<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on Carles Abarca</title><link>https://carlesabarca.com/tags/security/</link><description>Recent content in Security on Carles Abarca</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Carles Abarca</copyright><lastBuildDate>Sat, 11 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://carlesabarca.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Bring Your Own AI: When Individual Productivity Becomes Organizational Risk</title><link>https://carlesabarca.com/posts/bring-your-own-ai/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://carlesabarca.com/posts/bring-your-own-ai/</guid><description>BYOAI is not only a security threat. It is a signal that employees are already finding value in AI faster than organizations are designing ways to govern it.</description><content:encoded>&lt;p&gt;&lt;em&gt;The question is no longer whether employees will use artificial intelligence at work. They already are. The real question is whether the organization wants to govern that energy or allow it to become shadow AI.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;For years, organizations learned how to manage Bring Your Own Device. Employees brought their own phones, tablets and laptops to work because personal devices were often better, faster or more convenient than corporate tools.&lt;/p&gt;
&lt;p&gt;The enterprise response was not immediate. First came denial. Then partial bans. Then security policies, mobile device management, identity controls, data segmentation, conditional access and more mature governance models.&lt;/p&gt;
&lt;p&gt;With artificial intelligence, we are living through a deeper version of the same pattern.&lt;/p&gt;
&lt;p&gt;The difference is that employees are no longer bringing only a device. They are bringing an external cognitive capability: an assistant that can summarize documents, write code, analyze spreadsheets, prepare presentations, draft emails, interpret internal policies, generate images, translate content, create agents and automate work.&lt;/p&gt;
&lt;p&gt;That is &lt;strong&gt;Bring Your Own AI&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;And, as usually happens with technologies that are genuinely useful, adoption is not waiting for committees to finish deliberating.&lt;/p&gt;

&lt;h2 class="relative group"&gt;Employees are not waiting for permission
 &lt;div id="employees-are-not-waiting-for-permission" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#employees-are-not-waiting-for-permission" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The most important signal behind BYOAI is that it comes from a real need.&lt;/p&gt;
&lt;p&gt;Employees are not using ChatGPT, Claude, Gemini, Perplexity, Copilot, Cursor or dozens of specialized tools because they want to challenge Security or Legal. They use them because they get work done. Because they reduce friction. Because they help them deliver faster. Because in many cases the official corporate tool does not exist yet, is not good enough or is too constrained.&lt;/p&gt;
&lt;p&gt;The data from Microsoft and LinkedIn&amp;rsquo;s 2024 Work Trend Index was striking: 75% of knowledge workers were already using generative AI at work, and among those users, 78% were bringing their own AI tools into the workplace. The same research revealed a telling paradox: while 79% of leaders said AI adoption was critical to remain competitive, 60% admitted their company lacked a vision and plan to implement it.&lt;/p&gt;
&lt;p&gt;Employees fill that gap between executive urgency and organizational capability.&lt;/p&gt;
&lt;p&gt;Slack reported in 2025 that 60% of workers were already using AI, and that daily usage had grown 233% in six months. This is not a marginal trend or a niche experiment. It is a new productivity layer becoming part of daily work.&lt;/p&gt;
&lt;p&gt;The right interpretation is not: &amp;ldquo;employees are disobeying.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The right interpretation is: &lt;strong&gt;the organization has not yet designed a good enough way to absorb this capability&lt;/strong&gt;.&lt;/p&gt;

