March 27, 2026
3
MIN READ

AI Security Risks in the SaaS Stack: What Finance and IT Need to Know

No items found.

AI tools now process a company's most sensitive data, from source code to financial models, yet most organisations lack the governance to manage the security risks that come with rapid AI adoption. Nearly 79% of companies on the Cledara platform pay for AI tools, with the average running 3.2 distinct AI subscriptions. IBM reports that 13% of organisations have experienced AI-related breaches, with 97% lacking proper access controls. This guide breaks down the six core AI security risks (data leakage, training data exposure, shadow AI, integration vulnerabilities, supply chain risk, and compliance violations), provides a vendor evaluation checklist and risk classification matrix, and walks through a practical five-step AI security audit. It also covers how Cledara gives IT and Finance teams shared visibility into AI tool usage, compliance certifications, and the ability to shut down compromised tools instantly via virtual card controls.

Illustration for AI Security Risks in the SaaS Stack: What Finance and IT Need to Know
by
Harald Meyer-Delius

The AI Security Landscape in 2026

AI tools now process some of a company's most sensitive data: financial models, source code, customer records, strategic plans, and internal communications. Across companies on the Cledara platform, nearly 79% are actively paying for AI tools, with the average company running 3.2 distinct AI subscriptions. That number has grown rapidly: the companies adopting new AI subscriptions in 2025 nearly doubled compared to 2023.

This growth creates a compounding security problem. Every AI tool that touches company data introduces a potential vector for data exposure, and the speed of AI adoption has outpaced most organisations' ability to assess and govern it. According to IBM's 2025 Cost of Data Breach Report, 13% of organisations reported breaches involving AI models or applications, and 97% of those lacked proper AI access controls at the time of the incident.

The Samsung ChatGPT data leak in 2023 remains the most cited cautionary example. Samsung engineers pasted proprietary semiconductor source code into ChatGPT to debug errors, submitted internal code for equipment optimisation, and used the tool to generate minutes from a confidential meeting. Because OpenAI's consumer product retained user inputs for model training at the time, Samsung's trade secrets were effectively shared with a third party. The company restricted ChatGPT access across its network in response.

But the Samsung incident was visible. The deeper risk is what you cannot see: shadow AI, the tools employees adopt without IT or Finance approval. (For a deeper look at this phenomenon, see our guide to AI SaaS tools for growing scaleups.) Research from Gartner found that 69% of organisations suspect employees are using prohibited AI tools, and a study by BlackFog revealed that 60% of employees would take data security risks to meet deadlines. When employees paste customer data into an unapproved AI tool, nobody in your organisation knows it happened.

6 AI Security Risks Every Company Should Assess

Not all AI security risks are equal. Some are immediate and high-impact; others are slow-building compliance liabilities. Here are the six categories that every IT and Finance team should evaluate across their AI stack.

1. Data Leakage Through Prompts

Employees routinely paste sensitive information into AI tools: source code, financial spreadsheets, customer lists, HR data, and strategic documents. A 2025 enterprise analysis found that 18% of employees paste data into generative AI tools, and more than 50% of those paste events include corporate information. The Samsung incident is the highest-profile example, but this behaviour is happening at scale across every industry. Each prompt containing sensitive data is a potential disclosure to a third-party system whose data handling policies your security team may never have reviewed. The risk scales with the number of AI tools in use: across the Cledara platform, companies with five or more AI subscriptions are common, and each additional tool multiplies the potential for accidental data exposure.

2. Training Data Exposure

The question "does this AI vendor train on my inputs?" has a more nuanced answer than most companies realise. Most major AI providers (OpenAI, Anthropic, Google) now distinguish between consumer and enterprise tiers. Consumer and free-tier products may use your inputs for model training by default, requiring you to opt out. Enterprise and API plans typically do not train on your data. Anthropic, for example, updated its privacy policy in 2025 to use consumer conversation data for training unless users opted out by a specific deadline, while its business and API products remained excluded. The risk is clear: if employees use consumer-tier AI accounts for work tasks, their inputs may be incorporated into the vendor's training data.

3. Shadow AI Tools With No Security Review

Shadow AI is the fastest-growing blind spot in enterprise security. Research indicates that 98% of organisations have some level of unsanctioned AI use, and nearly 47% of generative AI users access these tools through personal accounts that completely bypass enterprise controls. Across companies on the Cledara platform, the average company uses 3.2 AI tools, but without active discovery, the true number is almost certainly higher. Shadow AI breaches cost an average of $670,000 more than traditional security incidents, according to IBM, and take longer to detect (247 days versus 241 for conventional breaches).

4. Third-Party Plugin and Integration Risks

AI tools rarely operate in isolation. They connect to your CRM, email, file storage, and communication platforms through plugins and API integrations. Each integration expands the attack surface. In mid-2025, researchers identified the EchoLeak vulnerability (CVE-2025-32711) in Microsoft 365 Copilot, a zero-click prompt injection that could exfiltrate enterprise data without any user interaction. The risk multiplies with every AI plugin that has read access to your company's systems: a compromised or poorly secured integration can silently extract data from platforms you thought were protected.

5. Supply Chain Risk

Your AI tools depend on upstream model providers, API infrastructure, and third-party services that can change without notice. A model provider might update its terms of service, change its data retention policies, or experience a security breach that affects all downstream customers. In early 2026, the OpenClaw open-source AI agent framework exposed over 21,000 instances to critical vulnerabilities through malicious marketplace exploits. Companies that had integrated OpenClaw into their workflows discovered that a supply chain compromise at the framework level cascaded into their own environments. AI supply chain risk requires monitoring not just your direct vendors, but the infrastructure those vendors depend on.

6. Compliance Violations From Uncontrolled AI Usage

Uncontrolled AI usage can trigger violations across multiple regulatory frameworks. If employees input personal data into AI tools without proper data processing agreements, your organisation may breach GDPR, CCPA, or sector-specific regulations. Financial services firms face additional scrutiny around AI-generated outputs used in decision-making. Healthcare organisations must consider HIPAA implications when clinical data enters AI systems. IBM's research found that 65% of shadow AI breaches compromise personally identifiable information and 40% expose intellectual property: exactly the categories most heavily regulated.

AI Security Assessment Framework

Knowing the risks is only useful if you have a structured way to evaluate them. This framework gives IT and Finance teams a practical method to assess AI tool security across three dimensions: vendor evaluation, internal policy, and risk classification.

Vendor Evaluation Checklist

Before approving any AI tool, assess the vendor against these criteria:

  • Data handling and retention: Does the vendor train on your inputs? What is the data retention period? Is there a zero-data-retention option? Confirm whether you are on a consumer or enterprise tier, as policies differ significantly between the two.
  • Security certifications: Does the vendor hold SOC 2 Type II, ISO 27001, or ISO 42001 (the AI-specific management standard)? SOC 2 is increasingly a baseline contractual requirement, and many enterprise buyers refuse to work with vendors lacking it.
  • Data residency: Where is your data processed and stored? This matters for GDPR compliance (EU data must remain in the EU unless adequate safeguards exist) and for industry-specific regulations.
  • Subprocessor transparency: Does the vendor disclose which third parties process your data? Can you be notified of subprocessor changes?
  • Incident response: Does the vendor have a documented breach notification process? What is the committed notification timeline?

Internal Usage Policy Requirements

A vendor evaluation means nothing if employees bypass approved tools. Your internal AI usage policy should define:

  • Approved tools list: Which AI tools are sanctioned for use, and on which tier (e.g., only the enterprise plan of ChatGPT, not the free version)?
  • Data classification rules: What types of data can and cannot be entered into AI tools? At minimum, PII, financial data, source code, and strategic documents should have explicit rules.
  • Approval workflow: How do employees request new AI tools? A structured procurement process prevents shadow AI from accumulating.
  • Training requirements: Employees need to understand why these policies exist, not just that they exist. The Samsung incident happened because engineers were trying to do their jobs faster, not because they intended to leak data.

Risk Classification Matrix

Classify each AI tool by the sensitivity of data it accesses:

Risk LevelData TypesReview RequiredExample Tools
LowPublic information, generic queries, non-sensitive contentSelf-service approvalGrammar checkers, generic research assistants
MediumInternal documents, non-sensitive business dataManager + IT approvalPresentation builders, content drafting tools
HighCustomer PII, financial data, employee recordsIT Security + Legal reviewAI analytics tools, CRM-integrated AI, coding assistants with repo access
CriticalSource code, trade secrets, regulated data (healthcare, financial)Full security assessment + DPAAI coding agents with write access, AI tools processing health or financial records

AI Security Audit Checklist

Use this checklist to run a practical AI security audit across your organisation. It works whether you have 5 AI tools or 50.

Step 1: Inventory All AI Tools

You cannot secure what you cannot see. Start by building a complete inventory of every AI tool in use, including the ones nobody approved. This means going beyond your subscription list to discover shadow AI. Browser-based discovery tools can identify AI services employees access that never went through procurement. On the Cledara platform, the Engage browser extension discovers all SaaS tools employees use, including unapproved AI tools, making it the starting point for any AI security audit.

Step 2: Review Each Vendor's Data Processing Terms

For every AI tool on your inventory, answer three questions: Does the vendor train on your inputs? What is the data retention period? Is there a data processing agreement (DPA) in place? Pay close attention to the distinction between consumer and enterprise tiers. An employee using ChatGPT on a free account has fundamentally different data protections than one using it through an enterprise agreement.

Step 3: Verify Compliance Certifications

Check each AI vendor for SOC 2 Type II, ISO 27001, and any sector-specific certifications your organisation requires. Document which vendors hold current certifications and which do not. With Cledara, you can tag each vendor with their compliance certifications (SOC 2, ISO 27001, GDPR) for at-a-glance security assessment, turning a manual spreadsheet exercise into an always-current compliance view.

Step 4: Check Data Residency and Retention

Map where each AI tool processes and stores data. For organisations subject to GDPR, verify that EU personal data remains within adequate jurisdictions. Review retention policies: some AI vendors retain prompt data for 30 days for abuse monitoring, while others may retain it indefinitely unless you configure otherwise. Document these details in a centralised register. Pay particular attention to usage-based AI tools (such as OpenAI API and Anthropic API), where data volume processed can fluctuate significantly month to month, potentially changing your risk profile.

Step 5: Assess Employee Usage Patterns

Review how employees actually use AI tools, not just which tools they have access to. Look for patterns that indicate risky behaviour: high-volume data pasting, use of consumer-tier accounts for work tasks, or AI tools connected to sensitive internal systems without security review. Usage analytics from browser-based discovery tools can surface these patterns before they become incidents. On the financial side, review AI spending trends: the average company on the Cledara platform spends over $9,000 per year with OpenAI alone and nearly $5,000 with Anthropic. If those numbers look unfamiliar, it may indicate that AI spending is happening outside your approved channels.

How Cledara Reduces AI Security Risk

Managing AI security across a growing tool stack requires more than policies and spreadsheets. Cledara provides the infrastructure to enforce AI governance at the operational level, giving IT and Finance shared visibility and control.

Full visibility into every AI tool in use. The Engage browser extension discovers all AI tools employees access, including unapproved shadow AI. Across companies on the Cledara platform, the average organisation uses 3.2 AI tools it pays for, but shadow AI adds to that count. Engage surfaces the complete picture so your security audit starts with accurate data, not guesswork.

Certification tags for at-a-glance compliance. Tag each AI vendor with their security certifications: SOC 2 Type II, ISO 27001, GDPR compliance status. Instead of maintaining a separate compliance spreadsheet, your entire AI vendor security posture is visible inside the platform where you manage those subscriptions.

Compliance questionnaires baked into purchasing. Cledara's customisable compliance questionnaires include sections for data privacy, risk assessment, and security review. Before any new AI tool is purchased, the requesting employee completes a structured review that surfaces risks upfront. This shifts security review from a reactive audit to a proactive gate in the procurement process.

Suspicious transaction detection. Automated alerts flag unusual AI tool spending patterns. A sudden spike in API usage costs or an unexpected charge from a new AI vendor triggers an alert, giving Finance and IT early warning of potential shadow AI or compromised accounts.

One-click cancellation for compromised tools. Because every Cledara subscription runs on a dedicated virtual card, shutting down a compromised or non-compliant AI tool takes one click. Freeze the card, and the vendor loses payment access immediately. No waiting for vendor support to process a cancellation; no continued charges during a security review. This is particularly valuable for AI tools, where a data exposure incident demands an immediate response.

Protected Card Access. An enhanced security layer for card transaction management ensures that only authorised personnel can view or modify the virtual cards funding AI subscriptions, adding an extra barrier against internal misuse.

Together, these capabilities create a closed loop: discover AI tools, assess their security posture, enforce compliance at the point of purchase, monitor for anomalies, and take immediate action when needed. For companies navigating the tension between AI adoption and security governance, this operational layer is what turns policy documents into enforceable controls.

Building an AI Security Culture

The most effective AI security strategy combines tooling with culture. Employees will find ways around rigid policies if those policies slow them down without clear justification. The goal is to make secure AI usage the path of least resistance.

Start with visibility: you cannot govern what you have not discovered. Then establish clear, practical policies that distinguish between low-risk and high-risk AI usage rather than blanket bans that drive behaviour underground. Embed security review into your procurement process so it happens before tools are adopted, not months later in a retrospective audit. And give both IT and Finance a shared view of the AI tool landscape, because security risk and financial risk from AI tools are two sides of the same coin.

The companies that manage AI security well in 2026 will not be the ones that banned AI tools. They will be the ones that built the governance infrastructure to adopt AI tools safely, with full visibility into what is being used, how data is being handled, and the ability to act instantly when something goes wrong.

AI security is not a one-time audit. It is an ongoing discipline that evolves as your AI stack grows, as vendors update their policies, and as new risk categories emerge. The organisations that treat it as a continuous process, supported by the right tooling and cross-functional collaboration between IT and Finance, will capture the productivity benefits of AI without exposing themselves to unnecessary risk.

What are the biggest AI security risks for businesses in 2026?
The six primary AI security risks are data leakage through prompts (employees pasting sensitive data into AI tools), training data exposure from consumer-tier AI accounts, shadow AI tools operating without security review, third-party plugin vulnerabilities, AI supply chain risk from upstream model providers, and compliance violations from uncontrolled usage. IBM reports that 13% of organisations experienced AI-related breaches in 2025, with shadow AI incidents costing $670,000 more than traditional breaches.
How can companies detect shadow AI tools employees are using?
Companies can detect shadow AI through browser-based discovery tools that monitor which SaaS applications employees access, including unapproved ones. Cledara's Engage browser extension automatically identifies all AI tools in use across the organisation, surfacing shadow AI that never went through procurement. Research shows that 98% of organisations have some unsanctioned AI use and 47% of employees access AI tools through personal accounts.
Does ChatGPT train on company data entered by employees?
It depends on the subscription tier. OpenAI's free and consumer ChatGPT plans may use inputs for model training by default, though users can opt out. Enterprise and API plans do not train on customer data. The same consumer-versus-enterprise distinction applies to Anthropic's Claude and Google's Gemini. Companies should verify that employees use enterprise-tier accounts for any work involving sensitive data.
How does Cledara help manage AI security and compliance?
Cledara provides five layers of AI security control: the Engage browser extension discovers all AI tools including shadow AI, certification tags track each vendor's SOC 2 and ISO 27001 status, compliance questionnaires embed security review into the purchasing process, suspicious transaction detection flags unusual AI spend, and one-click virtual card cancellation instantly shuts down compromised tools.
What should an AI security audit checklist include?
A practical AI security audit should cover five steps: inventory all AI tools including shadow AI, review each vendor's data processing and training policies, verify compliance certifications (SOC 2 Type II, ISO 27001), check data residency and retention policies, and assess employee usage patterns for risky behaviour like pasting sensitive data into consumer-tier AI accounts. Companies should run this audit quarterly as AI tool adoption evolves.

Contents

Contents

The software management solution for finance teams.

Learn more

Subscribe to our newsletter

Receive the latest insights in your inbox

Harald Meyer-Delius

Harald was told that he could never write for a living, so he became a Content Writer to prove them wrong. Now, with over ten years of experience, he is a content marketing professional specializing in fintech and startups. In his spare time he likes playing video games, writing fiction, and drinking coffee.

Share this post

Subscribe to our newsletter and stay informed on the latest SaaS insights

Sign up

Explore more

No items found.