AI tools and data security

Jack Fletcher, Senior Director, Technology Advisory, FTI Consulting, shares his thoughts on the use of AI in the workplace and the implication it can have on data security, while our Ambassadors share their thoughts on the same topic.

AI tools such as ChatGPT have become ubiquitous and are being used for anything from developing the perfect holiday itinerary to writing tricky work emails. The rapid use of AI is also radically changing how we work, and a range of companies have successfully deployed in-house AI tools which are having positive impacts on productivity and organisation. However, the use of unapproved ‘shadow AI’ in work environments presents an array of data and security risks that can seriously undermine the compliance posture of an organisation and expose valuable commercial and sensitive information.

A key tenet of many data privacy regulations concerns data reuse and transparency, and central to this is the idea that personal data should not be used for a secondary purpose that was not communicated to the individual when the personal data was provided and/or consent to use the data was granted. Similarly, data privacy regulations often impose restrictions on where personal data can be sent, while certain AI tools may rely upon data storage in countries with poor standards of data protection and security, which may bring your organisation into contravention with data protection and security regulations if protected information has been input into an AI tool.

There is also a myriad of security risks associated with the use of AI tools. While sophisticated and more reputable AI tools may deploy strong security controls, this does not prevent sensitive or commercially sensitive information, including intellectual property, from being leaked or mishandled. To compound this issue, the ability of security teams to actively monitor and prevent against this form of data exfiltration is made difficult if the use does not take place on a company device and is performed using shadow AI.

So, what can be done? Like with many compliance initiatives, the emphasis should be on encouraging positive behavioural shifts by training employees on the risk of using shadow AI tools and reminding employees of the core principles of key policies such as acceptable use policies. Where possible, employees should be steered towards in-house AI tools and encouraged to use corporate devices for all corporate activities.

From the Ambassadors

“In order to use AI responsibly, organisations must have policies that outline the rules for AI use and in particular protection of data and client’s data. The objective is to ensure that we harness the power of AI, whilst promoting the responsible use of AI to protect values, data, and intellectual property. This is of upmost importance when utilising public or third-party AI tools.

Basic rules to be followed when using AI systems include, for instance: Don’t input any data or personal information into AI systems; be mindful of generated personal information; be transparent when people may be impacted and don’t use AI systems for purposes that people would not reasonably expect (e.g. obtain participants’ consent for call recording); confirm accuracy: all outputs must be proofread, validated and fact checked to ensure accuracy and reliability before being published or used; and respect third party intellectual property (IP) rights. We must not plagiarise or violate third party IP rights.

“The above will help mitigate risks associated with the use of public or third-party AI systems.”
Andrew Long, Principal Consultant – Security Risk Management, WSP

“The increasing adoption of AI tools offers significant rewards, such as improved efficiency and advanced data analysis. However, it also presents complex security and privacy risks, including potential exposure of sensitive information and difficulties in erasing data due to AI’s immutable nature. As AI systems process vast amounts of data, ensuring secure handling throughout each stage of the AI lifecycle is critical to prevent breaches and unauthorised access.

“With increased querying, the attack surface expands, further elevating security concerns. Additionally, achieving true impartiality remains elusive, as models are influenced by their training data and embedded values, which can inadvertently reinforce biases. To mitigate these risks, organisations must adopt comprehensive security protocols, effective data governance frameworks and bias mitigation strategies. Responsible management of AI’s security and privacy challenges is essential for harnessing its full potential while maintaining trust and compliance.”
Ian Keller, Global information technology expert

“As AI tools become increasingly integrated into modern security and business environments, the dual challenge of maximising value while safeguarding data grows more complex.

“AI’s ability to process and analyse vast amounts of data enables enhanced decision-making, predictive security and operational efficiency. However, this capability also introduces new vulnerabilities. Sensitive data fed into AI systems — whether for training or real-time decision-making — must be protected across its entire lifecycle, from collection and storage to processing and output.

“The use of third-party AI platforms raises further concerns about data residency, unauthorised access and compliance with data protection regulations. Furthermore, algorithmic bias remains a pressing issue, potentially compromising fairness and trust in AI-driven decisions.

“From a security leader’s perspective, it is essential to balance innovation with responsibility. Embedding security and privacy into AI design (‘secure by design’) and implementing robust governance frameworks are critical steps. Ultimately, the successful deployment of AI tools depends not only on their technical capabilities, but also on our commitment to protecting the data they rely on.”
Turki Almalki, Security Facilities & Vigilance Manager at Riyadh Air

“AI is becoming deeply embedded in enterprise environments, driving automation, real-time decision-making and operational efficiency. But for security professionals, this shift introduces a new layer of complexity. Each interaction with an AI system — whether through prompt, output, or log — creates a data artifact that may persist beyond user intent. Unlike conventional software, AI systems process vast, unstructured datasets, often without clear data lineage or retention boundaries. This creates challenges around auditability, confidentiality and exposure management.

“The recent NYT v. OpenAI case illustrates how AI data can quickly move from operational asset to legal evidence. Deleted chats were ordered preserved, raising red flags about whether “ephemeral” truly means temporary. For CISOs, DPOs and CAIOs, this signals the need for stronger controls over AI access, logging and privacy disclosures.

“AI’s benefits are real — but only if matched with security practices that address data retention, model behaviour and legal risk. As AI adoption accelerates, organisations must embed privacy and security by design, ensure transparency in data usage, and define clear accountability across the AI lifecycle. Ignoring these risks now may mean dealing with regulatory or legal fallout later.”
Betania Allo, Cyber Policy & Law Expert

No Comments

Sorry, the comment form is closed at this time.

1