31204762065?profile=RESIZE_400xAs generative AI spreads through daily workflows, organizations are being urged to address employee behavior, not just technical safeguards.  Organizations racing to adopt artificial intelligence are facing a growing challenge that cannot be solved by technical controls alone: the everyday choices employees make when using AI tools. Security leaders say the next phase of AI risk management will depend on building a stronger culture of AI security across the workforce.[1]

That shift comes as workers increasingly turn to free or easily accessible AI systems to draft documents, summarize information, analyze data, and speed up routine tasks. While those tools can improve productivity, they also introduce risks when employees upload sensitive information, rely on unverified outputs, or use unapproved platforms outside company oversight.

A New Risk Landscape - Traditional AI risk frameworks often focus on technical failures, systemic threats, model performance, or regulatory compliance.  But the rapid spread of consumer-grade AI tools has created a more complicated problem: individual users can now introduce risk quickly, often without malicious intent and without security teams knowing.

These adopter-driven risks span several categories, including governance and accountability, privacy and data protection, reliability and performance, human and societal impact, security and safety, and ethics and fairness. Sentiment analysis of security leaders cited in the source material found governance and accountability to be the leading concern, followed by privacy and data risks.

The problem is commonly described as “shadow AI,” a term for the use of artificial intelligence tools outside formal approval, monitoring, or governance processes.  Recent security research has warned that shadow AI can expose sensitive data, expand attack surfaces, and leave organizations with limited visibility into how AI is being used across business functions.

From Compliance to Daily Behavior - Experts argue that organizations need to define the specific behaviors they want employees to practice.  In-role behaviors include the habits embedded in daily work, such as verifying AI-generated output before using it, following clear rules for data classification, and understanding where information goes when it is entered into an AI system.

Extra-role behaviors go a step further.  They include employees educating themselves about safe AI use, sharing best practices with colleagues, reporting suspected vulnerabilities, and speaking up when they notice risky AI activity.  Security leaders say those actions can raise the baseline for an entire team.

To reduce shadow AI, leaders are encouraged to route employees toward approved tools and create a “speak-up” culture that allows accidental exposures or concerns to be reported without fear of punishment.  The goal is to make the secure path easier than the risky one.

Security as a Shared Responsibility - Building an AI security culture requires more than publishing a policy.  The source outline emphasizes a collective mindset in which security is not viewed as the sole responsibility of the information security team.  Instead, every employee who uses AI has a role in protecting company data, intellectual property, customers, and decision-making processes.

That approach also requires a change in how security teams communicate.  Rather than relying only on rigid compliance mandates, organizations are being urged to adopt “security marketing” techniques: targeted micro-campaigns, storytelling, practical examples, and non-punitive events that make secure AI use feel relevant to everyday work.

Security teams can also build trust by positioning themselves as gateways to innovation rather than blockers.  The preferred message, according to the outline, is “guardrails, not handcuffs”: employees should feel that security teams are helping them use AI safely, not preventing them from using it at all.

Five Actions for Leaders - The outline identifies five mechanisms that leaders can use to accelerate cultural change.  First, leaders should model the behaviors they expect by visibly practicing secure AI use and discussing how they evaluate AI-generated work.  Second, they should recognize positive behavior through simple incentives such as digital badges or peer recognition.

Third, organizations can launch AI ambassador programs that train local champions inside business units.  These ambassadors can translate security guidance into the language and workflows of their teams, making safe practices more practical and easier to adopt.

Fourth, secure AI practices can be embedded into expectations, objectives, and performance reviews.  That may include responsible tool use, output verification, completion of relevant certifications, and adherence to approved data-handling processes.

Finally, organizations can establish AI Centers of Excellence to create “paved roads” for adoption.  These centers can offer fast vetting of tools, approved testing environments, and low-friction reporting channels that allow employees to raise concerns without blame.

Measuring Cultural Change - Security leaders caution that culture change is gradual and must be measured over time.  Useful leading indicators include adoption of approved AI tools, voluntary reports of near misses, employee sentiment surveys, and participation in ambassador or training programs.  Lagging indicators may include AI-related security incidents, audit findings, and evidence of shadow AI activity.

An early increase in voluntary reporting should not necessarily be treated as a sign of failure.  Instead, it may indicate that employees trust the process and believe they can disclose mistakes or concerns without being punished.  That kind of “just culture” can help organizations detect problems earlier and respond more effectively.

Organizations are also being warned against relying on vanity metrics such as training completion or policy acknowledgment rates.  The stronger test is whether employees demonstrate durable, unprompted behavior change when AI tools are part of their daily work.

As AI becomes more deeply embedded in business operations, the article’s central message is clear: the organizations best positioned to manage AI risk will be those that combine governance, technical safeguards, and a workforce culture that treats secure AI use as everyone’s responsibility.

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

[1] https://www.aiuc-1.com/consortium

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!