The AI Security Landscape in 2026
AI tools now process some of a company's most sensitive data: financial models, source code, customer records, strategic plans, and internal communications. Across companies on the Cledara platform, nearly 79% are actively paying for AI tools, with the average company running 3.2 distinct AI subscriptions. That number has grown rapidly: the companies adopting new AI subscriptions in 2025 nearly doubled compared to 2023.
This growth creates a compounding security problem. Every AI tool that touches company data introduces a potential vector for data exposure, and the speed of AI adoption has outpaced most organisations' ability to assess and govern it. According to IBM's 2025 Cost of Data Breach Report, 13% of organisations reported breaches involving AI models or applications, and 97% of those lacked proper AI access controls at the time of the incident.
The Samsung ChatGPT data leak in 2023 remains the most cited cautionary example. Samsung engineers pasted proprietary semiconductor source code into ChatGPT to debug errors, submitted internal code for equipment optimisation, and used the tool to generate minutes from a confidential meeting. Because OpenAI's consumer product retained user inputs for model training at the time, Samsung's trade secrets were effectively shared with a third party. The company restricted ChatGPT access across its network in response.
But the Samsung incident was visible. The deeper risk is what you cannot see: shadow AI, the tools employees adopt without IT or Finance approval. (For a deeper look at this phenomenon, see our guide to AI SaaS tools for growing scaleups.) Research from Gartner found that 69% of organisations suspect employees are using prohibited AI tools, and a study by BlackFog revealed that 60% of employees would take data security risks to meet deadlines. When employees paste customer data into an unapproved AI tool, nobody in your organisation knows it happened.
6 AI Security Risks Every Company Should Assess
Not all AI security risks are equal. Some are immediate and high-impact; others are slow-building compliance liabilities. Here are the six categories that every IT and Finance team should evaluate across their AI stack.
1. Data Leakage Through Prompts
Employees routinely paste sensitive information into AI tools: source code, financial spreadsheets, customer lists, HR data, and strategic documents. A 2025 enterprise analysis found that 18% of employees paste data into generative AI tools, and more than 50% of those paste events include corporate information. The Samsung incident is the highest-profile example, but this behaviour is happening at scale across every industry. Each prompt containing sensitive data is a potential disclosure to a third-party system whose data handling policies your security team may never have reviewed. The risk scales with the number of AI tools in use: across the Cledara platform, companies with five or more AI subscriptions are common, and each additional tool multiplies the potential for accidental data exposure.
2. Training Data Exposure
The question "does this AI vendor train on my inputs?" has a more nuanced answer than most companies realise. Most major AI providers (OpenAI, Anthropic, Google) now distinguish between consumer and enterprise tiers. Consumer and free-tier products may use your inputs for model training by default, requiring you to opt out. Enterprise and API plans typically do not train on your data. Anthropic, for example, updated its privacy policy in 2025 to use consumer conversation data for training unless users opted out by a specific deadline, while its business and API products remained excluded. The risk is clear: if employees use consumer-tier AI accounts for work tasks, their inputs may be incorporated into the vendor's training data.
3. Shadow AI Tools With No Security Review
Shadow AI is the fastest-growing blind spot in enterprise security. Research indicates that 98% of organisations have some level of unsanctioned AI use, and nearly 47% of generative AI users access these tools through personal accounts that completely bypass enterprise controls. Across companies on the Cledara platform, the average company uses 3.2 AI tools, but without active discovery, the true number is almost certainly higher. Shadow AI breaches cost an average of $670,000 more than traditional security incidents, according to IBM, and take longer to detect (247 days versus 241 for conventional breaches).
4. Third-Party Plugin and Integration Risks
AI tools rarely operate in isolation. They connect to your CRM, email, file storage, and communication platforms through plugins and API integrations. Each integration expands the attack surface. In mid-2025, researchers identified the EchoLeak vulnerability (CVE-2025-32711) in Microsoft 365 Copilot, a zero-click prompt injection that could exfiltrate enterprise data without any user interaction. The risk multiplies with every AI plugin that has read access to your company's systems: a compromised or poorly secured integration can silently extract data from platforms you thought were protected.
5. Supply Chain Risk
Your AI tools depend on upstream model providers, API infrastructure, and third-party services that can change without notice. A model provider might update its terms of service, change its data retention policies, or experience a security breach that affects all downstream customers. In early 2026, the OpenClaw open-source AI agent framework exposed over 21,000 instances to critical vulnerabilities through malicious marketplace exploits. Companies that had integrated OpenClaw into their workflows discovered that a supply chain compromise at the framework level cascaded into their own environments. AI supply chain risk requires monitoring not just your direct vendors, but the infrastructure those vendors depend on.
