Tech Multiplier
Tech Multiplier is the podcast for smart business leaders who want to turn technology into a competitive advantage. Each episode explores how to use tech as a force multiplier—to accelerate growth, streamline operations, and protect what you’re building.
Join us as we break down the latest tools, trends, and strategies that help you lead with confidence and scale with intention. Whether you're looking to level up your tech stack or avoid common digital pitfalls, Tech Multiplier gives you actionable insights to multiply what matters—your impact, profits, and success.
Subscribe now and start turning tech into your growth engine. For resources and more, visit mytek.net.
Tech Multiplier
Why Your Star Employees May be Creating an AI Cybersecurity Risk (Without Even Realizing It)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What if the employees driving the most productivity in your organization are also creating one of your biggest security blind spots? In this episode, we explore the rise of Shadow AI—the unauthorized use of tools like ChatGPT, Gemini, and Claude in the workplace.
Learn why well-intentioned employees are turning to AI to work faster, the hidden risks this creates for sensitive business data, and how organizations can embrace AI innovation without sacrificing security, compliance, or control.
Learn more about MyTek, an Arizona-based Managed IT Services and IT Security firm: https://mytek.net/
So back in early 2023, um some of the absolute smartest engineers at Samsung were dealing with this highly sensitive semiconductor source code.
SPEAKER_01Right, highly proprietary stuff.
SPEAKER_00Exactly. And they were on a tight deadline, they wanted a quick fix. So uh they took that confidential code and just pasted it straight into Chat GPT.
SPEAKER_01Which is just wild when you think about it.
SPEAKER_00It really is. And within a matter of weeks, the company discovered three separate massive data leaks that originated directly from that chatbot. Wow. Yeah. I mean, Samsung has a cybersecurity budget that rivals the GDP of some small nations, right? Yet this massive security apparatus didn't even register a blip until the data was already out the door.
SPEAKER_01He was just gone.
SPEAKER_00Exactly. So today on the deep dive, we are looking at why your absolute most productive employees are uh currently your biggest security threat.
SPEAKER_01Yeah. And if a global tech titan with, you know, walls of monitors and dedicated threat hunting teams can get burned that badly, that should immediately terrify anyone listening to this who runs a typical business. I mean, picture an 18-person accounting firm in Tempe, Arizona, right? It's tax season. Everyone is buried in paperwork, and half the staff is secretly toggling over to their personal AI accounts just to survive the sheer volume of work.
SPEAKER_00Just to get through the day.
SPEAKER_01Right. And nobody approved it. Nobody in management has any visibility into it at all.
SPEAKER_00So we're taking you through this really fascinating article today. It's called The Invisible Threat: Managing Shadow AI in the Workplace by MyTech, which is an Arizona-based IT group.
SPEAKER_01Yeah, it's a great piece.
SPEAKER_00It really lays it all out. Our mission today is to understand this massive glaring blind spot sitting in offices all over the world. We are unpacking how our obsession with workplace efficiency is, well, actively dismantling corporate security from the inside out.
SPEAKER_01And the terminology we use to describe this is shadow AI.
SPEAKER_00Right.
SPEAKER_01It's when you have employees or even vendors running unauthorized artificial intelligence tools. They're feeding your proprietary data into systems that your IT department just they can't see it, they can't control it, and they can't audit it.
SPEAKER_00I want to pause on that term, actually, because you know, anyone listening who's been in business for a while is probably familiar with shadow IT.
SPEAKER_01Oh, yeah. The classic headache.
SPEAKER_00Exactly. That's been a problem for over a decade. You know, people downloading an unapproved PDF editor or maybe keeping a client list on a personal Dropbox account because they just don't like the company's clunky file server.
SPEAKER_01Right. Yeah, we've all seen that.
SPEAKER_00Aaron Powell So how is Shadow AI fundamentally any different from those shadow IT problems we've been dealing with since like 2010?
SPEAKER_01Aaron Powell Well what's fascinating here is that the mechanics of the threat are entirely different. I mean, shadow IT was basically a software storage problem. It was an unapproved application sitting on a hard drive, right? It was passive.
SPEAKER_00Okay, okay. Like an employee sneaking an unapproved coffee machine into the break room.
SPEAKER_01Aaron Powell Exactly. But Shadow AI is an active data extraction engine. It's fundamentally different. When you feed data into a public large language model or LLM, it isn't just dropping a file into a digital folder.
SPEAKER_00Wait, so what is it doing?
SPEAKER_01The AI actively ingests that data. It tokenizes it, and frequently it uses that data to train its future models.
SPEAKER_00So to build on that coffee machine analogy, shadow AI is like an employee taking your confidential file cabinets and just handing them over to a stranger on the street who promises to organize them at his house.
