The Ethical and Legal Implications of Shadow AI in Sensitive Industries: A Focus on Healthcare, Finance and Education
Adebayo Yusuf Balogun, Olufunke Cynthia Metibemu, Abayomi Titilola Olutimehin, Adekunbi Justina Ajayi, Damilola Comfort Babarinde, Oluwaseun Oladeji Olaniyi
Journal of Engineering Research and Reports · pp. 1–22 · Published 13 Feb 2025
10.9734/jerr/2025/v27i31414Abstract
This study examines the ethical and legal implications of Shadow AI in healthcare, finance, and education by analyzing unauthorized AI deployments and their impact on data privacy, cybersecurity, and regulatory compliance. Using a quantitative research approach, descriptive statistics, ordinal regression modeling, and network analysis were employed to assess AI violations using the MITRE ATLAS AI Incident Database, EU AI Act Public Database, and IBM X-Force Threat Intelligence Report. Findings reveal that privacy breaches are most prevalent in education (22 cases), bias-related issues dominate finance (20 cases), and cybersecurity risks are highest in healthcare (19 cases). Legal risk analysis shows a 20% probability of regulatory intervention, with breach type as the strongest determinant. Anomaly detection identified healthcare as the most vulnerable to AI-driven cyber threats (8 anomalies). This study contributes to AI governance literature by quantifying the impact of regulatory interventions on Shadow AI risks, demonstrating how enforcement actions influence unauthorized AI adoption trends. It also underscores the limitations of current frameworks (e.g., GDPR, HIPAA, SEC regulations) in mitigating AI-related violations. The findings emphasize the urgent need for sector-specific AI compliance frameworks, AI ethics committees, and real-time cybersecurity monitoring systems to mitigate risks. Strengthening legal accountability and regulatory enforcement is critical to preventing the unchecked proliferation of Shadow AI in sensitive industries. Recommendations include sector-specific AI compliance frameworks, AI ethics committees, cybersecurity policies, and stricter regulatory enforcement.
Cited by 8
Yaşar Şahin · Uluslararası İktisadi ve İdari İncelemeler Dergisi · 2025
Thamburaj Anthuvan, Sunitha Prabhuram, Kajal Maheshwari · 2025
Melissa Li Sa Liow · Empowering Value Co-Creation in the Digital Era · 2025
Mario Silic, Dario Silic, Kathrin Kind‐Trüller · Strategic Change · 2025
Nanyeneke Ravana Mayeke · Computer Science & IT Research Journal · 2025
Hong-Yan Wang, Rui-Hong Liu, Lie Ao · Frontiers in Psychology · 2025
Showing 6 of 8 known citations — external sources report more than can currently be individually listed.
Related research
- Artificial Intelligence and Global Security: Strengthening International Cooperation and Diplomatic Relations — shares topic coverage
- Exploring the Challenges of Artificial Intelligence in Data Integrity and its Influence on Social Dynamics — shares topic coverage
- Artificial Intelligence and Information Governance: Strengthening Global Security, through Compliance Frameworks, and Data Security — shares topic coverage
- Data Sovereignty and Digital Health Transformation in Saudi Arabia: A Review with Policy Implications for Vision 2030 — shares topic coverage
- Balancing Deregulation and Risk: A Framework for AI Deployment in U.S. Municipal Governance — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
8
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.