{
  "access": {
    "embargo": {
      "active": false,
      "reason": null
    },
    "files": "public",
    "record": "public",
    "status": "open"
  },
  "created": "2026-01-27T10:18:07.350698+00:00",
  "custom_fields": {},
  "deletion_status": {
    "is_deleted": false,
    "status": "P"
  },
  "files": {
    "count": 1,
    "default_preview": "Shadow AI and Prompt Injection.pdf",
    "enabled": true,
    "entries": {
      "Shadow AI and Prompt Injection.pdf": {
        "access": {
          "hidden": false
        },
        "checksum": "md5:16cd579718d2d8f94bf470b2e51b7708",
        "ext": "pdf",
        "id": "f35195e3-78b2-47a3-8060-009c9704fbbf",
        "key": "Shadow AI and Prompt Injection.pdf",
        "links": {
          "content": "https://zenodo.org/api/records/18385897/files/Shadow%20AI%20and%20Prompt%20Injection.pdf/content",
          "iiif_api": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/full/0/default.png",
          "iiif_base": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf",
          "iiif_canvas": "https://zenodo.org/api/iiif/record:18385897/canvas/Shadow%20AI%20and%20Prompt%20Injection.pdf",
          "iiif_info": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/info.json",
          "self": "https://zenodo.org/api/records/18385897/files/Shadow%20AI%20and%20Prompt%20Injection.pdf"
        },
        "metadata": {
          "height": 792,
          "width": 612
        },
        "mimetype": "application/pdf",
        "size": 8145325,
        "storage_class": "L"
      }
    },
    "order": [],
    "total_bytes": 8145325
  },
  "id": "18385897",
  "is_draft": false,
  "is_published": true,
  "links": {
    "access": "https://zenodo.org/api/records/18385897/access",
    "access_grants": "https://zenodo.org/api/records/18385897/access/grants",
    "access_links": "https://zenodo.org/api/records/18385897/access/links",
    "access_request": "https://zenodo.org/api/records/18385897/access/request",
    "access_users": "https://zenodo.org/api/records/18385897/access/users",
    "archive": "https://zenodo.org/api/records/18385897/files-archive",
    "archive_media": "https://zenodo.org/api/records/18385897/media-files-archive",
    "communities": "https://zenodo.org/api/records/18385897/communities",
    "communities-suggestions": "https://zenodo.org/api/records/18385897/communities-suggestions",
    "doi": "https://doi.org/10.5281/zenodo.18385897",
    "draft": "https://zenodo.org/api/records/18385897/draft",
    "file_modification": "https://zenodo.org/api/records/18385897/file-modification",
    "files": "https://zenodo.org/api/records/18385897/files",
    "latest": "https://zenodo.org/api/records/18385897/versions/latest",
    "latest_html": "https://zenodo.org/records/18385897/latest",
    "media_files": "https://zenodo.org/api/records/18385897/media-files",
    "parent": "https://zenodo.org/api/records/18385896",
    "parent_doi": "https://doi.org/10.5281/zenodo.18385896",
    "parent_doi_html": "https://zenodo.org/doi/10.5281/zenodo.18385896",
    "parent_html": "https://zenodo.org/records/18385896",
    "preview_html": "https://zenodo.org/records/18385897?preview=1",
    "quota_increase": "https://zenodo.org/api/records/18385897/quota-increase",
    "request_deletion": "https://zenodo.org/api/records/18385897/request-deletion",
    "requests": "https://zenodo.org/api/records/18385897/requests",
    "reserve_doi": "https://zenodo.org/api/records/18385897/draft/pids/doi",
    "self": "https://zenodo.org/api/records/18385897",
    "self_doi": "https://doi.org/10.5281/zenodo.18385897",
    "self_doi_html": "https://zenodo.org/doi/10.5281/zenodo.18385897",
    "self_html": "https://zenodo.org/records/18385897",
    "self_iiif_manifest": "https://zenodo.org/api/iiif/record:18385897/manifest",
    "self_iiif_sequence": "https://zenodo.org/api/iiif/record:18385897/sequence/default",
    "thumbnails": {
      "10": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/%5E10,/0/default.jpg",
      "100": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/%5E100,/0/default.jpg",
      "1200": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/%5E1200,/0/default.jpg",
      "250": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/%5E250,/0/default.jpg",
      "50": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/%5E50,/0/default.jpg",
      "750": "https://zenodo.org/api/iiif/record:18385897:Shadow%20AI%20and%20Prompt%20Injection.pdf/full/%5E750,/0/default.jpg"
    },
    "versions": "https://zenodo.org/api/records/18385897/versions"
  },
  "media_files": {
    "count": 1,
    "enabled": true,
    "entries": {
      "Shadow AI and Prompt Injection.pdf.ptif": {
        "access": {
          "hidden": true
        },
        "ext": "ptif",
        "id": "6c6a7ba6-0848-4f81-955b-d3ecf9b32ef8",
        "key": "Shadow AI and Prompt Injection.pdf.ptif",
        "links": {
