Education & Training
Preventing AI Data Breaches and Leaks
As AI becomes part of daily operations, it’s essential to have safeguard in place to protect company data.

Approximately 612,000 UK businesses experienced a cybersecurity breach in the past year, according to the UK Government's Cyber security breaches survey with OpenAI and Anthropic most recently having committed data breaches from uninstructed cyberattacks.
Meanwhile, ‘private’ conversations from Claude were indexed on Google, and according to AvePoint’s State of AI 2026 report, 88.4% of companies have experienced an AI agent-related security breach.
AI risk has seen the biggest rise in concern for companies in almost all industry sectors and highlights how companies across all sectors need to secure their data to protect it from AI-driven exposure.
Preventing AI Data Breaches
Signs of an AI data breach to look out for:
- Company information surfacing somewhere it shouldn't be
- AI tools holding broader permissions than a task requires
- Unfamiliar tools showing up in network traffic or expense reports
- Integrations or API keys no one remembers approving
“Employees should feel empowered to hang up and call back through a known channel to check if those on the phone really are their supplier or CEO.”
1. Build verification habits into the culture to protect from social engineering attacks
The vast majority of attacks involve some level of social engineering, which no technology can fully fix. With AI making impersonation cheaper and more convincing, verification habits need to be built into the company culture.
Employees should feel empowered to hang up and call back through a known channel to check if those on the phone really are their supplier or CEO. Organizations should ensure all employees know their most important asset to protect, as well as the level of risk associated with their accounts and systems to help prevent social engineering attacks.
2. Keep permissions to a minimum to prevent phishing attacks
Phishing attacks remain the most prevalent type of breach or attack, experienced by 38% of businesses, but the phishing threat has industrialized. Passwords were conceived in an era when phishing was largely manual. That era is over, and the answer isn't stronger passwords, it's fewer passwords and in-depth defense, with authentication built on cryptographic proof rather than human memory. Keeping permissions minimal will help to reduce the attack surface.
“Providing a sanctioned AI tool that meets employee’s needs and is convenient will limit shadow AI use.”
Preventing AI data leaks
1. Provide sanctioned and secure AI tools to tackle shadow AI
Employees using AI in their personal lives —or at work regardless of what the policy says — is usually called shadow IT, but this is now shadow AI. New AI tools are appearing every day, so it becomes hard to keep track of what's out there and what employees are using. In a business without a dedicated security function, nobody is even trying to keep track, and that's where the exposure builds up quietly.
Providing a sanctioned AI tool that meets employee’s needs and is convenient will limit shadow AI use. Configure it according to company policies as much as possible and set up additional security controls. Employees shouldn't need any particular knowledge of security or encryption to be protected; it should come with the product.
Reduce the number of tools, applications and systems the organization uses (and must therefore support) and keep the toolset small and permissions minimal, to keep the business as secure as possible.
2. Set clear norms to prevent accidental oversharing
Often an AI assistant will be granted access to email, files or calendars without an employee registering it. Its access then outlives the task it was installed for and puts company data at risk.
Employees can also slip into a vicious cycle of feeding AI agents incremental amounts of information until they're sharing data they wouldn’t have shared on day one.
Leaders need to interrupt this drift with clear, concrete norms about what goes into which tool, and with sanctioned tools that are secure by default, so employees don't need a security mindset just to do their jobs safely.
Lastly, get the foundations right, because AI risk sits on top of ordinary risk. Reducing reliance on passwords and moving toward passkeys and cryptographic authentication removes a key attack vector. Pairing this with secure devices, continuous monitoring, awareness training and basic cyber hygiene, you’ll have a much clearer picture of your risk levels and security preparedness.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





