- The Exposure Nobody Logged
How Employees Leak Company Data to AI Tools
It is almost never malicious and it is almost never logged. Here are the seven ways company information actually ends up in a consumer AI tool, and what stops each one.
Start Here
Your Staff Are Not the Problem
Every conversation about this starts in the wrong place. The instinct is to treat it as a discipline issue, someone did something they should not have. In practice, the person pasting a contract into a chatbot at nine at night is trying to finish work that needs finishing, using a tool that is free, fast, and one browser tab away. They are behaving rationally inside a system that gave them no sanctioned alternative.
This matters because it determines what actually works. A blanket ban moves the behavior onto personal phones, where you cannot see it, cannot log it, and cannot help. A sanctioned tool plus a clear written policy keeps the work visible and keeps the data inside your tenant. That is the whole of the strategy, and it is why we treat this as an enablement problem with a security wrapper rather than the other way around.
The seven routes below are the ones we find in real environments. Most businesses have at least three of them running right now.
Most of the leakage we find in Dallas offices is not malicious. It is a well-meaning employee pasting a client document into a personal chatbot login to save an hour, and no one in the building knows it happened until we run the review from our Plano office.
THE SEVEN ROUTES
Where Company Data Actually Goes
1
Pasting Documents in for Summarizing
The single most common route. Contracts, proposals, board minutes, and patient correspondence pasted whole into a free chatbot because reading forty pages before a meeting is not realistic.
What stops it: data-loss prevention rules on upload, plus fixing the underlying data quality problem.
2
Drafting Client Communication
“Write a polite response to this complaint”, with the complaint, the client name, the account history, and the internal note about why they are upset all included for context.
What stops it: training on what counts as identifying context, plus a sanctioned drafting tool.
3
Spreadsheet and Data Cleanup
Uploading a customer export, a payroll sheet, or a donor list to have it deduplicated or reformatted. The file is often the most sensitive thing the business owns.
What stops it: data-loss prevention rules on upload, plus fixing the underlying data quality problem.
4
Browser Extensions Nobody Approved
An AI writing assistant installed from a browser store that reads the content of every page it sits on, including your practice management system and your webmail.
What stops it: extension allow-listing through managed browser policy. Cheap, and almost never configured.
5
Meeting Transcription Bots
A note-taker joins a call because one attendee connected it to their calendar. It records everything said, retains it on a third-party service, and often nobody in the meeting consented.
What stops it: meeting-platform policy controlling which apps can join, plus a stated rule about consent.
6
Personal Accounts on Personal Devices
Work photographed or retyped on a phone, outside every control you have. This is where a ban sends the behavior, which is precisely why bans make the picture worse.
What stops it: giving people a sanctioned tool that is genuinely good enough to prefer.
7
Free Tiers of Tools You Think You Control
The subtlest one. Your business pays for a platform, but staff signed up individually for the free consumer tier of the same brand, where the terms permitting training on submitted content are materially different from your enterprise agreement. The logo is identical; the contract is not.
What stops it: tenant-level sign-in enforcement, so the work account is the only one that works on company devices. Covered in vetting an AI vendor.
What To Do
The Order That Works
1. Find out what is running
Not by asking. Sign-in logs, browser extensions, and connected apps tell you the truth without anyone having to confess.
2. Sanction something good
Give people a tool inside your tenant that does the job they were trying to do. This step does more than the other three combined.
3. Write it down
One page: what is approved, what is never allowed, and who to ask. Our template is free.
4. Then close the gaps
Extension allow-listing and upload rules land far better once people already have a sanctioned way to work.
FAQS
Frequently Asked Questions
What owners ask once they realize this is already happening.
Can we find out what has already been shared?
Partly. You can establish which tools have been signed into with work accounts, which extensions are installed, and which apps are connected to your platforms. What you generally cannot recover is the content of individual prompts on personal accounts. That asymmetry is the argument for acting now rather than investigating forever.
Is data pasted into a chatbot used to train the model?
It depends entirely on the tier and the terms, which is the point. Enterprise agreements typically exclude it; consumer free tiers frequently do not, and the terms change. This is exactly what we check during a vendor review rather than assume.
Should we just block AI sites at the firewall?
On its own, no. Blocking without providing an alternative reliably moves the same work onto personal phones on cellular, which is worse in every respect, no logging, no policy, no ability to help. Blocking is a reasonable fourth step, not a first one.
Someone already pasted patient information into a chatbot. What now?
Treat it as a potential incident and work it in order rather than reacting. We have set out the sequence in what to do when data goes into an AI tool. Do not start by disciplining the person. You need their account details and their honest recollection.
BK
Written and reviewed by Bob Kehr, President & Founder of Kehr Technologies, Plano City Council member, and Plano Chamber Small Business Person of the Year 2022, all seven of these routes are ones his team has found in real Dallas businesses, not hypotheticals.
Last reviewed August 2026 · Questions we have not answered here? Call 214-444-3583. Kehr Technologies is based in Plano, Texas, and works with businesses throughout the Dallas area.