Understanding the No tool for AI usage monitoring risk
BarracudaONE displays this risk when it detects that your environment doesn’t include a tool for monitoring which users are accessing AI tools, which AI tools are being used, and how often. Because you don’t have an AI monitoring tool, you can’t measure the AI-related security of your systems, and you can’t implement compliance policies.
Why this is a risk
AI systems can affect people, decisions, and data at scale. Not monitoring the presence and usage of AI applications means you can’t set meaningful AI policies or enforce that they are being followed. There may be unregulated or even potentially dangerous AI software on your network that has access to sensitive data or even malignant applications that purposely exposes your environment to exposure.
Resolving this risk
Resolving this risk involves enabling the discovery of AI usage monitoring by setting up Cisco Umbrella or Barracuda SecureEdge.
Cisco Umbrella analyzes DNA traffic logs to identify the AI tools users access in your environment, but doesn’t enforce access policies in your network.
Barracuda SecureEdge identifies AI tools and lets you set up and enforce access policies.
To resolve the No tool for AI usage monitoring risks
In the left navigation menu, select Home
.
In the Start mitigating risks section, do one of the following:
Select the No tool for AI usage monitoring risk.
Select another risk, then use the arrows to navigate to the No tool for AI usage monitoring risk.
In the Resolution criteria section, select Enable discovery
.
Select one of the following:
Use Barracuda SecureEdge Access
Use Cisco Umbrella
When this criteria is met, the risk auto-resolves.
Once you have resolved this risk
Once you put a tool in place to identify AI applications on your system and how they are being used, you can regulate and ensure AI is used in a way that is:
Safe - Doesn’t cause harm through errors or unsafe outputs
Secure - Doesn’t expose or leak sensitive data, or get exploited
Accountable - Ensures traceability for decisions and failures
Compliant - Meets privacy, security, and sector-specific rules
Reliable - Measures, documents, and continuously improves performance