6. Compliance Violations From Uncontrolled AI Usage
Uncontrolled AI usage can trigger violations across multiple regulatory frameworks. If employees input personal data into AI tools without proper data processing agreements, your organisation may breach GDPR, CCPA, or sector-specific regulations. Financial services firms face additional scrutiny around AI-generated outputs used in decision-making. Healthcare organisations must consider HIPAA implications when clinical data enters AI systems. IBM's research found that 65% of shadow AI breaches compromise personally identifiable information and 40% expose intellectual property: exactly the categories most heavily regulated.
AI Security Assessment Framework
Knowing the risks is only useful if you have a structured way to evaluate them. This framework gives IT and Finance teams a practical method to assess AI tool security across three dimensions: vendor evaluation, internal policy, and risk classification.
Vendor Evaluation Checklist
Before approving any AI tool, assess the vendor against these criteria:
- Data handling and retention: Does the vendor train on your inputs? What is the data retention period? Is there a zero-data-retention option? Confirm whether you are on a consumer or enterprise tier, as policies differ significantly between the two.
- Security certifications: Does the vendor hold SOC 2 Type II, ISO 27001, or ISO 42001 (the AI-specific management standard)? SOC 2 is increasingly a baseline contractual requirement, and many enterprise buyers refuse to work with vendors lacking it.
- Data residency: Where is your data processed and stored? This matters for GDPR compliance (EU data must remain in the EU unless adequate safeguards exist) and for industry-specific regulations.
- Subprocessor transparency: Does the vendor disclose which third parties process your data? Can you be notified of subprocessor changes?
- Incident response: Does the vendor have a documented breach notification process? What is the committed notification timeline?
Internal Usage Policy Requirements
A vendor evaluation means nothing if employees bypass approved tools. Your internal AI usage policy should define:
- Approved tools list: Which AI tools are sanctioned for use, and on which tier (e.g., only the enterprise plan of ChatGPT, not the free version)?
- Data classification rules: What types of data can and cannot be entered into AI tools? At minimum, PII, financial data, source code, and strategic documents should have explicit rules.
- Approval workflow: How do employees request new AI tools? A structured procurement process prevents shadow AI from accumulating.
- Training requirements: Employees need to understand why these policies exist, not just that they exist. The Samsung incident happened because engineers were trying to do their jobs faster, not because they intended to leak data.
Risk Classification Matrix
Classify each AI tool by the sensitivity of data it accesses:
| Risk Level | Data Types | Review Required | Example Tools |
|---|---|---|---|
| Low | Public information, generic queries, non-sensitive content | Self-service approval | Grammar checkers, generic research assistants |
| Medium | Internal documents, non-sensitive business data | Manager + IT approval | Presentation builders, content drafting tools |
| High | Customer PII, financial data, employee records | IT Security + Legal review | AI analytics tools, CRM-integrated AI, coding assistants with repo access |
| Critical | Source code, trade secrets, regulated data (healthcare, financial) | Full security assessment + DPA | AI coding agents with write access, AI tools processing health or financial records |
AI Security Audit Checklist
Use this checklist to run a practical AI security audit across your organisation. It works whether you have 5 AI tools or 50.
Step 1: Inventory All AI Tools
You cannot secure what you cannot see. Start by building a complete inventory of every AI tool in use, including the ones nobody approved. This means going beyond your subscription list to discover shadow AI. Browser-based discovery tools can identify AI services employees access that never went through procurement. On the Cledara platform, the Engage browser extension discovers all SaaS tools employees use, including unapproved AI tools, making it the starting point for any AI security audit.
Step 2: Review Each Vendor's Data Processing Terms
For every AI tool on your inventory, answer three questions: Does the vendor train on your inputs? What is the data retention period? Is there a data processing agreement (DPA) in place? Pay close attention to the distinction between consumer and enterprise tiers. An employee using ChatGPT on a free account has fundamentally different data protections than one using it through an enterprise agreement.
Step 3: Verify Compliance Certifications
Check each AI vendor for SOC 2 Type II, ISO 27001, and any sector-specific certifications your organisation requires. Document which vendors hold current certifications and which do not. With Cledara, you can tag each vendor with their compliance certifications (SOC 2, ISO 27001, GDPR) for at-a-glance security assessment, turning a manual spreadsheet exercise into an always-current compliance view.
