According to a report by LayerX Security, employees regularly paste sensitive corporate data into AI chatbots, often through personal and unmanaged accounts that bypass internal company security controls.
As much as 77 percent of Internet access to large language models refers to ChatGPT, while approximately 18 percent of employees in companies enter data into generative AI tools. More than half of these entries contain confidential business information, reports ICT Business.
And this can lead to the leakage of corporate data. And this through AI tools can cause serious geopolitical consequences, regulatory and compliance problems, and lead to corporate data being used unauthorizedly to train artificial intelligence if it is exposed through employees’ personal accounts.
The report’s findings point to an increasingly pronounced identity and data management crisis within corporate environments. LayerX collected the data by analyzing telemetry from employee browsers in global organizations, where it was determined that 45 percent of users in enterprises are actively using generative AI platforms, and even 43 percent of them use ChatGPT exclusively.
The research also shows that generative AI tools have become the main channel for transferring corporate data into personal settings, responsible for 32 percent of all unauthorized information transfers.
Nearly 40 percent of files uploaded by employees contain personal identification or payment card information, while 22 percent of text entries include sensitive regulatory information. For companies operating under regulations such as GDPR, HIPAA, or SOX, such exposure poses a serious risk of regulatory violations and loss of trust.
LayerX researchers found that most risky interactions with AI tools occur through unmanaged browsers and personal accounts that are completely outside the control of identity management systems. As much as 71.6 percent of access to generative AI tools takes place through non-corporate accounts, and a similar pattern was observed with other large SaaS platforms such as Salesforce, Microsoft Online and Zoom.
What makes the whole problem particularly dangerous is the fact that most of the transmission of confidential data occurs through simple and everyday user behavior – copying and pasting content. Users who regularly paste text into generative AI tools do so an average of 6.8 times per day, and more than half of those actions involve confidential company data.
Such a manual but invisible process completely bypasses traditional protection systems such as data loss prevention systems, firewalls and access controls. Malicious actors and data aggregators can exploit these vulnerabilities in a number of ways – from training their own AI models based on exposed data, to targeting specific industries through compromised code, credentials or proprietary business processes.
In a world where information has become the most valuable asset, such failures can have long-term consequences for the business reputation and security of entire sectors.
In order to protect organizations from data leaks and attacks related to artificial intelligence, experts advise introducing a multi-layered approach to security that includes protecting user interactions, but also strengthening the infrastructure itself. This implies the establishment of centralized access controls based on the principle of least privileges, as well as mandatory authentication through single sign-on.
Organizations should continuously monitor browsers and endpoints to monitor data flows and prevent unauthorized use of AI tools or information leakage. It is necessary to further strengthen AI systems and application interfaces through segmentation, validation and filtering of queries, thus preventing malicious manipulation of entries.
It is also important to constantly monitor the working environment and recognize anomalies, unauthorized activities and attempts to retain access to systems. Establishing a robust AI governance and security posture monitoring system enables organizations to monitor their AI resources, assess risks, and implement regulatory-compliant security policies.
In addition to technical measures, employee education on the safe use of AI tools plays a key role in data protection. Employees should be clearly warned about the risks of data sharing and prompt manipulation, as human error remains the weakest link in any security system.
Security teams should regularly conduct forensic analysis of browser logs and network traffic to detect potential AI-related incidents in a timely manner and ensure that plans to respond to such incidents are up-to-date and effective.
A report by LayerX Security presents a worrying picture of today’s digital reality, where the application of artificial intelligence in enterprises is advancing faster than the establishment of clear security frameworks.
(Vijesti.ba)



