Transcript
A (0:00)
Welcome to the IA on AI podcast, part of the Audit Podcast network where we bring you weekly updates on AI from the internal auditor's perspective. Here we go.
B (0:11)
From natlawreview.com the AI oversight gap. IBM's 2025 data breach report reveals hidden costs of ungoverned AI. We also talked about this report from IBM last week.
A (0:26)
The article is linked in the show.
B (0:28)
Notes highly recommend going there checking out the report. So overall, from this cost of data breach report from IBN the IBM, they found that nearly all of the AI security incidents from. Damn it. They found that nearly all of these AI security incidents stemmed from unauthorized or unmanaged shadow AI tools.
A (0:52)
You might also have heard shadow AI referred to as bring your own AI or by bring your own O. BYO AI.
B (1:02)
We kind of gone back and forth.
A (1:03)
I feel like shadow AI is a little easier to say. We're gonna do a shadow AI audit. We're gonna do a BYO AI.
B (1:10)
Okay, we're gonna call it shadow AI from now on here.
A (1:13)
So anyway, it's from shadow AI. It's from folks that are using unauthorized unapproved AI tools.
B (1:21)
The article from NatLaw Review goes on to say that the most striking finding is that 97% of organizations experienced AI related security incidents lacked proper AI access controls. Access controls, that's like audit 101 stuff. While 63% of breached organizations had no governance policies for managing AI or detecting unauthorized use access controls and governance policies.
A (1:47)
That is like right up our alley at this point.
B (1:51)
I don't know what excuse you have.
A (1:53)
For not having an AI governance policy, an AI governance committee, and there's a bigger risk in not having those and saying no AI used in this organization.
B (2:05)
Because as you'll.
A (2:07)
You've seen here, I'm going to read another stat from another article here in a second.