          "content": "https://zenodo.org/api/records/18385897/files/Shadow%20AI%20and%20Prompt%20Injection.pdf.ptif/content",
          "self": "https://zenodo.org/api/records/18385897/files/Shadow%20AI%20and%20Prompt%20Injection.pdf.ptif"
        },
        "metadata": null,
        "mimetype": "application/octet-stream",
        "processor": {
          "source_file_id": "f35195e3-78b2-47a3-8060-009c9704fbbf",
          "status": "finished",
          "type": "image-tiles"
        },
        "size": 0,
        "storage_class": "L"
      }
    },
    "order": [],
    "total_bytes": 0
  },
  "metadata": {
    "creators": [
      {
        "affiliations": [
          {
            "id": "00qmy9z88",
            "identifiers": [
              {
                "identifier": "00qmy9z88",
                "scheme": "ror"
              },
              {
                "identifier": "grid.444463.5",
                "scheme": "grid"
              },
              {
                "identifier": "0000 0004 1796 4519",
                "scheme": "isni"
              }
            ],
            "name": "Higher Colleges of Technology"
          }
        ],
        "person_or_org": {
          "family_name": "Aoudi",
          "given_name": "Samer",
          "identifiers": [
            {
              "identifier": "0000-0003-3887-0119",
              "scheme": "orcid"
            }
          ],
          "name": "Aoudi, Samer",
          "type": "personal"
        },
        "role": {
          "id": "researcher",
          "title": {
            "de": "WissenschaftlerIn",
            "en": "Researcher"
          }
        }
      }
    ],
    "description": "<p><span lang=\"EN-US\">This working paper examines Shadow AI and prompt injection as systemic governance and security challenges in enterprise AI adoption. It argues that the proliferation of unsanctioned and embedded AI capabilities, combined with unresolved vulnerabilities such as indirect prompt injection and RAG poisoning, represents a sociotechnical failure rather than a purely technical one.</span></p>\n<p><span lang=\"EN-US\">&nbsp;</span></p>\n<p><span lang=\"EN-US\">The paper provides a risk-based, governance-first framework tailored for CISOs, enterprise architects, AI governance boards, and policymakers. It explicitly acknowledges the limits of technical prevention and emphasizes architectural controls, observability, incident response, and human-in-the-loop safeguards. Key contributions include analysis of irreversible data leakage via model training, SaaS-driven &ldquo;Shadow AI by default,&rdquo; AI observability trade-offs, and operational concepts such as vector database hygiene and skeptical resilience.</span></p>\n<p><span lang=\"EN-US\">&nbsp;</span></p>\n<p><span lang=\"EN-US\">This document is intended as a decision-ready reference for enterprise AI governance and may be updated as practices, standards, and regulatory guidance evolve.</span></p>",
    "publication_date": "2026-01-27",
    "publisher": "Zenodo",
    "resource_type": {
      "id": "publication-workingpaper",
      "title": {
        "de": "Arbeitspapier",
        "en": "Working paper"
      }
    },
    "rights": [
      {
        "description": {
          "en": "The Creative Commons Attribution license allows re-distribution and re-use of a licensed work on the condition that the creator is appropriately credited."
        },
        "icon": "cc-by-icon",
        "id": "cc-by-4.0",
        "props": {
          "scheme": "spdx",
          "url": "https://creativecommons.org/licenses/by/4.0/legalcode"
        },
        "title": {
          "en": "Creative Commons Attribution 4.0 International"
        }
      }
    ],
    "title": "Shadow AI And Prompt Injection: Governance Failures In Enterprise AI Security"
  },
  "parent": {
    "access": {
      "owned_by": {
        "user": "1496884"
      },
      "settings": {
        "accept_conditions_text": null,
        "allow_guest_requests": false,
        "allow_user_requests": false,
        "secret_link_expiration": 0
      }
    },
    "communities": {},
    "id": "18385896",
    "pids": {
      "doi": {
        "client": "datacite",
        "identifier": "10.5281/zenodo.18385896",
        "provider": "datacite"
      }
    }
  },
  "pids": {
    "doi": {
      "client": "datacite",
      "identifier": "10.5281/zenodo.18385897",
      "provider": "datacite"
    },
    "oai": {
      "identifier": "oai:zenodo.org:18385897",
      "provider": "oai"
    }
  },
  "revision_id": 4,
  "stats": {
    "all_versions": {
      "data_volume": 814532500.0,
      "downloads": 100,
      "unique_downloads": 70,
      "unique_views": 76,
      "views": 91
    },
    "this_version": {
      "data_volume": 814532500.0,
      "downloads": 100,
      "unique_downloads": 70,
      "unique_views": 76,
      "views": 91
    }
  },
  "status": "published",
  "swh": {},
  "updated": "2026-01-27T10:23:08.907624+00:00",
  "versions": {
    "index": 1,
    "is_latest": true
  }
}