Problems displaying this newsletter? View online.
Database Weekly
The Complete Weekly Roundup of SQL Server News by SQLServerCentral.com
Hand-picked content to sharpen your professional edge
Editorial
 

Shining a Light on Shadow AI - Responsible Data Protection When AI is Everywhere

As someone who has had the honor of delivering keynotes at both Oracle and SQL Saturday data events, I’ve spent time with professionals on both sides of the database world.  I’ve held the title of database administrator, developer, engineer and architect for structured, transactional giants and the analytics-heavy ecosystems of eight different database platforms, (not counting Cloud platforms).  My keynotes have often been focused on a topic that unites us all today: the urgent need to address the threat of Shadow AI.

Shadow AI refers to the unauthorized or unmonitored use of artificial intelligence tools - particularly public, cloud-based generative AI.  This risk is often unintentional by employees or teams and as expected, without official IT oversight. It’s the new Shadow IT, but far more dangerous. In my keynotes on data protection and ethics in the AI era, I’ve emphasized that the biggest security gap in AI today isn’t the models - it’s the humans using them.

Recent research by Harmonic AI discovered that sensitive personal information (PII), including names, emails, and even health data, was estimated between 8% in 4th quarter of 2024 and upwards of 16% by 1st quarter of 2025 just in the free version of ChatGPT.  This unintentionally exposes organizations and customers to potential misuse or unintended storage in AI model training data. Add to that authentication keys, source code, internal documents, and employee records being submitted for "help" or "summarization" and you’ve got a ticking compliance time bomb.

Database professionals know what’s at stake. We've spent decades architecting systems to protect PII, meet HIPAA, PCI-DSS, and GDPR requirements, and now a single unauthorized API call to a free AI tool can bypass all that governance built into our relational systems.

Shadow AI poses a unique and unprecedented risk:

  • It operates outside corporate audit trails.
  • It often runs on systems that have no SLA, no enterprise support, and no logging.
  • And it’s being fed the exact kind of sensitive data we’ve spent years safeguarding.

This isn’t a philosophical problem, it’s a very real and growing liability. The answer isn’t to stop AI innovation. It’s to approach it responsibly, with clear policies, well-communicated training programs, and the use of enterprise-grade AI tools that are approved, governed, and monitored.

Organizations must:

  • Define what AI tools are authorized.
  • Train employees on how and when to use them safely.
  • Block or sandbox access to public AI tools whenever data classification policies are violated.
  • Ensure enterprise tools are configured to comply with data governance and retention requirements.

The future of AI is powerful, but it must also be ethical, secure, and compliant. If you have access to critical data, the threat of Shadow AI is real, and our collective responsibility is to ensure we don't trade innovation for risk. Let’s start to talk about the risk of Shadow AI and build data-driven organizations with policies and protections in place to ensure it doesn’t bypass everything we’ve all worked so hard to secure at the database level.

DBAKevlar Out

Kellyn Gorman

Join the debate, and respond to the editorial on the forums

 
The Weekly News
All the headlines and interesting SQL Server information that we've collected over the past week, and sometimes even a few repeats if we think they fit.
AI/Machine Learning/Cognitive Services

AI’s Errors Are Increasing Despite Advances in Reasoning – Experts Theorize Why

From Past News - RSS Feeds

AI initially seemed amazing with its many capabilities

Administration of SQL Server

Recovering data in SQL Server without full backup

From Simple Talk

In more than 10 years of experience...

The Script-Based Nature of SQL Agent Jobs

From Curated SQL

Rob Farley praises the textual nature of SQL Agent.

T-SQL Tuesday #186 – Managing SQL Agent Jobs

From Deb the DBA

Happy T-SQL Tuesday! This month, Andy Levy 

T-SQL Tuesday #186 - Agent Job History Visualization

From FLX SQL

I’m hosting T-SQL Tuesday this month

Predicting When SQL Server Will Hit the CPU Wall

From Brent Ozar Unlimited

Most of the time, we use wait stats to identify SQL

Stop Wasting Time Rebuilding Indexes Every Night

From DallasDBAs.com

Too many IT teams run index rebuild jobs on autopilot. Every night. Every index. No questions asked. Here’s the truth: if you’re doing this daily on indexes smaller

Managing SQL Agent Jobs with DBADash

From Curated SQL

David Wiseman shows off an open-source product: For T-SQL Tuesday #186, Andy Levy asks, “How do you manage and/or monitor your SQL Server Agent jobs?” 

Is OUTPUT Broken In SQL Server?

From Erik Darling Data

Is OUTPUT Broken In SQL Server? Going Further If this is the kind of SQL Server stuff you love learning about, you’ll love my training. I’m offering a 75%

Azure Databricks, Spark and Snowflake

Parent – Child Task Automation in Snowflake via Task Graph

From Simple Talk

In the fast-paced world of business, fast, effective

Azure SQL

Managed Instance Gotchas – Configuration Items

From Simple Talk

In my last post I described issues that might stop...

Conferences, Classes, Events, and Webinars

DevOps Devour Hour – New York City Lunch & Learn – May 23, 2025

From Erik Darling Data

DevOps Devour Hour – New York City Lunch & Learn – May 23, 2025 Going Further If this is the kind of SQL Server stuff you love learning about.

The first speakers and sessions have just been announced for PASS Summit 2025!

We’re delighted to share the Pre-Con schedule for Monday, November 17 and Tuesday, November 18, 2025. Take a look at the line-up of industry experts here!

