• News/
  • https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts

Employees Enter Sensitive Data Into GenAI Prompts Far Too Often

Dark Reading
·
Kristina Beek
·
Published Jan 17, 2025
·
Updated

A wide spectrum of data is being shared by employees through generative AI (GenAI) tools, researchers have found, legitimizing many organizations' hesitancy to fully adopt AI practices. Every time a user enters data into a prompt for ChatGPT or a similar tool, the information is ingested into the service's LLM data set as source material used to train the next generation of the algorithm. The concern is that the information could be retrieved at a later date via savvy prompts, a vulnerability, or a hack, if proper data security isn't in place for the service. That's according to researchers at Harmonic Security, who analyzed thousands of prompts submitted by users into GenAI platforms such as Microsoft, Copilot, OpenAI ChatGPT, Google Gemini, Anthropic's Clause, and Perplexity. In their research, they discovered that though in many cases employee behavior in using these tools was straightforward, such as wanting to summarize a piece of text, edit a blog, or some other relatively simple task, there were a subset of requests that were much more compromising. In all, 8.5% of the analyzed GenAI prompts included sensitive data, to be exact. The sensitive data that employees are sharing often falls into one of five categories: customer data, employee data, legal and finance, security, and sensitive code, according to Harmonic Security. Customer data holds the biggest share of sensitive data prompts, at 45.77%, according to the researchers. An example of this is when employees submi...

Read full article

Affected Software

10 affected components
Microsoft Copilot
OpenAI ChatGPT
Google Gemini
anthropic Clause
Perplexity
OpenAI ChatGPT
Microsoft Copilot
Google Gemini
anthropic Clause
Perplexity Perplexity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main concern regarding employee usage of generative AI tools?

Employees are frequently entering sensitive data into generative AI prompts, posing significant security risks.

2

Which generative AI tools are mentioned as being used by employees?

The article mentions tools such as Microsoft Copilot, OpenAI ChatGPT, Google Gemini, Anthropic Clause, and Perplexity.

3

What is the impact of employees sharing sensitive data with AI tools on organizations?

The prevalence of sharing sensitive data has led many organizations to hesitate in fully adopting generative AI technologies.

4

What type of data are employees likely to input into generative AI prompts?

A wide spectrum of sensitive data, including private and confidential information, is being shared by employees.

5

Why is there reluctance among organizations to adopt AI practices according to the article?

Organizations are hesitant to embrace AI practices due to the risks associated with data exposure through generative AI tools.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203