Skip to content
Research Article Open access CC BY 4.0

The Ethical and Legal Implications of Shadow AI in Sensitive Industries: A Focus on Healthcare, Finance and Education

Adebayo Yusuf Balogun, Olufunke Cynthia Metibemu, Abayomi Titilola Olutimehin, Adekunbi Justina Ajayi, Damilola Comfort Babarinde, Oluwaseun Oladeji Olaniyi

Journal of Engineering Research and Reports · pp. 1–22 · Published 13 Feb 2025

10.9734/jerr/2025/v27i31414

Abstract

This study examines the ethical and legal implications of Shadow AI in healthcare, finance, and education by analyzing unauthorized AI deployments and their impact on data privacy, cybersecurity, and regulatory compliance. Using a quantitative research approach, descriptive statistics, ordinal regression modeling, and network analysis were employed to assess AI violations using the MITRE ATLAS AI Incident Database, EU AI Act Public Database, and IBM X-Force Threat Intelligence Report. Findings reveal that privacy breaches are most prevalent in education (22 cases), bias-related issues dominate finance (20 cases), and cybersecurity risks are highest in healthcare (19 cases). Legal risk analysis shows a 20% probability of regulatory intervention, with breach type as the strongest determinant. Anomaly detection identified healthcare as the most vulnerable to AI-driven cyber threats (8 anomalies). This study contributes to AI governance literature by quantifying the impact of regulatory interventions on Shadow AI risks, demonstrating how enforcement actions influence unauthorized AI adoption trends. It also underscores the limitations of current frameworks (e.g., GDPR, HIPAA, SEC regulations) in mitigating AI-related violations. The findings emphasize the urgent need for sector-specific AI compliance frameworks, AI ethics committees, and real-time cybersecurity monitoring systems to mitigate risks. Strengthening legal accountability and regulatory enforcement is critical to preventing the unchecked proliferation of Shadow AI in sensitive industries. Recommendations include sector-specific AI compliance frameworks, AI ethics committees, cybersecurity policies, and stricter regulatory enforcement.

Shadow AI AI governance cybersecurity risks regulatory compliance algorithmic bias

Cited by 8

DİJİTAL LİDERLİĞİN YAPAY ZEKÂ İLE İLİŞKİSİNİN META-ANALİZ YÖNTEMİ İLE İNCELENMESİ

Yaşar Şahin · Uluslararası İktisadi ve İdari İncelemeler Dergisi · 2025

Value Co-Creation

Melissa Li Sa Liow · Empowering Value Co-Creation in the Digital Era · 2025

From Shadow It to Shadow AI–Threats, Risks and Opportunities for Organizations

Mario Silic, Dario Silic, Kathrin Kind‐Trüller · Strategic Change · 2025

Showing 6 of 8 known citations — external sources report more than can currently be individually listed.

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

8

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.