SPEAKER_01Aaron Powell That is exactly it, because it ceases to be a discrete file. The information gets baked into the neural network's actual parameters. Wow. Yeah. The system learns from your proprietary code or your client's financial data, and it adjusts its internal weights based on what you fed it. Trevor Burrus, Jr.
SPEAKER_00Meaning your company's intellectual property is now just part of the cognitive fabric of a public tool. Aaron Powell Right.
SPEAKER_01Sitting on external servers completely outside your control.
SPEAKER_00Trevor Burrus That brings up a terrifying stat I saw on here. There's this Cyberhaven AI adoption report from early 2026. They found that over 60% of AI use at work is running through personal accounts.
SPEAKER_01Over half.
SPEAKER_00Yeah, 60%. Not company-managed enterprise accounts that have like negotiated data protections. We're talking personal accounts signed up with a natus gmail.com address. And even more alarming, they found that 39.7% of all AI interactions involve sensitive data on systems the business cannot monitor. Trevor Burrus, Jr.
SPEAKER_01Nearly 40 percent. I mean, we are not talking about an employee asking a chatbot to write a polite rejection letter. Trevor Burrus, Jr.
SPEAKER_00Right. Or a generic meeting agenda.
SPEAKER_01Exactly. They are taking raw, unfiltered business data customer lists, financial spreadsheets, proprietary code, and just handing it over to a third-party black box.
SPEAKER_00Aaron Powell And it's not always just copy and pasting, is it?
SPEAKER_01Aaron Powell No, not at all. They're using unvetted browser extensions that can read literally everything on their screen, or they're hooking up unauthorized API keys to connect their personal AI workspace straight into their corporate email inbox.
SPEAKER_00Aaron Powell Okay, let's unpack the psychology of this because here's where it gets really interesting. This brings up the most counterintuitive part of the MyTech report, which is this paradox of good intentions. If nearly 40% of these interactions involve highly sensitive data, the knee-jerk assumption is that, well, these employees are careless or malicious or actively trying to sabotage the company, but the data shows the exact opposite.
SPEAKER_01Yeah, nobody wakes up, pours a cup of coffee, commutes to the office, and thinks, I'm gonna cause a massive data breach today. Right. The root cause of shadow AI isn't malice. It's the conflict between modern expectations of speed and traditional bureaucracy.
SPEAKER_00Aaron Powell Let me bring in this brilliant example from the source material about a bookkeeper. Imagine a bookkeeper at a mid-sized firm, okay, it's 1.45 p.m. They are sinking down a hard 2.00 p.m. deadline for a massive client presentation.
SPEAKER_01Oh, I've been there.
SPEAKER_00Right. And the spreadsheet of financial projections they were handed is completely mangled. The formatting is broken, columns are misaligned. Doing it manually would take like three hours.
SPEAKER_01Easily.
SPEAKER_00But they know for a fact that a public generative AI tool can clean up that data, write the macros, and perfectly format the sheet in about 30 seconds.
SPEAKER_0130 seconds versus three hours. And what are their alternatives? If they submit an IT ticket asking for a secure company approved tool, assuming they even have an IT team.
SPEAKER_00Right. Small businesses might just have one guy.
SPEAKER_01Exactly. That ticket has to be routed, reviewed for compliance, approved by a manager. That process takes three days, and the client needs the presentation in 15 minutes.
SPEAKER_00Isn't the real villain here the slow approval process then? Because the instinct to use AI in that moment is the exact same instinct that makes someone a great, highly productive employee.
SPEAKER_01Yes, exactly. They're taking initiative, they're refusing to miss a deadline.
SPEAKER_00So the raw client financials get dropped into the prompt, the spreadsheet gets fixed, the bookkeeper makes the meeting, the boss praises them for their efficiency, and boom, the company's proprietary data just quietly walked out the front door.
SPEAKER_01Into a public training set. Yeah, there's a Lair X security report that notes around 50% of employees actively admit to dropping sensitive business data into generative AI tools.
SPEAKER_00Half the office.
SPEAKER_01One out of every two people. And they're doing it because we've built a corporate culture that demands tenfold output, but we only give them sluggish, outdated tools. When you put a worker in a vice like that, they take the path of least resistance.
SPEAKER_00It fundamentally flips the definition of an insider threat on its head, doesn't it?
SPEAKER_01It really does.
SPEAKER_00Historically, the insider threat was the angry employee downloading blueprints to a thumb drive before quitting. Now, the insider threat is your employee of the month, who just wants to clear out their inbox faster so they can go to their kids' soccer game.
