TL;DR: 2025 saw record-setting breaches, widespread AI-related leakage and repeated supply chain compromise, according to Ground Labs, while 155 countries now have enacted data protection and privacy laws, underscoring the gap between regulatory ambition and operational control. Data security is shifting from point-in-time compliance to continuous visibility, containment and governance across data, AI and third-party ecosystems.
NHIMG editorial — based on content published by Ground Labs: Data security 2025: A retrospective perspective
By the numbers:
- 70% of organizations have experienced data leakage through, through employee use of AI tools.
- 13% of organizations reported breaches of their AI models or applications, and 97% of those were linked to ineffective AI access controls.
- 155 out of 195 countries have enacted data protection and privacy legislation, equivalent to 82% of the world’s population.
Questions worth separating out
Q: How can organisations reduce data exposure in AI tools?
A: Start with data classification, then map where sensitive information can flow into prompts, connectors, and logs.
Q: Why do third-party services create such a large data security risk?
A: Third parties often sit inside trusted workflows with broad permissions, so a compromise can expose data at scale without needing direct user compromise.
Q: What do organisations get wrong about AI data retention?
A: They often assume retention is an operational setting rather than a security decision.
Practitioner guidance
- Map data access across human, machine and AI users Inventory who and what can reach sensitive datasets, including service accounts, API keys, AI tools and external integrations.
- Treat AI prompts and outputs as governed data flows Apply classification, logging and policy controls to prompt content, retrieved context and model outputs so that sensitive information cannot move into unmanaged tools or jurisdictions.
- Shrink third-party trust to minimum necessary privilege Review supplier accounts, file-transfer platforms and package dependencies for excess permissions, then rotate or revoke secrets that are broader than the service function requires.
What's in the full article
Ground Labs' full blog post covers the operational detail this post intentionally leaves for the source:
- Per-incident analysis of the biggest 2025 breaches, including the downstream effects on customers, suppliers and recovery costs.
- Discussion of how AI leakage, sovereignty concerns and regulatory changes interacted across the year.
- Context on specific supply chain attacks involving Oracle EBS, MOVEit and malicious package repositories.
- The article’s retrospective framing on how these trends shaped the year-end data security agenda.
👉 Read Ground Labs’ retrospective on data security breaches, AI leakage and supply chain risk →
Data security 2025: what breach trends mean for control gaps?
Explore further