Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

Instead of blocking generative AI tools, Datadog's CISO proactively provided ChatGPT licenses to every employee. This approach avoids the 'all oops moment' of employees using unapproved tools with personal accounts, which creates shadow IT. By providing an official, governed solution with data retention controls, the company enables innovation while managing risk.

Related Insights

Esper established a clear policy for employees to pilot new AI tools. They can experiment without ingesting proprietary data, then submit promising tools to an IT and security-led committee that promises a quick decision. This approach balances fostering innovation with maintaining security.

The practice of banning generative AI tools within large companies has ended. The focus has shifted to controlled adoption, as the rapid pace of model improvement means restricting employees to a single platform is now a significant competitive disadvantage.

The Hugging Face incident reveals a critical internal security threat. The primary concern for CISOs is not just external attacks, but employees easily downloading tools to build powerful, unmonitored AI agents on company networks. The focus is shifting from blocking access to gaining visibility and control over these agents.

Instead of reacting to unsanctioned tool usage, forward-thinking organizations create formal AI councils. These cross-functional groups (risk, privacy, IT, business lines) establish a proactive process for dialogue and evaluation, addressing governance issues before tools become deeply embedded.

Similar to "Shadow IT," employees are using powerful, unmanaged AI agent tools without corporate oversight. These "shadow agents" can gain the same system access as a powerful employee but without any identity, limits, or oversight, creating a significant and often invisible risk for CISOs and CTOs.

Employees often use personal AI accounts ("secret AI") because they're unsure of company policy. The most effective way to combat this is a central document detailing approved tools, data policies, and access instructions. This "golden path" removes ambiguity and empowers safe, rapid experimentation.

Instead of punishing employees for using unapproved AI tools, leaders should view it as a critical signal. It's often the highest performers who do this, not out of malice, but because the company's sanctioned tools are inadequate. They are identifying gaps and potential solutions for the organization.

For companies given a broad "AI mandate," the most tactical and immediate starting point is to create a private, internalized version of a large language model like ChatGPT. This provides a quick win by enabling employees to leverage generative AI for productivity without exposing sensitive intellectual property or code to public models.

When companies don't provide sanctioned AI tools, employees turn to unsecured public versions like ChatGPT. This exposes proprietary data like sales playbooks, creating a significant security vulnerability and expanding the company's digital "attack surface."

Esper's executive team preemptively created a cross-functional AI policy, appointing a coordinator while mandating that each functional leader develop their own strategy. This prevented rogue AI use and ensured a cohesive, company-wide approach instead of isolated efforts.