The New Risk of Shadow AI
“80% of companies plan to increase security spending under the SCS evaluation system” and “2 in 3 IT managers report a rise in shadow AI” – these survey results reported by ASCII.jp have sent shockwaves through many business leaders.
The SCS evaluation system is the assessment criteria for the “Security Clearance System” that the Information-technology Promotion Agency (IPA) will launch in fiscal year 2026. It allows companies to have their security levels evaluated by a third party, earning trust from business partners.
To comply with this system, as many as 80% of companies are planning to increase their security investments. However, a serious problem is brewing beneath the surface: the rapid rise of “shadow AI,” where employees start using generative AI (such as ChatGPT or Copilot) without official permission.
Data shows that 2 out of 3 IT managers are witnessing this phenomenon. This is the result of management failing to define rules for AI use, leaving teams to act on their own.
The Management Decision Forced by the SCS Evaluation System
The SCS evaluation system is not just a security check. It is a benchmark for business partners to determine, “Can we safely do business with this company?”
For SMEs in particular, responding to this system can be a matter of survival. If large companies start requiring SCS evaluations from their partners, SMEs that cannot comply risk losing business opportunities.
Yokohama Information Equipment’s “YJK365 Security” is a service designed precisely to address this challenge. It combines a “simplified SOC (Security Operations Center)” for SMEs with IT department BPO, covering even SCS evaluation system compliance.
What makes this service noteworthy is that it provides “security measures from a management perspective,” not “IT maintenance centered on equipment sales.” Traditional IT vendors would sell servers and network equipment and call it a day. However, YJK365 Security offers total support that includes operations and evaluation.
This serves as a catalyst for business leaders to rethink IT as something that “delivers value through continued use” rather than “buy it and you’re done.”
Structural Factors Behind Shadow AI
Why is shadow AI on the rise? The reason is simple: management has not provided a clear policy on AI use.
Employees want to use AI to improve work efficiency. But the company hasn’t said “you can use AI” or “you cannot use AI.” So, they start using ChatGPT or Copilot on their own judgment. This is the typical pattern for how shadow AI emerges.
The problem is that if this situation continues, the risk of information leaks increases. Customer information or confidential data entered by employees could leak externally as training data for the AI.
Furthermore, even if the AI’s responses contain errors, no one verifies them. The risk of management decisions being made based on incorrect information cannot be ignored.
According to the ASCII.jp survey, 2 out of 3 IT managers report an increase in shadow AI. This is evidence of a serious gap between the front lines and the IT management department.
Why Management Should Define AI Rules
The key point here is that management should directly define the rules for AI use.
Many business leaders tend to think, “AI is a technical matter, so let’s leave it to the IT department.” However, AI use is a core business strategy. Deciding which tasks to use AI for and which data can be input into AI are matters that should be determined by management.
For example, whether customer information can be input into AI involves legal risk assessment. Whether AI responses can be provided directly to customers involves quality assurance. It’s unrealistic to leave these decisions solely to the IT department.
Here are three things business leaders should do:
First, clarify the purpose of AI use. Instead of an abstract goal like “improve productivity,” specifically decide “this part of this task will be handled by AI.”
Second, establish data handling rules. Set standards such as “do not input customer information into AI” or “handle internal confidential data only in a dedicated AI environment.”
Third, create a system to verify AI outputs. Instead of using AI responses directly, design a process where humans review them before use.
Three Actions SMEs Should Take
To simultaneously address SCS evaluation system compliance and shadow AI countermeasures, the following three actions are effective:
First, outsource security. Utilize services like Yokohama Information Equipment’s YJK365 Security to achieve the necessary security level without hiring in-house security experts. Many services start at a few tens of thousands of yen per month (approx. $200–$300), making them accessible even for SMEs.
Second, create AI usage guidelines. Document a “list of approved AI tools,” “list of prohibited data for input,” and “process for verifying output results.” The trick is to summarize it on a single A4 sheet for easy internal sharing.
Third, establish regular dialogue between IT and management. Set aside 30 minutes once a month for management to hear directly from IT about “what AI tools are being used on the front lines” and “what security risks exist.” This dialogue is the first step toward making shadow AI visible.
Conclusion: Time to Make IT a Management Resource Again
Responding to the SCS evaluation system is not just an added cost. It is an excellent opportunity for management to elevate IT from “leave it to the experts” to a “management resource.”
The rise of shadow AI is a warning that management failed to define AI use. Employees are seeking efficiency. The question is whether that energy can be harnessed in alignment with business strategy, rather than descending into ruleless chaos.
New security services like Yokohama Information Equipment’s YJK365 Security show that the era has arrived when even SMEs can implement expert-level measures. To avoid falling behind, business leaders must make decisions now.
IT is no longer a “I don’t understand it, so I’ll leave it” domain. It is a management resource that management must directly define, design, and evaluate. This recognition will determine future competitiveness.


Comments