|
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
|
| Volume 187 - Issue 135 |
| Published: August 2026 |
| Authors: Tendai Nemure, Ruvimbo Mashinge, Bikadho Arafat, Maxwell Zambezi |
10.5120/ijcaac974b33a885
|
Tendai Nemure, Ruvimbo Mashinge, Bikadho Arafat, Maxwell Zambezi . The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS. International Journal of Computer Applications. 187, 135 (August 2026), 56-71. DOI=10.5120/ijcaac974b33a885
@article{ 10.5120/ijcaac974b33a885,
author = { Tendai Nemure,Ruvimbo Mashinge,Bikadho Arafat,Maxwell Zambezi },
title = { The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS },
journal = { International Journal of Computer Applications },
year = { 2026 },
volume = { 187 },
number = { 135 },
pages = { 56-71 },
doi = { 10.5120/ijcaac974b33a885 },
publisher = { Foundation of Computer Science (FCS), NY, USA }
}
%0 Journal Article
%D 2026
%A Tendai Nemure
%A Ruvimbo Mashinge
%A Bikadho Arafat
%A Maxwell Zambezi
%T The Shadow AI Dilemma: Redefining Insider Threats and Security Architectures in the Era of Unsanctioned LLMS%T
%J International Journal of Computer Applications
%V 187
%N 135
%P 56-71
%R 10.5120/ijcaac974b33a885
%I Foundation of Computer Science (FCS), NY, USA
The ubiquitous integration of generative artificial intelligence into enterprise workflows has precipitated a critical structural vulnerability: the proliferation of shadow AI. This phenomenon represents a fundamental evolution of the insider threat paradigm, transitioning from traditional malicious or negligent vectors to a novel "constructive-intent" threat model. In pursuit of operational efficiency, high-performing employees routinely bypass established security perimeters, inadvertently exposing proprietary data to third-party Large Language Models (LLMs). This unsanctioned usage introduces severe organizational risks, including intellectual property exfiltration, regulatory non-compliance, and susceptibility to adversarial prompt injection. To resolve the inherent tension between productivity enablement and data security, this paper introduces the Secure Enterprise LLM Sandbox—a semantically-aware Zero Trust architecture. By integrating an Intelligent Forward Proxy, a Contextual Data Loss Prevention (DLP) engine powered by Bidirectional Encoder Representations from Transformers (BERT), and privacy-preserving User and Entity Behavior Analytics (UEBA) utilizing Federated Learning, the proposed framework neutralizes exfiltration risks without degrading the user experience. Ultimately, this research provides a comprehensive socio-technical blueprint for governing AI integration, ensuring that enterprises can harness generative cognitive capabilities while maintaining absolute data sovereignty.