Join our Newsletter — 33% off our NHI Course

AI data leaks and shadow AI: what IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: AI data leaks now span prompts, coding assistants, training data, and autonomous agent workflows, and 20% of organizations with a breach said shadow AI was involved in 2025, according to WitnessAI. The real issue is not just leakage, but that existing DLP and CASB controls were never built for intent-driven AI interactions or machine-speed data movement.

Editorial analysis by NHI Mgmt Group, based on content published by WitnessAI: “What Are AI Data Leaks? Risks, Costs, and Prevention”.

By the numbers:

  • 20% of organisations that suffered a data breach said the security incidents involved shadow AI in 2025.

Key questions

Q: What breaks when employees use unapproved AI tools with company data?

A: Governance breaks because the organisation loses visibility into where data and secrets are going, who can access them, and how they are being reused.

Q: Why do AI data leaks create a different risk than traditional data loss?

A: Traditional data loss controls assume static content, known channels, and predictable movement.

Q: How can organisations tell whether AI governance is actually working?

A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped.

Practitioner guidance

  • Establish an AI acceptable-use policy Define which AI tools, data classes, and use cases are permitted, then pair the policy with enforcement so it cannot be bypassed through personal accounts or shadow tools.
  • Extend visibility across all AI surfaces Track browser use, desktop apps, coding assistants, embedded copilots, and agent connections so prompts and outputs are visible where data first enters or leaves the environment.
  • Classify by intent and context Evaluate what the user is trying to do, not just the words in the prompt, so legitimate analysis does not trigger the same controls as pre-disclosure sharing or exfiltration.

Bottom line: AI data leaks are now a governance issue because ordinary work interactions can move sensitive information into AI systems outside traditional visibility and control.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.