Policy

Unsecured ChatGPT and Gemini Use Exposes Corporate Data

With over 70 percent of employee ChatGPT activity occurring on personal accounts, enterprises are facing massive data leaks that legacy security tools cannot detect.

Unite.AI1 day agoPolicy
Image: Unite.AI

Recent research highlights a massive shift toward shadow AI in the workplace, where employees use unauthorized personal accounts for work tasks. Specifically, 73.8% of employee engagement with OpenAI's ChatGPT occurs on noncorporate accounts. This trend is even more pronounced for Google's models, with personal account usage reaching 94.4% for Gemini and 95.9% for Bard. Because legacy data loss prevention (DLP) tools only monitor file downloads and email attachments, they completely miss when employees copy and paste sensitive information directly into browser-based AI prompts. This blind spot is highly risky, as third-party solutions are responsible for 55% of all AI failures.

The real-world consequences of these security gaps are severe. In April 2023, Samsung allowed its staff to use ChatGPT, only to experience three separate leaks of highly confidential data within just 20 days. Employees pasted proprietary semiconductor database source code to check for errors, uploaded code designed to identify equipment defects, and submitted recorded meeting transcripts to generate minutes. Because public AI models train on user inputs, Samsung could not retrieve the leaked intellectual property and ultimately banned the tool entirely.

To mitigate these risks, organizations are turning to AI-driven threat detection and centralized data governance. Artesia General Hospital addressed its security limitations by deploying Darktrace technology. Instead of relying on static rules, Darktrace's Cyber AI Analyst learns normal network behavior to flag anomalies, successfully reducing daily security alerts from 100 benign notifications to just two or three critical incidents. Similarly, insurance firm AXIS Capital secured its siloed systems by standardizing reference hierarchies, such as the North American Industry Classification System and Standard Industrial Classification codes, creating a single secure source of truth.

For security practitioners, these developments show that traditional DLP is no longer sufficient. To safely leverage generative AI, companies must implement active, browser-level monitoring and enforce strict internal access controls. Standardizing data permissions ensures that even approved internal AI tools do not accidentally expose sensitive HR files or financial records to unauthorized staff.

This is our own summary of reporting by Unite.AI

More in Policy