New Research: AI Is Already the #1 Data Exfiltration Channel in the Enterprise
Briefly

New Research: AI Is Already the #1 Data Exfiltration Channel in the Enterprise
"For years, security leaders have treated artificial intelligence as an "emerging" technology, something to keep an eye on but not yet mission-critical. A new Enterprise AI and SaaS Data Security Report by AI & Browser Security company LayerX proves just how outdated that mindset has become. Far from a future concern, AI is already the single largest uncontrolled channel for corporate data exfiltration-bigger than shadow SaaS or unmanaged file sharing."
"The findings, drawn from real-world enterprise browsing telemetry, reveal a counterintuitive truth: the problem with AI in enterprises isn't tomorrow's unknowns, it's today's everyday workflows. Sensitive data is already flowing into ChatGPT, Claude, and Copilot at staggering rates, mostly through unmanaged accounts and invisible copy/paste channels. Traditional DLP tools-built for sanctioned, file-based environments-aren't even looking in the right direction. In just two years, AI tools have reached adoption levels that took email and online meetings decades to achieve."
"Almost one in two enterprise employees (45%) already use generative AI tools, with ChatGPT alone hitting 43% penetration. Compared with other SaaS tools, AI accounts for 11% of all enterprise application activity, rivaling file-sharing and office productivity apps. The twist? This explosive growth hasn't been accompanied by governance. Instead, the vast majority of AI sessions happen outside enterprise control. 67% of AI usage occurs through unmanaged personal accounts, leaving CISOs blind to who is using what, and what data is flowing where."
AI adoption in enterprises accelerated rapidly: 45% of employees use generative AI tools and ChatGPT reaches 43% penetration. AI now represents 11% of enterprise application activity, comparable to file-sharing and productivity apps. Two-thirds of AI usage occurs through unmanaged personal accounts, creating blind spots for CISOs. Sensitive data is already entering GenAI tools at high rates: 40% of uploaded files contain PII or PCI, with nearly 40% of those uploads made from personal accounts. Traditional DLP solutions focused on sanctioned, file-based workflows miss copy/paste and unmanaged-account channels, making AI the primary uncontrolled exfiltration vector.
Read at The Hacker News
Unable to calculate read time
[
|
]