&lt;h2 class="relative group"&gt;BYOAI is not a technology problem. It is an organizational symptom.
 &lt;div id="byoai-is-not-a-technology-problem-it-is-an-organizational-symptom" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#byoai-is-not-a-technology-problem-it-is-an-organizational-symptom" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;When shadow AI appears, the instinctive reaction is usually control: block domains, prohibit tools, send restrictive policies or require prior approval for any AI usage.&lt;/p&gt;
&lt;p&gt;Sometimes blocking is necessary. Some tools do not meet minimum security standards. Some data should never leave the corporate environment. Some industries require strict traceability. Some uses are clearly unacceptable.&lt;/p&gt;
&lt;p&gt;But if the response is limited to prohibition, the problem moves rather than disappears.&lt;/p&gt;
&lt;p&gt;BYOAI happens because there is a gap between three speeds:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the speed at which employees discover new capabilities,&lt;/li&gt;
&lt;li&gt;the speed at which the organization can buy, integrate and govern tools,&lt;/li&gt;
&lt;li&gt;and the speed at which internal processes adapt to new ways of working.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That gap cannot be closed with a memo.&lt;/p&gt;
&lt;p&gt;It requires architecture, governance, education, measurement and corporate alternatives that are good enough.&lt;/p&gt;
&lt;p&gt;This is the uncomfortable part: many organizations want to avoid the risk of BYOAI, but they do not want to pay the cost of building an official AI experience that can compete with the tools employees already use. They end up in the worst possible middle ground: employees use AI anyway, but the organization has no visibility, no adequate contracts, no traceability, no data control and no way to capture institutional learning.&lt;/p&gt;

&lt;h2 class="relative group"&gt;The real risk is not that someone uses AI. It is that no one knows how they are using it.
 &lt;div id="the-real-risk-is-not-that-someone-uses-ai-it-is-that-no-one-knows-how-they-are-using-it" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-real-risk-is-not-that-someone-uses-ai-it-is-that-no-one-knows-how-they-are-using-it" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The risk of BYOAI should not be exaggerated into panic, but it should not be minimized either.&lt;/p&gt;
&lt;p&gt;There are at least five concrete risks.&lt;/p&gt;
&lt;p&gt;The first is &lt;strong&gt;sensitive data leakage&lt;/strong&gt;. An employee may paste customer data, source code, financial information, contracts, academic records, research material, commercial strategy or internal documents into a personal tool. Even if the provider has reasonable controls, the organization may lose governance over what data left, under which terms, with what retention and with what auditability.&lt;/p&gt;
&lt;p&gt;The second is &lt;strong&gt;loss of intellectual property and strategic context&lt;/strong&gt;. AI is increasingly used to explore decisions, summarize documents, analyze products, review code and prepare plans. That means it is not only data that flows out. Intentions, hypotheses, priorities and business knowledge flow as well.&lt;/p&gt;
&lt;p&gt;The third is &lt;strong&gt;ungoverned quality&lt;/strong&gt;. If an AI-generated response enters a document, contract, technical decision or external communication without sufficient review, the problem is no longer only privacy. It becomes a matter of reliability, accountability and reputation.&lt;/p&gt;
&lt;p&gt;The fourth is &lt;strong&gt;economic fragmentation&lt;/strong&gt;. Dozens or hundreds of individual subscriptions may look inexpensive, but they create an invisible economy: duplicated payments, redundant tools, licenses without enterprise negotiation, lack of discounts and no return-on-investment measurement.&lt;/p&gt;
&lt;p&gt;The fifth is &lt;strong&gt;fragmented organizational learning&lt;/strong&gt;. When every employee experiments alone, the organization loses a valuable opportunity: understanding which use cases work, which prompts repeat, which tasks are being automated, which processes should be redesigned and where the real value is emerging.&lt;/p&gt;
&lt;p&gt;In other words: BYOAI does not only expose data. It also disperses knowledge.&lt;/p&gt;

