HomeSecurity77% of employees share company secrets on ChatGPT

77% of employees share company secrets on ChatGPT

Corporate data security is facing an unprecedented crisis as new research reveals widespread misuse of generative AI platforms (e.g. ChatGPT) by employees .

corporate secrets in ChatGPT

A comprehensive study examining enterprise browsing behavior has revealed alarming patterns of exposure sensitive data in organizations worldwide. The research, based on real telemetry data from corporate browsers, shows that artificial intelligence tools have become the primary vehicle for unauthorized data transfer from corporate environments.

See also: Service Finder: Hackers exploit vulnerability in WordPress theme

Leveraging AI in corporate environments

The study reveals how quickly generative AI has become embedded into work routines, with 45% of enterprise users now actively engaging with AI platforms. ChatGPT dominates this landscape, capturing 43% of total employee usage and accounting for 92% of total generative AI activity within organizations. This widespread adoption places AI tools alongside established categories, such as email and file sharing, in terms of everyday usage.

Reporting and exporting corporate data through AI platforms

Most alarming is the scale of exposure of sensitive information through these platforms. The research reveals that 77% of employees regularly paste data into generative AI, with 82% of this activity occurring through unmanaged personal accounts that bypass corporate oversight. This behavior has positioned generative AI as the primary channel for corporate data extraction (representing 32% of all unauthorized data movement outside of approved environments).

77% of employees share company secrets on ChatGPT
77% of employees share company secrets on ChatGPT

LayerX Security analysts identified these patterns through comprehensive monitoring of enterprise browsing activity, providing unprecedented visibility into employee interactions with AI platforms. Their research methodology involved deploying security solutions directly into users’ browsers across multiple large enterprises.

See also: APT35: Structure, tools and espionage operations revealed

The financial and regulatory implications are staggering. 40% of files uploaded to generative AI platforms contain personally identifiable information (PII) or payment card industry (PCI) data. Similarly, 22% of data pasted into these tools includes sensitive regulatory information. This exposure poses significant risks for organizations subject to data protection regulations such as GDPR and HIPAA.

Employees are a risk to businesses

The research reveals a massive crisis identity management within enterprise environments, where traditional access controls have failed to curb employee behavior. The use of personal accounts dominates the high-risk categories, with 67% of access to generative AI occurring through unmanaged accounts that exist outside of corporate identity systems. This pattern extends beyond AI tools, impacting critical business applications such as Salesforce (77% non-corporate access), Microsoft Online (68% non-corporate access), and Zoom (64% non-corporate access).

Even when employees use corporate credentials, authentication weaknesses remain in enterprise systems. The study found that 83% of ERP connections and 71% of CRM access occur without single sign-on (SSO) federation, effectively treating corporate accounts as personal. This creates huge visibility gaps, where sensitive business workflows operate outside of IT oversight and security controls.

See also: Vulnerabilities in CrowdStrike Falcon Sensor for Windows allow file deletion

77% of employees share company secrets on ChatGPT
77% of employees share company secrets on ChatGPT

Copy-paste behavior represents the most dangerous method of data transfer , as it completely bypasses traditional data loss prevention (DLP) systems. Employees perform an average of 46 paste operations per day, with personal accounts generating an average of 15 pastes per day, including at least four containing sensitive data. Popular destinations include ChatGPT , services Google , Databricks, LinkedIn, Snowflake, and Slack , showing how corporate information flows to various external platforms through productivity routines.

Chat and instant messaging apps exacerbate these risks (with 87% of activity occurring through unmanaged accounts, while 62% of users pasting PII/PCI data on these platforms).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS