The VienerX Bi-Weekly Newsletter is Produced Entirely In-House at VienerX Offices in Rockville, MD

For the full experience, please click the view in browser option located in the top right, or enable media for this email.

Table of Contents

Follow Us on Social Media

Ancient Tech with Shay and Bill

VienerX has been in business since 1991. In that time period the technological landscape has changed to a nearly unrecognizable degree. Last week, one of our technicians learned how true that is.

VienerX tech Shay Rouse has been working with technology since the late 80s. He challenged his younger counterpart Bill, to name technology components from days long done. It went…about as well as we expected. Check out the video above for a blast from the past.

Image Via Wiz

What is Shadow AI? How Does It Threaten Your Business?

VienerX Technology Insights

Imagine your HR manager needs to quickly fix up a spreadsheet of employee salaries. It's Friday afternoon, they're busy, and ChatGPT is just a browser tab away. They paste the data in, get their answer, and move on. In thirty seconds, sensitive employee financial data has left your organization forever, and no one even knows the security breach occurred.

That is Shadow AI at work, and it is happening in your organization right now.

What is Shadow AI?

Shadow AI stems from an earlier, well-known concept in IT circles: Shadow IT. Shadow IT occurs when employees use tools and services not approved by the organization to do company work, personal cloud storage, unauthorized email accounts, Google Docs, and so on. The core risk is that sensitive data moves outside of organizational security and control.

Shadow AI is the same principle, applied to AI platforms. According to Info Security Magazine, over one-third of users admitted to using personal AI tools for sensitive work, and that study was conducted in 2024. Since then, ChatGPT's active user base has increased by nearly 600 million people worldwide. Today, the number of users using personal AI tool for professional work is likely an even greater percentage of 1/3 of ChatGPTs 900 million total users. People are more comfortable with the technology, they are more likely to trust it more than they should.

The Risks Are Real

The risks of Shadow AI should not be minimized. At the top of the list are data breaches and data security failures.

A 2024 poll of Chief Information Security Officers (CISOs) found that 1 in 5 large UK companies had experienced some form of data leakage directly attributable to Shadow AI. Perhaps more striking: over 75% of those same CISOs identified employee behavior as a greater security risk than external threats. The danger is not always coming from outside your walls.

Shadow AI also creates serious compliance exposure. Standards such as HIPAA, SOC-1, SOC-2, and GDPR govern how sensitive data must be stored, processed, and protected. HIPAA protects patient health information; GDPR governs the personal data of EU citizens; SOC standards define security controls for financial and operational data.

Standard consumer AI platforms almost never meet these requirements. When an employee feeds regulated data into a non-compliant tool, the organization, not the AI company, is typically the one held liable.

There is also a more fundamental question worth asking: what happens to data entered into free and consumer AI tools? The technology industry has answered this question clearly over the last fifteen years. If you are not paying for the product, the product is your data.

Facebook, Google, and countless others have built empires on this model, Google alone generated over $400 billion in revenue in 2025, with the majority driven by data-powered advertising. Now consider what happens when the data being fed into these systems includes your proprietary formulas, financial projections, customer lists, or internal strategy documents. The value of that data to a third party is difficult to overstate.

How to Protect Your Organization

We discussed the answer to this question in our last newsletter issue with Managed AI. The reality is that AI has become a layer of the modern workflow, whether organizations planned for it or not. Asking employees to simply stop using AI is not a realistic strategy, and it will not work. What organizations need is a governance framework, and we recommend a three-pronged approach:

  1. Provide a controlled alternative. Rather than asking employees to give up AI tools entirely, give them a secure, managed platform they can use for company work. Meet people where they are.

  2. Block unapproved platforms. At the managed device or network level, restrict access to AI tools that fall outside your approved framework. Policy without enforcement is just a suggestion.

  3. Educate your team. The risk is real and significant. Help employees understand why this level of care is necessary, not just what the rules are. People follow policies they understand and believe in.

Organizations that acknowledge AI's role in the modern workplace and build their IT strategy around it will be better positioned for what comes next. Those that ignore it are already behind.

Image: Geralt via Pixabay

Where Did My AI Assistant Go?

By: Wayne Viener

I was attending an HP seminar on Friday when I opened my laptop to look up an answer. I reached for Codex, my preferred AI assistant, but it was gone.

At least, that was how it appeared.

I searched the desktop and then noticed an icon I had not seen the day before: ChatGPT. Had I installed something? Had I changed a setting? No. On Thursday, I had Codex. On Friday, I had ChatGPT.

It is a little unsettling when your AI software seems to transform itself on your computer while you are not looking. But welcome to the modern age of artificial intelligence.

Let me explain what happened.

I have been a ChatGPT user from way back. I even gave my original ChatGPT assistant a name: “Doc.” She was impressive and enormously helpful, especially in those early days when conversational AI still felt almost magical.

More recently, however, I began using Codex.

Codex was initially presented as OpenAI’s specialized agent for software development. But I found it useful for much more than writing code. Codex works through assignments in a structured way. It can examine files, use tools, follow a sequence of steps, test its work and revise the result. Most importantly for me, it tends to follow the same logical path that I use myself.

That difference matters.

Traditional ChatGPT often feels like a very knowledgeable conversational partner. Codex feels more like a collaborator working through a process. As someone whose thinking has been shaped by accounting, technology and business systems, I found Codex’s approach more natural, and, for my purposes, more powerful.

So when it seemed to disappear, I noticed immediately.

As it turns out, Codex had not really vanished. OpenAI had introduced a new unified ChatGPT desktop application that brings several different AI experiences into one workspace.

The familiar Chat experience remains available for questions, brainstorming, writing and quick conversations. ChatGPT Work is designed for longer assignments involving research, files, connected tools and completed deliverables such as documents, spreadsheets, presentations, reports and websites. Codex remains the specialized environment for software development, technical work and structured assignments involving local files and tools.

In other words, my assistant had not been taken away. The rooms had been rearranged, the sign on the building had changed, and Codex had moved into a much larger home.

The initial surprise gave way to curiosity. I began exploring the new interface and, so far, I love it. Instead of treating conversation, research, document creation and technical execution as unrelated activities, the new workspace begins to connect them.

That is a meaningful change in how we work with AI.

A conventional chatbot waits for a question and returns an answer. A workspace can remain connected to a project, gather information, work across approved files and tools, produce a finished result and continue when the user returns. The interaction begins to feel less like consulting a reference source and more like collaborating with an assistant.

There are still important distinctions within the new application. If I want a quick answer or an informal conversation, I can use Chat. If I want research developed into a polished business deliverable, I can use Work. When I want the disciplined, step-by-step working style I have come to appreciate, I can use Codex.

Bringing these capabilities together may also make advanced AI more approachable. Many businesspeople would never think to open a product described as a coding agent. Yet the underlying ability to examine evidence, follow instructions, use tools and verify a result is valuable far beyond software development. Accountants, analysts, consultants, engineers and other process-oriented professionals may recognize that style of work immediately.

The transition was not flawless from my perspective. Software that changes overnight can leave users wondering what happened, particularly when a familiar tool has become part of their daily routine. An explanation presented before, or at least during, the transition would have made the experience less disorienting.

Nevertheless, the result is promising.

My Friday began with a simple and slightly alarming question: Where did my AI assistant go?

The answer was that it had not gone anywhere. Codex was still there, now joined by Chat and Work inside a unified ChatGPT workspace.

In the rapidly changing world of AI, even our assistants may move while we are not looking. This time, mine appears to have moved into a better office.