Safety

Managing AI in the Workplace: Productivity Booster or Hidden Security Hazard?

At the AI Business conference, Kuti Anita of p2m Cégcsoport warned that many employees already use AI tools informally, creating 'Shadow AI' risks such as data leakage, hallucinations and algorithmic bias.

"AI is not knocking anymore; it is already sitting with us in the office." Kuti Anita, head of the Information Security division at p2m Cégcsoport, opened her talk at the AI Business conference with this observation. Her main point: while many organizations still discuss planning AI adoption at executive meetings, in practice a large share of employees likely already use some AI tools for daily tasks — often without approval or oversight.

Why Shadow AI emerges

According to Kuti Anita, the phenomenon stems from time pressure and the natural desire for efficiency. The entry barrier for AI is very low: a single registration can produce a presentation outline or a complex Excel formula. If a company does not provide legal and secure alternatives, employees will find their own ways, such as using public ChatGPT or image-generation services — a practice she labeled "Shadow AI."

The invisible hazards

Kuti emphasized three main areas where uncontrolled AI use can cause serious consequences:

  • Data leakage and protection of intellectual property: when internal documents (for example, strategic plans or client contracts) are pasted into public models, the information leaves the organization’s control. Because public models learn from inputs, those data could theoretically appear later in responses to other users.
  • "Hallucinations" and lack of verification: AI can be confidently wrong; sending a legal or technical analysis without expert review can cause business, reputational, or legal damage. AI is an assistant, not a responsible decision-maker.
  • Algorithmic bias: blindly trusting AI outputs (for example, in HR selection or credit scoring) without understanding the underlying data can lead to discriminatory or flawed decisions.

The recommended approach: three pillars

Kuti Anita stressed that banning AI is not a solution; the aim should be to curb Shadow AI by offering approved, transparent and secure alternatives. A responsible AI strategy rests on three pillars:

  1. Regulatory compliance: within the frameworks of the EU AI Act and the GDPR, organizations must determine the risk category of a given AI solution and their transparency obligations.
  2. Information security: prefer closed, enterprise-hosted or otherwise properly controlled models where it can be guaranteed that input data will not leave the organization unnecessarily.
  3. Business value creation: AI should be introduced where it produces measurable benefits; promising use cases include customer service automation, code generation, and document analysis.

Practical steps for secure rollout

The consultant noted that AI adoption is an organizational change-management project, not just an IT deployment. Recommended steps:

  • Inventory and classification: assess who is using what AI tools today and with which data; classifying data (public, internal, confidential) is the entry point for secure use.
  • Pilot and Proof of Concept (PoC): start small in a well-defined area, measure accuracy and security risks, and apply lessons learned before wide-scale rollout.
  • Continuous monitoring and human oversight: AI systems cannot be left unattended; apply a human-in-the-loop approach so that experts validate critical outputs.

Closing thought

Kuti Anita returned to the conference’s opening question: is AI a business accelerator or an information-security minefield? Her answer: it depends on organizations’ choices. Allowing Shadow AI to spread unchecked introduces invisible risks; directing AI use into controlled, well-designed frameworks can make AI one of the most powerful business accelerators. Control is therefore not an obstacle to progress but a prerequisite for safe and sustainable growth.