Articles

Your employees are sharing company data with AI. Do you know what happens next?

Two Data Booster colleagues working together at a laptop in the office

Register here

Register

AI is already inside your organization. It is in your employees' browsers, their workflows, and their daily decisions. The question is no longer whether your people are using AI, it is whether anyone is in control of how they are using it. Today, we want to shine a light on what we call the silent killer: the growing gap between AI adoption and AI governance.

Let's talk numbers

It gets worse. 88% of employees now use AI at work, but 43% of companies have no AI usage policy. Only about a third have anything formal in place. Meanwhile, 56% of workers say they have received zero clear guidance on what’s okay to share with AI and what isn’t. So the tools are everywhere, with no guardrails to be found.

Shadow AI - which is the use of unapproved AI tools within organizations - has increased 156% since 2023. And 38% of employees openly admit to sharing sensitive company data with AI tools without permission. That is not a hypothetical risk. That is happening right now, in your organization.

What does this actually cost?

IBM's Cost of a Data Breach Report 2025 puts the global average breach at $4.44 million. Breaches involving a high level of shadow AI cost an extra $670,000 on top of that, and 97% of the organizations that suffered an AI-related breach said they lacked proper AI access controls.

The scale of exposure is the other half of the problem. Concentric AI's 2025 Data Risk Report found that Microsoft Copilot accessed close to 3 million sensitive records per organization in the first half of the year. If that can happen inside a sanctioned, enterprise-grade tool, it can happen anywhere your people paste company data.

The governance gap

The headlines speak for themselves. Stolen databases, leaked customer records, exposed internal documents; it feels like we cannot go two weeks without another breach making the news. And when you look at the numbers behind these incidents, it all starts to make sense. According to IBM, 63% of breached organizations had no AI governance policy in place, or were still developing one.

In the same report, 20% of breached organizations were compromised through shadow AI — unapproved AI tools adopted without security sign-off. These are not edge cases. Grok alone had over 370,000 user conversations indexed by search engines because its share feature produced public URLs without any no-index protection, and government documents marked "For Official Use Only" have been uploaded straight into ChatGPT. The pattern is clear: where governance is missing, exposure follows.

Training is the other gap. Only a minority of employees have had any formal AI training, and organizations consistently name knowledge and training gaps as their biggest barrier to responsible AI.

Regulation is coming, and it is close

If the business risks are not enough to move you, the legal ones should be. The EU AI Act becomes fully enforceable on 2 August 2026 — next month. The penalties for prohibited practices run to €35 million or 7% of global annual turnover, whichever is higher. That is above the GDPR ceiling, and many organizations still cannot say which risk category their AI systems fall into.

This is not a "nice-to-have" conversation anymore. This is a "get-ready-or-pay-the-price" reality.

So, what do we do about it?

The good news is: this is fixable. But it requires action, not just awareness. Organizations that lead in AI governance share a few things in common. They have clear, communicated AI usage policies that every employee knows about. They assign real ownership for AI governance, not just a committee that meets once a month. They embed governance into existing workflows instead of treating it as an afterthought. And critically, they invest in AI literacy across the entire organization, not just the tech team.

There is one more piece that often gets overlooked: upskilling. Having a governance policy on paper is one thing but making sure your people actually understand it is another. Teams need to know what responsible AI looks like in practice; what data can and cannot be shared, how to evaluate AI outputs critically, and where the boundaries are.

But it does not stop at governance awareness. People also need the skills to actually work with AI effectively and within the guardrails your organization has set. Without that, you either get shadow AI (people finding workarounds) or stagnation (people avoiding AI altogether out of fear). The sweet spot is when your workforce understands both the rules and the tools. That is when governance stops being a blocker and starts being a competitive advantage.

The most mature organizations have figured out something important: governance does not slow down innovation. It enables it. When people know the boundaries, they move faster and with more confidence.

At Data Booster, we help organizations close this gap and we do it at scale. We work with internationally operating companies to build capability programs that don't just inform employees about responsible AI use, but serve as a prerequisite for getting access to AI tools in the first place. Before your people touch the tools, they understand the rules. Through hands-on training and tailored programs, we equip teams with the AI literacy and governance understanding they need; so your people don't just use AI, they use it responsibly. Because the silent killer only stays silent until the damage is done.

These teams went before you

Rabobank logoING logoPostNL logoJust Eat Takeaway logoSkyscanner logoJumbo logoPGGM logoAllianz Partners logoJaarbeurs logoSHV Energy logoProvincie Limburg logo