Riktlinjer för Gen-AI-användning: En studie om deras roll för stärkt organisatorisk säkerhet
Ines Suhonjic, Tobias Björklund · Diva portal (Dalarna University Library) · 2026
The integration of generative AI (Gen-AI) into the workplace has occurred at a pace thathas challenged the ability of organizations to regulate its use. Previous research indicatesa lack of clear user guidelines for Gen-AI. Furthermore, where guidelines do exist, they areoften perceived as hindrances rather than support, leading to low compliance as employeesactively circumvent security policies to maintain work efficiency. This has given rise to thephenomenon of ”Shadow AI,” where employees utilize external AI tools outside of formalorganizational control, posing significant information security risks.This study examines employee attitudes toward Gen-AI and existing security guidelineswithin a large organization. Furthermore, the study explores how guidelines can bedesigned to balance security requirements with usability. The study employs a mixedmethods approach, beginning with a literature review to gain knowledge about, and toframe the study with regards to, the current situation. Following this, a quantitative survey is employed to map current usage and attitudes at a large organization, followed byqualitative semi-structured interviews with employees. Subsequently, a proposed framework for how to design user friendly guidelines are presented.The research shows that Gen-AI is here to stay but its potentials needs to be weighedagainst the risks. From the data we collected we conclude that productivity is valued highdespite contradictory attitudes towards Gen-AI. A tension exists between the importanceof guidelines and their practical limitations. These findings are concluded in a proposeduser guideline framework.