AI Security in the Enterprise – How to Protect Data When Employees Use Personal GenAI Tools
Employees are adopting personal GenAI tools faster than companies can establish rules for their use. AI security, however, is not about imposing bans. It is about controlling where data goes. This article covers the real risks of shadow AI and the five pillars of data protection in the enterprise.
TL;DR
This article explains what AI security means in an organization and how to mitigate risk when employees use personal GenAI tools. It examines the scale of shadow AI and the specific risks it creates, from data leakage and decisions based on hallucinations to prompt injection. It outlines five pillars of AI security: on-premises deployment, sensitive data masking, auditability, governance, and a secure alternative available across the organization. It concludes with an overview of GDPR and AI Act requirements, as well as practical implementation steps.
The threat to corporate data no longer comes exclusively from outside the organization. Increasingly, risk originates with well-intentioned employees who paste a contract excerpt, source code or customer data into a public GenAI tool to complete a task faster. A Gartner study conducted between May and November 2025, involving 175 employees, found that more than 57% used personal GenAI accounts for work purposes, while one-third admitted uploading sensitive information to tools not approved by their organization. This phenomenon is known as shadow AI.
Security teams should not be asking, “How do we block AI?” but rather, “How do we protect data without slowing down productivity?” Below is a practical look at what AI security means in an organization, the real risks created by shadow AI, and the model that combines control with accessibility.
Shadow AI – Why Employees Turn to Personal Tools
Shadow AI refers to the use of artificial intelligence tools without the knowledge or approval of IT, security and compliance teams. Its scale is significant: according to Gartner, 69% of security leaders have evidence or suspicions that employees are using public GenAI tools at work. This practice rarely results from malicious intent. More often, it stems from the lack of an approved, secure alternative. The mechanisms behind shadow AI and the scale of the issue are covered in a separate article: shadow AI in the enterprise and GDPR risk.
When an organization does not provide a secure solution, employees find one on their own. A public model is readily available, works immediately and can save hours of work. The issue is that the prompt sent to such a model may contain data that should remain within the company, with no one recording or monitoring that activity.

What the Organization Is Actually Risking
AI security spans several layers of risk that are difficult to assess in isolation:
- Data leakage to public models. A 2025 KPMG study found that nearly 90% of people using AI at work rely on publicly available tools that sit outside the organization’s control. IBM’s 2025 report indicates that incidents involving shadow AI cost, on average, approximately USD 670,000 more than other incidents. Among organizations that reported an AI-related security incident at all, representing 13% of respondents, as many as 97% lacked adequate access controls for AI tools. The most high-profile example, the Samsung source code leak, is discussed in more detail in the article on data leaks caused by shadow AI.
- Lack of auditability. Without a central control point, the organization does not know who used AI, when they used it or what data was involved. This makes it impossible to respond effectively to an incident or reconstruct its course.
- Legal liability rests with the company. Under the GDPR, the data controller is responsible for the processing of personal data. Claiming that it was “an employee’s private initiative” does not remove the organization’s accountability.
- New attack vectors. Prompt injection is a technique in which an attacker hides an instruction in content processed by the model, for example in a document, message or web page. The model may treat it as a user instruction and disclose data or perform an action that conflicts with the organization’s intent. Today, this is the most common vulnerability in the LLM layer and cannot be eliminated entirely. The risk grows with AI agents because an agent not only provides answers but can also perform operations in enterprise systems. Input validation, guardrails and human approval requirements for higher-risk operations help mitigate this risk.
- Incorrect decisions based on hallucinations. A model can generate an answer that sounds credible but is factually incorrect. If it makes its way into a pricing proposal, legal analysis or report without verification, the organization may make decisions based on fabricated information.
- No approval gates in the process. Delegating tasks to AI without human approval points means that an error made early in the workflow can move downstream and propagate through subsequent process steps.
- Lack of AI management tools. Without an inventory of models, permissions and costs, the organization does not know how many AI solutions are actually operating across its environment or who is accountable for them.
The scale of the problem will continue to grow. Gartner predicts that by 2028, 25% of enterprise GenAI applications will experience at least five minor security incidents per year, compared with 9% in 2025.
Why a Ban Alone Does Not Work
A total ban may appear to be a straightforward solution, but in practice it pushes the problem into the shadows. Employees who see a genuine benefit in AI will find workarounds: a personal phone, a home laptop or an account created “on the side.” A ban does not eliminate risk. It simply deprives the organization of visibility and control.
A more effective approach reverses the logic: rather than blocking, organizations should guide adoption. The same pattern can be seen in common reasons AI projects fail – security and AI governance treated as an afterthought and addressed at the end of implementation usually fail.
The key is controlled AI democratization: making AI available to business teams, but within an environment that the organization can genuinely supervise and govern.
Five Pillars of AI Security in the Enterprise
A mature AI security strategy is built on five complementary elements:
- On-premises or private cloud deployment. Data is processed within the organization’s infrastructure and does not reach external servers. This is a foundation for GDPR compliance and industry-specific regulatory requirements. This architecture is available, for example, through the on-premises GenAI platform, where data never leaves the company.
- Sensitive data masking. Before a prompt reaches the model, a masking mechanism replaces personal and confidential data with fictitious equivalents. Once a response is returned, it restores the original values. This allows users to see the conversation in its real, unchanged form while making it possible to safely use even external models.
- Auditability and AgentOps. A complete history of activity – who used AI, when and for what purpose – together with agent monitoring. Without it, incident response and compliance with documentation requirements are not possible.
- Governance and access control. Role-based access, consistent authorization models and guardrails that stop an agent when it exceeds the acceptable level of risk. An agent should access only what is necessary to complete its task.
- A secure alternative deployed across the organization. A single tool for one team does not solve the problem. A secure alternative is a scalable solution made available to all teams, meeting the four previous pillars and governed by an acceptable use policy. A common starting point is deploying a dedicated, controlled AI assistant powered by the company’s knowledge base. Technical controls alone, however, do not close the issue. If an agent using a corporate knowledge base through RAG is also given internet access within the same workflow, data can still leak despite a sound implementation. Every AI tool therefore requires clear usage rules, permission controls and oversight of what an agent can do with data.

Personal GenAI Tools vs. a Controlled Enterprise Platform
| Dimension | Personal GenAI Tools (Shadow AI) | Controlled Enterprise Platform |
|---|---|---|
| Data location | Provider’s public servers | Company infrastructure (on-premises / private cloud) |
| Auditability | None – activity is invisible to IT / Compliance | Complete history of activities and agent actions (AgentOps) |
| Access control | Individual accounts outside company policy | Role-based access and guardrails |
| Data masking | None – data is sent in full | Sensitive data is masked before being sent |
| Compliance (GDPR / AI Act) | Risk of violations and penalties | Architecture supports data location, logging and access control requirements |
AI Security and Compliance – GDPR and the AI Act
Security and compliance are increasingly becoming two sides of the same coin. However, the AI Act timeline changed in 2026. The amending regulation, known as the Digital Omnibus on AI, Regulation (EU) 2026/1744, has applied since 27 July 2026 and postponed certain deadlines. From 2 August 2026, transparency requirements have applied, including the labelling of AI interactions and AI-generated content. The main obligations for standalone high-risk systems under Annex III, including systems used in recruitment, credit scoring or education, will apply from 2 December 2027. For AI embedded in regulated products under Annex I, they will apply from 2 August 2028. The regulation requires, among other things, technical documentation, human oversight and operational auditability. Penalties for breaches of high-risk system obligations can reach EUR 15 million or 3% of worldwide annual turnover, while prohibited practices can result in fines of up to EUR 35 million or 7%.
Importantly, the AI Act applies directly. As of 11 August 2026, Poland’s Act on Artificial Intelligence Systems is also in force. It established KRiBSI – the Commission for the Risk and Security of Artificial Intelligence Systems – as the national supervisory authority and single point of contact. The Commission will include representatives of, among others, the Polish Financial Supervision Authority, the Office of Competition and Consumer Protection, the Office of Electronic Communications and the National Broadcasting Council. Its full membership and Chair will be appointed by November 2026. GDPR requirements also apply wherever personal data is processed.
An organization that has built AI security around on-premises deployment, data masking and auditability has already addressed many of these requirements at their foundation. Governance is not an add-on to implementation. It is a core component designed in parallel with the solution architecture. This also includes support for GenAI transformation and consulting.
