The al tool you use could be your biggest leak risk

AI tools are already part of the daily work routine for most professionals. Summarizing meeting minutes, reviewing a contract, analyzing a spreadsheet, preparing a presentation: tasks that used to take hours now take minutes, and almost no one has gone back. The problem is not the technology. It is what goes along with the prompt: the data an employee pastes into the chatbot so that the response makes sense.

This data does not trigger any monitoring system. It does not generate a log. It does not create an alert. It leaves the corporate perimeter silently, while the task is completed and the result is praised at the next meeting. It is a type of data leak that, in most cases, the company only discovers when the damage has already been done or never discovers at all.

What happens to what you type into a public chatbot

Most language models available for free or aimed at end consumers may use user interactions to refine their algorithms. Data entered today could become part of the tool’s knowledge base and, in theory, reappear in responses generated for other users. Even when this does not happen directly, the information has left the company’s controlled environment and is now subject to the terms of use and privacy policies of a third party, on servers that may be located in any country.

The most well-documented case so far is Samsung’s, in 2023. Employees entered sensitive source code and internal data into ChatGPT to speed up technical tasks. The incident became public, the company temporarily banned the use of the tool, and the episode became part of the industry’s body of evidence that the risk is real, not hypothetical. Samsung was not an isolated case: it was the first widely publicized example of a pattern that already existed in many organizations without anyone realizing it.

The numbers that show this is already happening in your company

Recent research provides a concrete picture of the problem. The Microsoft and LinkedIn Work Trend Index, conducted with more than 31,000 professionals in 31 countries, including Brazil, showed that 75% of knowledge workers already use generative AI at work, and 78% of them bring their own tools without IT approval.

The 2025 Enterprise AI & SaaS Data Security Report, from security company LayerX, detailed what goes into these prompts: 77% of corporate generative AI users copy and paste data directly into chatbot queries, and 22% of these operations include personal data or payment card information. A study by Harmonic Security identified the typical composition of what is entered: legal and financial data account for 30.8% of cases, customer information for 27.8%, personal data of data subjects for 14.9%, employee records for 14.3%, and source code for 10.1%.

Netskope’s Cloud and Threat Report, published in January 2026 based on telemetry from millions of corporate users, recorded that the average company accumulates 223 AI-related data policy violation incidents per month, more than double the number from the previous year. In Brazil, where AI adoption by companies jumped from 20% to 51% in twelve months, the magnitude is consistent with the global average. In many cases, these incidents never even come to IT’s attention because the data leak does not trigger any detection system installed in the corporate environment.

Environments that appear to be protected but have never been verified from the perspective of what leaves them tend to concentrate exactly this type of exposure: data leaving through channels that were never mapped as risk vectors.

Shadow AI: the use of AI tools that IT cannot see

The phenomenon has a name: shadow AI. It is the use of AI tools without approval, knowledge, or monitoring by the technology department. The employee is not acting in bad faith: they found a chatbot that solves a real problem, used it, it worked, and they started using it every day. IT never knew.

The Cisco 2024 Data Privacy Benchmark Study, conducted with 2,600 security and privacy professionals in 12 countries, revealed that 27% of organizations have completely banned the use of generative AI. Even so, 48% of employees at these same companies admitted to entering non-public information into these tools even after the ban.

Formal restrictions without a secure alternative and without education about the risk create an illusion of control while the use continues outside the field of vision of those who should be managing the exposure.

What does the LGPD require in this scenario?

When an employee enters customers’ personal data into a public chatbot, three situations with direct legal implications occur simultaneously: transmission of data to a third party, potential international transfer of data under Article 33 of the LGPD, and failure to comply with the security principle established in Article 46 of the law.

Article 42 of the LGPD is direct: responsibility falls on the company that controls the data, regardless of whether the initiative came from a single employee. The statement that “an employee pasted the data into the chatbot on their own” does not change the organization’s legal position before the ANPD. In 2025, the Brazilian Data Protection Authority was elevated to the status of a special autonomous agency, with expanded powers to supervise and impose sanctions, making this regulatory risk even more concrete for Brazilian companies.

The dynamic is analogous to what happens with IT outsourcing: the company is responsible for what the third party does with the data it received, even when the transfer was not formally authorized by anyone with decision-making authority.

Banning it does not solve the problem: what actually works

The temptation to solve the problem with a ban policy is understandable, but the data shows that it does not contain the use. What the 48% noncompliance rate among companies that banned generative AI reveals is that, without a secure alternative and without education about the risk, a ban simply pushes the behavior outside IT’s field of vision. The risk remains present; it is simply less monitored.

What produces results is a structured approach: visibility into the chatbots and assistants already in use, classification of the data that may or may not leave the environment, definition of secure corporate versions of the most widely used platforms, and real-time monitoring of information flows. Without a formal process that assigns responsibility and establishes review criteria, the risk of generative AI in companies reproduces the pattern of any other risk without an owner: tacitly tolerated and without a clear point of responsibility when the incident occurs.

What IT managers and leadership need to put into practice

The starting point is knowing what is already happening. Before any policy, it is necessary to map which AI tools are being used in the company, by which departments, and with what types of data. This mapping rarely appears in traditional software inventories because most chatbots are accessed through a browser, without installation or registration in the corporate environment.

From this visibility, the next steps involve:

  • Classify data by sensitivity: formally define which categories of information may never be entered into external tools, including customer data, contracts, source code, financial information, and employee records.
  • Evaluate enterprise versions of the most widely used platforms: solutions such as ChatGPT Enterprise and equivalents from other providers offer corporate controls that include not using data to train models and formalizing a Data Processing Agreement (DPA), which substantially changes the legal framework for their use.
  • Include generative AI in the information security policy: the use of AI chatbots and assistants needs to be covered by the same rules governing access to internal systems, sending files to external services, and sharing information with third parties.
  • Develop an incident response plan that covers this vector: AI-related data leaks have characteristics that differ from traditional incidents: they do not generate alerts, leave no trace in the corporate environment, and may take months to be detected, if they are detected at all.

Identifying what is being used without IT approval is exactly the type of exposure that a well-conducted security audit brings to the surface: active applications without registration, data moving through channels that were never mapped as risks.

The risk is not using AI; it is using it without governance

AI tools will continue to be adopted, with or without a formal policy. Gartner projects that, by 2027, 75% of employees will acquire, modify, or create technology outside the field of vision of corporate IT. A ban will not change this trajectory. What can change is the level of exposure the company carries while this use takes place.

The difference between an organization that benefits from AI and one that exposes itself because of it is not the platform it chose, but the governance it built around its use. Visibility into what is being used, classification of what may and may not leave the environment, secure alternatives for the most in-demand tools, and continuous monitoring are the elements that separate controlled adoption from risky adoption.

How STWBrasil can help

STWBrasil maps the use of AI tools in corporate environments, identifies data exposures that bypass traditional monitoring systems, and helps structure the governance needed so that AI use can generate value without expanding the attack surface. If your company still has no visibility into what employees are using and what data they are using with it, this is the starting point. Contact STWBrasil.

Leading company in information security. The digital protection of your company is our priority. We rely on state-of-the-art technology used by highly specialized professionals.

(11) 3939-0827
R. São Bento, 365 – 8o Andar – Centro Histórico de São Paulo, São Paulo – SP,
CNPJ: 05.089.825/0001-48.

Copyright ©️ 2023 – All rights reserved. Check out our  Privacy Policy.