The Problem: Your Staff Are Already Using AI, Approved or Not
Most confidential-data leaks through AI do not involve an attacker. They involve a capable employee under time pressure who pastes a contract, a code snippet or a formulation into whichever tool is fastest. The concern is not that people are careless; it is that nobody has told them which tools are safe for which data, and nobody can see what they do.
The available survey data, all of it from interested parties, points the same way. In the Okta-sponsored survey of 306 CISOs (published July 2026), 68% reported detecting unsanctioned AI tool use by staff without security approval. Netrio's survey of 401 US IT leaders at companies with 200 to 5,000 employees (June 2026; Netrio is a managed IT services provider) found that 82% have AI in production or widespread use, but only 42% have formal AI policies with enforced controls, only 53% have visibility into AI tool usage, and 73% have experienced confirmed incidents or near-misses. Aon, an insurance broker, reports that 47% of employees still use unapproved AI tools. In Switzerland, EY's May 2026 survey of 604 companies found that 89% use AI solutions daily and that 19% cite security and data protection concerns as a main barrier.
On cost, a secondary write-up of IBM's 2025 Cost of a Data Breach report (via Kiteworks, which does not state the sample size) puts the average shadow AI breach at $4.63 million against $3.96 million for standard incidents, and says only 17% of companies have technical controls that stop unauthorized AI uploads. We have not checked those figures against the IBM report itself, so treat them as indicative.
The Solution: Protect the Crown Jewels and Give People a Safe Fast Path
Blanket bans tend to push usage out of sight, which is the opposite of what you want. A more workable position has two halves: identify the small set of information whose loss would really hurt, and give employees an approved way to get value from AI without exposing it.
The legal stakes are worth understanding, with a caveat. In Trinidad v. OpenAI (N.D. Cal., January 2026), as described by the law firms Troutman and Ropes and Gray, a court dismissed a US trade secret claim because the plaintiff had voluntarily disclosed the alleged secrets to a consumer-tier AI platform whose terms imposed no confidentiality obligation. That was one plaintiff's own material and one US court, and Swiss and EU trade secret analysis will differ, so it is not a prediction for your company. But the principle is one your counsel will recognize: protecting a trade secret depends on taking reasonable measures to keep it secret, and courts are starting to ask whether you addressed AI tools as a specific disclosure risk. Ropes and Gray adds that even enterprise tools carry operational risk, because many process prompts through third-party systems, may retain inputs, and may allow provider personnel access, and Goodwin notes that once data is absorbed into a model's weights, its influence persists.
The earlier, well-known example is Samsung in 2023, where engineers uploaded proprietary source code to ChatGPT and the company subsequently banned such tools.
The Approach: Five Steps From Blind to Controlled
1. Map actual usage. Combine technical signals (browser, network and SaaS logs) with an amnesty-style conversation with teams. The aim is a real picture, not a list of offenders.
2. Name your crown jewels. Decide which categories of information must never enter an unapproved tool: source code, formulations, unpublished clinical or research data, pricing, M&A material, personal data. Keep the list short enough that people can remember it.
3. Provide approved paths. For each common use case, offer a tool with contractual terms on data retention, training use and access rights. If the approved tool is slower or worse than the shadow one, usage will not move.
4. Add proportionate controls. Data-loss-prevention and browser-level controls can warn or block on the most sensitive categories. Apply them where the risk is highest rather than everywhere.
5. Write the rules and train against real examples. A one-page policy that names approved tools, permitted information categories and an approval route works better than a long one that nobody reads. Review periodically, because the tools change quickly.
The goal is not zero AI use. It is that every use of AI on sensitive material is one you chose.
How ANG Associates Can Help
ANG Associates runs an AI Exposure Check for mid-size and large companies. We map where AI is really being used across your organization, work with your business, legal and security leads to identify the crown-jewel information that needs protecting, and rank the gaps between current practice and what your policy says. You receive a prioritized action list, a proposed set of approved tool paths by use case, a one-page usage policy, and a plan for training and periodic review.
Where technical controls are warranted, we help you choose and configure them from the market, and we are not tied to any one vendor. For companies in Life Sciences, we pay particular attention to research data, clinical information and quality records. To be clear about scope: we are not a law firm, so how trade secret law applies to your facts is a question for your counsel, and we make sure that question is asked with the evidence in hand.
This is one of six services in our ANG AI Trust Compass offering.
Sources
- Cybersecurity Insiders, report on the Okta-sponsored CISO survey (306 CISOs, published 31 July 2026; sponsor is an identity-governance vendor)
- Netrio, mid-market AI adoption survey (401 US IT leaders, companies of 200 to 5,000 employees, fielded by Censuswide, published 15 June 2026; Netrio sells managed IT and AI advisory services)
- Aon, AI risk 2026: a practical agenda (Aon is an insurance broker; the 47% figure is as reported by Aon)
- EY Switzerland, AI survey of Swiss companies (604 respondents, May 2026)
- Kiteworks, summary of IBM's 2025 Cost of a Data Breach report (secondary source; sample size not stated in this summary)
- Troutman, article on AI tools and trade secret protection
- Ropes and Gray, alert on trade secret protection in the age of AI (July 2026)
- Goodwin, insights on proprietary data and specialist AI in Life Sciences transactions (July 2026)