Your employees are probably already using AI tools that IT and security haven't approved. They may also be putting company data into those tools without knowing whether they're allowed to.
This isn't a future problem. It's happening right now.
That's what shadow AI means: AI tools, plugins, or agents that employees use without IT or security knowing about them.
"It's becoming a normal part of how people work."
- 1 in 5 organizations has already had a breach involving unsanctioned AI, adding roughly $670,000 to the average breach cost and a median of 247 days to detect, according to IBM's 2025 Cost of a Data Breach Report. Shadow AI isn't a future line item. It's already inside the breach-cost numbers.
- 77% of employees paste data into AI prompts, and 82% of those pastes come from personal accounts IT has no visibility into at all, per LayerX's 2025 Enterprise AI and SaaS Data Security Report.
Case studies
These incidents happened for different reasons. In one, employees bypassed company policy. In the other, a platform feature exposed data in a way people hadn't expected. But the result was the same: sensitive data ended up somewhere it shouldn't have, without the security team noticing.
Samsung: three leaks in twenty days
In early 2023, Samsung temporarily blocked employees from using generative AI tools because of concerns about sensitive data. The restriction was lifted on March 11, partly because engineers wanted access to the latest AI tools to help with their work.
- Within about three weeks of the ban lifting, an engineer copied the full source code of a semiconductor database download program into ChatGPT and asked it to find a fix, information tied directly to Samsung's chip manufacturing process.
- A second engineer uploaded code used to identify defects in semiconductor equipment, seeking optimization help from the tool.
- A third employee recorded an internal confidential meeting, ran it through a transcription tool, then fed the transcript into ChatGPT to generate meeting notes.
- Under ChatGPT's terms of service at the time, anything entered could be retained and used to improve the model, with no enterprise data agreement in place to prevent it. Once submitted, that source code and those transcripts were sitting on infrastructure Samsung didn't control and couldn't delete from on demand.
- Three separate incidents, three separate teams, in under 20 days. Samsung banned generative AI tools on company devices company-wide by May 1, 2023 and started building an internal AI system with proper data controls instead.
That's what makes this case interesting. There was no attacker breaking into Samsung's network. The employees weren't trying to do anything malicious. They simply found a tool that could make their jobs easier and started using it.
ChatGPT's share feature: private conversations, public search results
This one didn't involve anyone going around IT. It involved a feature working exactly as designed, designed in a way almost nobody understood the consequences of. The chain of failures:
- ChatGPT's "Share" feature let users generate a public link to a conversation, useful for showing a colleague a result or publishing an example. A toggle labeled "Make this chat discoverable" sat alongside it.
- That toggle did more than its label suggested. Turning it on flagged the conversation for indexing by Google and other search engines, and the shared pages carried no noindex tag to stop crawlers from picking them up.
- Many users enabled it without realizing "discoverable" meant "searchable by anyone on the internet," not just "reachable by someone with the link."
- By late July 2025, researchers had found roughly 4,500 of these conversations indexed and publicly searchable. They included resumes, home addresses, names of children, workplace grievances, confidential business strategy discussions, and in at least one case a health professional's therapy chats with identifying details intact.
- OpenAI disabled the discoverability toggle on July 31, 2025, and began working with search engines to de-index the exposed pages. Cached and scraped copies remained reachable elsewhere for some time after.
No credentials were stolen and no system was hacked. A confusing checkbox did all the work. For a business, the lesson lands the same way it did with Samsung: once sensitive information reaches an AI tool's infrastructure, whether by an employee's choice or a UI element they misread, the organization no longer controls where it ends up or how long it stays reachable.
What to actually do about it
Banning AI tools completely doesn't really solve the problem. It can just push the same behavior onto personal accounts, phones, and laptops where the security team has even less visibility.
A more practical approach is to control how people use AI rather than pretending they won't use it.
Give people a sanctioned tool before you take away the unsanctioned ones. Samsung's engineers weren't being reckless, they were trying to get their work done faster. Remove the shortcut without providing an approved replacement, and the same behavior just moves further out of view.
Use business or enterprise accounts for company work. If employees are going to use ChatGPT, Claude, or another AI service, give them an organization-managed account instead of leaving them to use personal accounts. Enterprise plans can provide things like administrative controls, contractual data protections, and audit capabilities that aren't available in the same way on consumer accounts.
Monitor for AI traffic the way you'd monitor for any other data exfiltration path. DLP and network controls can help identify sensitive information being sent to known AI services. You don't necessarily need to read every prompt. Start by looking for things that should never leave the organization in the first place: source code, credentials, customer records, internal documents, and other sensitive data.
Read the terms of service before you approve a tool, every time. Don't assume every AI service treats company data the same way. Look at retention, training, logging, deletion, access, and whether the provider offers an appropriate enterprise agreement. These details matter a lot more than the name of the AI tool.
Treat every sharing or export feature as a potential public-by-default setting until proven otherwise. AI tools increasingly have features for sharing chats, generating public links, exporting files, connecting external apps, or handing data to other services. These features can create another path for sensitive information to escape. Treat them like any other external sharing mechanism and make sure people understand what happens when they use them.
Train people on what actually happens to the data. A policy saying “Don't put confidential information into AI tools” is easy to ignore. Show employees what that actually means. What happens when they paste source code? Who can access a shared conversation? Where does an uploaded document go? Can it be deleted later?
DLP for AI. Credit: Lotusfeet Consulting
The bottom line
Shadow AI isn't a future problem. It's already happening inside companies today. Employees are using AI tools that security teams haven't approved or even know about.
Samsung's leaks happened without anyone hacking them. The ChatGPT search incident also didn't involve an attacker.
In both cases, the problem was simple: people were using AI in ways security couldn't see.
The answer isn't to ban AI and hope people stop using it. The better approach is to make approved AI tools easy to use, set clear rules, and keep an eye on what other tools employees are using.
Sources
- 1 in 5 organizations has suffered a breach involving unsanctioned shadow AI, adding roughly $670,000 to average breach cost, with a median 247 days to detect. IBM, Cost of a Data Breach Report 2025
- 77% of employees paste data into GenAI prompts; 82% of those pastes come from personal accounts outside company oversight. LayerX, Enterprise AI and SaaS Data Security Report 2025
- Share of corporate data entered into AI tools that is sensitive rose from 10.7% (2023) to 27.4% (2024) to 34.8% (2025); 71.7% of AI tools employees use are rated high or critical risk. Cyberhaven, AI Adoption and Risk Report, based on a 7-million-worker dataset
- 39.7% of AI interactions expose sensitive data; 32.3% of ChatGPT usage happens through personal accounts. Cyberhaven 2026 AI Adoption & Risk Report
- Gartner predicts that by 2030, more than 40% of global organizations will experience a security or compliance incident caused by unauthorized AI tool use. Cited via Areebi's Shadow AI Statistics 2026
- Source code is the single most common data type uploaded to unauthorized AI systems, ahead of images and structured data, based on analysis of 858,440 DLP events. Verizon 2026 Data Breach Investigations Report
- Samsung: three separate confidential data leaks to ChatGPT within 20 days of lifting an internal ban (March 11 to March 30, 2023), including semiconductor source code and confidential meeting transcripts; company-wide ban on generative AI tools followed by May 1, 2023. Original reporting via Bloomberg and The Register; incident record via AI Incident Database; additional detail via Forbes
- ChatGPT's "Share" feature indexed roughly 4,500 conversations to public search engines via a "make this chat discoverable" toggle, exposing personal and business-sensitive content, before OpenAI disabled the feature on July 31, 2025. Reporting via Cybernews, Gulf News, and Bitdefender
