In March 2023, Samsung engineers uploaded secret semiconductor source code to ChatGPT to fix bugs faster. It happened three times in 20 days. The company banned generative AI entirely. Nobody "hacked" Samsung — the employees handed the data over themselves.
This incident is not an isolated case but a symbol of the most widespread security problem enterprises face today: well-intentioned employees who want to be effective hand over confidential data to AI tools every day. And traditional protection systems don't see it.
The scale of the problem: numbers
Per LayerX Security's Enterprise AI and SaaS Data Security Report 2025, 50% of employees admitted uploading confidential business data to generative AI tools. Another 18% shared highly confidential data — including proprietary development data. 77% of online LLM requests go to ChatGPT. About 18% of employees regularly upload data to GenAI tools, and corporate information is involved in more than half of these cases.
Cyberhaven, monitoring 1.6 million employees, found an even more worrying dynamic: the share of confidential data in information flowing into AI tools tripled in two years — from 10.7% to 34.8%. Most importantly, 82% of these "uploads" go through personal accounts invisible to the company. 68% of employees admitted uploading company data to AI tools without checking what they share.
The cost question is also clear: per IBM's Cost of a Data Breach Report 2025, the average cost of a single data breach is $4.88 million. A breach via AI creates additional risk — data is stored on a third-party server, can be used in training, and cannot be retrieved.
Data leaves through three paths
Analysis shows: business data leaves through AI via three documented paths — in a ten-person company and in a ten-thousand-person one alike.
The first path: employees hand it over themselves. The Samsung case is the most famous, but not the only one. In July–August 2025, it emerged that the acting head of the US Cybersecurity Agency (CISA) uploaded at least four confidential government documents to the public ChatGPT version — including contract materials designated for official use. Another real case: a company executive uploaded the company's full strategy document into a chat to prepare slides. The motive is always the same — finish the work faster.
The second path: the platform itself leaks. In February 2025, a hacker claimed to have breached the OmniGPT platform (an aggregator connecting to ChatGPT, Claude, and Gemini) and published chat messages of 34 million users. The samples included office projects, market analyses, and documents with saved logins and passwords. In July–August 2025, researchers found ~4,500 shared ChatGPT conversations indexed in Google search — about 100,000 conversations were scraped in total, including names, resumes, and personal data. OpenAI disabled the "discoverable sharing" feature in August 2025, but once-indexed data never fully disappears.
The third path: connected tools become the door. In June 2025, hackers entered the AI competitive-intelligence platform Klue via credentials created in 2022 and never deleted, then pulled contacts, prices, and deal records from the connected Salesforce systems of companies. The attackers claimed 195 victims; among the confirmed are LastPass, HackerOne, and Huntress — even security companies themselves were breached through a trusted AI tool.
LayerX Security CEO Or Eshed comments on this risk:
"Corporate data leakage through AI tools can trigger geopolitical issues, regulatory and compliance concerns, and lead to inappropriate use in training of corporate data disclosed through personal AI tools."
Why "banning" doesn't work
Some organizations chose the easiest path: banning AI tools entirely. Samsung, Apple, and JPMorgan at various times restricted ChatGPT use. But practice shows: when a ban is imposed, people don't give up AI — they move to personal devices. As a result, the company loses visibility entirely, and the risk grows instead of shrinking.
In this era, the winners are not those who fight AI adoption but those who manage it smartly. The goal is not to slow employees down but to accelerate them safely.
Practical guide: seven steps
1. Make a list of approved tools. Approve not just any AI tools, but versions with a signed corporate agreement and a guarantee not to use data in training. An "allowlist" is more effective than a blacklist, because new tools come out every week.
2. Require enterprise mode and "zero retention" terms. Major AI providers offer corporate clients modes where requests are not stored and not used in training. Fix this in the contract as a written guarantee — a verbal promise is not enough.
3. Categorize data. Introduce a simple three-color system: "red" — never enter (personal data, financial reports, source code, contracts); "yellow" — enter only anonymized; "green" — free to use (open marketing texts, etc.). Every employee must know which category applies to their work.
4. Make anonymization a habit. Before turning to AI, mask or generalize names, account numbers, addresses, and other identifiers. For many tasks, "client A" and "company B" are enough — the model doesn't need real names.
5. Set up control at the prompt level. Traditional DLP (data loss prevention) systems monitor email and file transfer but don't see what's typed into a chat window in the browser. Modern solutions work exactly at the prompt level: when confidential data is detected, they warn or block.
6. Train employees with real examples. A dry policy document doesn't work — show the Samsung case, the CISA incident. People think "this isn't about me"; real examples shatter that confidence. Training should be not for punishment but for safe-working skills. The most effective format is short interactive trainings: an employee is given a real work scenario and determines for themselves which data can be entered. Such sessions should be repeated not once but every quarter, because AI tools and their risks change fast.
7. Check vendor contracts. Every AI vendor should have a data processing agreement (DPA): where data is stored, who can access it, whether it's used in training, whether data is deleted when the contract ends. Be especially careful with third-party aggregators (like OmniGPT) — they're an extra weak link.
The Uzbek context: local reality
Uzbekistan has personal data legislation, and data localization requirements are tightening. This means uncontrolled uploading of citizens' personal data to foreign AI platforms is not only a security risk but a legal one.
Special attention should go to IT Park residents: nearly half of their exports go to North America, and they work with foreign clients' confidential data. Western clients impose increasingly strict compliance requirements — a contractor without an AI policy can lose a tender. So privacy here is not "goodwill" but a condition of export competitiveness.
For banks and fintech (including large ecosystems), regulation is even stricter: entering clients' financial data into public AI tools is absolutely unacceptable. When deploying AI in government agencies, the privacy of citizens' data must also come first — the CISA case showed that even the cybersecurity agency itself is no exception.
For small and medium businesses, the starting step doesn't require a big budget: it's enough to first publish a list of approved tools, explain the "red line" rules to employees, and switch to AI accounts accessed via corporate email. These three steps bring the bulk of "shadow AI" under control and return visibility to the company. At the next stage — contracts and technical control tools.
Conclusion: a short checklist for leaders
- [ ] Is a list of approved AI tools published?
- [ ] Is the "zero retention" guarantee in the contract in enterprise mode?
- [ ] Are data categories (red/yellow/green) defined?
- [ ] Are employees trained with real examples?
- [ ] Is prompt-level monitoring or DLP working?
- [ ] Are DPA agreements signed with vendors?
- [ ] Is there a personal-account usage policy?
- [ ] Is an incident response plan ready?
The most important conclusion: AI security is not a technical problem but a management problem. The tool cannot be banned — it must be learned to manage. One hour spent today developing policy will save weeks eliminating an incident tomorrow.