Hurry! Sponsor Early Bird Rates End May 22

Early bird rates for sponsor packages at the 2025 PASS Data Community Summit end May 22. Join us Nov 17-21 at the Seattle Convention Center. Sign up early for lower pricing, prime booth locations, coveted speaking times, extended branding, and more. Packages start at $9,000.

Data Storytelling and Visualisation

How Self-Service Analytics Reduces Dependence on Data Teams

From Dataversity

A self-service analytics tool should allow non-technical

Using a Python Notebook using Semantic Link Labs to write a DAX Query output to a Lakehouse Table

From FourMoo

In this blog post I am going to explain how to use a Python Notebook with Semantic Link Labs

Database Design, Theory and Development

Set-Based Comparisons for Data Validation

From Curated SQL

Jeffry Schwartz looks for exceptions

DevOps and Continuous Delivery (CI/CD)

Behind the Scenes: Building a Robust Ads Event Processing Pipeline

From Netflix TechBlog - Medium

Kinesh SatiyaIntroductionIn a digital advertising with Robust Ads Event Processing Pipeline

Git Branching for Small Teams

From Curated SQL

Adron Hall takes us through a branching strategy: ...

HA/DR/Always On/Clustering

Database Snapshots in High-Availability Setups

From Curated SQL

Stephen Planck adds one more layer of complexity

MDX/DAX

Writing DAX Query Outputs to Lakehouse Tables

From Curated SQL

Gilbert Quevauvilliers does a bit of writing: In this blog post I am going to explain how to use a Python Notebook using the Semantic model

Microsoft Fabric ( Azure Synapse Analytics, OneLake, ADLS, Data Science)

Shortcut Caching in Microsoft Fabric now GA

From Curated SQL

Trevor Olson announces a feature has become GA

Direct Lake vs Import vs Direct Lake+Import | Fabric semantic models (May 2025)

From SQLBI

Direct Lake + Import composite mode explained

Billing and Microsoft Fabric Preview Features

From Curated SQL

Nicky van Vroenhoven explains that TANSTAAFL

Comparing Microsoft Fabric Engines

From Curated SQL

Nikola Ilic performs a comparison

Fabric Data Factory Pipeline Execution From Azure Data Factory

From AndyLeonard.blog()

Fabric Data Factory Pipeline Execution from Azure Data Factory

Comparing Data Importation Modes in Fabric Semantic Models

From Curated SQL

Marco Russo has a guide: When I presented “Choosing Between Import Mode, Direct Lake, and Composite Models” at Fabric Conf 2025 in Las Vegas, the room overflowed.

Oracle/PostgreSQL/MySQL/other RDBMS

Troubleshooting ‘resmgr:cpu quantum’ and High CPU in Oracle

From DBAKevlar

After publishing my last post on Oracle Wait Class, let's talk about a specific wait event!

Hash Indexes in MySQL

From Curated SQL

Lukas Vileikis explains how hash indexes work in MySQL

MySQL Shell Basic Configuration Management (Part 4 – Optimizing MySQL Performance)

From Simple Talk

Welcome back to our journey of understanding MySQL...

Performance Tuning SQL Server

SQL Server Performance Office Hours Episode 11

From Erik Darling Data

SQL Server Performance Office Hours Episode 11

A SQL Server Query Plan Answer

From Erik Darling Data

A SQL Server Query Plan Answer Going Further 

SQL Data Type Conversions: Your Key to Clean Data & Sharp Queries

From SQLServerCentral Blogs

If you're a data analyst juggling varied datasets

Last Page Insert Contention

From Curated SQL

Haripriya Naidu is trying to slam a lot of transactions through the same door: When operations wait to acquire a latch on a page

PostgreSQL

Deepak Mahto: PostgreSQL 18 Beta Preview – Export or Amend Statistics with Ease

From Planet Postgres

PostgreSQL 18 beta has been released!

Partitioning in PostgreSQL

From Curated SQL

Umair Shahid takes us into partitioning strategies.

Ian Barwick: PgPedia Week, 2025-05-11

From Planet Postgres

This week saw the routine quarterly round of PostgreSQL

Umair Shahid: Step by Step Guide on Setting Up Physical Streaming Replication in PostgreSQL

From Planet Postgres

Physical streaming replication in PostgreSQL

Introduction to PostgreSQL for the Data Professional

From Simple Talk

Learning something new has elements of bliss

Setting up Physical Streaming Replication in PostgreSQL

From Curated SQL

Umair Shahid pushes the contents of the write-ahead log to another machine: Physical streaming replication in PostgreSQL allows you to maintain a live copy

Professional Development

Making AI available for everyone

From AllAnalytics

Making AI available for everyone

Certifications Boost IT Pro Job Prospects, Salaries

From IT Pro - Microsoft Windows Information, Solutions, Tools

Employers are increasingly favoring skill-validated certifications

Tools for Dev (SSMS, ADS, VS, etc.)

sudo in Windows

From Curated SQL

Patrick Gruenauer elevates our access

 
RSS FeedTwitter
This email has been sent to {email}. To be removed from this list, please click here. If you have any problems leaving the list, please contact the webmaster@sqlservercentral.com. This newsletter was sent to you because you signed up at SQLServerCentral.com. Note: This is not the SQLServerCentral.com daily newsletter list, and unsubscribing to this newsletter will not stop you receiving the SQL Server Central daily newsletters. If you want to be removed from that list, you can follow the instructions on the daily newsletter.
©2019 Redgate Software Ltd, Newnham House, Cambridge Business Park, Cambridge, CB4 0WZ, United Kingdom. All rights reserved.
webmaster@sqlservercentral.com

 

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -