Lots of sensitive data is still being posted to ChatGPT

Business person chatting with a smart AI using an artificial intelligence chatbot developed by OpenAI. Artificial intelligence system support is the future.
(Image credit: Shutterstock/Miha Creative)

New data from Netskope has claimed employees are continuing to share sensitive company information with AI writers and chatbots like ChatGPT despite the clear risk of leaks or breaches.

The research covers some 1.7 million users across 70 global organizations, and found an average of 158 monthly incidents of source code being posted to ChatGPT per 10,000 users, making it the most significant company vulnerability ahead of other types of sensitive data.

While cases of regulated data (18 incidents/10,000 users/month) and intellectual property (four incidents/10,000 users/month) being posted to ChatGPT are much less common, it’s clear that many developers are simply not realizing the damage that can be caused by leaked source code.

Be careful what you post on ChatGPT

Alongside continued exposures that could lead to weak points for enterprises, Netskope also highlighted the boom in interest in artificial intelligence. The figures point at a 22.5% growth in GenAI app usage over the past two months, with large enterprises of over 10,000 users using an average of five AI apps daily.

ChatGPT takes the lead, accounting for eight times as many daily active users than any other GenAI app. With an average of six prompts daily, each user has the potential to cause considerable damage to their employer.

Rounding up the top three generative AI apps in use by organizations globally besides ChatGPT (84%) are Grammarly (9.9%) and Bard (4.5%), which itself is experiencing healthy growth of 7.1% per week compared with 1.6% per week for ChatGPT.

Many will argue that uploading source code or other sensitive information can be avoided, but Netskope’s Threat Research Director, Ray Canzanese, says that it is “inevitable.” Instead, Canzanese places the responsibility on organizations to implement controls around AI.

James Robinson, the company’s Deputy Chief Information Security Officer, added: “Organizations should focus on evolving their workforce awareness and data policies to meet the needs of employees using AI products productively.”

For admins and IT teams, the company suggests blocking access to unnecessary apps or those that pose a disproportionate risk, providing frequent user coaching, and adopting sufficient modern data loss prevention technologies.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A profile of a human brain against a digital background.
Securely working with AI-generated code
Workplace AI Adoption
ChatGPT remains the most popular AI tool in offices worldwide, survey finds, with India leading the way
DeepSeek
Experts warn DeepSeek is 11 times more dangerous than other AI chatbots
An AI face in profile against a digital background.
Worried about DeepSeek? Well, Google Gemini collects even more of your personal data
A person using DeepSeek on their smartphone
DeepSeek ‘incredibly vulnerable’ to attacks, research claims
DDoS attack
ChatGPT security flaw could open the gate for devastating cyberattack, expert warns
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)