Are Your Employees Oversharing Company Data With ChatGPT?

Employees are oversharing company data with ChatGPT and other generative AI (GenAI) tools right now. And it's a bigger risk than many business owners realize.

The concept of shadow IT isn’t new: it’s the practice of using apps, tools, or services that haven’t been approved, regulated (or even reviewed) by your company’s IT security team.

According to new research from LayerX, employees frequently provide these platforms with sensitive data, including internal documents, client lists, and even personally identifiable information (PII) or payment card details (PCI). While these tools can boost productivity and spark creativity, they’ve also created a new kind of cybersecurity concern.

Let's explore why.

The Statistics on AI Usage for Employees

  • 75% of global knowledge workers are using generative AI in some form. (Microsoft)
  • 57% of GenAI users have entered confidential company information into public AI tools like ChatGPT and Gemini. (TELUS)
  • Harmonic Security found 26.4% of all files uploaded to GenAI by employees contained sensitive information (source code, credentials, M&A documents, customer/employee records, financials).
  • Gallup’s workplace AI data finds that while over 40% of employees say their organization has begun integrating AI, only around 30% report clear guidelines or formal policies for how to use AI at work.

The problem is that once a GenAI tool has that data, it’s effectively out of your control. Even if the platform claims to protect employee privacy, there’s still a risk that this information may be stored, accessed, or used in future AI training models.

Real-World Case Studies: When ChatGPT Data Leaks Became Headlines

We're not talking about theoretical risks. Real companies have suffered real breaches because employees casually pasted confidential data into ChatGPT.

Case Study 1: Samsung Electronics Source Code Breach (2023)

Samsung identified three incidents within about 20 days where engineers pasted confidential source code and internal meeting content into ChatGPT to debug or summarize work.

What happened:

  • Sensitive semiconductor manufacturing code went to OpenAI's servers
  • Code could be used by competitors
  • Samsung had no control over what OpenAI did with the data

Business impact:

  • Complete AI tool ban (affecting employee productivity)
  • Reputational damage in tech industry
  • Potential competitive disadvantage
  • Regulatory scrutiny

Case Study 2: JPMorgan Chase AI Restriction (2023)

In 2023, JPMorgan Chase was among the first major banks to introduce internal restrictions on employee use of ChatGPT and similar generative‑AI tools, framing it as a third‑party‑software and regulatory‑risk issue rather than a reaction to a specific breach.

Why JPMorgan acted:

  • Financial data is heavily regulated (PCI-DSS, Gramm-Leach-Bliley, SOX)
  • Client confidentiality is critical (investment details, trading strategies)
  • Compliance violations can trigger massive fines

Case Study 3: Unregulated Patient Information

A concrete example used in governance discussions: one 600‑bed hospital discovered, after deploying AI‑usage detection, that clinical staff had been pasting discharge summaries containing PHI into a general‑purpose AI assistant for eight months, with no awareness from compliance or IT because policy alone didn’t catch it.

Core issues:

  • Most consumer AI tools (ChatGPT, Gemini, many SaaS add‑ons) do not operate as HIPAA‑covered entities or sign BAAs
  • Without network‑layer detection of outbound AI API calls, organizations frequently don’t realize PHI is leaving their environment via AI tools
  • In healthcare, the majority of identified data‑policy violations involve PHI, not just generic documents, meaning AI misuse is directly a regulatory and patient‑trust issue.

The Quiet Risk of “Helpful” Oversharing

Most employees who overshare company data with ChatGPT aren’t acting maliciously. They’re just trying to get their work done more efficiently. Unfortunately, they may accidentally expose confidential information or upload files that were never meant to leave the company’s secure systems in the process. Understanding why they do it is critical to prevention.

Reason #1: Lack of Awareness: Employees don't connect "pasting data into ChatGPT" to "corporate data breach", they think of it as a writing tool, not a security risk.

Read more: Cybersecurity Awareness for Employees

Reason #2: Perceived Safety: Many users assume that ChatGPT is an isolated environment, that chats are private, and that data is deleted (it's not).

Reason #3: Convenience: ChatGPT is free, easy and instant and can be easily installed on personal devices.

Reason #4: Lack of Secure Alternatives: If you haven't provided secure alternatives to ChatGPT and GenAI, employees will use the one they know and can access.

When employees hide their use of AI, and misuse it, it can quickly snowball into a major issue. When sensitive data lands in the wrong hands, or even just outside your network, it can result in data leakage, compliance violations, or even breaches of client trust.

Even worse? AI makes it harder to trace where that data ends up.

How To Protect Your Business: Building Your AI Usage Policy

So, what can you do to keep your data safe while still embracing GenAI? You can't ban AI. But you can establish clear boundaries. Here's what your AI Usage Policy should include.

