AI Is Putting Critical Business Data at Risk

AI

‍AI is becoming part of everyday work faster than many organizations can govern the data moving through it.

Employees are using public AI tools, enterprise copilots, embedded SaaS features, coding assistants and AI agents to complete real work. Netskope reported that 94% of organizations were using generative AI applications in 2024, up from 81% one year earlier. The average organization used 9.6 generative AI applications, while the percentage of employees using them tripled during the year. (Netskope)

Each of these tools creates a new path for customer information, contracts, pricing, source code, employee records and intellectual property to be submitted, retrieved or exposed.

That creates the central business challenge: enabling AI productivity without losing control of critical business data.

AI Creates a New Data Movement Problem

‍AI interactions often feel informal, but the underlying activity is not.

A prompt can transmit confidential context. An uploaded spreadsheet can expose customer or financial data. A connector can allow AI to search cloud storage, email or internal systems. An agent can retrieve information and take action across several applications.

The business may not know which model received the data, where it was processed, how long it was retained, whether it was used beyond the immediate request or whether the activity can be reconstructed later.

AI has become another data path that must be governed alongside email, cloud applications, endpoints, collaboration platforms and third parties.

The Risk Extends Beyond Shadow AI

Shadow AI remains an important warning sign because personal accounts, browser extensions, department-purchased applications and unreviewed tools may operate outside normal visibility and contractual protections.

The issue is already widespread. A Gartner survey of 302 cybersecurity leaders found that 69% of organizations suspected or had evidence that employees were using prohibited public generative AI tools. Gartner predicts that more than 40% of enterprises will experience a security or compliance incident linked to unauthorized Shadow AI by 2030. (Gartner)

But sanctioned AI can also create similar exposure.

Approval may improve administration, identity integration and vendor terms, yet risk remains when prompts and files are unrestricted, connectors reach too much data, permissions are not carried through, retention is unclear or outputs reveal information the user should not receive.

The issue is therefore not simply whether an AI tool is approved. It is whether the organization can control what data AI can receive, retrieve, retain and reveal.

Critical Data Determines the Business Consequence

The risk becomes material when AI touches information that creates customer trust, contractual obligations, regulatory exposure or competitive advantage.

Customer and employee information can create privacy and legal issues. Contracts, pricing and financial forecasts can weaken negotiating positions. Source code, product plans and proprietary processes can expose intellectual property and security weaknesses.

These are no longer hypothetical concerns. Microsoft’s 2026 Data Security Index found that generative AI was involved in 32% of the data security incidents reported by surveyed organizations. (Microsoft)

Once that information moves into the wrong workflow, the organization may be unable to recover it, prove how it was handled or determine who else could access it.

The result can include investigation costs, compliance obligations, customer distrust, reputational damage and loss of competitive advantage.

Policy and Approval Need Enforceable Controls

Policies establish expectations, but they cannot inspect a prompt, identify sensitive content in an upload, restrict an over-permissioned connector or stop confidential information from appearing in an output.

Approval alone cannot perform those functions either.

Effective protection requires a control model that considers the user, application, data, connected systems and business context. Depending on the situation, the organization may allow the activity, coach the user, redact sensitive information, block the transaction or redirect the work to a more controlled environment.

Governance defines what should happen. Technical and operational controls help make those expectations enforceable.

From Visibility to Control

Effective AI security starts with understanding where AI is being used, what critical data is involved and how exposure could occur. That understanding should lead to a practical control model rather than a broad policy statement or an automatic ban.

Discover AI Use

Identify public AI tools, enterprise platforms, embedded features, personal accounts, browser extensions, model APIs, connected applications and agents. Discovery should be continuous because AI capabilities are being added to existing software as quickly as new tools are introduced.

Prioritize Critical Data

Define the information that would create the greatest business consequence if exposed.

This may include customer data, employee information, contracts, pricing, financial data, source code, regulated records, product plans and intellectual property.

Assess AI Applications and Workflows

Review how each tool or workflow handles prompts, files, connected data, permissions, retention and generated outputs. Distinguish approved, restricted and prohibited use based on business value, contractual protections and the sensitivity of the data involved.

Apply Controls at the Point of Use

Protect information as it enters or leaves an AI workflow. Depending on the data and context, the organization may allow the activity, coach the user, redact or mask sensitive content, block the transaction or redirect the work to a more controlled environment.

Protect Sanctioned AI

Enforce identity, least-privilege access, connector governance and existing permissions inside enterprise copilots, internal knowledge tools, custom applications and agents. ‍Approval should establish the beginning of control, not the end of the review.

Monitor and Improve

Track adoption, new applications, policy violations, recurring exposure patterns and the effectiveness of controls. ‍Use those findings to refine policies, improve approved services and expand AI use where business value and risk can be managed together.

Emerging Solutions That Can Help Today

Organizations do not need to wait for one fully mature AI security platform before taking action. Many existing security technologies are being extended with AI-specific capabilities that can provide meaningful protection across both unmanaged and sanctioned AI use.

The control gap remains significant. Microsoft reported that only 47% of surveyed organizations were implementing security controls specifically designed for generative AI. At the same time, 32% of reported data security incidents involved the use of generative AI tools. (Microsoft)

That gap does not mean practical protection is unavailable. It means organizations need to determine which existing and emerging capabilities can address their most immediate exposures.

Discover and Classify AI Applications

Secure web gateways, cloud access security brokers and security service edge platforms can identify many generative AI applications being accessed from corporate users and devices.

These tools can help distinguish between approved and unapproved services, assess application risk and control access based on factors such as the user, device, application and activity.

This gives the organization a more reliable view than relying only on employee surveys or policy acknowledgments.

Inspect Prompts, Pasted Text and Files

Data loss prevention controls can inspect supported prompts, pasted text and file uploads for sensitive information.

Depending on the platform and policy, the organization may be able to detect customer records, financial information, regulated data, source code, credentials and other classified information before it leaves the managed environment.

When sensitive content is detected, the system may warn the user, request justification, redact information, block the transaction or direct the employee to an approved AI service.

Reduce Exposure Inside Sanctioned AI

Approved AI environments can also benefit from monitoring, data classification, identity enforcement and data loss prevention.

Security controls may help identify sensitive information being used in prompts or generated responses, investigate risky interactions and apply existing policies to enterprise copilots, internal knowledge tools and supported agents.

This helps address the misconception that an enterprise license automatically makes every AI workflow safe.

Identify Overshared Data and Excessive Access

Data security posture management tools can identify sensitive files with overly broad access, excessive permissions, missing classifications and repositories that may be available to copilots or agents.

This can reduce exposure before the AI system retrieves the information.

Rather than focusing only on what users type into a prompt, the organization can also reduce the amount of sensitive data available to the AI workflow in the first place.

Govern Connectors, APIs and Agents

Identity and access management, privileged access controls and application governance remain central to AI security.

These controls can help limit which users, connectors, plug-ins, APIs and agents can reach critical systems and data.

AI should not gain access to information or actions that the user would not be permitted to access directly.

Agents may require additional controls because they can retrieve information and take action across multiple applications. Higher-risk actions may require narrow permissions, runtime monitoring or human approval.

This need is becoming more urgent as agent adoption expands. Microsoft reported that more than 80% of Fortune 500 companies were already using AI agents, while 29% of surveyed employees said they had used unsanctioned agents for work tasks. (Microsoft)

Support Monitoring and Investigation

Security monitoring and investigation tools can record AI application use, sensitive-data events, policy violations and other relevant activity.

That evidence can help security, compliance and business leaders determine:

·         Who used the application

·         Which data or systems were involved

·         Which policy was triggered

·         Whether the activity was allowed, coached or blocked

·         Whether the incident was isolated or part of a recurring pattern

Coverage is not complete across every application, traffic path, device or deployment model. These solutions also do not replace governance, accurate data classification or sound access design.

They do, however, make it possible to reduce meaningful AI data risk today while a broader security and governance program matures.

The Path Forward

AI will continue moving deeper into everyday work.

The organizations positioned to benefit will be those that can support useful AI without allowing critical information to move beyond appropriate boundaries.

That is becoming more achievable. Existing security controls and emerging AI-specific capabilities can provide visibility, detect sensitive data, enforce policy and reduce excessive access across both unmanaged and sanctioned AI.

The priority is to move from awareness to enforceable protection—so AI can create business value without weakening the customer trust, intellectual property and information the business depends on.

Scott Michael Stevens

Scott Michael Stevens is the Managing Director of Confidence Innovation, a managed IT services and technology development firm. For over 25 years, Scott has helped private & public sector customers use innovative technology to meet complex cybersecurity, networking, and data needs. He has led product and services portfolios at Dell, Trustwave, and BMC Software that were recognized as global market leaders by industry analysts Gartner, IDC and Forrester. A US Army veteran, Scott holds a graduate degree in Business from Johns Hopkins University and currently lives in Austin, Texas.

Next
Next

When More Cybersecurity Investment Does Not Mean More Protection