&lt;h2 class="relative group"&gt;The data already shows the size of the problem
 &lt;div id="the-data-already-shows-the-size-of-the-problem" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-data-already-shows-the-size-of-the-problem" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The evidence points in one direction: informal AI adoption is moving faster than governance.&lt;/p&gt;
&lt;p&gt;Cyberhaven&amp;rsquo;s analysis of real AI usage in corporate environments reported that between March 2023 and March 2024 the amount of corporate data entered into AI tools grew 485%. In its 2026 report, the company noted that one third of employees accessed AI tools through personal accounts and that 82% of the top 100 generative AI applications fell into medium-to-critical risk categories.&lt;/p&gt;
&lt;p&gt;IBM&amp;rsquo;s Cost of a Data Breach Report 2025 introduced an even harder signal: breaches associated with shadow AI were more expensive. According to analysis of the report, incidents with high levels of shadow AI added roughly $670,000 to the average cost of a breach.&lt;/p&gt;
&lt;p&gt;Cisco&amp;rsquo;s AI Readiness Index shows the structural gap as well. Only 13% of surveyed companies considered themselves fully prepared to capture AI&amp;rsquo;s potential, and only 32% reported high readiness from a data perspective to adapt, deploy and leverage AI technologies.&lt;/p&gt;
&lt;p&gt;These data points do not mean AI should be slowed down.&lt;/p&gt;
&lt;p&gt;They mean that adoption without governance creates operational debt that later gets paid through incidents, duplication, loss of trust and reactive decisions.&lt;/p&gt;

&lt;h2 class="relative group"&gt;The mistake of treating BYOAI as compliance only
 &lt;div id="the-mistake-of-treating-byoai-as-compliance-only" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-mistake-of-treating-byoai-as-compliance-only" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Many BYOAI discussions get trapped in compliance language: what is allowed, what is prohibited, which data can be shared, which provider has better terms, which clauses need to be reviewed.&lt;/p&gt;
&lt;p&gt;All of that matters.&lt;/p&gt;
&lt;p&gt;But if BYOAI is treated only as a compliance problem, half of its strategic value is lost.&lt;/p&gt;
&lt;p&gt;Informal AI adoption is also a map of demand.&lt;/p&gt;
&lt;p&gt;When a team uses external tools to summarize meetings, maybe internal documentation processes are too heavy. When a developer pays for Cursor or Claude Code out of pocket, maybe the official engineering platform is not providing enough leverage. When a professor, consultant or analyst uses ChatGPT to prepare materials, maybe the organization has not yet turned AI into a natural creation tool. When a team uploads documents to an external tool to find answers, maybe the internal knowledge system is not working.&lt;/p&gt;
&lt;p&gt;Shadow AI does not only reveal risk.&lt;/p&gt;
&lt;p&gt;It reveals where the organization is failing to enable productivity.&lt;/p&gt;
&lt;p&gt;That is why the mature response is not to &amp;ldquo;turn off&amp;rdquo; BYOAI. It is to convert it into organizational intelligence: discover what is being used, why it is being used, what value it creates, what risks it introduces and which parts should be institutionalized.&lt;/p&gt;

&lt;h2 class="relative group"&gt;The right model: freedom inside a perimeter
 &lt;div id="the-right-model-freedom-inside-a-perimeter" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-right-model-freedom-inside-a-perimeter" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;A mature organization does not need to choose between total freedom and total lockdown.&lt;/p&gt;
&lt;p&gt;It needs to design an AI perimeter.&lt;/p&gt;
&lt;p&gt;That perimeter should have at least five layers.&lt;/p&gt;
&lt;p&gt;The first is a &lt;strong&gt;clear data classification model&lt;/strong&gt;. Not all data is the same. A serious policy should distinguish between public, internal, confidential, regulated, sensitive, personal, contractual, academic, financial and strategic information. Without that taxonomy, any AI rule becomes too generic to be useful.&lt;/p&gt;
&lt;p&gt;The second is an &lt;strong&gt;approved tools catalog&lt;/strong&gt;. Employees need to know what they can use and for what. It is not enough to say &amp;ldquo;use the corporate tool.&amp;rdquo; Organizations should specify when to use ChatGPT Enterprise, Copilot, Gemini, Claude, an internal tool, a privately deployed open source model or a specialized agent.&lt;/p&gt;
&lt;p&gt;The third is a &lt;strong&gt;use-case policy&lt;/strong&gt;. The governance unit should not be only the tool. It should be the use case. Using AI to improve the style of a public text is not the same as summarizing sensitive records. Generating ideas is not the same as generating a customer response. Individual assistance is not the same as automated decision-making.&lt;/p&gt;
&lt;p&gt;The fourth is &lt;strong&gt;observability without paranoia&lt;/strong&gt;. The organization needs visibility into usage, cost, adoption, risks and patterns, but it should avoid turning AI into an individual surveillance mechanism. Measuring categories of use, data flows, tool types and consumption volume is different from intrusively policing every prompt.&lt;/p&gt;
&lt;p&gt;The fifth is &lt;strong&gt;practical education&lt;/strong&gt;. Most risks are not solved by policies alone; they are solved by judgment. Employees need to understand which data they should not share, how to verify responses, how to cite sources, how to review generated code, how to avoid dangerous automation and when to escalate a case.&lt;/p&gt;