SPEAKER_01And that is a profound shift in corporate risk. The drive to be efficient is exactly what puts the data out of reach, which means we need to look at what actually happens when that data crosses the threshold.
SPEAKER_00Yeah, let's map that out. What is the real cost?
SPEAKER_01The MyTech report outlines three pillars of risk. The first one is the complete loss of chain of custody.
SPEAKER_00Loss of chain of custody. Okay, what does that look like?
SPEAKER_01The moment you hit enter on that prompt, the data is gone. You don't know where the servers are geographically, you don't know which engineers at the AI company have access to the chat logs. You don't know if your data is going to pop up in someone else's query three months from now.
SPEAKER_00The lack of a revoke button is terrifying. Yeah. It's almost like hitting reply all with a list of company passwords, but worse, because you don't even know whose inbox it landed in.
SPEAKER_01That's a great way to put it. Because with a traditional breach, say a hacker gets into an email server, your cybersecurity team can perform forensics. They look at the server logs, see what files were copied, and determine the exact blast radius. Aaron Powell Right.
SPEAKER_00They can lock it down.
SPEAKER_01Exactly. Force password resets, all of that. But with shadow AI, there is absolutely no forensic trail. There are no logs to pull because it happened on a personal account outside your network.
SPEAKER_00And because of how the AI ingests data, you can't just call up the tech company and demand they delete your specific file.
SPEAKER_01Aaron Powell Right. It's not sitting in a folder. I always say it's like pouring a cup of red dye into the ocean. You can't scoop that specific cup of colored water back out once it mixes with the currents.
SPEAKER_00Wow. Okay, so if the data is fundamentally unrecoverable, that leads straight into the second massive risk, which is compliance liability.
SPEAKER_01Oh, huge. Especially if we go back to that accounting firm in Tempe. You have heavily regulated industries in Arizona and everywhere, really medical practices, law firms, financial advisors.
SPEAKER_00Operating under strict legal frameworks. Right. IPA confidentiality agreements.
SPEAKER_01Exactly. So if an overworked paralegal feeds a client's confidential deposition into an unvetted tool for a quick summary, they aren't just breaking an office rule. They are potentially committing a federal violation.
SPEAKER_00And regulators do not care that it was an accident.
SPEAKER_01They absolutely do not. They don't care that the paralegal was trying to be efficient. A breach of protected health information is a breach. The fines, the mandatory disclosures, the loss of trust, it can bankrupt a firm overnight.
SPEAKER_00Okay, but how do you even defend against that? If the data is leaving through personal accounts, how are companies stopping this?
SPEAKER_01Well, they aren't. And that's the third risk. Defenselessness. IBM released a terrifying statistic. They found that only 17% of companies have any technical controls in place to stop employees from uploading confidential data to public AI.
SPEAKER_00Wait, really? 17%? That implies 83% of businesses are just running on hope and trust.
SPEAKER_01Hope is literally the prevailing security strategy for over four-fifths of the corporate world right now.
SPEAKER_00Aaron Powell But why? If we know this is a catastrophic threat, why is it so technically difficult to just block the connection?
SPEAKER_01If we connect this to the bigger picture, it's a giant game of whack-a-mole. If you block the main website for ChatGPT on the corporate firewall, the employee might just use a browser extension to bypass it. If you block the extensions, they'll log into some new AI tool you haven't even heard of yet. And if you force all laptops to use a strict VPN, the employee will just turn on their smartphone's 5G hotspot, tether the laptop to it, and bypass your entire network architecture.
SPEAKER_00So the defenselessness makes those first two risks exponentially more dangerous. You can't defend what you can't see.
SPEAKER_01Precisely. You can't contain a data leak when you don't even know the game is being played.
SPEAKER_00So what does this all mean? If you're a business owner facing unrecoverable data leaks and massive fines, the immediate knee-jerk reaction is to just ban everything, right? Just like Samsung did.
SPEAKER_01Right, draconian prohibition.
SPEAKER_00But the source material provides a totally different roadmap here. And it was modeled by a surprisingly forward-thinking entity, which is the local government in Arizona.
SPEAKER_01Yeah, it's rare to see a state government operating at the bleeding edge of tech agility, but their approach in early 2025 was fantastic.
SPEAKER_00So what did they do?
SPEAKER_01Well, under Governor Hobbes, they realized they couldn't just pretend AI didn't exist. They established a 19-person AI steering committee to write a playbook, and they partnered with an organization called Innovate US.
SPEAKER_00Right, to train the employees.
SPEAKER_01Exactly. Their strategy wasn't to block the tools, they made responsible AI use a prerequisite. State employees have to finish a specialized training course before they get access to generative AI.
