled entities. Your agency loses visibility into what happens to the data.
  • Compliance violations can result in discipline or termination.
  • If your agency doesn't have approved tools you need, request approval for new tools. Don't work around the system.
  • Approved tools might be slower or more limited, but they're secure. Speed is not worth data exposure.

TERMS / GLOSSARY ITEMS

Shadow AI: Unapproved AI tools used for government work, typically personal accounts on commercial services.

Audit Logging: Recording who accessed what data and when.

Compliance: Following regulations and policies.

Data Exposure: When data ends up where it shouldn't be, often accessible to unauthorized parties.

You're a policy analyst. You need to analyze 500 pages of regulations to identify key themes.

Your approved tool for this is your agency's AI system, but it's slow and has a usage queue. You're on deadline.

Wrong: Use ChatGPT with your personal account.

You copy the regulations into ChatGPT. It's fast. You get your analysis done quickly.

But your agency's regulations are now on OpenAI's servers. They're retained for training. Your agency has no audit trail. You've violated policy.

Right: Work with your approved tool or find alternatives.

  • Ask your agency if you can get priority access to the approved tool
  • Request expedited approval for a faster alternative
  • Do part of the analysis yourself and use the approved tool strategically
  • Ask your supervisor if the deadline can be extended

These options respect policy and protect your agency's data.

10 minutes.

Make a list of all the AI tools you've used in the past month (personal or work).

For each one, ask:

  • Is it on my agency's approved list?
  • Did I use it for government work?
  • What data did I share?
  • What are the risks?

For any tool not approved, commit to not using it for government work going forward.

Using approved tools might be slower or less convenient. But convenience is not worth data exposure and policy violation. Use approved tools. If you need new tools, request approval. Don't take shortcuts.

Government AI CLUB Certification Program

Level 1: AI Aware | How AI Changes the Threat Landscape | Lecture 4.3

A GOVT.CLUB initiative.

<- 1.4.3 Data Leakage: When Sensitive Info Enters AI 1.4.5 Prompt Injection and Manipulation ->

Start Your CLUB Certification

This lecture is part of L1: AI Aware—8 hours of comprehensive government AI training.

Explore CLUB Certification

L1 1.4.1—How AI Changes the Threat Landscape 10 min - Video

L1 1.4.2—Recognizing AI-Generated Threats 10 min - Video + Exercises

L1 1.4.3—Data Leakage: When Sensitive Info Enters AI 10 min - Video + Scenarios

Frequently Asked Questions

What will I learn in Approved vs. Shadow AI?

In this 10 min video + policy lecture, you will Risks of using unapproved AI tools. Why personal AI accounts are dangerous for government work. The shadow AI epidemic

What level is Approved vs. Shadow AI?

This is a Level 1 (AI Aware) lecture, part of Chapter 1.4 \u2014 Safety and Security. It is designed for all government employees.

How long is lecture 1.4.4?

Lecture 1.4.4 (Approved vs. Shadow AI) takes 10 min. It is delivered as a video + policy format.

Do I need prerequisites for Approved vs. Shadow AI?

This lecture is part of L1 (AI Aware). Prerequisites: None.

What is the CLUB Certification?

CLUB (Community Leading Unified Benchmarks) is a maturity-based AI certification for government professionals with 5 levels (L1-L5), 215 lectures, and 25 chapters aligned with NIST AI RMF, OMB, and GAO frameworks.