A county IT security team inventories AI tools that public-records staff are already using unofficially, then sorts each tool into approved, blocked, or under-evaluation categories. What organizational risk is this process primarily managing?
Select an answer to reveal the explanation.
Short Explanation
Staff finding a handy free AI tool and quietly pasting public records into it is the digital equivalent of someone bringing an unapproved filing cabinet into the office and nobody knowing what's in it. That's shadow AI, and an inventory is how you find those cabinets before something sensitive goes missing.
Full Explanation
Shadow AI refers to staff adopting AI tools on their own, outside any official procurement or governance review, often because the tool is free, convenient, or already familiar from personal use. The specific risk is that sensitive data, in this case public-records content, can flow into tools nobody vetted for security, data-retention, or legal compliance, with no oversight over what happens to that data afterward. Sorting tools into approved, blocked, and under-evaluation categories is precisely how an organization brings unofficial usage back under visible governance rather than pretending it isn't happening. Model drift describes accuracy decay in a tool already formally deployed and monitored, which is a different problem from staff quietly adopting unvetted tools in the first place. Vendor lock-in concerns dependency on one supplier after a deliberate procurement choice, not the unmanaged sprawl of tools staff picked themselves. Algorithmic bias concerns unfair outcomes from an approved system's predictions, which presumes the tool is already known and evaluated, unlike shadow AI, where the tool may not even be on anyone's radar yet. As a concrete check, the security team should confirm whether any inventoried tool's terms of service allow the vendor to retain or train on uploaded records data, since that's often the exact exposure an unofficial tool creates.