Shadow AI: Why Companies Should Rethink the Risk of Data Leaks Through GenAI
Over the past two years, the use of generative artificial intelligence (GenAI) in companies has grown explosively. Tools such as ChatGPT, Microsoft Copilot, Google Gemini or Claude have long become part of daily work for many employees. They speed up processes, increase efficiency and open up entirely new possibilities in analysis, creativity and automation. Yet the price of this wave of innovation is becoming increasingly clear: a massive, often invisible risk to data security and corporate governance.
File Uploads: An Underestimated Problem
Several recent studies show that the use of GenAI tools regularly leads to the unintended disclosure of sensitive information. A few examples:
- Harmonic Security analysed over one million prompts and 20,000 uploaded files. Result: 22% of files and 4.37% of prompts contained confidential information, ranging from source code and M&A documents to personally identifiable information (PII).
- LayerX Security reported that almost 90% of GenAI usage happens outside controlled IT channels, a phenomenon known as “shadow AI”. Employees copy content from emails, CRM systems or internal documents directly into AI tools, on average up to four times a day.
- Netskope documented that the volume of data sent to GenAI tools grew thirtyfold within a single year, a growth rate that translates directly into higher security risk.
Files Are More Dangerous Than Prompts
While prompts often contain confidential text, file uploads carry a considerably greater risk. PDFs, spreadsheets and Word documents carry highly sensitive data. According to Harmonic Security, 79% of credit card leaks and 75% of customer profile leaks were caused by file uploads. On average, each company studied uploaded more than one gigabyte of files to GenAI tools, with no control over where that data is processed or stored.
Invisible Usage: Shadow AI
A central risk is that many GenAI applications are used without any control. This often involves free versions or AI features embedded within SaaS tools, for example in Canva, Grammarly or DeepL. These are not perceived as AI tools in daily use, yet they still process highly sensitive content, escaping conventional security and compliance mechanisms.
An increasingly critical point: according to Harmonic, almost 8% of employees already use Chinese GenAI tools such as DeepSeek or Baidu Chat. These applications often sit outside regulatory control and significantly raise the risk of data leakage and industrial espionage.
Mounting Pressure on Governance
The numbers are clear: companies are steadily losing control over which data flows into GenAI systems. Blocking applications falls short, because AI functions are now deeply embedded in standard software. Raising employee awareness alone is not enough to solve the problem either.
IT governance needs to be realigned:
- Data-centric controls: companies must monitor not only which tools are used, but above all which types of data flow into those tools.
- Creating transparency: without full visibility into GenAI usage, risk cannot be managed. This applies equally to seemingly harmless SaaS applications with built-in AI features.
- Context-dependent policies: not every data field is equally critical. Governance must recognise whether it involves source code, financial data, PII or internal strategy documents, and respond accordingly.
- Contracts and policies: companies should ensure their data is not used to train third-party models. Clear contractual terms with vendors are essential.
Possible Solutions
For decision makers, the task is not only to recognise risk, but to respond to it in a structured, systematic way. Several product-independent approaches stand out:
- Clear company policies: set binding guidelines on which types of data may and may not be processed with GenAI tools. These rules should be communicated across all departments and reviewed regularly.
- Training and awareness: raise employee awareness of shadow AI and data leak risks on an ongoing basis. Practical training and concrete examples work better than theory alone.
- Risk assessment in business decisions: when introducing any new technology or tool, weighing data protection, compliance and information security risk should be a fixed part of the decision process.
- Strengthening company culture: foster a culture where responsible handling of data is second nature. Security should not be perceived as an obstacle, but as a precondition for sustainable success.
- Regular audits: regardless of specific products, regular reviews should take place to ensure policies are followed and new risks are identified early.
- Board-level monitoring: GenAI security should become a fixed item on board and executive team agendas. Only then does it remain part of strategic oversight.
AI Agents: The New Risk
A further challenge comes from the use of autonomous AI agents. Studies by SailPoint and Dimensional Research show:
- 82% of companies studied already use AI agents for automation.
- 23% of IT professionals report that agents were successfully manipulated into disclosing credentials.
- 80% observed unexpected, potentially harmful actions.
This makes clear that as AI systems gain autonomy, new attack surfaces emerge that conventional security measures cannot cover.
The Strategic Dimension
For boards and executive teams, this means GenAI security is not merely a technical question, but a strategic challenge. It concerns the protection of intellectual property, data protection (GDPR, the Swiss nDSG and similar laws), regulatory compliance and, ultimately, competitiveness.
Three dimensions matter:
- Strategy: companies need a clear policy on GenAI use, covering which tools are permitted, how they may be used, which data may be processed and which safeguards apply.
- Technology: DLP, AI usage control and continuous monitoring must become part of the security architecture.
- Culture: employees must be enabled to use GenAI responsibly. Only through education and awareness can the tension between innovation and security be managed.
Summary and Recommendations
GenAI has secured a firm place in the corporate world in a short time, both as part of official work processes and through hidden use that circumvents security barriers. Blocking GenAI and related services such as Canva, Grammarly or DeepL cannot prevent their use. In many cases it makes the security problem worse, because access shifts to personal devices instead.
Its use carries substantial risk for data protection, compliance and intellectual property. Studies show clearly that file uploads, uncontrolled use (“shadow AI”) and autonomous AI agents create new attack surfaces that conventional security measures do not adequately cover.
Recommendations for Executive Teams and Boards
- Strengthen governance: establish clear policies for handling sensitive data in GenAI tools.
- Create transparency: systematically track GenAI usage and report on it regularly.
- Introduce risk-based controls: use data classification and context-dependent approvals.
- Enable employees: establish training programmes that promote the safe use of GenAI.
- Expand the board agenda: anchor GenAI security as a fixed item in oversight and board meetings.
Companies can only capture the opportunities of GenAI safely if they protect their data effectively. Technology alone is not enough. Only the coordinated interplay of governance, processes, culture and technology creates a resilient level of security.
Sources:
- Harmonic Security Blog: GenAI Data Exposure Report Q2 2025
- LayerX Security: LayerX Security Report, The Hacker News, 27 February 2025
- Netskope: Netskope, Cloud and Threat Report: Generative AI 2025
- Palo Alto Networks: GenAI’s Impact: Surging Adoption and Rising Risks in 2025
- Menlo Security: How AI is Shaping the Modern Workspace 2025
- Axios: Workers are spilling secrets to chatbots
- Techradar: How AI resurrected an unsolved security problem: data sprawl
- Knostic: GenAI Security Statistics