1. Scope (What's Covered)

  • Which AI tools are covered (ChatGPT, Claude, Gemini, etc.)
  • Which data types are restricted
  • Which employees are covered (all or specific roles)

2. Prohibited Data Categories

  • Customer PII (names, addresses, phone, email, account numbers, payment cards)
  • Patient data (medical records, diagnoses, treatment plans)
  • Financial data (budgets, pricing, profit margins, salary info)
  • Source code (internal development, algorithms, infrastructure)
  • Legal documents (contracts, attorney communications, litigation plans)
  • Proprietary information (trade secrets, confidential strategies)

3. Permitted Use Cases

  • General writing assistance (with no company data)
  • Brainstorming (without specific company info)
  • Learning/skill development
  • Approved business use (only with enterprise-approved tools)

4. Approved vs Unapproved Tools

  • Approved: Microsoft Copilot, ChatGPT Enterprise, Azure OpenAI, Google Cloud AI, Anthropic Claude
  • Unapproved: ChatGPT Free/Plus, any AI tool without enterprise security

5. Consequences

  • First violation: Warning + retraining
  • Second violation: Disciplinary action (depends on severity)
  • Third violation: Potential termination
  • Malicious violations (intentional data theft): Immediate termination + legal action

6. Approval/Exception Procedures

  • How employees request approval to use ChatGPT for specific tasks
  • What information needs to be reviewed
  • Who makes approval decisions
  • How to escalate

7. Enforcement Mechanisms

  • DLP monitoring
  • Browser monitoring
  • Regular audits
  • Employee reporting incentives

8. Training & Communication

  • Initial policy training (mandatory)
  • Annual refresher training
  • Role-specific training (developers vs accountants have different risks)
  • Awareness campaigns

Learn more: Shadow AI: Are Your Employees Putting Your Business at Risk

Generative AI is powerful, but it’s not foolproof. As these tools continue to shape modern workflows, business owners must pay attention to how employees are using them. If you have employees oversharing company data with ChatGPT, your organization could be one upload away from a serious corporate security breach.

By setting clear boundaries and offering secure alternatives, and emphazising cybersecurity awareness you can help your employees work more effectively without compromising confidential information.

 

FAQ: ChatGPT Data Security Questions Answered

Q: Is ChatGPT Enterprise safe for business use?

A: ChatGPT Enterprise provides enterprise-grade security (no model training on your data, data isolation, admin controls). However, it's only safe if you have a strong AI usage policy preventing sensitive data uploads. Technology alone doesn't prevent human error.

Q: Can I legally monitor employee ChatGPT use?

A: Yes, if you have a written policy stating monitoring will occur and employees acknowledge it. Monitor using DLP tools focused on data protection, not keyloggers or screen recording (which raise privacy issues).

Q: Should I ban ChatGPT entirely?

A: Blanket bans don't work. Employees will use ChatGPT secretly, making it undetectable. Better approach: approve enterprise-grade tools, establish clear policies, and monitor for violations.

Q: What's the difference between shadow IT and shadow AI?

A: Shadow IT = unapproved tools (Dropbox, Slack). Shadow AI = unapproved AI tools (ChatGPT, Claude). Shadow AI is more dangerous because of data volume and model training concerns.

Q: If an employee accidentally shares customer data with ChatGPT, what do I do?

A: 1) Verify what was shared, 2) Notify legal/compliance immediately, 3) Check OpenAI's data deletion procedures (limited), 4) If personally identifiable info involved, prepare breach notification, 5) Update your training, 6) Consider consequences.

Q: How do I get employees to report AI misuse voluntarily?

A: Create a reporting procedure without punishment for honest mistakes. Make it easy to report (anonymous if possible). Celebrate security wins. If you create a blame-focused culture, employees hide violations instead of reporting them.

Q: Can ChatGPT access my company's data stored in the cloud?

A: No. If you paste data into ChatGPT manually, that's when exposure happens. ChatGPT doesn't automatically access cloud storage. The exposure happens through human copy-paste, not hacking.

Q: What if an employee intentionally shares trade secrets with ChatGPT?

A: That's corporate espionage. You should terminate, consider legal action, and notify law enforcement if appropriate. This is different from accidental oversharing and warrants severe consequences.

Q: Can I use ChatGPT for brainstorming if I don't share real data?

A: Yes, as long as you don't include company-specific information. Brainstorming "features for a productivity tool" is fine. Brainstorming "features for our proprietary widget" using real details is not.

Your employees are already using AI. Do you have a policy for it?

Shadow AI is one of the fastest-growing data risks for SMBs. Our free AI Usage Policy Template gives you a ready-to-deploy framework to govern AI tools before they govern you.

Get the free template

Used with permission from Article Aggregator