How to Implement AI Security in the Enterprise – 5 Steps
Organizations that have effectively reduced shadow AI typically followed several steps:
- Audit the current state: identify which AI tools are actually being used and for what purposes.
- Define a policy: establish clear rules on what is allowed, what is prohibited and who is accountable.
- Choose a GenAI platform provider with AI governance built in, rather than layering controls onto off-the-shelf tools.
- Run a pilot with one or two teams: validate the solution in real processes before scaling.
- Scale across the organization, while monitoring adoption and outcomes.
Practical guidance on the right implementation sequence is available in the GenAI implementation guide.
Summary
AI security in 2026 is not a choice between innovation and control. It is the ability to combine both. Shadow AI will not disappear because of a ban. It will decline when the organization provides a solution that is equally convenient but also secure. Keeping data within company infrastructure, applying data anonymization, ensuring auditability and embedding governance from day one turns risk into an advantage.
A practical first step is to see how a controlled GenAI platform works in real organizational processes. Book a platform demo to see what AI security looks like in practice.
FAQ
How can an organization reduce shadow AI?
Shadow AI is reduced not through bans, but by providing a secure alternative: an enterprise GenAI platform with data hosted in the organization’s infrastructure, sensitive data masking, access control and auditability. An acceptable use policy and an inventory of AI tools complement this approach. A separate article discusses the phenomenon itself and its GDPR implications.
Is it enough to prohibit employees from using public GenAI?
A ban alone usually does not work, as employees find workarounds and the organization loses visibility. A more effective approach is to provide a secure, controlled alternative that complies with company policy.
How does an on-premises deployment improve AI security?
In an on-premises model, data is processed within the organization’s infrastructure and does not leave the company. This reduces the risk of data leakage and makes it easier to meet GDPR and industry-specific regulatory requirements.
What is data masking in the context of AI security?
It is a mechanism that replaces sensitive data with fictitious equivalents before a prompt is sent to a model, then restores the original values after the response is received. It enables the safe use of external models as well.
What does the AI Act mean for AI security in the enterprise?
The timeline was changed by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which has applied since 27 July 2026. Transparency requirements have applied since 2 August 2026. The main obligations for standalone high-risk systems under Annex III, including recruitment and credit scoring, will apply from 2 December 2027. For AI embedded in regulated products under Annex I, they will apply from 2 August 2028. Since 11 August 2026, Poland’s Act on Artificial Intelligence Systems has also been in force, establishing KRiBSI as the national supervisory authority. An architecture based on on-premises deployment, data masking and comprehensive activity logging addresses most of these requirements at the foundation, regardless of the applicable deadline.
Sources
[1] Gartner, Gartner Identifies the Top Cybersecurity Trends for 2026 (badanie V–XI 2025, próba 175 pracowników), 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026
[2] Gartner, Gartner Identifies Critical GenAI Blind Spots That CIOs Must Urgently Address (69% liderów bezpieczeństwa), 2025. https://www.infosecurity-magazine.com/news/gartner-40-firms-hit-shadow-ai/
[3] Gartner, Predicts 25% of Enterprise GenAI Applications Will Experience Five Minor Security Incidents Per Year By 2028, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-04-09-gartner-predicts-25-percent-of-all-enterprise-gen-ai-applications-will-experience-at-least-five-minor-security-incidents-per-year-by-2028
[4] KPMG, Sztuczna inteligencja w Polsce. Krajobraz pełen paradoksów, 2025. https://kpmg.com/pl/pl/wiedza/technologia/sztuczna-inteligencja-w-polsce.html
[5] IBM Newsroom, IBM Report: 13% of Organizations Reported Breaches of AI Models or Applications, 2025. https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls
[6] European Commission, Regulatory framework for AI / harmonogram EU AI Act, 2026. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
[7] Extentum AI, Dlaczego 9 na 10 projektów AI kończy się fiaskiem, 2026. https://extentum.ai/pl/projekty-ai-dlaczego-koncza-sie-fiaskiem/
[8] Extentum AI, Co to jest shadow AI i dlaczego pracownicy wrzucają dane firmowe do ChatGPT, 2026. https://extentum.ai/pl/shadow-ai-ryzyko-rodo-wycieki-danych/