You have an AI policy, but shadow AI is everywhere

Cybersecurity
 |  
Sep 2026
 |  
RH-ISAC
Save to favorites
Your item is now saved. It can take a few minutes to sync into your saved list.

What: Despite AI policies being nearly universal among retail and hospitality organizations, unsanctioned "shadow AI" use persists because approval processes move too slowly for employees' actual work needs.

Why it is important: Retail and hospitality employees routinely handle sensitive customer, loyalty, and guest data, making them especially exposed when that data is pasted into unreviewed consumer AI tools with unclear training and retention practices.

A joint RH-ISAC/IANS survey of 201 retail and hospitality CISOs found AI-related data exposure now outranks ransomware and phishing as their top concern. Three out of four cited company data leaving through public AI tools as their principal fear. Yet only 3% of surveyed organizations had no AI policy at all, and four in five had some governance framework in place — the policies exist, but shadow AI is happening anyway.

The article identifies three recurring patterns: employees pasting company data into personal AI accounts, AI features embedded inside already-approved vendor tools, and internal data teams experimenting directly with production datasets, including customer records and loyalty profiles. Traditional DLP and CASB tools largely miss this traffic, since prompts are retyped rather than copied and consumer AI services often have no OAuth footprint to detect.

Beyond security, the exposure carries compliance weight: unreviewed AI use can leave PCI DSS scope documentation and privacy disclosures (e.g. CCPA) inaccurate, and introduces unassessed third-party risk.

IADS Notes: Similar warnings have circulated in recent months. RH-ISAC, August 2026 argued that AI agents executing refunds, loyalty adjustments and access changes need clear ownership and auditability rather than technical guardrails alone. BCG's CISO survey, August 2026 found that nearly nine in ten organizations already report AI-enabled attacks, while most have adopted only minimal AI-specific security controls — pointing to a broader gap between AI-driven risk and organizational readiness. Journal du Net, June 2026 made a related point in a procurement context, noting that AI increases operational risk in the absence of governance frameworks and reliable, centralized data — reinforcing that the core issue across use cases is accountability and oversight rather than the technology itself.

You have an AI policy, but shadow AI is everywhere