Cyber Security

Is your organization using AI safely?

There is a chance someone in your organization used an AI tool today to draft an email, summarize a document or work through a problem. That is not inherently a bad thing. However, there is a potential it happened outside of a system your IT or security team has configured. When this happens, the risk lands on your organization.

The 2026 Verizon Data Breach Investigations Report (DBIR) puts a number to what many leaders are beginning to sense: 45% of employees are now considered regular users of AI (authorized or note) on their corporate devices, up from 15% in the previous year (p.13). Of those, 67% of users are using non-corporate accounts on their corporate devices to access AI services (p. 13).

Unregulated AI usage is one of the top insider threats, introducing risk to every organization. While people are not acting with malicious intent, they are still working without a clear path to use these tools safely.

What is the risk?

When employees route work through unapproved AI tools, the content or information they submit can leave your organization’s control entirely. No longer can the organization apply proper oversight or protections. This may expose confidential or proprietary data, as well as information with contractual or regulatory obligations to protect.  

The Verizon DBIR found that the most common type of data submitted to external AI models was source code (p.60).  Internal research and technical documentation were also among the types of data being fed to unauthorized systems, which raises questions about intellectual property exposure.

Beyond that, more than 15% of corporate users had unregulated AI tools running in their web browser, often installed as browser extensions in just a few clicks, without IT approval. These tools can collect information about what you’re viewing or working on and send it to outside servers. Once that information leaves your environment, you have no control over how it's stored, who can access it, or how it may be used. For any organization handling sensitive documents, client data or proprietary processes, this is just one example of a gap that traditional security safeguards were not designed to cover.

For most organizations, this reveals a gap that traditional security safeguards were not designed to cover.

Standards and safeguards lag behind adoption

With the constant buzz around AI, the rapid increase in its usage isn’t unexpected.

Employees are finding new ways to work faster and smarter, often more quickly than security policies and procedures can keep up. When this happens, employees end up making their own decisions because there isn’t a clear or approved way to move forward. Many organizations charge employees with incorporating innovation and AI, but don’t provide the context or means to do so safely. Employees may recognize the benefits of automation adoption without fully weighing the risks, resulting in a growing blind spot for the organization.

The goal for organizations is balancing how to provide your teams with the tools they need while maintaining a trusted environment.

What should an AI program look like?

Organizations that manage AI usage effectively better align their approach with how work actually gets done, and can better guide their employees rather than relying solely on strict policies. This means first gaining visibility into what tools employees are using, whether approved or not. You can’t manage what you can’t see, so it starts with proactively identifying where sensitive information may already be flowing outside your control. Check in with your team about how they're using AI day-to-day. You may find the answer could be either more than you expected, or that there is a lack of tools for their needs. When employees come to you with a request, leaders don't need to have all the answers. Having a simple, consistent process for evaluating those conversations goes a long way.

It’s also important to set clear, practical guidelines so employees feel confident they can use AI safely and effectively while protecting the company from harm. Effective policies focus on how information is handled and shared, not just which tools are permitted or prohibited. When employees understand the reasoning behind the rules, they are more likely to make good decisions in situations the policy does not anticipate.

If employees are turning to outside tools, it’s usually because there is a real need and no clear path forward. Giving them approved options that meet those needs is often more effective than a blanket ban. It also makes compliance the easiest path rather than being an obstacle.

Where we can help

Managing an organization’s cybersecurity is about giving leaders the visibility and confidence to move forward in today’s rapidly evolving tech landscape. This includes new tools, threats and workflows that use AI which might be glossed over or improperly regulated.

TrueNorth’s Cyber Consulting Practice works with leadership to assess how emerging risks like misuse of AI fit into the broader picture, then build a practical, prioritized roadmap that reflects both operations and risk tolerance. Reach out to get your cybersecurity questions answered today.

Related posts

Group of colleagues sit together at a boardroom table.

Your mid-year employee benefits checklist for 2026

Benefits
Jason Smith and Patrick Lencioni at the TrueNorth Summit

A fireside chat on leadership and organizational health

Corporate