May 6, 2026 · Scheman Building, Ames, IA

Shadow AI: When Everyone Becomes a Data Leak Waiting to Happen

Leadership and Workforce

TRACK Leadership and Workforce
FORMAT Expert Talk
ROOM 204-208

Shadow IT kept CIOs up at night for decades. Shadow AI rewrote the rules. The old threat required someone who knew how to code. The new one requires someone with a browser and a deadline. Data leaves your organization through thousands of well-meaning employees who have no idea they sent protected health information, trade secrets, or personnel records to a third-party model nobody evaluated.

In this session, cybersecurity leader Aaron Warner draws on patterns from mid-market healthcare, manufacturing, higher education, and financial services to reframe how you should think about AI adoption risk and opportunity.
You will explore:

  • Why Shadow AI spreads virally. A single useful prompt shared in Slack creates fifty unmonitored data leakage points overnight. Traditional Shadow IT never moved this fast.
  • The hidden regulatory exposure you are carrying right now. OpenAI’s privacy policy allows submitted content to train models unless users opt out. A federal court ordered indefinite retention of all ChatGPT logs as part of the New York Times lawsuit.
  • How vendors are compounding the problem without your knowledge. AI features show up inside HRIS, ERP, CRM, and email platforms with no security team involvement.
  • Why prohibition backfires every time. Locking down AI access guarantees workarounds with even less visibility, accelerating the exact risks you are trying to prevent.
  • A strategic framework for engagement over suppression. Practical approaches to policy, training, and compliant AI alternatives that let your organization capture productivity gains without sacrificing security or regulatory standing.

 

This session is for anyone responsible for deploying or supporting the deployment of AI, as well as business leaders looking to understand the new sources of risk from Shadow AI and how to take advantage of the technology without putting the firm at risk.

Key Takeaways

  • Shadow AI is already inside your organization. Unlike traditional Shadow IT, no technical skill is required. Shared prompts spread it across departments fast. Your exposure is almost certainly larger than you think.
  • Prohibition accelerates risk. Blanket bans push AI usage underground with zero visibility, creating more data leakage points, not fewer. Engagement-based policies paired with compliant alternatives are the only sustainable path forward.
  • The regulatory ground is shifting under you. Court-ordered data retention, evolving vendor privacy policies, and AI features silently embedded in your existing platforms mean yesterday's compliance posture is already outdated.
Continue the conversation with Aaron Warner at the Leadership & Workforce Facilitated Discussion — 3:10 PM - 3:55 PM, Room 220-230-240

Transcript from Summit:

Session Transcript