INSIGHTS

Is Your Company's Data Safe When You Use AI?

Back to all articles

Is Your Company's Data Safe When You Use AI?

What happens to your company's data when you use ChatGPT or other AI tools: real risks, GDPR, the AI Act, and the differences between consumer and enterprise plans.

AI data security for business · GDPR artificial intelligence SMEs · company data ChatGPT risks · safe AI for companies

Back to all articles

«We're launching internal projects to work with artificial intelligence»: it's a phrase we hear often, with a mix of enthusiasm and, at times, scepticism. But it only looks at the official initiatives, the ones with a budget and clear objectives. AI data security in the enterprise has already been at stake for a while, because artificial intelligence came in through the back door: in employees' browsers, in conversations with ChatGPT or similar services. Free, at least on the surface.

The price, almost always, is data. In the first weeks of a project, we often ask the companies we work with a simple question: can you tell us what your employees pasted into an AI tool this month? Most of the time the answer is an embarrassed silence, followed by a «but who cares about my data anyway?». No one steals that data: the company, without realising it, has already handed it over itself.

77% of employees who use generative AI paste company data directly into prompts, 14 times a day on average.1 In 82% of cases they do it from a personal account, not managed by the company, and therefore outside any control, log or policy.2

This article directly answers, without alarmism, a question almost every company asks itself and almost none addresses openly: is your company's data safe when you use AI?

AI has already come in, without asking permission

The problem here isn't artificial intelligence itself, but the use that's made of it, as with any other tool. Most companies let it in without realising what they're bringing into the house, and the risks it carries.

The most common case: an employee discovers that ChatGPT or Copilot saves them an hour a day, and starts using it to summarise emails or draft contracts. No one has forbidden it, so they do it. Meanwhile IT hasn't activated anything, management isn't aware of it, and the company policy, when it exists, dates back a few years.

This is the phenomenon known as shadow AI: everything artificial intelligence does in a company without the company knowing about it. The term echoes the shadow IT of ten years ago, with one substantial difference: an AI tool doesn't just run on an unauthorised server. It reads and processes whatever it's fed, and in some cases it retains it.

Shadow AI doesn't measure how much a company has adopted AI: it measures how much, within the company, no one has yet decided how to do it.

The Italian numbers show just how unbalanced the phenomenon is relative to the ability to govern it: in 2025, 71% of large Italian enterprises had launched at least one structured AI project, but only 9% had formal governance for the use of these tools. 84% had purchased licences for generative AI solutions, but just 24% had explicitly banned the use of non-company tools, and only 19% of employees said they used exclusively approved tools.3

Here company size matters little; timing matters. Adoption arrived before the rules. When that happens, what AI can or can't do with company data is decided by the tool's vendor, by default, or in the worst case by the individual employee, prompt after prompt, without management knowing.

What happens when you paste data into an AI tool

To understand the real risk, three different aspects that often create confusion need to be distinguished: using the data to train the model, its retention — meaning temporary storage on the provider's servers — and its purely operational use to generate the response.

Training. Some AI tools, especially on free or consumer plans, may use conversations to improve future models, unless the user explicitly configures otherwise. A snippet of code, a piece of company or client data could, in theory, influence the answers that same tool will give other users in the future.

Retention. Even without training, data still remains stored for a period ranging from a few days to about two months, depending on the provider, for security purposes, on servers the company doesn't directly control and whose geographic location is often not clearly disclosed.

Operational use. This is the least risky part, but not therefore harmless: once data leaves the company, the company loses control of it. It can no longer track it according to its own policies, nor delete it on request.

A concrete example: in spring 2023, some Samsung engineers pasted portions of proprietary source code into ChatGPT to help with debugging. A work habit, not a cyberattack — one that today millions of employees replicate every day.4

The phenomenon is accelerating: the share of sensitive company data shared with AI tools went from 10.7% to 34.8% in two years, with a sharp jump visible in the last year alone, from 27.4% to 34.8%.5

The phenomenon has stopped being an isolated behaviour or the carelessness of a few: it has become the main channel through which confidential information leaves companies — more than email, more than the USB drives that were once the nightmare of IT managers.

The precedents that prove it

The authorities have already taken concrete action on this phenomenon, a few years back.

On 30 March 2023 the Italian Data Protection Authority (Garante) ordered a temporary restriction on OpenAI's processing of Italian users' data, citing the lack of a legal basis for training the algorithms and of age-verification systems. It was the first temporary block of a generative AI in Europe.6

A few weeks later, the service resumed thanks to measures introduced by OpenAI, but the investigation continued, ending with a corrective order and a €15 million fine for failing to promptly notify a data breach and for unlawful processing.

Imagine two companies adopting the same AI tool at the same price. The first just hands out credentials to employees. The second checks the data processing agreement, and trains its employees after disabling the use of its own data for model training. Only the second will be able to prove it protected its information in the event of an inspection.

This is a decisive issue for Italian SMEs: those who use consumer plans like ChatGPT Plus or Claude Pro for individual employees often don't have a valid corporate DPA, because the terms of service exclude it. The risk is twofold: breach of the GDPR and of the provider's own terms.7

The real cost of not knowing

How concrete the issue is is also shown by the numbers on the economic cost of an AI-related data breach. According to IBM's Cost of a Data Breach Report 2026, the global average cost of a data breach rose to $4.99 million, a 12% increase that represents the highest value ever recorded, driven by higher detection costs and greater business loss.8

In the same period, AI-driven attacks grew by 56%, and breaches traced back to a model-inversion attack — the technique that exposes the data used to train a model — cost on average $6 million: a confirmation of how much more complex protecting data becomes once artificial intelligence enters the picture.

Companies that make extensive use of AI and automation for security save, on average, $1.93 million per breach compared to those that don't. The difference between risk and advantage often lies in governance, not in the tool itself.8

These numbers hit close to home: from 2 August 2026 the European AI Act entered its enforcement phase, and for the most serious violations — including non-compliant use of high-risk systems — it provides for administrative fines of up to €35 million or 7% of global annual turnover, whichever is higher. Reduced thresholds apply to SMEs and startups, but the underlying sanctioning logic remains unchanged.9

The AI Act also introduces an obligation in force since 2 February 2025 for every company, regardless of size: to adopt measures to promote employees' AI literacy, so that they know how to recognise which data must never be entered into an AI system.10 Since July 2026 the obligation has been made more proportionate to the company's size and risk level, but it remains valid for everyone, SMEs included.11

Consumer vs enterprise: the difference no one explains

What's the difference between «using AI at work» and «using a corporate version of AI»? This is the heart of the matter: they aren't the same thing, even if the tool chosen looks identical.

A consumer plan, whether ChatGPT Plus or another equivalent personal service, is designed for individual use. An enterprise plan, on the other hand, comes with extra elements, designed specifically for corporate use and its policies:

AspectConsumer planEnterprise plan
Model trainingOften on by defaultExcluded, unless configured by the company
Data retentionNot manageable by the companyZero Data Retention available
DPA (data processing agreement)Not providedIncluded for business use

Source: providers' Enterprise privacy documentation (e.g. OpenAI).

It matters little to ask whether AI is safe in the abstract. What matters is asking whether this specific system is, with these settings, for this use, and with this data.

Treating cybersecurity and privacy as secondary details, leaving the configuration of corporate plans and staff training until after the AI tools have already been activated, is a strategic mistake. Those who postpone these decisions think they're saving time and resources, but they're actually choosing to discover and face the problem at the worst possible moments, when it will be too late.

The questions to ask before adopting an AI tool

Before activating, or continuing to use, an artificial intelligence tool at work — whether ChatGPT, Copilot, Gemini, Claude, or a vertical tool built into some business software — it's important to ask precise questions and have a clear answer. No advanced legal skills are needed: any serious provider already makes all the necessary information publicly available.

  • Is my data used to train the model? This can be checked in the service settings, in the privacy policy, or in the provider's documentation. For enterprise plans the answer is generally no, but it should still be checked and confirmed.
  • Where is the data physically stored? Keeping data within or outside the European Union has a direct impact, given the obligations set out by the GDPR.
  • Is there a data processing agreement valid for corporate use? Usually only a business plan covers this requirement, with a DPA signed by the company. For personal subscriptions this is, as a rule, not provided.
  • Who, internally, can access the conversations? Enterprise plans usually allow granular access management and detailed audit logs to monitor the actions taken.
  • What happens to the data if the subscription is cancelled? It's important to check whether the data is deleted immediately or remains accessible, for how long, and whether early deletion can be requested.
  • Have employees been trained on what should never be shared? Since 2 February 2025 this is a regulatory obligation: the company must have adopted measures to support employees' literacy on the responsible use of AI.

There's no need to give up AI: you just need to never take it for granted, whatever tool it's built into.

Why governance matters more than technology

Coming back to the opening question — whether your company's data is safe when you use AI — the honest answer is: it depends on the awareness shown in configuring and contracting these tools as a company, and in explaining them to the people who use them every day.

The latest Italian data show widespread delay on this front: 76% of Italian SMEs haven't invested, and don't plan to invest, in artificial intelligence in the near future, and only 7% have launched structured training programmes for their staff. In most cases the problem is a lack of clarity over who, within the company, decides on AI-related issues, including data security — more than caution.1314

Using AI at work is the easy part. The part that takes real work is always knowing where information ends up once it leaves: a provider with a verified data processing agreement, and staff trained on what should never be shared.

Want to know if your AI tools are configured securely? Request a conversation with the Aevoluta team and find out where your company's AI governance really stands.

Sources

  1. 1.Enterprise AI and SaaS Data Security Report 2025 — LayerX, riportato da Federprivacy, giugno 2026
  2. 2.Enterprise AI and SaaS Data Security Report 2025 — LayerX, riportato da Cybersecitalia, ottobre 2025
  3. 3.Osservatorio Artificial Intelligence — Politecnico di Milano, 2026 (dati ripresi da Agenda Digitale)
  4. 4.L'inconsapevole fuga di dati: come l'uso aziendale di ChatGPT espone a rischi di riservatezza — Economyup, novembre 2025
  5. 5.2025 AI Adoption and Risk Report — Cyberhaven, riportato da Unio Digital
  6. 6.Provvedimento n. 112/2023 — Garante per la protezione dei dati personali, 30 marzo 2023, e comunicato di chiusura istruttoria
  7. 7.Blog tecnico — Maurizio Fonte, su DPA e piani consumer
  8. 8.Cost of a Data Breach Report 2025 — IBM, in collaborazione con Ponemon Institute
  9. 9.AI Act 2026: guida a divieti, sanzioni e nuove scadenze di compliance — Cyber Security 360, marzo 2026
  10. 10.Regolamento (UE) 2024/1689 (AI Act) — EUR-Lex, 12 luglio 2024
  11. 11.Regolamento (UE) 2026/1744 (Omnibus digitale sull'IA) — EUR-Lex, 24 luglio 2026
  12. 12.Enterprise privacy — OpenAI, pagina ufficiale
  13. 13.AI Act, formazione ancora al palo: imprese esposte alla fuga di dati — Agenda Digitale, agosto 2026
  14. 14.Osservatorio Innovazione Digitale nelle PMI — W.Training, Politecnico di Milano, maggio 2026

Stay updated on AI trends. No spam.