TL;DR: Employees input sensitive information into AI tools once every three days on average, while data movement into and out of GenAI SaaS rose 80% year over year, underscoring how conversational interfaces are bypassing legacy DLP and governance controls, according to Cyberhaven. The practical issue is not AI itself, but whether security programmes can see and control data egress where work now happens.
NHIMG editorial — based on content published by Cyberhaven: Top Generative AI Security Risks in the Enterprise
By the numbers:
- Cyberhaven's 2026 AI Adoption & Risk Report found that employees input sensitive information into AI tools on average once every three days.
- There’s been an 80% year-over-year increase in data movement events into and out of GenAI SaaS.
- 32.3% of ChatGPT usage, 58.2% of Claude usage, and 60.9% of Perplexity usage in the enterprise occurs through personal rather than corporate accounts.
Questions worth separating out
Q: How should security teams govern personal AI assistants that act on behalf of employees?
A: Treat each assistant as a distinct non-human actor with its own identity, policy scope, and audit trail.
Q: Why do generative AI tools increase data security risk?
A: Generative AI tools increase risk because they expand the number of places where sensitive content can be ingested, copied, surfaced, or misused.
Q: What breaks when DLP only monitors file transfers instead of AI prompts?
A: It misses the dominant leakage channel.
Practitioner guidance
- Inventory AI usage by identity type Classify which tools are used through corporate SSO, which are accessed through personal accounts, and which sessions lack enterprise logging or retention.
- Extend DLP to conversational egress Add controls that inspect prompts, pasted text, and file uploads in browser-based AI sessions, then map those interactions to data sensitivity and user identity.
- Bind AI access to managed identity and audit trails Require SSO-backed access for sanctioned tools, preserve session records, and make account provenance visible to compliance and insider-risk teams.
What's in the full article
Cyberhaven's full blog covers the operational detail this post intentionally leaves for the source:
- Examples of the data categories most commonly entering AI prompts, including source code, customer records, legal documents, and regulated data.
- Detailed explanation of how personal accounts bypass SSO enforcement, centralized logging, retention policies, and governance controls.
- Step-by-step guidance on visibility-first AI policy design, including risk-based monitoring and blocking thresholds.
- Discussion of how endpoint controls can distinguish corporate from personal AI sessions in practice.
👉 Read Cyberhaven's analysis of the top generative AI security risks in the enterprise →
Generative AI security risks: are DLP controls keeping up?
Explore further
AI security is becoming an identity governance problem. When employees use personal AI accounts, the organisation loses the policy enforcement, logging, and accountability that make access governable. That means AI usage cannot be treated as a standalone productivity issue; it must be tied to identity assurance, session context, and data classification. For practitioners, the real control question is whether the account behind the AI interaction is managed enough to be governed.
A question worth separating out:
Q: Who is accountable when an AI agent accesses regulated data improperly?
A: Accountability sits with the teams that govern the agent's identity, the data classification, and the policy that allowed the access path. If those controls are disconnected, no single owner can explain why the access existed or why it was not removed sooner. Shared context is what makes accountability traceable.
👉 Read our full editorial: Generative AI security risks are exposing data governance gaps