What happens when employees paste customer data into ChatGPT?

Banner promoting secure AI usage, asking whether organizations can see what employees share with AI tools.

Imagine what happens when your employees use ChatGPT to:

Copy customer emails to draft clearer responses

Upload revenue data into Google Gemini to analyze growth trends

Paste customer chat transcripts into Claude to summarize issues quickly

Use GitHub Copilot to generate complex code snippets

Each task will be completed in seconds, efficiently, and the user will move on.

In many organizations, this happens every day—without detection, review, or documentation.

There is no malicious intent. No involvement of threat actors or security incidents. No sense that a boundary has been crossed. For most teams, this has simply become part of how work gets done.

As generative AI usage continues to proliferate, increasing volumes of customer data, proprietary business information, and confidential revenue details are being shared in prompts across the organization. Once Enter is pressed, that data leaves the organization’s direct control and moves into an environment governed by the rules, retention policies, and security practices of third parties—often providers the organization does not actively manage or have a direct relationship with.

For most organizations, this creates an uncomfortable reality. Generative AI usage is widespread and critical data is involved, and yet there is limited visibility into when it occurs, what information is shared, how frequently it happens, etc. Understanding this gap is crucial and it's not about assigning blame or restricting productivity. It's about recognizing that the risk surface has shifted—and security controls must now shift with it.

This blog is not about bad actors or reckless employees. It is about a common, well-intentioned workflow that many organizations have yet to fully address, the challenges of implementing shadow AI governance without hindering productivity, and how to do it effectively.

The swift rise of shadow AI in the workplace

The actions undertaken by employees like copying emails, pasting revenue data, summarizing chat transcripts, etc., using generative AI illustrate what is increasingly referred to as shadow AI. So what is shadow AI?

Shadow AI refers to the use of artificial intelligence tools, systems, or models by employees within an organization without explicit oversight, approval, governance, or integration by the central IT. This includes all interactions with generative AI tools such as ChatGPT, Gemini, ClaudeAI, Perplexity, Synthesia, etc., Shadow AI is analogous to the concept of shadow IT—where business units adopt technology outside official channels— but it is distinct in that it applies specifically to AI-driven capabilities.

What makes shadow AI ubiquitous and pervasive is how easily it blends into everyday workflows. There are over 6,500 generative AI domains and 3,000 apps monitored, providing a plethora of choices to users. Also, these AI tools are browser-based, intuitive, and often free to use, requiring no provisioning or technical setup. As a result, adoption happens organically and quickly, often without security teams being aware that it is occurring at all.

As it's use continues to expand, understanding the risk it imposes—and its implications—is becoming increasingly relevant for all organizations.

Recent generative AI statistics on adoption trends and risk factors

71–78% of organizations regularly use generative AI in at least one business function, indicating widespread adoption beyond pilot projects, according to the McKinsey Global Survey 2025.

89% of enterprise AI usage is invisible to the organization, the LayerX’s Enterprise GenAI Security Report 2025 found.

Almost 40% of files uploaded to AI tools contain PII or PCI data, that same report discovered.

Over 40% of AI-related data breaches by 2027 will stem from unapproved or improper generative AI use, Gartner determined.

An average of 223 GenAI data policy violation incidents per month are now reported, a rapidly increasing number according to the Netskope Cloud and Threat Report 2026. 

Understanding the risk surface of shadow AI

The rise of shadow AI has fundamentally altered the risk landscape of an organization introducing new pathways for security breach that existing security controls were not designed to manage. Key risks include:

  • Uncontrolled and unmonitored data sharing

With employees sharing customer communications, internal documents, financial data, and proprietary business information with generative AI tools to accelerate routine tasks, the risk is implicit as when business-critical data leaves the organization’s boundaries it immediately increases the risk of exposure or breach.

  • Loss of accountability and visibility

With most AI usage occurring via employees' personal accounts and unmanaged browsers, organizations lack visibility and control over what data is shared, by whom, when, and across which AI tools, etc.

  • Compliance and regulatory exposure

A lot of generative AI usage—including the sharing of PII, financial, and regulated data—can violate regulations such as the GDPR, the PCI-DSS, and HIPAA which are designed to protect data privacy, integrity, and confidentiality.

  • Bypassing existing security controls

Browser-based AI tools, plug-ins, and extensions can easily circumvent traditional data and network-centric security controls. They operate within user browser sessions and rely on encrypted, session-based interactions that allow sensitive data to be shared via copy-paste or file uploads without triggering existing inspection or enforcement mechanisms.

  • Expanded attack surface

Each AI tool, domain, or extension that employees interact with represents an additional entry point for data leakage, credential exposure, and malicious exploitation.

Collectively, these risks make it clear that shadow AI is a real and growing concern for enterprises today. The question, then, is whether organizations can—or should—attempt to ban generative AI outright. In practice, such an approach is neither effective nor sustainable. Employees will continue to seek out AI tools to improve efficiency, and generative AI has become a critical capability for remaining competitive in today’s market. Rather than attempting to eliminate its use, organizations must acknowledge its inevitability and focus on managing it responsibly through visibility, governance, and control.

This requires security and governance approaches that are purpose-built to monitor and secure AI interactions in real time—without disrupting productivity or legitimate business workflows.

How to track and secure generative AI at work

To secure AI usage effectively organizations need to shift and adapt to a visibility- and context-driven controls that operate at the data level. By focusing on how AI is accessed, what data is shared, and the risk associated with each interaction, organizations can reduce exposure without disrupting legitimate business use. Organizations should focus on:

  • Establishing full-spectrum visibility into AI usage by capturing telemetry on who uses which AI tools, how often, and for what purpose—including prompt content.

  • Monitoring data shared with AI tools to determine whether it includes PII, financial, or other sensitive information, across both sanctioned and unsanctioned applications.

  • Enforcing risk based controls that allows benign use cases while enforcing safeguards when sensitive or regulated data is shared. This may include redaction, warnings, policy enforcement, or restrictions based on the data classification.

  • Employing strong generative AI usage auditing solutions establish accountability and to support compliance, incident response, and internal governance.

  • Educating employees on safe usage of AI tools and platforms with clear guidelines and well-defined boundaries around acceptable data sharing.

Shadow AI might sound like an emerging trend, but it's not. It's already embedded in everyday workflows and is an integral part of how modern work gets done. Employees are adopting generative AI tools to move faster, communicate better, and make more informed decisions, often without malicious intent or awareness of the associated risk. This behavior introduces new data exposure, compliance, and security challenges that traditional governance models controls were never designed to address.

The path forward is not to restrict AI adoption, but to govern it intelligently. Organizations that succeed will be those that embrace visibility, apply context-aware controls, and secure AI usage at the browser and data level—without disrupting productivity.

Shadow AI cannot be eliminated, but it can be made safe, accountable, and aligned with business objectives.

Tracking shadow AI usage with ManageEngine DataSecurity Plus

ManageEngine DataSecurity Plus enables centralized monitoring of generative AI usage by reporting on prompts shared across leading generative AI platforms, including ChatGPT, GitHub Copilot, Claude, Google Gemini, and more. It also enables security teams to enforce policy-based controls by blocking AI services below a defined reputation threshold, blocklisting unauthorized AI platforms, and restricting specific categories of AI applications to prevent shadow AI usage and reduce data exposure risks—without disrupting employee workflows.

Explore DataSecurity Plus' shadow AI detection capabilities