top of page

LATEST INSIGHTS

Expert insights across your SaaS environment

Blogs and papers from the SAASiQ team on enterprise SaaS, cloud and AI.

Two-Thirds of Executives Believe Unapproved AI Tools Have Leaked Company Data, WRITER Survey Finds

Writer: SAASiQ.ai
SAASiQ.ai
Apr 17
6 min read

Updated: 6 days ago

Title: Two-Thirds of Executives Believe Unapproved AI Tools Have Leaked Company Data, WRITER Survey Finds

Date: 17 April 2026

Type: Blog

Author: SAASiQ (contact@saasiq.ai)

Word count: 1565 words

Reading time: 6 min

Published: 17-04-2026


WRITER, which sells an enterprise AI platform, published a survey on 7 April in which 67 per cent of executives said they believe their company has suffered a data leak or security breach because an employee used an unapproved AI tool. In the same survey 36 per cent said they had no formal plan for supervising AI agents, and 35 per cent admitted they could not immediately 'pull the plug' on a rogue agent. The figures record what executives believe, and IBM and Netskope have published measured figures on the same question.


What the WRITER survey found

WRITER ran the research with the independent firm Workplace Intelligence between 17 December 2025 and 25 January 2026. It covered 2,400 people using AI at work in the US, UK, Ireland, Benelux, France and Germany, half of them C-suite executives and half employees, at companies with between 100 and more than 10,000 staff across about 30 industries.


On the employee side, 35 per cent said they had entered proprietary company information into public AI tools. WRITER also reported that 29 per cent of employees admitted to what it called sabotaging their company's AI strategy, a category that includes using unapproved tools. Among executives, 55 per cent described AI use at their company as a 'chaotic free-for-all', 79 per cent said AI applications were being created in silos, and 97 per cent said they had deployed AI agents in the past year.


WRITER has a commercial interest in the finding that unmanaged tools are a problem, and the 67 per cent figure measures belief rather than confirmed incidents.


What has been measured

IBM's Cost of a Data Breach Report, published on 30 July 2025 and based on research by the Ponemon Institute across 600 organisations, found that one in five had suffered a breach linked to shadow AI, meaning AI tools that staff adopt without IT or security approval. A high level of shadow AI added $670,000 to the global average breach cost, which IBM put at $4.44 million. Of the organisations that had an AI-related security incident, 97 per cent said they lacked proper AI access controls, and 63 per cent of all those studied had no AI governance policy to manage AI or stop staff using shadow AI.


Netskope, which sells security tools that sit between users and cloud services, publishes figures from its customers' traffic. Its Cloud and Threat Report in January found that 47 per cent of people using generative AI at work did so through personal accounts, down from 78 per cent a year earlier. The average organisation recorded 223 data policy violations involving generative AI each month, and the top quarter about 2,100. Source code made up the largest share, followed by regulated data, intellectual property, and passwords and keys.


Gartner said on 19 November 2025 that 69 per cent of the 302 cybersecurity leaders it surveyed between March and May 2025 suspected or had evidence that employees were using prohibited public generative AI tools. It predicted that by 2030 more than 40 per cent of enterprises would have a security or compliance incident linked to shadow AI.


How the data leaves

Text pasted into a chatbot under a personal login is held by the provider under consumer terms. OpenAI, for example, says it does not use data from ChatGPT Enterprise, ChatGPT Business or its API to train its models by default, while conversations in personal ChatGPT accounts can be used for training unless the user switches off 'Improve the model for everyone' in the data controls.


In one early case, Bloomberg reported on 2 May 2023 that Samsung had banned staff in one of its biggest divisions from using generative AI tools after engineers uploaded sensitive internal source code to ChatGPT the previous month. Samsung's memo said data sent to such services is stored on outside servers, where it is hard to retrieve and delete.


Controls are now being placed in the browser itself. At the RSA Conference on 23 March, Microsoft said prompt-level data protection in Purview was generally available in Edge for Business. It inspects prompts and file uploads to consumer AI sites as they are entered, audits or blocks those containing sensitive data, and shows the user a policy notice with a button that sends them to Microsoft 365 Copilot instead. It applies whenever the user is signed in to Edge with an Entra ID account, on managed or unmanaged devices.


Controls for agents

Supervising agents is a separate problem from supervising chatbot use, because an agent acts through whatever tools and credentials it has been given. Microsoft announced on 9 March that Agent 365, its control system for agents, will be generally available on 1 May at $15 per user per month, or inside a new Microsoft 365 E7 suite at $99 per user per month.


Agent 365 keeps a registry of agents and gives each one an identity in Microsoft Entra, so that conditional access and identity governance can be applied to it as they are to a user. Purview's data loss prevention extends to what agents read and write, and their tool calls pass through a gateway where threats can be blocked at runtime.


Agents built inside business applications can carry the application's security with them. When Oracle launched AI Agent Studio for Fusion Applications in March 2025, it said agents follow Fusion's existing security configurations, policies and access controls, so an agent working for a user sees only the data and functions that user's roles allow.


Prompt injection

The UK's National Cyber Security Centre warned on 8 December 2025 against treating prompt injection as a version of SQL injection. Dave Chismon, its technical director for platforms research, wrote that SQL injection can be fixed because parameterised queries keep instructions and data apart, whereas a large language model handles everything as one stream of text. He described LLMs as 'inherently confusable' and said the risk can be reduced but may never be fully removed.


The NCSC's advice is to design on the assumption that the model will sometimes be fooled. When a model processes content from an outside party, its privileges should drop to that party's level. The actions it can take should be limited by safeguards that do not depend on the model, and inputs, outputs, tool use and API calls should be logged so that attackers probing the system are spotted early.


OWASP's Top 10 for Large Language Model Applications, in its 2025 edition, lists prompt injection first. It also lists system prompt leakage, and says credentials and connection strings should not be placed in a system prompt and that a system prompt should be treated neither as a secret nor as a security control.


NIST and the UK code

NIST's AI Risk Management Framework, version 1.0 from January 2023, organises AI governance into four functions: Govern, Map, Measure and Manage. Its Generative AI Profile, NIST AI 600-1, followed in July 2024. On 16 December 2025 NIST released a preliminary draft Cyber AI Profile, NIST IR 8596, which sets AI risks against its Cybersecurity Framework 2.0. Comments closed on 30 January, and NIST plans an initial public draft this year.


In the UK, the government published a voluntary AI Cyber Security Code of Practice on 31 January 2025, with 13 principles running from secure design to end of life, and submitted it to ETSI as the basis for the standard TS 104 223. It counts any employee using an AI system as an end user in the AI supply chain.


The EU AI Act on 17 April

The EU AI Act entered into force on 1 August 2024. Its bans on prohibited practices and the AI literacy duty in Article 4, which requires providers and deployers to take measures so that staff using AI systems understand them well enough, have applied since 2 February 2025. Under the text as it stands, the obligations for high-risk systems and the Article 50 transparency rules apply from 2 August 2026.


That date is being renegotiated. The Commission's Digital Omnibus on AI, published on 19 November 2025, proposed deferring the high-risk obligations. The Council agreed its position on 13 March and the European Parliament adopted its mandate on 26 March by 569 votes to 45, and both back fixed dates: 2 December 2027 for the stand-alone high-risk systems listed in Annex III, and 2 August 2028 for AI in products covered by Annex I. Trilogue talks have begun, and A&O Shearman reported on 9 April that a political agreement was expected at the next trilogue on 28 April. Until an amendment is agreed and published, 2 August 2026 remains the legal date.


The literacy duty is also under negotiation. The Commission and Council proposed reducing it to encouragement by the Commission and member states, while Parliament kept a softer duty on providers and deployers. UK organisations are outside the Act's direct reach unless they operate in the EU.


What happens next

SAASiQ's view is that an inventory of the AI tools and agents already in use, including those reached through personal accounts, is the first control to put in place, since each of the frameworks above assumes an organisation knows what is running.


The next trilogue on the Digital Omnibus is scheduled for 28 April, Agent 365 becomes generally available on 1 May, and NIST's initial public draft of the Cyber AI Profile is due later this year.

SAASiQ - Intelligent Solutions for SaaS ©

Optimise your SaaS licences and software subscriptions with SAASiQ

bottom of page