SPEAKER_00They built guardrails instead of roadblocks.
SPEAKER_01Yes. The core philosophy they adopted, which MyTech strongly advocates for, is simple. Govern, don't ban.
SPEAKER_00Okay, wait, let me push back on that hard. Sure. You just spent the last 10 minutes explaining that these tools ingest proprietary data, that pouring this data into an LLM is like pouring dye into the ocean, and that one mistake triggers a massive IPA fine. Right. How do you actually convince a terrified business owner that giving employees a sanctioned version of that tool is safer than pulling the plug entirely? Why isn't a total zero tolerance ban the safest move?
SPEAKER_01Because a total ban is an illusion of security. This raises an important question. If you ban AI on the corporate network, do you actually stop your employees from using AI?
SPEAKER_00No, because they just tether to their phones.
SPEAKER_01Exactly. You don't stop the behavior. You simply force them to use it where you can't see them. You can't put the productivity genie back in the bottle.
SPEAKER_00So banning it just guarantees that you lose all visibility.
SPEAKER_01It pushes the problem completely underground. It takes a shadow threat and turns it pitch black. So you have to meet the employee where they are. Do you want your staff using AI in the light where you can guide them, or in the dark, where they're feeding financials into some unvetted app?
SPEAKER_00Okay. Behaviorally, that makes perfect sense. But technically, doesn't my data still get poured into the ocean if I let them use it?
SPEAKER_01Not if you provide the right tools. And this is the practical core of the MyTech playbook. You don't just say use whatever, you provide enterprise tier tools.
SPEAKER_00How is an enterprise-tier tool different from the free version I use at home?
SPEAKER_01Sandboxing and zero-day retention policies. When a business invests in a governed tool like Enterprise Chat GPT or a Microsoft Copilot, they operate under completely different terms of service.
SPEAKER_00Oh, I see.
SPEAKER_01Yeah. The AI provider guarantees that your company's prompts are not used to train the public model. The data is walled off, it processes the answer, and then it is immediately discarded. Your data never touches the ocean.
SPEAKER_00Aaron Powell So you're giving the employee that easy button they want, but replacing the engine with one that actually protects your data.
SPEAKER_01Exactly. You satisfy their need for speed and your need for security.
SPEAKER_00Let's run through the practical steps MyTech gives for this transition. Step one is basically just surfacing what's already happening.
SPEAKER_01Yeah, an honest, non-punitive inventory. You need network monitoring tools or an IT partner to see what AI apps are currently running. And you have to ask your team why they use them. What broken workflow is AI fixing?
SPEAKER_00And once you know that, step two is writing the policy. And I love their advice here. Keep it incredibly brief, a plain English, one-page acceptable use policy.
SPEAKER_01Not a 40-page legal document that gathers dust, just one page. What's sensitive data like social security numbers, source code, and what specific tools are approved?
SPEAKER_00Which leads right into providing those sanctioned tools. Put Copilot right on their desktop so they don't even need a workaround.
SPEAKER_01And the final step is setting up KPIs, key performance indicators, to monitor the usage. You need to make sure they are actually adopting the secure tools. If nobody logs in for a month, that's a red flag. They probably went back to their shadow accounts.
SPEAKER_00Right, because the secure tool was too clunky. The report also notes that most small businesses don't have an IT director to set all this up. So partnering with a managed service provider is crucial to handle the audits and deploy the sandbox tools.
SPEAKER_01Because shadow AI isn't a passing fad, the businesses that drag it out of the shadows and manage it today will thrive. The ones relying on hope and prohibition will end up in tomorrow's breach reports.
SPEAKER_00It really is wild to think about how much our perspective on security has to shift. We're so used to the medieval fortress model, thick walls keep the bad guys out. But today, the threat isn't a hacker storming the gates. It's a highly dedicated employee just trying to get their job done faster.
SPEAKER_01Which leaves us with a really fascinating and kind of uncomfortable implication to ponder on your own.
SPEAKER_00Oh, what's that?
SPEAKER_01If the root cause of Shadow AI is our desperate human desire to be incredibly fast and efficient at our jobs, how will the very definition of a hard worker have to change when doing things the slow manual way becomes the only truly secure option? If we keep rewarding speed above all else, aren't we just incentivizing the exact behavior that causes the breach?
SPEAKER_00Wow. The idea that our corporate obsession with productivity is fundamentally incompatible with data security. That is a heavy thought to leave you with today. Thank you so much for joining us on this deep dive into the hidden world of shadow AI, the paradox of the overachieving employee, and how to bring these tools into the light. Stay curious, stay secure, and we'll catch you on the next deep dive.