Said It Here

How to secure and support internal AI apps built by non-technical employees

Non-technical employees are building internal business applications using AI tools that bypass standard IT reviews, creating a massive queue for production sign-off and a wave of shadow IT. Because standard deployment processes like CI/CD are impossible for non-developers to follow, IT managers are left with no way to establish proper governance or security standards without breaking the speed of business.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Treating AI-built internal apps as ephemeral and securing the environment perimeter (paved road / managed infrastructure) rather than auditing every line of generated code
  2. 2
    Routing around IT or creating shadow IT when approval processes have too many technical hurdles
  3. 3
    Refusing to approve or run any AI-built applications due to safety and maintenance risks

In their words

Unedited, most upvoted first, each linked to the thread it came from.

How we ended up in a timeline where non tech people think they can shit out an app and have it actually operate in a serious business? No ideasource ↗

Diligent_Tech_Bro · r/ITManagers · 2 upvotes

Lol, this "paved road" is impossible to follow for someone not technical. I guarantee you have a boat load of shadow IT happening because Mike from accounting doesn't know what CI/CD issource ↗

Dodough · r/ITManagers · 1 upvotes

I have a growing queue of employee-built internal tools waiting for IT approval, and I need to establish a formal sign-off standard before granting production access.source ↗

NataliaCochran578 · r/ITManagers

Where this came up

People with this problem also raised