Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Artificial Intelligence

ChatGPT and Company Data Security: Shadow AI and Data Leak Risks

Staff paste customer lists, quotes and source code into ChatGPT. An eight-step control framework to stop data leaks without banning AI at work.

8 min read  · Digital Bridge Engineering Team
ChatGPT and Company Data Security: Shadow AI and Data Leak Risks

Putting company data into ChatGPT hands it to a service outside your organisation, and on a personal account you lose control of it. The risk lies less in the tool than in unmanaged use. The answer is not a ban: approve specific tools, list data that must never be entered, and offer a permission-controlled internal assistant for sensitive work.

What staff actually paste into ChatGPT

A salesperson pastes a quotation — customer name, discount and product list included — to polish the wording. A developer asks about a failing function, connection string and all. Someone in HR hands performance reviews to an AI to "make them sound kinder". None of them means any harm; they are all trying to work faster.

The problem comes together in three places:

  • The account is personal. Conversations in an account opened with a private email address are outside company control, and they stay there when the employee leaves.
  • Nobody knows the settings. Whether conversations are retained or used to improve models depends on the product tier and account settings. Most users have no idea where those settings are.
  • Data types are not distinguished. Customer data, trade secrets, source code and public information go into the same window with the same ease.

Tools used without the organisation's knowledge or approval are known as shadow AI. It is shadow IT in a new form, and it spreads far faster.

What shadow AI costs

This is no longer a fringe activity. According to Verizon's 2026 Data Breach Investigations Report, 45% of employees are now regular AI users on corporate devices, up from 15%, and 67% of users access AI services with non-corporate accounts. The same report found that source code was the most common data type submitted to unauthorised generative AI tools.

There is a breach bill attached. In IBM's Cost of a Data Breach Report 2025, one in five organisations reported a breach due to shadow AI, and those with high levels of shadow AI faced $670,000 in higher breach costs. In the same study, 63% of breached organisations had no AI governance policy or were still developing one.

The worry is not confined to security teams. Eurostat's statistics on AI use in enterprises show that 48.83% of EU businesses that considered AI but did not adopt it cited data protection and privacy concerns (2025). Unmanaged use creates risk and, at the same time, blocks managed use.

The data protection angle: GDPR and Türkiye's KVKK

When an employee enters text containing a customer's name, phone number or health details into an AI service hosted abroad, the organisation — not the employee — is the data controller for that processing. Under the EU GDPR this raises questions of lawful basis, transparency and international transfers.

The same applies in Türkiye under the KVKK (Law No. 6698 on the Protection of Personal Data). Article 9, amended in 2024, now ties transfers abroad to conditions broadly similar to the GDPR's — adequacy decisions, appropriate safeguards such as standard contracts — and a transfer made through an employee's private account rests on none of them. Article 12 requires controllers to take the necessary technical and organisational measures; having no written policy and no access control is a weak position to defend. We explain the transfer routes and standard contract notification in KVKK cross-border data transfer.

Even without personal data, trade secrets, quoted prices and source code engage the confidentiality clauses in your contracts.

That is why the risk of data leaking through ChatGPT should not be handled in isolation but as part of your KVKK compliance programme: AI services are added to the data inventory, privacy notices are updated and the transfer assessment is put in writing. For the organisation's own AI projects, our guide to AI and personal data protection in Turkey covers legal basis, transfers and automated decisions.

ChatGPT and company data security: an eight-step framework

  1. Classify your data. Four classes are enough: public, internal, confidential and personal data. Staff should be able to see on one page which class may go into which tool.
  2. Publish an approved-tools list. Which AI tools, which tier and which settings are allowed? Anything not on the list is not used. How these rules become a structured written document is covered separately in our company AI acceptable use policy guide; the focus here is preventing data leakage.
  3. Require company accounts. Business data should never be processed on a personal account. Company accounts can be opened and closed centrally, and linking them to single sign-on makes that easier.
  4. Write down what must never be entered. Customer identity and contact details, health data, passwords and access keys, unsigned quotation prices, sensitive parts of your source code. Our article on business password security covers how credentials should be handled.
  5. Offer a safe alternative for sensitive work. A ban alone does not work; staff need an answer to "so where can I do this?". An assistant that works from company documents with permission-based access fills that gap; we explain the architecture in retrieval augmented generation for the enterprise.
  6. Add technical controls. Use web filtering, data loss prevention (DLP) rules and endpoint management to spot sensitive data being uploaded to unapproved tools.
  7. Require human review of output. AI output should be checked by a person before it reaches a customer, a contract or official correspondence; reducing AI hallucinations explains why. If an assistant reads email or documents, see prompt injection security for how hidden instructions can leak data.
  8. Train people and manage leavers. Give short training with real examples, and when someone leaves, close their company AI accounts along with email and file access. See our guide to offboarding email access.

Most of these steps are simply a general SME cyber security checklist applied to AI, and can be added to your existing security policy as a single page.

How we approach this at Digital Bridge

Rather than banning AI, we aim to move its use into a safe channel:

  • We make current use visible. Through our cyber security consultancy we map which AI tools are in use, on which accounts and with which kinds of data, then write the data classification and use policy with your team.
  • We settle the data protection questions. Our data protection compliance service reflects AI use in your privacy notices, data inventory and transfer assessments, whether under the KVKK, the GDPR or both.
  • We build the safe alternative. We deploy an enterprise LLM assistant that works from your documents, cites a source in every answer and responds only from documents the user is authorised to see. Where data must not leave the organisation, it can run entirely on your own servers using open-source models.
  • We connect it to what you already use. Through AI integration the assistant is added to your ERP, help desk or intranet, so nobody needs to go looking for another tool.

Managed AI in daily work: SmartMail and SmartFiles

The two jobs staff most often turn to AI for are summarising email and making sense of documents. Smart360, our own product family, does both inside the company account and under administrator control:

  • SmartMail offers message summaries, automatic categorisation, asking questions of a message, writing assistance and translation into 30 languages. Each mailbox has nine separate permissions, two of which are "AI reinterpretation" and "AI chat" — so who uses AI is decided mailbox by mailbox.
  • In SmartFiles, AI is one of eight independent permissions and is granted to a person or a department. Each uploaded document gets a four-part report, and you can ask questions of a document or a folder. There is a monthly AI allowance, and an administrator can switch the feature off entirely.

Each organisation's data is held in a separate database for each product. Because every product sits behind a single identity (SmartID), a leaver's access closes in one step; sessions are listed with device details and can be ended remotely.

Next step

Run a quick, no-blame survey this week: which AI tools does the team use, on which accounts and for what? Map the answers against the four data classes. Then get in touch: we will write your AI use policy with you and scope a secure assistant for sensitive work. For where managed AI adoption should begin, read AI in business: where to start; for related topics, browse our complete Artificial Intelligence guide.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

Is data entered into ChatGPT used to train the model?

It depends on the product tier, the account type and its settings, and providers update their terms over time. That is why the organisation, not the individual, should decide which tier is used with which settings, and make company accounts mandatory. On a personal account there is no reliable way to know the settings are correct.

Should we simply ban ChatGPT at work?

Usually not. A ban tends to move use onto personal phones and accounts, and the organisation loses all visibility. It is more effective to approve specific tools, list the data types that must never be entered, require company accounts and provide a permission-controlled assistant that works from company documents for sensitive tasks.

Is entering personal data into ChatGPT a GDPR or KVKK breach?

Entering personal data into a service hosted abroad is processing and, often, an international transfer under both the GDPR and Türkiye's KVKK. If it happens without a lawful basis, proper notice and valid transfer conditions, it creates compliance risk. Each case needs its own assessment; the safest rule is not to enter personal data into such tools at all.

How can we detect shadow AI?

Start by asking: a short survey with no disciplinary consequences reveals most usage. Then review web filter and firewall logs for traffic to AI services, check browser extensions through endpoint management, and apply data loss prevention rules. The aim is not punishment but moving usage into an approved channel that the organisation can see and manage.

Can we run our own AI assistant in-house?

Yes. An assistant built on the RAG architecture over company documents cites a source in every answer and responds only from documents the user is allowed to see. Where data must stay inside the organisation, it can run entirely on your own servers using open-source language models; scope and cost are set after a needs analysis.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.