Employees Are Using AI at Work: What Company Data Are They Sharing?


September 10, 2026

Introduction

Employees don't set out to leak company data. They're trying to close a deal faster, get through a stack of CVs, or fix a bug before standup. AI tools make all of that easier, which is exactly why they've become the fastest-growing, least-visible channel for sensitive company information leaving the business.


We've written before about shadow AI, the unapproved apps, extensions and personal accounts employees bring in on their own. This piece goes a level deeper, into the specific mechanics of AI data leakage: what actually gets typed, pasted and uploaded in an ordinary working day, why it happens even at well-run companies, what security teams can and can't see when it does, and what a sensible, non-punitive response looks like.


If you take one idea from this article, make it this: employees sharing company data with AI is not primarily a discipline problem. It's a visibility and tooling gap. Fix the gap, and the behaviour changes on its own.

The scale of the problem, in numbers

Before getting into specific scenarios, it's worth being clear about how widespread this already is — because “a few employees experimenting with ChatGPT” understates it considerably.


  • Regular AI use on corporate devices has reached 45% of employees, roughly triple the figure from a year earlier.
  • 67% of users reach public AI tools from non-corporate accounts while using a corporate device — meaning the business has essentially no contractual or administrative relationship with the account doing the work.
  • Close to two in three AI users bring their own AI tools into the workplace without asking IT first.
  • Nearly 40% of AI interactions at work involve some form of sensitive data, according to recent enterprise monitoring research.
  • Source code is consistently the single largest category of sensitive data found flowing into AI tools from corporate devices.
  • Only around a third of security leaders say they have a clear, complete picture of which AI tools their own employees are actively using.


None of this means employees are being careless. It means AI adoption has outpaced AI governance almost everywhere, and the gap between the two is where AI data leakage happens.

Everyday situations that create AI data leakage risk

Nobody schedules a meeting to “leak data to AI.” It happens inside completely ordinary tasks, across almost every department.


Sales teams uploading customer proposals. A rep drops a customer's RFP response, pricing sheet or contract draft into an AI tool to tighten the language, translate it, or summarise it for a manager ahead of a pipeline review. That document can contain a client's commercial terms, negotiated discounts, technical requirements, renewal dates and named contacts, now sitting inside a third-party system the rep signed up for individually, often with a personal email address rather than a company one.


HR summarising CVs and candidate notes. Recruiters paste candidate CVs, interview notes, references and sometimes salary history into an AI assistant to draft a summary, screen applicants at scale, or write rejection emails faster. That's personal data, covered by data protection law in most jurisdictions, being processed by a tool that was never reviewed against the company's data processing obligations, and candidates were never told about.


Developers sharing source code. Engineers paste proprietary source code, API keys, internal architecture diagrams, database schemas or entire error logs into a coding assistant to debug faster, generate tests, or get a second opinion on an approach. Source code is easy to copy, hard for anyone else to review afterwards, and often contains secrets, credentials, internal hostnames, customer identifiers, buried inside otherwise unremarkable functions.



Finance and operations building forecasts. Analysts feed spreadsheets of revenue, headcount costs or unreleased financial results into an AI tool to draft a narrative for a board pack. Unreleased financial information carries its own regulatory weight, particularly for listed companies or those preparing for a raise or exit.


Executives and assistants drafting sensitive communications. Leadership teams increasingly use AI to draft messages about restructuring, M&A activity or personnel decisions, arguably the most sensitive category of all, since it's both commercially confidential and personally consequential if it surfaces anywhere else.


The pattern across every one of these: the underlying task is completely legitimate, and the AI tool genuinely helps. The problem is what's attached to the task, customer data, personal data, financial data or proprietary IP — travelling somewhere the company never approved, reviewed or logged.

Where the risk actually comes from

“AI data leakage” isn't one problem, it's five different risk factors stacking on top of each other, often without the employee realising any of them individually, let alone all five at once.


The tool itself. Not all AI tools handle data the same way. Some enterprise-grade tools contractually exclude customer prompts from model training and offer admin-level visibility. Many free consumer tools do not, and the free tier of an otherwise-approved enterprise tool can have completely different data-handling terms to the paid version, which employees rarely check.


The account type. This is one of the biggest and least discussed factors in AI data leakage. When someone uses a personal account instead of a company-issued one, the business loses any contractual protection, audit trail or admin control it might otherwise have had, even if the underlying product is a reputable one with good enterprise terms. Personal-account usage varies hugely by tool, from around a third of usage on some mainstream assistants to well over half on others, and it's almost always invisible to IT.


Settings employees never touch. Data retention windows, model-training opt-outs and chat-history settings are usually configurable — and usually left on their defaults, because nobody goes looking for them. Most consumer AI accounts default to allowing conversations to be used for training unless someone actively opts out, which very few individuals do.


Connected apps and plugins. Browser extensions, calendar integrations and “connect your Google Drive” style plugins expand what an AI tool can see far beyond the chat box. Unauthorised AI browser extensions are common enough that the average company has a meaningful share of its workforce running at least one, and many quietly retain content from every page an employee visits.

