A wide spectrum of data is being shared by employees through generative AI (GenAI) tools, researchers have found, legitimizing many organizations' hesitancy to fully adopt AI practices. Every time a user enters data into a prompt for ChatGPT or a similar tool, the information is ingested into the service's LLM data set as source material used to train the next generation of the algorithm. The concern is that the information could be retrieved at a later date via savvy prompts, a vulnerability, or a hack, if proper data security isn't in place for the service. That's according to researchers at Harmonic Security, who analyzed thousands of prompts submitted by users into GenAI platforms such as Microsoft, Copilot, OpenAI ChatGPT, Google Gemini, Anthropic's Clause, and Perplexity. In their research, they discovered that though in many cases employee behavior in using these tools was straightforward, such as wanting to summarize a piece of text, edit a blog, or some other relatively simple task, there were a subset of requests that were much more compromising. In all, 8.5% of the analyzed GenAI prompts included sensitive data, to be exact. The sensitive data that employees are sharing often falls into one of five categories: customer data, employee data, legal and finance, security, and sensitive code, according to Harmonic Security. Customer data holds the biggest share of sensitive data prompts, at 45.77%, according to the researchers. An example of this is when employees submi...
Employees Enter Sensitive Data Into GenAI Prompts Far Too Often
Dark Reading
·Kristina Beek
·Published Jan 17, 2025
·Updated
Affected Software
10 affected components
Microsoft Copilot
OpenAI ChatGPT
Google Gemini
anthropic Clause
Perplexity
OpenAI ChatGPT
Microsoft Copilot
Google Gemini
anthropic Clause
Perplexity Perplexity
Frequently Asked Questions
1
What is the main concern regarding employee usage of generative AI tools?
Employees are frequently entering sensitive data into generative AI prompts, posing significant security risks.
2
Which generative AI tools are mentioned as being used by employees?
The article mentions tools such as Microsoft Copilot, OpenAI ChatGPT, Google Gemini, Anthropic Clause, and Perplexity.
3
What is the impact of employees sharing sensitive data with AI tools on organizations?
The prevalence of sharing sensitive data has led many organizations to hesitate in fully adopting generative AI technologies.
4
What type of data are employees likely to input into generative AI prompts?
A wide spectrum of sensitive data, including private and confidential information, is being shared by employees.
5
Why is there reluctance among organizations to adopt AI practices according to the article?
Organizations are hesitant to embrace AI practices due to the risks associated with data exposure through generative AI tools.