A growing number of employees are using AI tools without their employer’s approval, according to recent reports. About 45% of workers are using these unauthorized AI systems, and nearly 36% of them are feeding confidential company data into those tools. This trend, known as "Shadow AI," has raised concerns among cybersecurity experts. Cybermalveillance.gouv.fr, a French government agency focused on cyber threats, has issued guidelines to help organizations manage this risk. The agency warns that sending sensitive information—such as HR records, legal documents, or strategic plans—to external AI platforms could expose companies to data breaches, as such data might be stored on third-party servers.
While some Chief Information Officers (CIOs) believe that giving employees unrestricted access to AI tools can foster innovation, cybersecurity experts caution against an unregulated approach. Tal Carmi, a CIO at WalkMe, explained that while employees might benefit from greater flexibility, the risks to company security and the Chief Information Security Officer (CISO) could be severe. This highlights the need for a balance between encouraging productivity and maintaining strict data protection protocols.
To improve digital safety around AI usage, Cybermalveillance.gouv.fr recommends that employees keep their personal and professional AI environments strictly separate. Using personal AI accounts for work tasks is discouraged, as it can blur data boundaries and increase the risk of leaks. The agency also outlines basic cybersecurity best practices, such as using unique, strong passwords for each AI service—each with at least 12 characters, including uppercase and lowercase letters, numbers, and symbols. Employees are also encouraged to enable two-factor authentication (2FA) whenever possible and to regularly review and adjust the privacy settings of their AI accounts to limit data retention or delete past interactions.
Securing AI tools is not just an employee responsibility—it also falls on company leaders, including CIOs and CISOs. These leaders must ensure that AI tools used within the company are legally and technically compliant with current regulations. Cybermalveillance.gouv.fr advises organizations to create and share an AI usage charter that clearly outlines acceptable practices for all employees. Additionally, companies must confirm that their officially approved AI services meet national and European standards, including GDPR and the AI Act, as well as sector-specific requirements, such as those related to handling health data.
Generative AI Use in Workplaces Raises Security Concerns, Government Agency Issues Guidelines
AI-rewritten from original reportingHow it works
aisecuritydata-leakshadow-aicybersecuritycompliance