The sensitivity of the information itself. The same tool, account and settings carry very different risk depending on whether someone pastes in a public FAQ or a signed customer contract. Categorising what actually counts as sensitive, customer data, financial data, source code, personal data, strategic information, is the piece most companies haven't done yet, which is why employees have no consistent way to judge risk in the moment.


Each factor is manageable on its own. Together, uncontrolled, they're why “employees sharing company data with AI” has become one of the fastest-moving categories of data risk that most security programmes weren't built to catch.

What security teams can see, and where the gaps are

Most security and IT teams are working with partial visibility into AI use, not none at all, and understanding exactly where that line sits is the first step to closing the gap.


Where visibility usually exists. AI tools purchased and deployed through the company typically come with admin consoles, usage logging and configurable retention controls. Web traffic to well-known AI domains is visible on the corporate network in most environments. And where endpoint or browser-based data-loss-prevention (DLP) tooling is deployed, it can often flag clearly sensitive content pasted into a web-based form, AI tools included.


Where the gaps sit. Personal accounts used on managed devices largely fall outside this picture: the traffic looks like ordinary browsing, not a policy violation, because nothing was “installed.” Mobile and personal-device use sits outside corporate monitoring altogether. Browser extensions frequently operate beneath the layer traditional DLP tools inspect, since they intercept content before it becomes a file upload or attachment. And even well-configured DLP was mostly designed to catch structured data leaving via email or removable drives, not a few unstructured sentences typed into a chat window.


The result is a visibility gap that's now well documented across the industry: a significant share of security leaders openly admit they don't have a clear picture of which AI tools their own employees are using day to day, and fewer than half of organisations have any formal programme in place for detecting unsanctioned AI use at all.


Meanwhile, in the DLP data that does exist, AI-directed activity has become one of the fastest-growing categories of non-malicious insider incidents, driven almost entirely by employees prioritising convenience and speed over policy, not by any intent to cause harm.


That gap is the subject of this article: not that employees are reckless, but that most companies still can't answer the question, “where is our sensitive data going?” whenever AI tools are involved.

How to reduce exposure without banning AI

None of this requires banning AI at work; in practice, that mostly just pushes the same behaviour further out of view, onto personal devices and personal accounts where the company has even less visibility than it started with. A more workable approach has five parts.


1. Give people an approved tool for the job they're already doing. Employees adopt AI tools because they solve a real, immediate problem faster than the alternative. If there's no sanctioned option, they will find one themselves within the hour. Approving at least one enterprise-grade AI tool per major use case — writing, coding, meeting notes, customer summarisation, with proper data-handling terms in place removes the reason to go around IT in the first place.


2. Write data-sharing rules that are specific, not generic. “Don't share confidential information with AI” is far too vague to act on in the moment an employee is deciding whether to paste something in. Effective guidance names the categories that actually matter to your business, customer contracts, personal data, source code, financial forecasts, unreleased product plans, and gives a clear yes-or-no answer for each one, tool by tool, rather than a single blanket rule everyone quietly ignores.


3. Put access controls around the highest-risk data and systems. Where AI tools connect directly to company systems, email, shared drives, CRM records, code repositories, scope those connections tightly and apply the same least-privilege thinking used for any other third-party integration.


Enterprise accounts with admin controls, single sign-on and training-data opt-outs should be the default path for every employee, with personal accounts blocked on managed devices wherever it's practical to do so.


4. Train people on the specific behaviours, not the abstract risk. General “AI security awareness” training rarely changes day-to-day behaviour, because it stays at the level of principle rather than practice. Concrete, role-based examples do, showing a salesperson exactly what to redact from a proposal before it goes anywhere near an AI tool, or telling a developer precisely what never goes into a coding assistant regardless of how proprietary the code already is, is far more effective than a generic once-a-year policy briefing.


5. Monitor usage and revisit the policy regularly. AI tools and their terms change quickly, often every few months, so a policy that was right twelve months ago may already be out of date. Building in a regular review and looking at whatever usage data is available keeps guidance grounded in what employees are doing now, not what they were doing when the policy was written.

What to do after accidental sharing, without blaming employees

Sensitive data will get shared with an AI tool at some point, even at well-run, well-intentioned companies. How the company responds in the following hour matters considerably more than how the sharing happened in the first place.


Make reporting easy and blame-free, first and immediately. If employees fear a disciplinary conversation, they simply won't report what happened, and an unreported leak is always worse than a reported one, because nobody can act on a risk they don't know exists. The first message from security or IT should be entirely about containment, not about consequences for the individual.


Establish exactly what was shared, and where. Identify the specific tool involved, the account type used (personal versus corporate), and the exact category of data shared. This single detail determines almost everything that follows, a prompt sent through a free public tool with model training enabled is a fundamentally different situation from the same content sent through an enterprise account with training disabled and a short, defined retention window.

Use the AI provider's own controls.


Most AI providers offer a mechanism to delete a specific conversation, request removal of content from training data, or close an account entirely. Enterprise and business-tier accounts typically have faster and more reliable versions of these controls than free consumer accounts do, which is one more reason to move as much usage as possible onto enterprise accounts well before any incident happens, rather than during one.


Assess exposure the same way you would for any other data incident. If personal data was involved, this may trigger notification obligations under data protection law such as UK GDPR. If customer data was involved, contractual notification clauses may apply. Loop in legal and compliance rather than treating it purely as an IT clean-up job.


Close the loop without shaming the individual involved. Once the immediate exposure is contained, use the incident, anonymised, to sharpen the specific guidance and approved-tool list described in the previous section. Employees who see that reporting a mistake leads to better tools and clearer rules, rather than punishment, are precisely the employees who will report the next near-miss too, instead of quietly hoping nobody notices.

Frequently asked questions about AI data leakage

What exactly is AI data leakage?

AI data leakage is when sensitive company or personal information, customer data, source code, financial figures, personal data, is entered into an AI tool (through typing, pasting, uploading a file, or a connected app) in a way the organisation didn't authorise, review or track. It usually happens through ordinary, well-intentioned work rather than malicious intent.


Can employers see what employees type into ChatGPT or similar tools?

Only in limited circumstances. If the company has deployed an enterprise version of the tool with admin controls, or has endpoint/browser-based DLP monitoring in place, some visibility exists. If an employee is signed in with a personal account on a personal or unmonitored device, the company typically has no visibility at all into what was shared.


Is it illegal for employees to share company or customer data with AI tools?

It depends on the data involved and the tool's terms. Sharing personal data (such as candidate CVs or customer contact details) with a tool that wasn't assessed for data protection compliance can create legal exposure under regimes like UK GDPR, independent of whether any breach or misuse ever occurs. Sharing customer data may also breach confidentiality clauses in customer contracts, even without any wider data protection issue.


How common is shadow AI use in the average company?

Very common. Recent research puts regular AI use on corporate devices at roughly 45% of employees, with a substantial majority of that usage happening through personal rather than company-issued accounts — meaning most organisations have significantly more AI activity happening than their IT and security teams are aware of.


What's the fastest way to reduce AI data leakage risk?

Start by giving employees at least one properly licensed, enterprise-grade AI tool for their most common use cases. In our experience, the single biggest driver of shadow AI use is the absence of any approved alternative — solve that first, and every other control (policy, access management, training) becomes far more effective.

See where your own exposure sits

Reading about AI data leakage in the abstract is one thing. Knowing which AI tools your employees are actually using, which accounts they're signed in with, and where sensitive company data might already be exposed right now is another.



We offer a free AI risk assessment that maps exactly that: the AI tools in active use across your organisation, how they're being accessed, and where your current visibility gaps are, so you know precisely where to focus first, rather than simply knowing the risk exists in general terms. Get in touch to book your free assessment.

Ready to strengthen your security posture? Contact us today for more information on protecting your business.


Let's get protecting your business

Disaster Recovery

Keep your data secure and protected at all times.


Cybergen News

Sign up to get industry insights, trends, and more in your inbox.

Contact Us

SHARE THIS

Latest Posts

September 7, 2026
Standard IT penetration testing can crash PLCs and trip safety systems. See the real OT failure modes and the safe SCADA testing method instead.
Hacker breaking into a laptop with a giant hook, showing a cybersecurity phishing attack.
September 3, 2026
AI phishing attacks have surged 14x and deepfake fraud has cost firms millions. Here's what every CISO needs to know in 2026, and how to defend against it.
Turquoise shield emblem with a white crowned castle on a dark blue background
September 2, 2026
What UK boards need to know about the Cyber Security and Resilience Bill, including its scope, 24-hour reporting rule, penalties and compliance steps.
Dark dashboard UI with purple glow, showing a 24/7 notification panel and task list
August 26, 2026
CISOs are closing the SME detection gap without building a SOC from scratch. See the real cost of 24/7 monitoring vs. accessing enterprise-grade protection through Cybergen.
Aerial view of a city freeway interchange with glowing blue traffic lines overlayed
August 15, 2026
Critical infrastructure organisations face increasing cyber threats. Discover how Thales security solutions help improve resilience and protect essential services.
August 11, 2026
Modern web applications are a primary attack target. Discover how CREST web application penetration testing identifies exploitable vulnerabilities before attackers do.
Glowing blue AI letters inside a neon circular digital interface
August 3, 2026
AI adoption is accelerating across organisations, increasing the need for stronger data protection, visibility, and access control strategies.
Blue digital tunnel of binary code spiraling toward a bright center
July 28, 2026
Discover why modern organisations are prioritising data security, encryption and access control to strengthen cyber resilience against evolving threats.
Glitched computer screen with pink warning triangle and static noise on a dark background
June 21, 2026
Learn how Cyber Threat Intelligence helps organisations reduce cyber risk, prioritise vulnerabilities, improve incident response and strengthen security in 2026.
Person interacting with futuristic holographic icons and touchscreen in a blue digital interface
June 11, 2026
Discover how Shadow AI, unmanaged AI usage and poor governance are creating compliance, security and data protection risks. Learn how to close the AI compliance gap and protect sensitive information.