Step 4: Check Data Residency and Retention
Map where each AI tool processes and stores data. For organisations subject to GDPR, verify that EU personal data remains within adequate jurisdictions. Review retention policies: some AI vendors retain prompt data for 30 days for abuse monitoring, while others may retain it indefinitely unless you configure otherwise. Document these details in a centralised register. Pay particular attention to usage-based AI tools (such as OpenAI API and Anthropic API), where data volume processed can fluctuate significantly month to month, potentially changing your risk profile.
Step 5: Assess Employee Usage Patterns
Review how employees actually use AI tools, not just which tools they have access to. Look for patterns that indicate risky behaviour: high-volume data pasting, use of consumer-tier accounts for work tasks, or AI tools connected to sensitive internal systems without security review. Usage analytics from browser-based discovery tools can surface these patterns before they become incidents. On the financial side, review AI spending trends: the average company on the Cledara platform spends over $9,000 per year with OpenAI alone and nearly $5,000 with Anthropic. If those numbers look unfamiliar, it may indicate that AI spending is happening outside your approved channels.
How Cledara Reduces AI Security Risk
Managing AI security across a growing tool stack requires more than policies and spreadsheets. Cledara provides the infrastructure to enforce AI governance at the operational level, giving IT and Finance shared visibility and control.
Full visibility into every AI tool in use. The Engage browser extension discovers all AI tools employees access, including unapproved shadow AI. Across companies on the Cledara platform, the average organisation uses 3.2 AI tools it pays for, but shadow AI adds to that count. Engage surfaces the complete picture so your security audit starts with accurate data, not guesswork.
Certification tags for at-a-glance compliance. Tag each AI vendor with their security certifications: SOC 2 Type II, ISO 27001, GDPR compliance status. Instead of maintaining a separate compliance spreadsheet, your entire AI vendor security posture is visible inside the platform where you manage those subscriptions.
Compliance questionnaires baked into purchasing. Cledara's customisable compliance questionnaires include sections for data privacy, risk assessment, and security review. Before any new AI tool is purchased, the requesting employee completes a structured review that surfaces risks upfront. This shifts security review from a reactive audit to a proactive gate in the procurement process.
Suspicious transaction detection. Automated alerts flag unusual AI tool spending patterns. A sudden spike in API usage costs or an unexpected charge from a new AI vendor triggers an alert, giving Finance and IT early warning of potential shadow AI or compromised accounts.
One-click cancellation for compromised tools. Because every Cledara subscription runs on a dedicated virtual card, shutting down a compromised or non-compliant AI tool takes one click. Freeze the card, and the vendor loses payment access immediately. No waiting for vendor support to process a cancellation; no continued charges during a security review. This is particularly valuable for AI tools, where a data exposure incident demands an immediate response.
Protected Card Access. An enhanced security layer for card transaction management ensures that only authorised personnel can view or modify the virtual cards funding AI subscriptions, adding an extra barrier against internal misuse.
Together, these capabilities create a closed loop: discover AI tools, assess their security posture, enforce compliance at the point of purchase, monitor for anomalies, and take immediate action when needed. For companies navigating the tension between AI adoption and security governance, this operational layer is what turns policy documents into enforceable controls.
Building an AI Security Culture
The most effective AI security strategy combines tooling with culture. Employees will find ways around rigid policies if those policies slow them down without clear justification. The goal is to make secure AI usage the path of least resistance.
Start with visibility: you cannot govern what you have not discovered. Then establish clear, practical policies that distinguish between low-risk and high-risk AI usage rather than blanket bans that drive behaviour underground. Embed security review into your procurement process so it happens before tools are adopted, not months later in a retrospective audit. And give both IT and Finance a shared view of the AI tool landscape, because security risk and financial risk from AI tools are two sides of the same coin.
The companies that manage AI security well in 2026 will not be the ones that banned AI tools. They will be the ones that built the governance infrastructure to adopt AI tools safely, with full visibility into what is being used, how data is being handled, and the ability to act instantly when something goes wrong.
AI security is not a one-time audit. It is an ongoing discipline that evolves as your AI stack grows, as vendors update their policies, and as new risk categories emerge. The organisations that treat it as a continuous process, supported by the right tooling and cross-functional collaboration between IT and Finance, will capture the productivity benefits of AI without exposing themselves to unnecessary risk.




