Artificial intelligence has already become a common part of work in companies. However, every new technology also brings new ways that can put sensitive data at risk. The complexity of the situation is also demonstrated by the fact that not only users but developers themselves are struggling with the pitfalls of AI. And that includes Google itself. What are the most common risks, and how can they be prevented?
Security Cannot Be “Added Later”
The whole issue was neatly summarized by Francis de Souza, one of the executives at Google Cloud, in an interview with TechCrunch. His main point is simple: security must be addressed from the outset, not only once a problem arises. It is similar to building a house. Locks and alarms need to be installed right away, not after your home has been burgled.
In practice, he primarily highlights two issues that the vast majority of companies struggle with. First, he believes that a company should choose AI tools with built-in data protection rather than having to add it later through a complicated process. Second, he warns that security cannot be left up to employees to handle on their own.
This second point brings us to a phenomenon known as “shadow AI”. This refers to a situation in which employees freely use common public tools such as ChatGPT for work and copy company contracts or customer data into them without informing anyone.
And these are certainly not isolated cases. According to a report by Menlo Security from August 2025, as many as 68% of employees use free AI tools, and 57% of them enter sensitive data into these tools.
Attacks Are Faster and Target New Areas
De Souza also pointed out that hackers now launch attacks much faster than they used to. The average time between the initial breach and the next phase of an attack has fallen from eight hours to 22 seconds, making the situation even worse.
Moreover, new vulnerabilities are constantly emerging. Whereas companies once only needed to protect their computers and internal networks, today the number of “entry points” into companies is growing. These include the AI models themselves, training data, AI agents, and text prompts that we give them. Each of these areas can be attacked.
Companies also often overlook data that has been sitting on their servers for years. This usually consists of archived documents or spreadsheets that were forgotten long ago. However, automated AI assistants typically move through this environment completely freely and may find and extract information from these forgotten files.
And the figures show that this is far from inexpensive. According to IBM data from 2025, a data breach caused by “shadow AI” costs a company an average of $670,000 more and takes ten days longer to resolve than a typical incident.
Even AI Creators Are Learning as They Go
And now for the most interesting part. While large companies advise others on how to set up security mechanisms, they sometimes run into their own mistakes.
According to TechCrunch, The Register described a series of cases in which developers received bills from Google amounting to thousands of dollars for AI services they had never knowingly enabled. It eventually emerged that attackers had obtained their access keys and begun using paid AI services at someone else’s expense. One victim even received a bill of more than $10,000 in just 30 minutes.
What should we take away from this? AI security appears to be a highly complex discipline. Even LinkedIn’s head of security, Lea Kissner, said that companies will need experts capable of dealing with new types of vulnerabilities.
Although it may seem that smaller companies without strong IT departments are the ones struggling with AI, the opposite is true. Even large technology companies currently face a gap between the advice they give others and how quickly they themselves are adapting.



