The typical organisation needs to manage just six GenAI applications in order to eliminate 92.6% of their potential data exposure according to new research of 22.4m prompts in 2025 by Harmonic Security.
ChatGPT led the pack with 71.2% of data exposures, despite only accounting for 43.9% of the 22.4m prompts. Microsoft Copilot (2.9%) of use and Gemini (3.2% ) also have disproportionate usage to risk ratios but on a smaller scale.
While most of the exposure occurred via business-provided tools, 17% of all exposures occurred via personal or free accounts where IT has zero visibility, no audit trails, and data may train public models. Of the 98,034 sensitive instances, the vast majority (87%) occurred via ChatGPT Free with Google Gemini 5,935 (6%), Microsoft Copilot 3,416 (3.5%), Claude 2,412 (2.5%) and Perplexity 1,245 (1.3%) making up the bulk of the rest.
Standard tools, like Cloud Access Security Brokers (CASBs), struggle to differentiate between types of accounts and often rely on a broad blocking approach.
Even the long tail of 600+ applications, however, provides a complex governance challenge. Rudimentary blocking approaches will look to block all data exposures risks, which can include sensitive data uploaded to high-usage AI embedded tools like Canva, Google Translate, Grammarly and Gamma.
Simply blocking these sites would cause significant organisational friction, so attempted controls are often abandoned.
Of the 22.4m prompts, 579k (2.6%) contained company-sensitive data. However, the type of data exposed is the final significant hurdle; most of it is highly unstructured and challenging to detect. Code, with 30% of data exposures was the leading risk, followed by legal discourse (22.3%), M&A data 12.6%, financial projections (7.8%), and investment portfolio data (5.5%) made up the top 5 with access keys, PII, and sales pipeline amongst others.
Recommended reading
- 82% of Firms Say the Exposure Management Gap is Widening
- Economic Turmoil Tops AI As Leading Emerging Risk of Q3 2025
- CEOs Bracing For An Explosion of Cyber-Fraud in 2026, Finds WEF
Alastair Paterson, CEO and co-founder of Harmonic Security comments: “Regulating access to the ‘big six’ GenAI apps can mean organisations take a giant step towards controlling their overall AI data exposure. ChatGPT in particular needs to be tightly controlled with a data exposure risk far greater than its use. But, critically, blocking isn’t the answer.
“There are multiple ways for employees to circumvent controls and organisations are at risk from missing out on the huge productivity benefits AI can provide.
“Organisations need to move to enablement whereby employees are given access to the best GenAI options for their business but with oversight whereby employees are warned and / or blocked from uploading sensitive information. This is a fast-moving area, just because six dominate there are 661 tools we found to be in use which includes specialised coding assistants, domain-specific tools, and AI features embedded in existing tools. Four percent of usage also came from China-based apps which have no oversight at all.
“The businesses who win tend to focus first on the ‘big six’ initially but lean into the long tail with fine-grained data controls.”





