Business
Unauthorized AI Tools Threaten Business Security and Data Integrity

Businesses face significant risks as employees increasingly turn to unauthorized artificial intelligence (AI) tools, commonly referred to as shadow AI, to enhance productivity. While these AI applications can offer quick solutions, they may inadvertently expose companies to security breaches and data leaks.
More employees are utilizing AI solutions for everyday tasks, often without corporate approval. According to Kareem Sadek, a partner at KPMG in Canada specializing in technology risk, this trend arises from a lag in corporate adoption of new technology. As workers seek convenient and fast responses, they may resort to third-party AI assistants that lack oversight. This reliance on shadow AI poses a substantial threat, as it could lead to the accidental exposure of sensitive internal data.
The growing concern among Canadian businesses, both large and small, is underscored by Robert Falzon, head of engineering at Check Point Software Technologies Ltd.. He stated, “Companies are struggling to make sure that their intellectual property is maintained and they are not leaking sensitive information about their business practices and customers.”
Compounding the issue is the fact that many users are unaware that interactions with chatbots are often stored and used to enhance AI capabilities. This means that an employee might share confidential information, such as financial statements or proprietary research, with an unsanctioned chatbot, inadvertently making that data accessible to unauthorized individuals. Falzon warns, “There’s a chance that the AI might dig back into its resources and training and find that piece of information about your company.”
A report from IBM and the Ponemon Institute revealed that 20 percent of surveyed companies experienced data breaches linked to shadow AI, a figure that is seven percentage points higher than those that encountered breaches involving approved AI tools. The average cost of a data breach in Canada surged to $6.98 million between March 2024 and February 2025, a 10.4 percent increase from the previous year.
To address these vulnerabilities, there is an urgent need for businesses to establish governance frameworks around AI use. Sadek proposed the formation of an AI committee comprising members from various departments, including legal and marketing, to evaluate tools and implement appropriate guidelines. He emphasized that governance failures, rather than technology itself, lead to security breaches.
Implementing a zero-trust policy could also help mitigate risks. This approach involves not trusting devices or applications that are not explicitly approved by the company. Falzon noted that at Check Point, employees are restricted from inputting sensitive research and development data into chatbots, ensuring that risks are communicated and managed effectively.
Creating awareness among employees is crucial for reducing the use of unauthorized AI tools. Sadek suggested conducting hands-on training sessions to educate staff about the risks associated with shadow AI. “It significantly reduces the use or holds the users or employees accountable,” he explained.
Some organizations are responding by developing their own internal chatbots, which can enhance security and protect sensitive data. Sadek highlighted that these solutions can be designed to operate within established security frameworks, providing reassurance to companies concerned about data leaks.
Despite these precautions, internal tools are not foolproof. Researcher Ali Dehghantanha demonstrated this by successfully breaching a Fortune 500 company’s internal chatbot in less than an hour during a cybersecurity audit. He found that the chatbot had access to numerous internal documents and communications, indicating a significant security lapse.
As organizations increasingly rely on AI technology, it is essential to allocate budgets for both the implementation and security of these tools. Dehghantanha advised, “Always consider the total cost of ownership… One part of that cost is how to secure and protect it.”
With the inevitability of AI usage in workplaces, Falzon urged employers to furnish employees with effective tools while ensuring they do not inadvertently create greater risks. “They want to be sure that things like data leakage don’t occur and that they’re not creating a greater risk than the benefit that they offer,” he concluded.
This report highlights the critical balance businesses must strike between leveraging innovative technologies and safeguarding their sensitive information in an increasingly digital landscape.
-
Science1 week ago
Microsoft Confirms U.S. Law Overrules Canadian Data Sovereignty
-
Technology1 week ago
Google Pixel 10 Pro Fold Specs Unveiled Ahead of Launch
-
Technology1 week ago
World of Warcraft Players Buzz Over 19-Quest Bee Challenge
-
Health6 days ago
Rideau LRT Station Closed Following Fatal Cardiac Incident
-
Science6 days ago
China’s Wukong Spacesuit Sets New Standard for AI in Space
-
Science1 week ago
Xi Labs Innovates with New AI Operating System Set for 2025 Launch
-
Lifestyle6 days ago
Vancouver’s Mini Mini Market Showcases Young Creatives
-
Technology6 days ago
Dragon Ball: Sparking! Zero Launching on Switch and Switch 2 This November
-
Technology1 week ago
New IDR01 Smart Ring Offers Advanced Sports Tracking for $169
-
Technology1 week ago
Humanoid Robots Compete in Hilarious Debut Games in Beijing
-
Science1 week ago
Infrastructure Overhaul Drives AI Integration at JPMorgan Chase
-
Top Stories1 week ago
Surrey Ends Horse Racing at Fraser Downs for Major Redevelopment
-
Business6 days ago
Canadian Stock Index Rises Slightly Amid Mixed U.S. Markets
-
Health6 days ago
B.C. Review Urges Changes in Rare-Disease Drug Funding System
-
Technology1 week ago
Future Entertainment Launches DDoD with Gameplay Trailer Showcase
-
Education6 days ago
Parents Demand a Voice in Winnipeg’s Curriculum Changes
-
Technology1 week ago
Global Launch of Ragnarok M: Classic Set for September 3, 2025
-
Science1 week ago
New Precision Approach to Treating Depression Tailors Care to Patients
-
Business6 days ago
Air Canada and Flight Attendants Resume Negotiations Amid Ongoing Strike
-
Health6 days ago
Rideau LRT Station Closed Following Fatal Cardiac Arrest Incident
-
Technology1 week ago
Innovative 140W GaN Travel Adapter Combines Power and Convenience
-
Business1 week ago
New Estimates Reveal ChatGPT-5 Energy Use Could Soar
-
Health1 week ago
Giant Boba and Unique Treats Take Center Stage at Ottawa’s Newest Bubble Tea Shop
-
Business1 week ago
Ukraine Strikes Lukoil Refinery, Halting Operations Amid Conflict