Research Article

The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS

by  Tendai Nemure, Ruvimbo Mashinge, Bikadho Arafat, Maxwell Zambezi
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 135
Published: August 2026
Authors: Tendai Nemure, Ruvimbo Mashinge, Bikadho Arafat, Maxwell Zambezi
10.5120/ijcaac974b33a885
PDF

Tendai Nemure, Ruvimbo Mashinge, Bikadho Arafat, Maxwell Zambezi . The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS. International Journal of Computer Applications. 187, 135 (August 2026), 56-71. DOI=10.5120/ijcaac974b33a885

                        @article{ 10.5120/ijcaac974b33a885,
                        author  = { Tendai Nemure,Ruvimbo Mashinge,Bikadho Arafat,Maxwell Zambezi },
                        title   = { The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 135 },
                        pages   = { 56-71 },
                        doi     = { 10.5120/ijcaac974b33a885 },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Tendai Nemure
                        %A Ruvimbo Mashinge
                        %A Bikadho Arafat
                        %A Maxwell Zambezi
                        %T The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 135
                        %P 56-71
                        %R 10.5120/ijcaac974b33a885
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

The ubiquitous integration of generative artificial intelligence into enterprise workflows has precipitated a critical structural vulnerability: the proliferation of shadow AI. This phenomenon represents a fundamental evolution of the insider threat paradigm, transitioning from traditional malicious or negligent vectors to a novel "constructive-intent" threat model. In pursuit of operational efficiency, high-performing employees routinely bypass established security perimeters, inadvertently exposing proprietary data to third-party Large Language Models (LLMs). This unsanctioned usage introduces severe organizational risks, including intellectual property exfiltration, regulatory non-compliance, and susceptibility to adversarial prompt injection. To resolve the inherent tension between productivity enablement and data security, this paper introduces the Secure Enterprise LLM Sandbox—a semantically-aware Zero Trust architecture. By integrating an Intelligent Forward Proxy, a Contextual Data Loss Prevention (DLP) engine powered by Bidirectional Encoder Representations from Transformers (BERT), and privacy-preserving User and Entity Behavior Analytics (UEBA) utilizing Federated Learning, the proposed framework neutralizes exfiltration risks without degrading the user experience. Ultimately, this research provides a comprehensive socio-technical blueprint for governing AI integration, ensuring that enterprises can harness generative cognitive capabilities while maintaining absolute data sovereignty.

References
  • Brynjolfsson, Erik, Danielle Li, and Lindsey Raymond. 2025. "Generative AI at Work." The Quarterly Journal of Economics 140, no. 2 (April): 889–942. doi:10.1093/qje/qjae044.
  • Silic, Mario, Dario Silic, and Klaus Kind‐Trüller. 2025. "From Shadow IT to Shadow AI–Threats, Risks and Opportunities for Organizations." Strategic Change (June). doi:10.1002/jsc.2682.
  • Yao, Yuanshun, Jiazhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, and Yue Zhang. 2024. "A Survey on Large Language Model (LLM) Security and Privacy: The Good, The Bad, and The Ugly." High-Confidence Computing 4, no. 2 (June): 100211. doi:10.1016/j.hcc.2024.100211.
  • Mark, Gurman. 2023. "Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak." Bloomberg. Accessed April 23, 2026. https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak.
  • Carlini, Nicholas, et al. 2020. "Extracting Training Data from Large Language Models." In USENIX Security Symposium. https://api.semanticscholar.org/CorpusID:229156229.
  • Software Engineering Institute. 2026. "Common Sense Guide to Mitigating Insider Threats, Seventh Edition." Carnegie Mellon University. Accessed April 23, 2026. https://www.sei.cmu.edu/library/common-sense-guide-to-mitigating-insider-threats-seventh-edition/.
  • Alzaabi, F. R., and A. Mehmood. 2024. "A Review of Recent Advances, Challenges, and Opportunities in Malicious Insider Threat Detection Using Machine Learning Methods." IEEE Access 12: 30907–27. doi:10.1109/ACCESS.2024.3369906.
  • National Institute of Standards and Technology (NIST). 2020. "Security and Privacy Controls for Information Systems and Organizations." SP 800-53r5. Gaithersburg, MD. doi:10.6028/NIST.SP.800-53r5.
  • Diro, Abebe, S. Kaisar, A. Saini, S. Fatima, P. C. Hiep, and F. Erba. 2025. "Workplace Security and Privacy Implications in the GenAI Age: A Survey." Journal of Information Security and Applications 89 (March): 103960. doi:10.1016/j.jisa.2024.103960.
  • European Parliament & Council. 2016. "Regulation (EU) 2016/679 of the European Parliament and of the Council." Official Journal of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679.
  • OWASP. 2024. "OWASP Top 10 for LLM & Generative AI Security." LLM Risks Archive. https://genai.owasp.org/llm-top-10/.
  • Gulyamov, Said, et al. 2026. "Prompt Injection Attacks in Large Language Models and AI Agent Systems: A Comprehensive Review of Vulnerabilities, Attack Vectors, and Defense Mechanisms." Information 17, no. 1 (January): 54. doi:10.3390/info17010054.
  • MITRE Corporation. 2026. "MITRE Adversarial Threat Landscape for Artificial-Intelligence Systems." Accessed April 24, 2026. https://oecd.ai/en/catalogue/tools/atlas-adversarial-threat-landscape-for-artificial-intelligence-systems.
  • Rose, Scott, Oliver Borchert, Stu Mitchell, and Sean Connelly. 2020. "Zero Trust Architecture." NIST SP 800-207. Gaithersburg, MD. doi:10.6028/NIST.SP.800-207.
  • Hevner, Alan, et al. 2004. "Design Science in Information Systems Research." MIS Quarterly 28, no. 1: 75–105.
  • Peffers, Ken, Tuure Tuunanen, Marcus Rothenberger, and Samir Chatterjee. 2007. "A Design Science Research Methodology for Information Systems Research." Journal of Management Information Systems 24, no. 3: 45–77.
  • Shostack, Adam. 2014. Threat Modeling: Designing for Security. Wiley. https://books.google.com.ng/books?id=asPDAgAAQBAJ.
  • ISO. 2023. "ISO/IEC 42001:2023 - AI Management Systems." International Organization for Standardization. Accessed April 24, 2026. https://www.iso.org/standard/42001.
  • Hardt, Dick. 2012. "The OAuth 2.0 Authorization Framework." Internet Engineering Task Force. RFC 6749. https://ia801604.us.archive.org/24/items/rfc6749/rfc6749.txt.pdf.
  • Devlin, Jacob, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. "BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding." May. http://arxiv.org/abs/1810.04805.
  • Feng, Zhangyin, et al. 2020. "CodeBERT: A Pre-Trained Model for Programming and Natural Languages." September. http://arxiv.org/abs/2002.08155.
  • Hinton, Geoffrey, Oriol Vinyals, and Jeffrey Dean. 2015. "Distilling the Knowledge in a Neural Network." March. http://arxiv.org/abs/1503.02531.
  • Liu, Zhenhua, Yunhe Wang, Kai Han, Siwei Ma, and Wen Gao. 2021. "Post-Training Quantization for Vision Transformer." June. http://arxiv.org/abs/2106.14156.
  • Greshake, Kai, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz. 2023. "Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection." May. http://arxiv.org/abs/2302.12173.
  • Zou, Andy, Zifan Wang, Nicholas Carlini, Milad Nasr, J. Zico Kolter, and Matt Fredrikson. 2023. "Universal and Transferable Adversarial Attacks on Aligned Language Models." December. http://arxiv.org/abs/2307.15043.
  • Zheng, Lianmin, et al. 2023. "Judging LLM-as-a-Judge with MT-Bench and Chatbot Arena." December. http://arxiv.org/abs/2306.05685.
  • Bai, Yuntao, et al. 2022. "Constitutional AI: Harmlessness from AI Feedback." arXiv:2212.08073.
  • Vaswani, Ashish, et al. 2017. "Attention Is All You Need." In Proceedings of the 31st International Conference on Neural Information Processing Systems (NIPS’17), 6000–6010. Red Hook, NY: Curran Associates Inc.
  • Kairouz, Peter, et al. 2021. "Advances and Open Problems in Federated Learning." March. http://arxiv.org/abs/1912.04977.
  • McMahan, H. Brendan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Agüera y Arcas. 2023. "Communication-Efficient Learning of Deep Networks from Decentralized Data." January. http://arxiv.org/abs/1602.05629.
  • Abadi, Martin, et al. 2016. "Deep Learning with Differential Privacy." October. doi:10.1145/2976749.2978318.
  • Tabassi, Elham. 2023. "Artificial Intelligence Risk Management Framework (AI RMF 1.0)." NIST. doi:10.6028/NIST.AI.100-1.
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

Shadow AI Insider Threat Taxonomy Generative AI Security Zero Trust Architecture Contextual Data Loss Prevention Federated Learning Enterprise Risk Management

Powered by PhDFocusTM