Shadow AI: Employees Are Leaking Sensitive Data Through ChatGPT Without Realising It
Employees across organisations routinely paste sensitive data — including PII, API keys, proprietary code, and confidential client documents — into public AI tools like ChatGPT to solve work problems faster, a practice known as shadow AI. Because such requests appear to network monitors as ordinary encrypted web traffic, traditional data loss prevention tools typically fail to detect or flag the leaks. A widely cited incident involved engineers pasting proprietary source code into ChatGPT, with the data becoming permanently unrecoverable and going undetected by security systems. Security experts warn that simply banning AI tool usage is ineffective, as employees tend to circumvent restrictions using personal devices or accounts, making the problem harder to monitor. The recommended approach combines an approved, organisation-controlled AI pathway, a clear and concise usage policy, and active detection mechanisms to make data governance enforceable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in