Why staff using ChatGPT, Claude and Gemini for work could create problems for employers
Cyber security experts have urged companies to be vigilant against the risks posed by employees using outside AI applications including Claude, ChatGPT and Gemini in the workplace. The practice, known as using shadow AI, can lead to important data being leaked and, in some cases, malware and viruses being uploaded into companies' internal systems. Firms are urged to ensure they are aware of what…
Cybersecurity experts have warned that employees using external AI applications, such as Claude, ChatGPT, and Gemini, for work could create significant problems for employers. Known as shadow AI, this practice can lead to data leakage, the introduction of malware and viruses into company systems, and issues with customer information and intellectual property.
Pasting documents or asking AI to edit emails means sensitive data is sent to an external cloud tool, risking exposure if the user's personal account is compromised. Vladislav Tushkanov, research and development group manager at Kaspersky, stated that employees may benefit from faster work but employers often lack records of the systems used or the information received.
To mitigate these risks, experts recommend educating employees on the use of only internal AI systems and implementing strict controls. Premchand Kurup, CEO of ParamountAssure, emphasized the importance of identifying unapproved AI use, establishing approved alternatives, and setting clear access limits. IBM's 2026 Middle East Cost of a Data Breach Report revealed that 26% of malicious breaches were AI-enabled, with an average cost of $8 million per incident.
The rapid advancements in AI and the emergence of agentic AI, which can operate with less human supervision, pose new challenges for accountability. Costi Perricos, Deloitte's global generative AI leader, suggested that businesses manage AI agents as a digital workforce with performance checks and responsibility assignments. The UAE government aims to introduce agentic AI across 50% of federal sectors within two years.
Companies should set access limits and require AI-assisted security investigations based on verified internal records. Ahmed Hafez, director of solution engineering for Snowflake, stressed the need for trusted information and controls over what AI agents can access, advocating for extensive testing in controlled environments with built-in governance and security.
Written by urgent.news from The National Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- ChatGPT, Gemini, and Claude imitated in fake ads that steal credentials and MFA codes techradar.com
- Why staff using ChatGPT, Claude and Gemini for work could create problems for employers thenationalnews.com
- I put Claude Opus 5.5 against Gemini 3.1 Pro on 3 everyday prompts, and I'm ready to pay for one less subscription now xda-developers.com