&lt;h2 class="relative group"&gt;Who pays for AI?
 &lt;div id="who-pays-for-ai" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#who-pays-for-ai" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Cost is one of the most delicate BYOAI questions.&lt;/p&gt;
&lt;p&gt;If the company does not pay, the most motivated or best-resourced employees will pay for personal tools. That creates internal inequality, lack of control and loss of visibility.&lt;/p&gt;
&lt;p&gt;If the company pays for everything for everyone, it can create enormous and poorly optimized spend. Not every employee needs the same level of access, the same model or the same tool.&lt;/p&gt;
&lt;p&gt;If the company centralizes too much, it can suffocate experimentation and fall behind the market frontier.&lt;/p&gt;
&lt;p&gt;The reasonable answer is usually hybrid.&lt;/p&gt;
&lt;p&gt;A corporate base layer for all knowledge workers. An advanced layer for intensive profiles: software development, analysis, research, operations, marketing, product, complex support, finance, legal, teaching, design. And a controlled experimental layer for testing new tools with clear criteria for security, data and cost.&lt;/p&gt;
&lt;p&gt;The goal is not to minimize spending.&lt;/p&gt;
&lt;p&gt;The goal is to move from invisible spending to governed investment.&lt;/p&gt;
&lt;p&gt;The right metric is not only cost per license. It is cost per improved task, cost per freed hour, cost per reduced cycle, cost per avoided error, cost per improved experience.&lt;/p&gt;

&lt;h2 class="relative group"&gt;From BYOAI to Enterprise AI Adoption
 &lt;div id="from-byoai-to-enterprise-ai-adoption" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#from-byoai-to-enterprise-ai-adoption" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The destination for BYOAI should not be elimination. It should be intelligent absorption.&lt;/p&gt;
&lt;p&gt;Organizations that do this well will continue to allow individual exploration, but inside a clear framework. They will learn from emerging uses. They will detect patterns. They will convert the best experiments into corporate capabilities. They will negotiate adequate contracts. They will protect sensitive data. They will measure impact. And they will create a culture where using AI well is part of work, not a clandestine activity.&lt;/p&gt;
&lt;p&gt;A mature sequence could look like this:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Discover which AI tools are already being used.&lt;/li&gt;
&lt;li&gt;Classify risk by data type and use case.&lt;/li&gt;
&lt;li&gt;Define an initial catalog of approved tools.&lt;/li&gt;
&lt;li&gt;Create a simple, understandable and actionable policy.&lt;/li&gt;
&lt;li&gt;Offer competitive corporate alternatives.&lt;/li&gt;
&lt;li&gt;Measure adoption, value, cost and risk.&lt;/li&gt;
&lt;li&gt;Turn repeated use cases into internal products or governed agents.&lt;/li&gt;
&lt;li&gt;Review the model every quarter, because the market changes too fast for an annual policy.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The key point is that AI governance cannot be a static document. It has to operate as a living system.&lt;/p&gt;

