Kehr Technologies

How Employees Leak Company Data to AI Tools

It is almost never malicious and it is almost never logged. Here are the seven ways company information actually ends up in a consumer AI tool, and what stops each one.

Start Here

Your Staff Are Not the Problem

Every conversation about this starts in the wrong place. The instinct is to treat it as a discipline issue, someone did something they should not have. In practice, the person pasting a contract into a chatbot at nine at night is trying to finish work that needs finishing, using a tool that is free, fast, and one browser tab away. They are behaving rationally inside a system that gave them no sanctioned alternative. 

This matters because it determines what actually works. A blanket ban moves the behavior onto personal phones, where you cannot see it, cannot log it, and cannot help. A sanctioned tool plus a clear written policy keeps the work visible and keeps the data inside your tenant. That is the whole of the strategy, and it is why we treat this as an enablement problem with a security wrapper rather than the other way around. 

The seven routes below are the ones we find in real environments. Most businesses have at least three of them running right now. 

Most of the leakage we find in Dallas offices is not malicious. It is a well-meaning employee pasting a client document into a personal chatbot login to save an hour, and no one in the building knows it happened until we run the review from our Plano office.

THE SEVEN ROUTES

Where Company Data Actually Goes

1

Pasting Documents in for Summarizing

The single most common route. Contracts, proposals, board minutes, and patient correspondence pasted whole into a free chatbot because reading forty pages before a meeting is not realistic.

What stops it: data-loss prevention rules on upload, plus fixing the underlying data quality problem.

2

Drafting Client Communication

“Write a polite response to this complaint”, with the complaint, the client name, the account history, and the internal note about why they are upset all included for context.

What stops it: training on what counts as identifying context, plus a sanctioned drafting tool.

3

Spreadsheet and Data Cleanup

Uploading a customer export, a payroll sheet, or a donor list to have it deduplicated or reformatted. The file is often the most sensitive thing the business owns.

What stops it: data-loss prevention rules on upload, plus fixing the underlying data quality problem.

4

Browser Extensions Nobody Approved

An AI writing assistant installed from a browser store that reads the content of every page it sits on, including your practice management system and your webmail.

What stops it: extension allow-listing through managed browser policy. Cheap, and almost never configured.

5

Meeting Transcription Bots

A note-taker joins a call because one attendee connected it to their calendar. It records everything said, retains it on a third-party service, and often nobody in the meeting consented.

What stops it: meeting-platform policy controlling which apps can join, plus a stated rule about consent.

6

Personal Accounts on Personal Devices

Work photographed or retyped on a phone, outside every control you have. This is where a ban sends the behavior, which is precisely why bans make the picture worse.

What stops it: giving people a sanctioned tool that is genuinely good enough to prefer.

7

Free Tiers of Tools You Think You Control

The subtlest one. Your business pays for a platform, but staff signed up individually for the free consumer tier of the same brand, where the terms permitting training on submitted content are materially different from your enterprise agreement. The logo is identical; the contract is not.

What stops it: tenant-level sign-in enforcement, so the work account is the only one that works on company devices. Covered in vetting an AI vendor.

What To Do

The Order That Works

1. Find out what is running

Not by asking. Sign-in logs, browser extensions, and connected apps tell you the truth without anyone having to confess.

2. Sanction something good

Give people a tool inside your tenant that does the job they were trying to do. This step does more than the other three combined.

3. Write it down

One page: what is approved, what is never allowed, and who to ask. Our template is free.

4. Then close the gaps

Extension allow-listing and upload rules land far better once people already have a sanctioned way to work.

FAQS

Frequently Asked Questions

What owners ask once they realize this is already happening.

Can we find out what has already been shared?

Partly. You can establish which tools have been signed into with work accounts, which extensions are installed, and which apps are connected to your platforms. What you generally cannot recover is the content of individual prompts on personal accounts. That asymmetry is the argument for acting now rather than investigating forever.

It depends entirely on the tier and the terms, which is the point. Enterprise agreements typically exclude it; consumer free tiers frequently do not, and the terms change. This is exactly what we check during a vendor review rather than assume.

On its own, no. Blocking without providing an alternative reliably moves the same work onto personal phones on cellular, which is worse in every respect, no logging, no policy, no ability to help. Blocking is a reasonable fourth step, not a first one.

Treat it as a potential incident and work it in order rather than reacting. We have set out the sequence in what to do when data goes into an AI tool. Do not start by disciplining the person. You need their account details and their honest recollection.

BK

Written and reviewed by Bob Kehr, President & Founder of Kehr Technologies, Plano City Council member, and Plano Chamber Small Business Person of the Year 2022, all seven of these routes are ones his team has found in real Dallas businesses, not hypotheticals.

Last reviewed August 2026 · Questions we have not answered here? Call 214-444-3583. Kehr Technologies is based in Plano, Texas, and works with businesses throughout the Dallas area.

Continue Reading

What is Shadow AI?

The umbrella problem this page is one symptom of.

The AI Security Audit

How we establish what is running without relying on self-report.

AI Use Policy Template

The one-page policy, free to download and adapt.

Scroll to Top