A Shift in Enterprise Security Priorities

A cybersecurity professional analyzing data on a computer, emphasizing the importance of AI security in corporate environments.

New research from LayerX, an AI and browser security company, has uncovered a startling truth: artificial intelligence (AI) is now the primary uncontrolled channel for corporate data exfiltration, surpassing even shadow SaaS and unmanaged file sharing. The findings, drawn from real-world enterprise browsing telemetry, challenge the long-held perception of AI as an “emerging” technology. Instead, the report shows that AI has already become deeply embedded in daily workflows, making it a critical concern for Chief Information Security Officers (CISOs).

The study highlights that nearly 45% of enterprise employees already use generative AI tools, with ChatGPT alone reaching a 43% penetration rate. However, this rapid adoption has not been matched by adequate governance. The report reveals that 67% of AI usage occurs through unmanaged personal accounts, leaving CISOs blind to the data being shared and the potential risks involved. Additionally, 77% of employees paste data into GenAI tools, with 82% of that activity coming from unmanaged accounts. This makes copy/paste into AI tools the leading vector for corporate data leakage.

The report also points out that traditional data loss prevention (DLP) tools, designed for file-based environments, are not equipped to monitor the flow of data through AI platforms. This gap in visibility has left organizations vulnerable as sensitive data, including personally identifiable information (PII) and payment card industry (PCI) data, is frequently uploaded into AI tools. The convergence of shadow AI and unmanaged instant messaging platforms further exacerbates the issue, creating a dual blind spot where data leaks into unmonitored environments.

According to the report, 40% of files uploaded into generative AI tools contain PII or PCI data, and nearly 40% of those uploads are done through personal accounts. Even more alarming is the fact that the real leakage isn’t just from file uploads—it’s through the ubiquitous act of copy/paste. On average, employees perform 14 pastes per day via personal accounts, with at least three containing sensitive data.

The report also highlights the “identity mirage” phenomenon, where corporate credentials do not equate to secure access. For example, 71% of CRM and 83% of ERP logins are non-federated, meaning employees can bypass single sign-on (SSO) protocols, making it difficult for security teams to track or control access.

As AI continues to reshape the enterprise landscape, the report urges CISOs to rethink their security strategies. The perimeter of data security has shifted from traditional file servers and sanctioned SaaS to the browser, where employees blend personal and corporate accounts and move sensitive data across both. The findings emphasize that the urgency for action is now, as AI is not just a productivity tool but a governance challenge that requires immediate attention.

LayerX’s report provides a comprehensive analysis of how AI and SaaS are being used inside the enterprise, offering CISOs and security teams unprecedented visibility into the risks and practical steps to secure AI-driven workflows. The report underscores that the future of data breaches may well be dictated by how well organizations adapt to this new reality.

Trending

Discover more from The Tower Post

Subscribe now to keep reading and get access to the full archive.

Continue reading