AI 中文总结
针对员工使用个人账户的非托管自带AI(BYOAI)问题,开发含五级成熟度阶梯、技术/治理/人力三支柱的参数化治理模型,发现分层控制方案可大幅降低数据泄露风险。
AI 中文摘要
员工越来越多地使用个人拥有的生成式AI工具,如ChatGPT、Gemini和Claude来完成日常工作,这种实践被称为自带AI(Bring Your Own AI,BYOAI),它是影子AI(Shadow AI)的一种独特形式,其中使用员工认证的个人账户,不受企业身份和安全控制的约束。现有的框架是为组织管理的AI工具设计的,其覆盖范围不延伸到使用个人账户的非托管AI工具。为解决这些问题,我们通过系统的文献综述开发了一种治理模型,该模型生成了风险分类法和框架参与概况。我们还开发了一种参数化治理模型,用于衡量某一治理成熟度水平降低残余风险的程度。一个五级成熟度阶梯通过一个链与技术控制架构相结合,其中控制层的覆盖范围影响安全结果。我们对包含30条记录(24项研究和6份框架文档)的精选语料库的研究表明,确定的最突出类别是数据暴露和合规性,且框架参与不一致。我们建立了三个相互支撑的支柱(技术、治理和人力)来支持防护措施。此外,模型结果表明,基于禁止的解决方案将产生接近基线解决方案实现的残余风险水平。在指定的参数化下,基于分层控制的解决方案大幅降低了建模的数据泄露风险,并增加了可执行的覆盖范围。
英文摘要
Employees are increasingly using personally owned generative AI tools such as ChatGPT, Gemini, and Claude for their daily work. This practice is known as Bring Your Own AI (BYOAI), which is a distinct form of Shadow AI in which employee-authenticated personal accounts are used outside of enterprise identity and security controls. Existing frameworks were designed for AI tools managed by organizations, and their coverage does not extend to unmanaged AI tools used with a personal account. In addressing these issues, we developed a governance model through a systematic review of the literature that produces a risk taxonomy and a framework-engagement profile. We also developed a parameterized governance model that measures how much a level of governance maturity reduces residual risk. A five-level maturity ladder is coupled to a technical control architecture through a chain in which the coverage of the control layer influences the security outcomes. Our study of a curated corpus of 30 records (24 research studies and 6 framework documents) indicated that the most prominent categories identified were data exposure and compliance, and framework engagement was inconsistent. Three mutually supporting pillars (technical, governance, and human) were established to support safeguards. Additionally, the results of the model demonstrated that prohibition-based solutions will result in residual risk levels close to those achieved through baseline solutions. Under the specified parameterization, layered control-based solutions substantially reduce modeled exfiltration risk and increase enforceable coverage.
Comments8 pages, 3 figures, 5 tables