← All news

general

Staff Are Quietly Feeding Company Data to ChatGPT

2026-06-19

Employees are feeding enterprise data into AI tools at nearly double the rate they were a year ago. According to Zscaler's 2026 AI Threat Report, the volume of company information shifted to AI and machine learning apps over the past twelve months hit 18,033 terabytes, a 93% year-on-year increase. Zscaler puts that in more human terms: roughly 3.6 billion photos worth of internal data sitting somewhere it probably shouldn't.

Two tools doing most of the work

The bulk of those transfers went through a small handful of apps. Grammarly accounted for 38% of the traffic. ChatGPT another 21%. The remainder was split across OpenAI's other products, Codium, GitHub Copilot, Perplexity, Microsoft Copilot, Gemini and Claude.

ChatGPT alone triggered more than 410 million data loss prevention violations over the year, up 99% on the previous twelve months. The categories of data flagged include financial records, personal information, healthcare data and source code. Not edge cases. The stuff most compliance frameworks are built around.

The coding assistants deserve a second look

Codium racked up 242 million DLP violations on its own, a 100% jump. That points to a lot of proprietary code and internal business logic being handed to third parties in exchange for faster autocomplete. GitHub Copilot and the various Copilot-branded tools sit alongside it in the same category, and the pattern is consistent: developers, under pressure to ship, are reaching for whatever speeds up the work.

Nobody is doing this maliciously

This isn't insider threat in any meaningful sense. Staff are using the tools that make their jobs easier. The unhappy coincidence is that the tools which make jobs easier happen to see everything someone is working on at the exact moment they're working on it.

The report's framing is a good one: the convenience is the risk. Writing helpers, coding assistants and AI features quietly bolted into collaboration suites are the riskiest precisely because nobody thinks twice before using them. There's no decision to make. The Grammarly extension is already installed. ChatGPT is already open in another tab. The Copilot icon is already in the ribbon.

The question worth asking

The instinct in a lot of organisations will be to ban things. Block ChatGPT at the proxy, kill the Grammarly extension, lock down browser plugins. That works for about a week, until people switch to personal devices, personal accounts, or one of the dozen other AI tools that didn't make the headline list.

The more useful question, and the harder one, is whether anyone in the business actually knows which AI tools their staff are already using, and what's being typed into them today. Not what the policy says. What's actually happening.

That's a visibility problem before it's a technology problem, and it's a behaviour problem before it's a visibility problem. People will keep reaching for the tools that make their day easier. The work is in making sure they understand what those tools see, and giving them safer ways to get the same lift.

Staff Are Quietly Feeding Company Data to ChatGPT | RiskSense