Worse than hackers: employees leak company data through AI

0
41

Shadow AI incidents more than doubled in a year, from 20% to 43% of breached organisations, averaging $5.39 million (IBM, 2026). With 91% of Malaysian organisations already running business AI tools, SearchInform Malaysia warns that data pasted into public chatbots leaves the company unrecorded, and under the PDPA the liability rests with the organisation, not the tool.

91% of Malaysian organisations have adopted business AI tools — and many have no visibility into how staff use them, exposing sensitive data to external platforms. 

Even the most responsible employees can create a serious problem by pasting source code, a client list, payment card details or unreleased financials into a chatbot to finish a report faster. According to IBM’s 2026 Cost of a Data Breach Report, shadow AI incidents more than doubled in a year, from 20% to 43% of breached organisations, with those incidents averaging $5.39 million.

The Shadow AI effect: this traffic looks like ordinary web browsing, so firewalls wave it through — but the data may be retained on external servers or used to train future models.

Expert perspective

You cannot protect data you cannot see, and right now numerous organisations are blind to this,” said Francis Yeoh, Country Director at SearchInform Malaysia. “When someone drops sensitive data, e.g., a customer database, into a public AI prompt, they just want to finish a business task faster — but the moment they hit paste, the data has left the building. So, the goal is to see what data is being transferred and whether this operation poses a risk to corporate security. If so, the operation should be blocked before a leak happens.”

What to do about it

Know your data. Classify data assets so that sensitive information cannot be shared with AI services. 

Apply technical controls. A Next-Gen DLP system that monitors data transfer operations to AI services blocks potential leaks and serves as an essential safeguard.  

Train employees regularly. Make sure the team knows exactly what data must never be shared with AI, whether through standalone tools or AI features built into business applications. 

For Malaysian organisations, the Personal Data Protection Act (PDPA) heightens the stakes: once regulated data enters an ungoverned external model, proving compliance becomes nearly impossible — and the liability rests with the organisation, not the tool.

LEAVE A REPLY

Please enter your comment!
Please enter your name here