AI is forcing enterprises to rethink security risk. Much of the conversation focuses on attackers using AI to scale phishing, automate reconnaissance, improve social engineering, and accelerate malware development. There is also a valid concern around how AI systems themselves are built, governed, and secured.
Those issues matter, but for most organizations, the biggest and most immediate AI security risk is not only how AI systems are built, it’s how employees are using AI with sensitive company data. That makes AI security, at its core, a data leakage problem.
Employees are bringing ChatGPT, Copilot, Claude, Gemini, and AI agents into everyday work because these tools help them draft, code, research, and respond faster. While the productivity gain is real, so is the exposure. Every prompt, file upload, and agent action can become a moment where sensitive data leaves the organization.
The danger is not that employees are trying to misuse AI. In most cases, they are using it exactly as intended: to move faster. AI simply changes the risk attached to normal work.
AI creates a new path for data to leave
Traditional data loss had familiar patterns. A file was emailed to the wrong person, a document was shared too broadly, or a spreadsheet was uploaded into an unsanctioned app. Those risks still exist, but AI creates a faster, less visible path for sensitive information to move.
Employees may paste customer context into prompts, ask coding assistants to debug proprietary code, upload contracts for summarization, analyze financial spreadsheets, or include customer records to resolve support issues faster.
Each action may seem reasonable. But each one can carry regulated or confidential data into an AI workflow the organization may not fully govern.
That is why enterprises need to separate two questions: “Is this AI system secure?” and “What sensitive data are employees putting into it?” A company can choose a reputable AI vendor and still face serious risk if employees copy sensitive data into AI without the right controls.
Most AI insider risk is accidental
Insider risk often brings to mind malicious employees stealing data. In the AI era, the more common scenario is an employee trying to move quickly and accidentally putting sensitive data somewhere it should not go.
AI changes the consequences of ordinary behavior because a single prompt can contain more sensitive context than an email. One upload can expose an entire business relationship, and one connected assistant can pull from multiple systems before moving information somewhere the company has less control. The “insider” is also changing: it is no longer only the employee at the keyboard, but increasingly the AI assistant acting on that employee’s behalf. Without visibility into the data itself, organizations cannot tell the difference between safe productivity and risky exposure.
That is why treating AI as an allow-or-ban decision rarely works. If employees believe AI helps them do their jobs better, they will find a way to use it. If approved tools are too restrictive or unclear, they may turn to personal accounts, unsanctioned apps, browser extensions, or other tools security teams cannot monitor.
The better approach is to give employees safe paths. Enterprises should approve specific tools, define acceptable use, and explain the difference between low-risk and high-risk interactions. Drafting generic copy is different from uploading a customer contract. Summarizing public information is not the same as pasting
Employees need clear rules, but they also need guardrails at the moment mistakes happen and the data begins to move.
Companies need context, not blanket control
To manage this risk, enterprises need to understand data movement around AI. What data is being used? Who is using it? Where did it come from? Where is it going? Does the action make sense for that employee, tool, and workflow?
Certain categories should clearly never be entered into unmanaged AI tools: customer records, PII, PHI, payment data, credentials, materials, security findings, trade secrets, product roadmaps, and incident response plans
But sensitivity is contextual. A single prompt can combine customer information, internal strategy, business logic, and code in a way that creates risk even if each element does not trigger a simple rule.
This is why companies need real-time contextual controls. If an employee pastes sensitive data into a prompt, uploads a risky file, or connects an AI assistant to a sensitive the data leaves
AI security risk is a data problem, and that risk is biggest at the employee level. The organizations that succeed will give employees safe ways to use AI, with visibility into what data is moving, context about where it is going, and controls that stop sensitive information before it becomes a leak.
Jonathan Kreiner is Co-Founder and CTO at ORION Security, which stops data loss by analyzing data in motion with context-aware AI agents. Prior to ORION, he led Application Security at WalkMe. Before that, he served in Unit 8200, the Israeli military’s elite signals intelligence unit. Jonathan was named to Forbes 30 Under 30 in 2025.
