Harmonic Security Report Reveals Data Sharing Risks with Generative AI Tools
- Securityish
- AI & Future Technology
Quick Summary
The Securityish Brief
The report from Harmonic Security indicates a troubling trend in data sharing with generative AI tools, analyzing 22.4 million prompts across six applications in 2025. The findings show that ChatGPT was responsible for 71% of the data exposures, while personal accounts with no organizational oversight accounted for 17% of these incidents. Among the 98,034 instances of sensitive data exposure, 87% were linked to ChatGPT Free, followed by Google Gemini, Microsoft Copilot, Claude, and Perplexity.
Of the analyzed prompts, 579,000 (2.6%) contained company-sensitive data, with code being the leading risk at 30%. Other significant categories included legal discourse (22.3%), merger and acquisition data (12.6%), financial projections (7.8%), and investment portfolio data (5.5%). Michael Marriott from Harmonic Security noted that most sensitive data was inadvertently shared when unstructured documents were exposed to AI models.
The analysis only covers six tools, but there are at least 661 generative AI applications, suggesting that the scale of potentially exposed data is much larger than many organizations realize. Alarmingly, 4% of the usage tracked involved applications storing data in China, raising concerns about data privacy compliance.
Cybersecurity teams face challenges as data shared with generative AI tools may not lead to immediate breaches, with risks of sensitive information appearing in future AI outputs. Some providers use collected data to train their models unless users opt out, increasing the likelihood of data misuse.
Organizations are encouraged to use commercial versions of these tools that include protective measures against data sharing. However, even these guardrails can be bypassed, highlighting the need for active monitoring of employee usage to minimize data leakage incidents.
Implications for Organizations and Users
The findings from this report underscore the necessity for organizations to reassess their use of generative AI tools. With sensitive data being shared unknowingly, companies must implement stricter controls and monitoring practices to safeguard their information.
Users should be aware of the risks associated with free AI tools, particularly regarding the potential exposure of sensitive data. Organizations should educate employees on the implications of sharing company information with these platforms.
As generative AI continues to evolve, staying informed about the tools being used and their data handling practices is crucial for maintaining data privacy and compliance.
Key Takeaways
- Review and limit the use of free generative AI tools that may expose sensitive data.
- Implement monitoring practices to track employee interactions with generative AI applications.
- Educate employees about the risks of sharing company information with AI tools.
- Consider using commercial versions of generative AI tools that offer better data protection.
- Regularly assess data privacy compliance regarding the storage locations of AI tool data.
Key Terms & Concepts
- Generative AI: In this article, generative AI refers to artificial intelligence systems that can create content based on user prompts.
- Data Exposure: Data exposure occurs when sensitive information is unintentionally shared or made accessible to unauthorized parties.
- ChatGPT: ChatGPT is a generative AI tool developed by OpenAI that has been widely used for various applications.
- Compliance Issues: Compliance issues arise when organizations fail to adhere to regulations regarding data privacy and protection.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.