Your Employees Are Using AI Every Day. Do You Know What They’re Sharing?

AI tools have landed in the workplace faster than almost any technology in recent memory. ChatGPT reached 100 million users in two months. GitHub Copilot is now standard tooling for engineering teams. Employees across every function are using AI assistants for drafting, summarizing, coding, and research, often without any explicit company policy governing how they do it.

The productivity case for AI is real. We’re not arguing against it. But the security case for understanding what’s flowing into those tools is equally real, and most small businesses haven’t built it yet.

The problem isn’t that employees are using AI. It’s that the data being sent to AI platforms is largely invisible to the companies whose data it is. Customer information, proprietary source code, financial models, internal strategy documents — these are being typed into chat interfaces and processed by external models, often with no logging, no DLP controls, and no way to know it’s happening. Our cybersecurity services page covers how we approach this as part of a broader security program.

What the Risk Actually Looks Like

The most cited public example remains instructive. In 2023, Samsung engineers accidentally leaked proprietary semiconductor source code and internal meeting notes by pasting them into ChatGPT for help with debugging and summarization. The data was processed by the model and, under OpenAI’s data practices at the time, potentially used for training. Samsung had no visibility into what had been shared and no controls to prevent it.

As the BBC reported at the time, three separate incidents occurred within weeks of each other before the company discovered the exposure. Samsung subsequently banned ChatGPT on corporate devices. That’s one option. But for most businesses, blocking AI outright means watching employees use it anyway on personal devices, with even less visibility.

The Samsung case was large enough to make headlines. The smaller version of this happens every day at companies of every size. An employee pastes a client contract into an AI tool to summarize the key terms. An HR manager feeds an AI a spreadsheet of compensation data to help draft a job description. A sales rep pastes an email thread containing deal terms and customer information into a chat interface for help with a response. None of these people are being careless. They’re using the tools available to them the way they were designed to be used.

The AI data exposure risk isn’t primarily a malicious insider problem. It’s a well-intentioned employee problem. The people sharing sensitive data with AI tools are usually trying to do their jobs more efficiently. That’s what makes it hard to solve with policy alone.

The Shadow AI Problem

Most companies that have thought about AI security have addressed the obvious platforms: they’ve set a policy about ChatGPT, or they’ve communicated something about not sharing sensitive data with AI tools. What they haven’t addressed is the full landscape of AI tools their employees are actually using.

In our experience running visibility assessments for new clients, the number of AI tools in active use across a company is almost always larger than IT or security leadership believes. The recognized tools like ChatGPT and Claude account for a fraction of the actual AI surface. There are AI writing assistants embedded in browsers, summarization tools accessed via bookmarks, specialized AI platforms for specific job functions, and productivity tools that have quietly added AI features that transmit data to external services.

Without active visibility into which AI tools are being used, by whom, and how frequently, a company’s AI security policy is effectively aspirational. It governs the tools people know about, not the ones they’re actually using.

What Proper AI Security Controls Actually Cover

The goal isn’t to prevent employees from using AI. It’s to ensure that when they do, the data flowing into those tools is appropriate, and that the company has the visibility and controls to know what’s happening and intervene when it isn’t.

Here’s what a properly implemented AI security layer provides:

Visibility into AI tool usage across the organization

A real-time inventory of every AI platform being accessed across the company: which tools, which employees, how frequently, and what types of files are being uploaded. This baseline is the prerequisite for everything else. You can’t manage what you can’t see.

Prompt logging with configurable transparency

Full logging of inputs submitted to AI platforms and the model responses returned, with configurable employee-facing notifications so people know their AI sessions are subject to review. This isn’t about surveillance. It’s about creating the same accountability that exists for corporate email. Employees generally accept it readily when it’s explained that the logging is for data protection, not performance monitoring.

In-flight PII and sensitive data redaction

The most technically sophisticated control: interception of AI-bound prompts at the browser level, before they leave the device, to detect and strip sensitive data patterns. Social security numbers, credit card numbers, source code, custom-defined key terms, specific document types. The employee’s intended prompt goes through. The sensitive data doesn’t. In many cases, the employee doesn’t notice the redaction because the context they needed for the AI response didn’t require the sensitive data to be present.

Corporate session enforcement

Ensuring employees access major AI platforms through authenticated corporate accounts rather than personal accounts. This matters because the data handling policies, training opt-outs, and enterprise-grade data protections offered by AI vendors are often only available on corporate subscriptions. An employee using their personal ChatGPT account on a company device has none of those protections. Enforcing corporate session login closes that gap.

File upload controls

Policy-enforced restrictions on which file types and categories of content can be uploaded to AI platforms. A company might permit employees to upload their own work products to an AI for editing assistance while blocking uploads of contract documents, financial data, or anything tagged as confidential.

Shadow AI blocking and redirection

The ability to block unauthorized or high-risk AI platforms entirely, while permitting access to company-approved ones. This is more nuanced than a blanket AI ban: it allows the company to maintain a managed AI environment rather than pushing usage to personal devices where there’s no visibility at all.

The goal of AI security controls isn’t to prevent AI adoption. It’s to ensure AI adoption happens within a managed environment where the company has visibility, control, and the ability to demonstrate compliance. Those aren’t competing objectives.

How This Fits Into a Broader Security Program

Browser-level AI security controls are one layer of a complete security posture, not a standalone solution. They work alongside:

  • MDM and endpoint security. Device-level controls that ensure the machines accessing AI tools are enrolled, encrypted, patched, and managed.
  • Google Workspace security hardening. For companies running Workspace, ensuring that Workspace’s own AI features (Gemini, summarization, data analysis) are governed by appropriate organizational policies.
  • Access control and offboarding. Ensuring that when an employee leaves, their access to AI platforms under corporate accounts is revoked alongside their access to other company systems.
  • Security awareness training. Employees who understand why AI data handling policies exist are far more likely to follow them than employees who receive a policy document without context.

We’ve been building layered security programs for Bay Area companies for 28 years. The AI security layer is new. The principle behind it is the same one that has always governed data security: you need visibility before you can have control, and you need control before you can have compliance.

Frequently Asked Questions

What are the biggest AI security risks for businesses in 2026?

The most significant risks are unmonitored data leakage into AI platforms (employees sharing proprietary or sensitive information without realizing it constitutes a data exposure), shadow AI usage through tools IT isn’t aware of, employees using personal AI accounts rather than corporate ones with appropriate data protections, and the absence of any audit trail for what data has been submitted to external AI services.

Can you prevent employees from sharing sensitive data with AI tools?

Yes, with the right controls in place. Browser-level DLP can detect and redact sensitive data patterns from AI-bound prompts in real time, before they leave the device. This covers common patterns like credit card numbers, SSNs, and source code, as well as custom-defined terms or document types specific to your business. The control operates transparently: the employee’s prompt goes through, the sensitive content is stripped.

How do you get visibility into which AI tools employees are using?

Browser-level visibility tools can inventory every AI platform accessed across the organization in real time, including platforms IT wasn’t aware of. The dashboard shows which tools are in use, which employees are using them, upload activity, and time spent. This baseline is typically the first thing we establish when clients engage us for AI security, because it reveals a significantly larger AI surface than most leadership teams expect.

Is logging employee AI prompts a privacy issue?

This is the question that comes up in almost every client conversation about AI security. The answer: prompt logging is comparable to corporate email logging, which has been standard practice in regulated industries for decades. The key is communication. Employees who are told clearly that their AI sessions on company systems are logged for data protection purposes, and who understand that the goal is protecting company data rather than monitoring their performance, generally accept it as reasonable. Configurable transparency banners that notify employees of logging at their chosen cadence help significantly.

How does AI security fit with SOC 2 or FINRA compliance?

AI data governance is an increasingly scrutinized area in compliance audits. SOC 2 requires demonstrable controls around how sensitive data is accessed and transmitted. FINRA requires firms to surveil and retain records of business communications, which regulators are beginning to interpret as extending to AI-assisted communication. Prompt logging, DLP controls, and shadow AI visibility all produce audit-relevant evidence of responsible AI data governance. Getting these controls in place now positions companies well for the compliance requirements that are still being written.

The question isn’t whether your employees are using AI. They are. The question is whether the data flowing into those tools is under any kind of organizational governance. For most small businesses right now, the honest answer is no. That’s a fixable problem, and the window to fix it proactively is still open.

Rating 5 stars.
Ignition (Laramie M) was super responsive -- I got an appointment right away and the issue was resolved in under 15 minutes. What could have been a frustrating process was seamlessly resolved. Thank you! Your company is very popular in our office!
Olivia Sears
President
Center for the Art of Translation
Noam Birnbaum
Founder & CEO
Your Employees Are Using AI Every Day. Do You Know What They’re Sharing?

Before founding Ignition, Birnbaum built his career inside the IT teams of Fortune 500 companies, major universities, and small businesses, starting his first consultancy, MacCentric Solutions, at age 23. He holds two master’s degrees and studied at Oberlin College. Today, he focuses on managed IT, cybersecurity, SOC 2 compliance, mobile device management, and helping venture-backed companies scale their IT infrastructure without the overhead of an in-house team. He has spent more than three decades responding to cyber incidents — from the Blaster and MyDoom worms to modern ransomware and breach response — and regularly advises media on topics including small business cybersecurity, remote workforce security, MDM strategy, and IT for startups. Birnbaum has served on the Board of Directors of Temple Beth Abraham in Oakland and the Entrepreneurs Organization.

More About
Noam Birnbaum

Join the Ignition IT Family

Make every workday more productive. Transform your IT from an annoying challenge into your competitive edge.