AI Can Steal Sensitive Data: How Artificial Intelligence Is Changing Corporate Security

AI Can Steal Sensitive Data: How Artificial Intelligence Is Changing Corporate Security

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
3. 6. 2026
3 minutes reading · 5 views
AI Can Steal Sensitive Data: How Artificial Intelligence Is Changing Corporate Security

Artificial intelligence has already become a common part of work in companies. However, every new technology also brings new ways that can put sensitive data at risk. The complexity of the situation is also demonstrated by the fact that not only users but developers themselves are struggling with the pitfalls of AI. And that includes Google itself. What are the most common risks, and how can they be prevented?

Security Cannot Be “Added Later”

The whole issue was neatly summarized by Francis de Souza, one of the executives at Google Cloud, in an interview with TechCrunch. His main point is simple: security must be addressed from the outset, not only once a problem arises. It is similar to building a house. Locks and alarms need to be installed right away, not after your home has been burgled.

In practice, he primarily highlights two issues that the vast majority of companies struggle with. First, he believes that a company should choose AI tools with built-in data protection rather than having to add it later through a complicated process. Second, he warns that security cannot be left up to employees to handle on their own.

This second point brings us to a phenomenon known as “shadow AI”. This refers to a situation in which employees freely use common public tools such as ChatGPT for work and copy company contracts or customer data into them without informing anyone.

And these are certainly not isolated cases. According to a report by Menlo Security from August 2025, as many as 68% of employees use free AI tools, and 57% of them enter sensitive data into these tools.

Attacks Are Faster and Target New Areas

De Souza also pointed out that hackers now launch attacks much faster than they used to. The average time between the initial breach and the next phase of an attack has fallen from eight hours to 22 seconds, making the situation even worse.

Moreover, new vulnerabilities are constantly emerging. Whereas companies once only needed to protect their computers and internal networks, today the number of “entry points” into companies is growing. These include the AI models themselves, training data, AI agents, and text prompts that we give them. Each of these areas can be attacked.

Companies also often overlook data that has been sitting on their servers for years. This usually consists of archived documents or spreadsheets that were forgotten long ago. However, automated AI assistants typically move through this environment completely freely and may find and extract information from these forgotten files.

And the figures show that this is far from inexpensive. According to IBM data from 2025, a data breach caused by “shadow AI” costs a company an average of $670,000 more and takes ten days longer to resolve than a typical incident.

Even AI Creators Are Learning as They Go

And now for the most interesting part. While large companies advise others on how to set up security mechanisms, they sometimes run into their own mistakes.

According to TechCrunch, The Register described a series of cases in which developers received bills from Google amounting to thousands of dollars for AI services they had never knowingly enabled. It eventually emerged that attackers had obtained their access keys and begun using paid AI services at someone else’s expense. One victim even received a bill of more than $10,000 in just 30 minutes.

What should we take away from this? AI security appears to be a highly complex discipline. Even LinkedIn’s head of security, Lea Kissner, said that companies will need experts capable of dealing with new types of vulnerabilities.

Although it may seem that smaller companies without strong IT departments are the ones struggling with AI, the opposite is true. Even large technology companies currently face a gap between the advice they give others and how quickly they themselves are adapting.

Advertisement

Content created with help from UpTier.

SEO and GEO on autopilot. UpTier’s multi-agent systems write and optimize content for search engines and AI answers.

Discover UpTier ↗

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Amazon releases Strands Decider 2B for AI workflow decisionsAmazon releases Strands Decider 2B for AI workflow decisions
Strands Decider 2B selects from predefined options and returns a confidence score. The fully open-source model is available now and small enough to run locally.
2 min read
1. 10. 2026
OpenAI says it disrupted a campaign to extract hidden model reasoningOpenAI says it disrupted a campaign to extract hidden model reasoning
OpenAI reported a coordinated effort to extract protected model reasoning and said it closed an extraction pathway. It attributed the main cluster of activity to individuals associated with Moonshot AI, the developer of Kimi.
3 min read
1. 10. 2026
Meta Enterprise Platform aims to bring AI tools to businessesMeta Enterprise Platform aims to bring AI tools to businesses
Meta’s new enterprise initiative plans to bring Muse, Meta Business Agent, Muse API and Muse Code to businesses and developers. Former MongoDB CEO CJ Desai will lead the effort.
1 min read
1. 10. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok