In March 2023, Samsung engineers pasted confidential semiconductor source code into ChatGPT to fix bugs faster. This was repeated three times within 20 days. The company banned generative AI entirely. Nobody "hacked" Samsung — the employees themselves handed over the data.

This incident is not an isolated case but a symbol of the most widespread security problem facing today's enterprises: well-intentioned employees who want to be productive paste confidential data into AI tools every day. And traditional protection systems do not see it.

The scale of the problem: the numbers

According to LayerX Security's Enterprise AI and SaaS Data Security Report 2025, 50 percent of employees admitted to pasting confidential business data into generative AI tools. Another 18 percent shared highly sensitive data — including proprietary development information. 77 percent of online LLM requests go to ChatGPT. About 18 percent of employees regularly paste data into GenAI tools, and corporate information is involved in more than half of these incidents.

Cyberhaven, tracking 1.6 million employees, found an even more alarming trend: the share of confidential data among data entering AI tools tripled in two years — from 10.7 percent to 34.8 percent. Most importantly, 82 percent of these "pastes" happen through personal accounts the company cannot see. 68 percent of employees admitted to pasting company data into AI tools without checking what they share.

The cost is also clear: according to IBM's Cost of a Data Breach Report 2025, the average cost of a single data breach is $4.88 million. A breach via AI creates additional risk — the data is stored on a third-party server, can be used in training, and cannot be retrieved.

Data leaves through three documented paths

Analysis shows that business data leaves through AI via three documented paths — in a ten-person company as well as a ten-thousand-person one.

The first path: employees hand it over themselves. The Samsung case is the most famous, but not the only one. In July–August 2025, it was discovered that the acting director of the U.S. Cybersecurity Agency (CISA) had uploaded at least four classified government documents to the public version of ChatGPT — including contract materials designated for official use. Another real case: one company executive pasted the company's entire strategy document into a chat to prepare slides. The motivation is always the same — to finish work faster.

The second path: the platform itself leaks. In February 2025, a hacker claimed to have breached the OmniGPT platform (an aggregator connecting to ChatGPT, Claude, and Gemini) and published 34 million users' chat messages. Among the samples were office projects, market analyses, and documents containing logins and passwords. In July–August 2025, researchers found about 4,500 shared ChatGPT conversations indexed in Google search — about 100,000 conversations were scraped in total, containing names, resumes, and personal data. OpenAI disabled the "discoverable sharing" feature in August 2025, but once-indexed data never fully disappears.

The third path: connected tools become the door. In June 2025, hackers entered the AI competitive-intelligence platform Klue using credentials created in 2022 and never deleted, then pulled contacts, prices, and deal records from connected companies' Salesforce systems. The attackers claimed 195 victims; among the confirmed are LastPass, HackerOne, and Huntress — meaning the security companies themselves were breached through an AI tool they trusted.

LayerX Security CEO Or Eshed described the risk this way:

"The leakage of corporate data through AI tools can raise geopolitical issues, regulatory and compliance concerns, and lead to the inappropriate use in training of corporate data disclosed through personal AI tools."

Why "banning" does not work

Some organizations chose the easiest path: banning AI tools entirely. Samsung, Apple, and JPMorgan restricted the use of ChatGPT at various times. But practice shows that when a ban is imposed, people do not give up AI — they switch to personal devices. As a result, the company loses visibility entirely, and the risk grows instead of shrinking.

In this era, the winners are not those who fight AI adoption but those who manage it smartly. The goal is not to slow employees down but to speed them up safely.

Practical guide: seven steps

1. Make a list of allowed tools. Approve not just any AI tool, but versions with a signed corporate agreement that guarantees data will not be used in training. An "allowlist" is more effective than a blocklist, because new tools appear every week.

2. Require enterprise mode and "zero retention" terms. Major AI providers offer corporate clients modes in which requests are not stored and not used in training. Lock this into the contract as a written guarantee — a verbal promise is not enough.

3. Classify the data. Introduce a simple three-color system: "red" — never entered (personal data, financial reports, source code, contracts); "yellow" — entered only after anonymization; "green" — free to use (open marketing texts and the like). Every employee must know which category applies to their work.

4. Make anonymization a habit. Before contacting AI, mask or generalize names, account numbers, addresses, and other identifiers. For many tasks, "client A" and "company B" are enough — the model does not need real names.

5. Put controls at the prompt level. Traditional DLP (data loss prevention) systems monitor email and file transfers but cannot see what is typed into a chat window in the browser. Modern solutions work exactly at the prompt level: if confidential data is detected, they warn or block.

6. Train employees with real examples. A dry policy document does not work — show the Samsung case, the CISA incident. People think "this does not concern me"; real examples break that belief. Training should not be for punishment but for the skill of working safely. The most effective format is short interactive trainings: an employee is given a real work scenario and determines themselves which data can be entered. Such sessions should not be one-off but repeated every quarter, because AI tools and their risks change fast.

7. Check vendor contracts. Have a data processing agreement (DPA) with every AI provider: where the data is stored, who can access it, whether it is used in training, whether the data is deleted when the contract ends. Be especially careful with third-party aggregators (like OmniGPT) — they are an additional weak link.