Exploring the Role of Gen-AI Usage Guidelines in Enhancing Organizational Security
2026 (English)Independent thesis Basic level (degree of Bachelor), 180 HE credits
Student thesisAlternative title
Riktlinjer för Gen-AI-användning: En studie om deras roll för stärkt organisatorisk säkerhet (Swedish)
Abstract [en]
The integration of generative AI (Gen-AI) into the workplace has occurred at a pace thathas challenged the ability of organizations to regulate its use. Previous research indicatesa lack of clear user guidelines for Gen-AI. Furthermore, where guidelines do exist, they areoften perceived as hindrances rather than support, leading to low compliance as employeesactively circumvent security policies to maintain work efficiency. This has given rise to thephenomenon of ”Shadow AI,” where employees utilize external AI tools outside of formalorganizational control, posing significant information security risks.This study examines employee attitudes toward Gen-AI and existing security guidelineswithin a large organization. Furthermore, the study explores how guidelines can bedesigned to balance security requirements with usability. The study employs a mixedmethods approach, beginning with a literature review to gain knowledge about, and toframe the study with regards to, the current situation. Following this, a quantitative survey is employed to map current usage and attitudes at a large organization, followed byqualitative semi-structured interviews with employees. Subsequently, a proposed framework for how to design user friendly guidelines are presented.The research shows that Gen-AI is here to stay but its potentials needs to be weighedagainst the risks. From the data we collected we conclude that productivity is valued highdespite contradictory attitudes towards Gen-AI. A tension exists between the importanceof guidelines and their practical limitations. These findings are concluded in a proposeduser guideline framework.
Place, publisher, year, edition, pages
2026. , p. 44
Keywords [en]
Generative AI, Organizational Security Policies, User-friendly Guidelines, Workplace AI Adoption, Responsible AI Use, Shadow AI
National Category
Information Systems
Identifiers
URN: urn:nbn:se:mau:diva-87477OAI: oai:DiVA.org:mau-87477DiVA, id: diva2:2092524
External cooperation
Security Company
Educational program
TS Informationsarkitekt
Supervisors
Examiners
2026-08-172026-08-152026-08-17Bibliographically approved