Digital shadow AI risk theory (DART): A framework for managing data disclosure and privacy risks of AI tools at work
提出了数字影子AI风险框架(DART),识别员工非正式使用AI带来的六类风险,并通过三波调查验证假设,为组织制定AI使用政策提供依据。
The swift adoption of generative and agentic AI tools in workplace settings has introduced new organizational risks related to data disclosure, privacy, and governance. This study introduces the Digital Shadow AI Risk Framework (DART), which identifies and explains the behavioral and organizational risks arising from the informal and often unregulated use of AI tools by employees. DART comprises six interrelated risk dimensions: unintentional disclosure risk, the trust–dependence paradox, data sovereignty conflict, knowledge dilution, the ethical black box problem, and organizational feedback loops. The framework is evaluated using a three-wave survey research combining hypothesis testing and covariance-based structural equation modeling (CB-SEM) across three cross-industry surveys of professionals (Survey-1: N = 374; Survey-2: N = 179; Survey-3: N = 220). Survey-3 introduced multi-item latent measures enabling direct tests of H4, H6, and the full H8 mediation chain (opacity → trust → comfort → disclosure). Results support six of eight hypotheses. Knowledge dilution is confirmed through replication, while data sovereignty conflict consistently operates as a boundary condition rather than a direct predictor. The findings reveal persistent gaps in employee awareness, training, and organizational controls surrounding AI use. DART's contribution lies in distinguishing Shadow AI from traditional Shadow IT by showing how everyday, efficiency-driven AI use embeds risk into routine knowledge work. By externalizing organizational knowledge into adaptive AI systems, Shadow AI introduces risks that extend beyond technical non-compliance to cognitive dependence and governance erosion. The framework informs future research and supports the development of organizational policies and controls for responsible AI use.