Do you know where your business data is?

Do you know where your business data is?

A lot of people are using AI these days; some people are even using it to help them with their work, but are staff using AI in your business with your knowledge or are they using it under the radar?  As we covered in last week's article, a lot of AI models use data to train on, what if a member of staff is using your company data and it's inadvertently being used to train AI which in turn could aid your competitors or leak your business data?

I'm going to go down memory lane, bear with me; a few years ago, we took a frantic call from a business that had suffered a serious data leak. Not because of a hacker. Not because of ransomware. Not because someone inside the company was trying to do harm.

It happened because a well-meaning member of staff wanted to carry on working from home. To make that easier, they uploaded company data into their own free personal Dropbox account. The intention was helpful. The outcome was catastrophic.

The data was now outside the company’s control, outside any proper business agreement, and outside the terms intended for that domestic service. Worse still, it was not protected to the standard the business needed. The result was a major data loss, reputational damage, and a very painful lesson: convenience can be dangerous when it bypasses proper controls.

The same risk has a new name: AI

Fast forward to today and the same pattern is happening again. This time, the tool is not personal cloud storage. It is artificial intelligence.

Staff are using AI tools to write emails, analyse spreadsheets, summarise documents, create proposals, polish reports, draft HR content, troubleshoot technical issues and speed up everyday work. In many cases, they are doing it with good intentions. They want to be faster. They want to be more productive. They want to help the business.

But if they are pasting customer information, contracts, financial data, internal processes, technical details, passwords, source code, sales figures or strategy documents into tools the business has not approved, then your confidential information may already be leaving the building.

Helpful does not always mean safe

The danger is that many employees do not realise what happens after they type or upload information into an AI platform. Some tools may store prompts. Some may use submitted data to improve or train their models. Some may be operated outside the UK. Some may have terms that are suitable for personal experimentation, but not for handling sensitive business data.

The risk is not always malicious. In fact, that is what makes it so dangerous. Your team may believe they are doing the right thing, while accidentally exposing commercially sensitive information to a system the business has not assessed, secured or approved.

Imagine a member of staff asking a free AI tool to summarise a confidential client proposal. Or to rewrite a disciplinary letter. Or to analyse a spreadsheet containing customer records. Or to explain a technical configuration that reveals how your systems are built. In each case, the employee is not trying to leak data. But the data may still be exposed.

Shadow AI is the new shadow IT

For years, businesses have worried about shadow IT: staff signing up for apps, storage services or software without telling the company. AI has made that problem bigger, faster and harder to see. It takes seconds to open an AI tool in a browser. It takes seconds to paste in confidential information. And once that data has gone in, you may have no easy way to get it back.

That creates serious questions for business owners:

  • Do you know which AI tools your staff are using?
  • Do your staff know what information they must never enter into AI?
  • Have you checked the terms, privacy settings and data handling policies of those tools?
  • Do you have an AI usage policy that is actually understood by your team?
  • Can you prove that client, employee and business data is being handled properly?
  • Is your data being processed whilst maintaining GDPR compliance?
  • Is your business data being used to train the AI model which exposes it to the public domain?

If the answer is “no” or “I’m not sure”, then this is not a future problem. It is a current risk.

AI needs rules, not guesswork

AI can be incredibly useful. Used properly, it can improve productivity, reduce admin, speed up research and help teams work smarter. The answer is not necessarily to ban AI completely. A ban often drives the behaviour underground, where it becomes even harder to manage.

The better approach is to put proper controls in place. Decide which tools are approved. Set clear rules on what can and cannot be entered. Train staff using real-world examples. Review supplier terms. Configure business-grade services correctly. Monitor for risky behaviour. Make AI part of your cyber security and data protection strategy, not an uncontrolled side project.

Most importantly, make sure your people understand the issue. In the same way that uploading business data to a free personal storage account can create a serious data breach, pasting business data into the wrong AI tool can expose information you are legally, commercially and morally responsible for protecting.

Be careful, try not to be too helpful when using AI tools

Let me ask you a simple question. "Would you like to improve this tool to help others?"  This sounds like an innocent question, and most people, by their very nature would think "yes, I want to help this tool improve for others" so they select yes, BUT what this question actually means is " we need your permission to use all the data you upload to train the AI model and it could expose your data to the world".  If the question were worded as the latter explaining the data will be exposed to the world, then everyone would select no, this is why they are very careful with how they word the question.  Be warned.

What does this mean for your business

If your staff are using AI without your knowledge, your business may already have a data protection problem waiting to surface. The good news is that this can be managed with the right policies, tools, training and technical controls. As your MSP, we can help you understand where AI is being used, identify the risks, put sensible guardrails in place and make sure your team can benefit from AI without putting your business data at risk.

 

At the very least you should have an AI usage policy for the business just so staff know the business stance on using AI.

If you need help, call us on 01722 411999.

Publish Date: Sep 23, 2026