Site navigation

‘Shadow AI’ Use Is Threatening Enterprise Data Security

Tom Quinn

,

Ai sensitive data
Tool sprawl and poor enforcement are undermining corporate AI policies, exposing businesses to governance and compliance risks.

Employees are routinely using personal accounts to interact with AI tools at work, with sensitive content, including everything from legal documents to source code, being routed through accounts that sit outside corporate controls. 

That’s according to Harmonic Security’s latest research, The AI Tightrope: Balancing Innovation and Exposure in the Enterprise, which found almost half (45%) of sensitive AI interactions came from personal email accounts, of which more than 57% were Gmail addresses.

Harmonic’s report, based on over 176,000 AI prompts and thousands of file uploads from 8,000 enterprise users, found that 79% of all sensitive data was submitted to ChatGPT, with 21% of that going to the free tier, where prompts can be retained and used for training unless users know to opt out.

Tool sprawl is also becoming an issue, with Harmonic finding that the average company interacted with 254 distinct AI applications over the first quarter of the year, many of which as unsanctioned by employers.

The resulting in ‘shadow IT’ can see sensitive data shared with AI tools built overseas, with questionable compliance to regional data privacy laws. 

Perhaps the most concerning example Harmonic discovered is the 7% of users who accessed Chinese-based apps that have data training and retention red flags, with DeepSeek being the most popular, although newcomers like Manus, Ernie Bot and Baidu Chat were not uncommon.

The report warns that due to regulations surrounding these Chinese-based apps, any data shared with the likes of DeepSeek should be considered visible to the Chinese government, putting companies’ information in jeopardy.

The use of unrestricted public AI apps is leaving companies open to serious governance and risk issues, with Harmonic warning that while companies might assume they have their AI policies locked in place, it’s clear employees are finding workarounds to gain more AI productivity benefits without understanding the security implications. 

The study found that over 30% of sensitive prompts involved legal and financial matters, including M&A activity, investment portfolios, financial projections and sales pipelines.


Recommended reading


Meanwhile, more than 10% contained sensitive code, including access keys, however the exposure of customer data (27%) and employee data (14%) has decreased, suggesting that AI use is shifting further into core, high-value business functions, heightening the potential impact of leakage.

To mitigate the risks of employees using unsanctioned AI tools, Harmonic said that firms should move beyond policy and focus on enforcement and behaviour shaping at the point of use.

That means investing in real-time detection of sensitive data in AI prompts and file uploads, maintaining browser-level visibility and enforcement, and employee-friendly interventions that nudge users toward safer choices, rather than punishing them after the fact.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI Startups

UK Gov Launches £100M Competition for AI Startups Boosting Public Services

Robotics

Glasgow Uni Researchers Guide Future of Social Robot Design

Business

Techscaler Selects 10 Scottish Founders for Silicon Valley Programme

Cybersecurity

Manchester Airport Group Suffers Data Breach of Customer Info