Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ColumnsCybersecurityManagementCybersecurity Education & TrainingSecurity Leadership and Management

Education & Training

Preventing AI Data Breaches and Leaks

As AI becomes part of daily operations, it’s essential to have safeguard in place to protect company data.

By Patricia Egger
security education & training
Image: Thinkhubstudio / iStock / Getty Images Plus / Via Getty Images
October 2, 2026

Approximately 612,000 UK businesses experienced a cybersecurity breach in the past year, according to the UK Government's Cyber security breaches survey with OpenAI and Anthropic most recently having committed data breaches from uninstructed cyberattacks.

Meanwhile, ‘private’ conversations from Claude were indexed on Google, and according to AvePoint’s State of AI 2026 report, 88.4% of companies have experienced an AI agent-related security breach.

AI risk has seen the biggest rise in concern for companies in almost all industry sectors and highlights how companies across all sectors need to secure their data to protect it from AI-driven exposure.

Preventing AI Data Breaches

Signs of an AI data breach to look out for:

  • Company information surfacing somewhere it shouldn't be
  • AI tools holding broader permissions than a task requires
  • Unfamiliar tools showing up in network traffic or expense reports
  • Integrations or API keys no one remembers approving

“Employees should feel empowered to hang up and call back through a known channel to check if those on the phone really are their supplier or CEO.”

 

1. Build verification habits into the culture to protect from social engineering attacks

The vast majority of attacks involve some level of social engineering, which no technology can fully fix. With AI making impersonation cheaper and more convincing, verification habits need to be built into the company culture.

Employees should feel empowered to hang up and call back through a known channel to check if those on the phone really are their supplier or CEO. Organizations should ensure all employees know their most important asset to protect, as well as the level of risk associated with their accounts and systems to help prevent social engineering attacks.

2. Keep permissions to a minimum to prevent phishing attacks

Phishing attacks remain the most prevalent type of breach or attack, experienced by 38% of businesses, but the phishing threat has industrialized. Passwords were conceived in an era when phishing was largely manual. That era is over, and the answer isn't stronger passwords, it's fewer passwords and in-depth defense, with authentication built on cryptographic proof rather than human memory. Keeping permissions minimal will help to reduce the attack surface.

“Providing a sanctioned AI tool that meets employee’s needs and is convenient will limit shadow AI use.”

 

Preventing AI data leaks

1. Provide sanctioned and secure AI tools to tackle shadow AI

Employees using AI in their personal lives —or at work regardless of what the policy says — is usually called shadow IT, but this is now shadow AI. New AI tools are appearing every day, so it becomes hard to keep track of what's out there and what employees are using. In a business without a dedicated security function, nobody is even trying to keep track, and that's where the exposure builds up quietly.

Providing a sanctioned AI tool that meets employee’s needs and is convenient will limit shadow AI use. Configure it according to company policies as much as possible and set up additional security controls. Employees shouldn't need any particular knowledge of security or encryption to be protected; it should come with the product.

Reduce the number of tools, applications and systems the organization uses (and must therefore support) and keep the toolset small and permissions minimal, to keep the business as secure as possible.

2. Set clear norms to prevent accidental oversharing

Often an AI assistant will be granted access to email, files or calendars without an employee registering it. Its access then outlives the task it was installed for and puts company data at risk.

Employees can also slip into a vicious cycle of feeding AI agents incremental amounts of information until they're sharing data they wouldn’t have shared on day one.

Leaders need to interrupt this drift with clear, concrete norms about what goes into which tool, and with sanctioned tools that are secure by default, so employees don't need a security mindset just to do their jobs safely.

Lastly, get the foundations right, because AI risk sits on top of ordinary risk. Reducing reliance on passwords and moving toward passkeys and cryptographic authentication removes a key attack vector. Pairing this with secure devices, continuous monitoring, awareness training and basic cyber hygiene, you’ll have a much clearer picture of your risk levels and security preparedness.

KEYWORDS: artificial intelligence (AI) employee training risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Patricia Egger is Head of Security for Proton. She received a Master’s degree in Applied Mathematics at the École polytechnique fédérale de Lausanne. She is also the co-founder and current President of Women in Cyber Switzerland.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Healthcare supplies

3 Healthcare Breaches in Quick Succession Raises Concerns

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man driving

150M Driver’s Licenses Exposed, Security Experts Discuss

Police lights

Family of Fatally Shot Security Guard Seeking Answers

Stressed woman

Ransomware Doesn’t Just Break Systems. It Breaks People.


AlertMedia sponsored webinar

Events

October 7, 2026

Modernizing Travel Risk Management: How Security Teams are Strengthening Duty of Care

LIVE: October 7, 2026 at 2 PM EDT Learn how security teams have strengthened travel risk management for a global workforce. Move beyond manual monitoring to earlier, verified awareness and a more defensible approach to security operations.

October 20, 2026

Beyond the Camera: How AI Is Transforming Physical Security

LIVE: October 20, 2026 at 2 PM EDT AI can connect security systems to detect threats earlier, validate incidents in real time, & accelerate response. Move from passive monitoring to proactive, intelligence-led security while maximizing existing tech investments.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Data Breach

    Data breaches: Preventing and responding

    See More
  • appSec

    Why application-layer security is critical in preventing data breaches

    See More
  • privileged-access-900

    Managing Privileged Access is Crucial to Preventing Data Breaches

    See More

Related Products

See More Products
  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

See More Products

Events

View AllSubmit An Event
  • April 15, 2026

    How AI is Closing the Decision Gap in Leading GSOCs

    ON DEMAND: Learn how modern security teams are evolving from alert-driven workflows to outcome-driven operations and how AI is enabling faster, more confident decisions at every stage of the incident response lifecycle.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing