Transcript
I want to talk about a topic today that should be top of mind for all organizations that worry about data security in conjunction with AI in particular. AI usage is something that's skyrocketing within our corporations and companies, simply because it's very attractive to users. It's also attractive to companies because it has several benefits, productivity gains, process improvements, et cetera, et cetera. Some considerations that are very important when thinking about AI within a given company are obviously, well, what AI is in use within my organization, right? In order to be able to understand what's going on, I need to get insights into what is being used. Also, something that's quite interesting and quite important next to the what question would be, who is using AI within my company? And this is not necessarily down to the individual person, while also interesting under certain situations, but this is also which department, right? Who is using that? What is the department in my company, the group of people that uses AI, so it can start finding out what's the purpose? Which is the next question? What is the purpose of AI usage by those groups and users within my organization? What are they using it for? Why are they using it? Is there a business need? Are they just checking the weather condition in the city that they want to go to vacation? And then the last one, what can I do to create an AI friendly environment? I do not only want to block, I want to allow, but I want to be in charge and I want to control. Those are key elements that I need to think about. And there's a lot more, right? But those are just some to think about. Now, let's think a bit about why there is a risk of using AI when it comes to data. We have the AI services listed here. And on the other side, we do have our workforce, the employees, the people working in my company, everybody. What are they using AI for? That's something that we should consider. This could be, for example, content creation purposes. I'm acquiring a different company. I will ask AI to write a press announcement about the acquisition. Worst case, this goes out prior to me making the acquisition. So I feed AI with confidential information, which, worst case, can be used to train the LLM. But last, I don't want it to leak prior to being okay. What about, for example, when I'm an organization with development? There's nothing easier in AI to say, well, can you please verify my source code, right? Check my source code. I made this invention. I don't know how it is functioning or if I developed it correctly. Please check it for me. And there are other ways where sensitive data can be sent to AI. Think about financial analysis, pipeline analysis, those kind of things. So all of those are reasons why we use AI to become more productive. And this is not by bad intent. Our workforce uses AI to get the job done more efficiently, to relieve them from tasks, from duties. Can't blame them for that. Still, we need to make sure that we safeguard the information and the usage of AI. So that said, there are several capabilities, from which we already discussed some in one of my previous videos, where we could apply certain effective countermeasures. One of them is, obviously, I need to apply access control. I need to make sure that I understand which AI is used and which I want to allow to be used, right? I need to control where my employees can go. Access control is a key element. The next one would be AI-friendly, and I want to allow people to go there. What do you do? Well, you can't just allow them to go to everything, but you want to make sure they access that very safely. So isolation is a key method. This is where you can allow, in an AI-friendly environment, where you allow a lot of access, but you are in control. You are still in charge by making sure that the access is only through the isolated browser. This allows you to type in, but you can't copy, you can't paste, only if it is your corporate application. There are other controls. We also can apply a DLP policy, for example, to make sure that non-sensitive data is sent and sensitive data can't be sent. Those are all things where we can make sure that, again, our workforce can use AI in a secure and effective way while making sure that sensitive data is blocked at the barrier of our technology set. Only when the data is non-sensitive, when the data checks out, when somebody is copy and pasting information that is non-sensitive, only when the technology stack decides the data is okay, the data can be sent to the AI services or to the AI services that are allowed, better said. We've seen several other questions before when we discussed those question marks, who, what, where, how, and that is where our GNI security report, our governance tool, comes into play. A dedicated tool that tells you, well, how many applications are in use. In my case, well, I've only got five applications. Think about this being in the thousands. The amount of data being sent, the files, sensitive files being sent, etc. I see the evolution or the usage of top applications in conjunction with several metrics. Those could be transactions, those could be bytes, etc. I see the evolution over time. Let me tell you an interesting story that I had with a customer at one point in time. We saw the spike of an application, of an AI application growing up over time. It was intense. We saw it starting and then going crazy. It turned out, very interestingly, that this was one employee who discovered an AI assistant application for writing content. He told his colleagues they liked it. It went through the roof. It became the number one application within the company. And that is also when we want to consider, for example, down here, the departments that would use AI. This is the who. Which department uses that? Maybe it helps me to pinpoint where this comes from. I can go to those people, ask them what they need it for. We also see, very importantly, the sensitive data analysis if we apply DLP to that traffic. And also, we have abilities to automatically classify information that's being sent using AI ourselves. And last, we also would see the user. The individual who are using AI sufficiently. One thing that's very important, this solution also gives you the ability, based on a setting, you need to enable it, to capture the prompt information. Capturing the prompt information in conjunction with knowing who it came from enables you, as company, to analyze the purpose. What are users using AI for? What is their intent? Is it business relevant? Is it personal? So, you can make educated decisions about allowing, acquiring AI tools, or preventing access in general. So, a dedicated solution for governing access to public AI, solving a multitude of questions, allowing you to do DLP, allowing you to look at the prompts, collect the prompts, analyze the prompts, and show you the evolution of AI within your company. And, as we introduced in one of my previous videos, using, for example, our Cloud App Control feature to provide isolated access to applications, or block them entirely, or the ones that you prefer as company, you can allow them.