&lt;h2 class="relative group"&gt;The question for leaders
 &lt;div id="the-question-for-leaders" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-question-for-leaders" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;The wrong question is:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;How do we stop people from using external AI tools?&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;The right question is:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;What is informal AI usage telling us about how our organization works?&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;BYOAI is a warning, but also an opportunity. It warns that artificial intelligence is entering the organization through undesigned routes. But it also reveals energy, need, initiative and value.&lt;/p&gt;
&lt;p&gt;Organizations that see only risk will react with late controls.&lt;/p&gt;
&lt;p&gt;Those that understand the full pattern will build an enterprise AI layer that is more useful, more secure and more aligned with real work.&lt;/p&gt;
&lt;p&gt;Because the future will not be &amp;ldquo;every employee with their own personal AI&amp;rdquo; or &amp;ldquo;one corporate AI for everything.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;It will be a distributed, governed and observable intelligence architecture where people have freedom to increase productivity without forcing the organization to give up security, privacy, cost control and collective learning.&lt;/p&gt;
&lt;p&gt;BYOAI is not the enemy.&lt;/p&gt;
&lt;p&gt;The enemy is letting it happen without design.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Carles Abarca is VP of Digital Transformation at Tecnologico de Monterrey and former CTO of Banco Sabadell. He writes about the strategic implications of AI, digital infrastructure and technology transformation at &lt;a href="https://carlesabarca.com" target="_blank" rel="noreferrer"&gt;carlesabarca.com&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;

&lt;h2 class="relative group"&gt;Sources reviewed
 &lt;div id="sources-reviewed" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#sources-reviewed" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft WorkLab: &lt;a href="https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part" target="_blank" rel="noreferrer"&gt;AI at Work Is Here. Now Comes the Hard Part&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Microsoft Source: &lt;a href="https://news.microsoft.com/source/2024/05/08/microsoft-and-linkedin-release-the-2024-work-trend-index-on-the-state-of-ai-at-work/" target="_blank" rel="noreferrer"&gt;Microsoft and LinkedIn release the 2024 Work Trend Index on the state of AI at work&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MIT Sloan: &lt;a href="https://mitsloan.mit.edu/ideas-made-to-matter/what-leaders-should-know-about-bring-your-own-ai" target="_blank" rel="noreferrer"&gt;What leaders should know about Bring Your Own AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Salesforce / Slack Workforce Index: &lt;a href="https://www.salesforce.com/news/stories/daily-ai-workforce-use-growth/" target="_blank" rel="noreferrer"&gt;New Slack Workforce Index Reveals Higher Daily AI Use&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyberhaven: &lt;a href="https://www.cyberhaven.com/resources/report/ai-adoption-risk-report-2026" target="_blank" rel="noreferrer"&gt;2026 AI Adoption &amp;amp; Risk Report&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cyberhaven: &lt;a href="https://www.cyberhaven.com/blog/shadow-ai-how-employees-are-leading-the-charge-in-ai-adoption-and-putting-company-data-at-risk" target="_blank" rel="noreferrer"&gt;Shadow AI: how employees are leading the charge in AI adoption and putting company data at risk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;IBM: &lt;a href="https://www.ibm.com/reports/data-breach" target="_blank" rel="noreferrer"&gt;Cost of a Data Breach Report 2025&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco: &lt;a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2024/m11/cisco-2024-ai-readiness-index-urgency-rises-readiness-falls.html" target="_blank" rel="noreferrer"&gt;2024 AI Readiness Index&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;NIST: &lt;a href="https://www.nist.gov/itl/ai-risk-management-framework" target="_blank" rel="noreferrer"&gt;AI Risk Management Framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenAI: &lt;a href="https://openai.com/business-data/" target="_blank" rel="noreferrer"&gt;Business data privacy, security, and compliance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google Workspace: &lt;a href="https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub" target="_blank" rel="noreferrer"&gt;Generative AI in Google Workspace Privacy Hub&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://carlesabarca.com/posts/bring-your-own-ai/featured.png"/></item></channel></rss>