Generative-AI assistants have quietly become one of the biggest data-loss channels in the enterprise. The 2026 Verizon Data Breach Investigations Report (DBIR) identified “Shadow AI” — staff using unsanctioned AI tools on corporate devices — as among the fastest-growing non-malicious insider actions seen in data-loss datasets.
What the data shows
- Shadow AI is now one of the most common non-malicious insider actions detected — a fourfold increase year on year.
- 45% of employees are regular AI users on corporate devices, up from just 15% a year earlier.
- Source code is the data type most often submitted to external AI models, ahead of customer records and financial data.
- Mimecast's 2026 report found 42% of organisations saw more malicious-insider incidents (up from 33% in 2024), each estimated to cost about USD 13.1 million.
Why it matters
Generative AI has introduced an exfiltration vector that traditional, network-centric controls were never designed to see. When an employee pastes proprietary code, customer data or a financial model into a chatbot, the data leaves the organisation through an ordinary HTTPS session to a legitimate service — invisible to tools looking only for malware or known bad destinations.
For Thai enterprises, this is also a compliance problem. Personal data flowing into a third-party AI service can breach the Personal Data Protection Act (PDPA), and “we didn't know staff were doing it” is not a defence. The answer is not to ban AI outright — that just drives it further into the shadows — but to gain visibility and apply policy to where sensitive data actually goes.
