Richard Golian

1995-born. Charles University alum. Head of Performance at Mixit. 10+ years in marketing and data.

Castellano Français Slovenčina

Manage subscription Choose a plan

RSS
Newsletter
New articles to your inbox

Article

Shadow AI: The Data Privacy Risk of Sharing Sensitive Information with AI

Shadow AI, data leakage, PII and GDPR: the corporate and personal privacy risks
Richard Golian
Richard Golian · 2 315 reads
Hi, I am Richard. On this blog, I share thoughts, personal stories, findings and what I am working on. I hope this article brings you some value.

In recent years, artificial intelligence (AI) has increasingly integrated into our daily lives, and its influence continues to grow. Chatbots and AI assistants help us complete tasks, automate processes, and improve efficiency. But it is astonishing how thoughtlessly corporate and personal data are shared with AI tools without considering the risks. Many fail to realise the extent of the exposure and potential consequences.

Shadow AI and the Leak of Corporate Data

I understand the temptation – uploading a spreadsheet into ChatGPT or Gemini and letting AI assist with analysis. The latest trend is the Chinese chatbot DeepSeek, which is rapidly gaining popularity. However, many employees do not consider that they are copying entire customer databases, internal reports, business strategies, product sales data, and other sensitive marketing information into these tools, without any idea where this data ultimately goes!

Why Sharing Company Data with AI Is a Data Leakage Risk

  • Loss of Control Over Data – Do we really think AI simply forgets what we provide? Data can become part of its knowledge base, and even though developers claim they do not store it, the truth is often more complicated.
  • Geopolitical Risks – DeepSeek is a Chinese AI, and we all know how things work in China. Companies are under government scrutiny, and if you think your data cannot end up in the wrong hands, it’s time to wake up.
  • Violation of GDPR and Other Regulations – Many do not realise that they might be violating GDPR, exposing their company to hefty fines. A single thoughtless action can create serious problems.
  • Competitive Threat – If we believe our competitors are not seeking ways to access valuable data, we are mistaken.

How Employees Can Protect Sensitive Data from AI

Employees must recognise that every interaction with AI can have consequences. It is crucial that they:

  • Think Before Sharing Data – Before uploading any data into an AI tool, they should evaluate whether it truly needs to be processed this way.
  • Consult Company Policies – Companies should have clearly defined rules on what data employees can share with AI. If such policies do not exist, it is in employees' own interest to push for their creation. This can prevent situations where they inadvertently create a problem that jeopardises not only the company but also their own job security.
  • Use Internal AI Solutions – Whenever possible, they should prioritise AI models managed and controlled by the company instead of public chatbots.
  • Improve Their Digital Literacy – The more employees understand how AI works, the better they can protect sensitive data.

AI, PII and the Profiling of Your Personal Data

Sharing data with AI is not just about databases and business strategies. Every question we ask chatbots provides them with details about our thinking, interests, and values. In the future, these insights could be sold to companies for even more aggressive advertising targeting or to political parties for manipulation of public opinion.

Our interactions with chatbots also reveal our knowledge, problem-solving abilities, and thinking patterns. Essentially, this creates a database of the intelligence of the entire human population. Even my imagination is not enough to grasp how this might be exploited in the future, but the probability that someone will use this information against certain groups of people is very high.

This is a serious issue, and it is high time we start acting responsibly. Let’s not be lulled by convenience and assume that this does not concern us. If we do not wake up now, it may soon be too late.

Common questions on this article's topic

Why is sharing corporate data with AI tools risky?
Because data uploaded to public AI tools like ChatGPT or Gemini may be used to train future models, retained for monitoring, or in some cases potentially accessible through security vulnerabilities. Research shows that 77% of employees have pasted company information into AI services, with sensitive data making up over a third of inputs. In the article, the core concern is that employees upload customer databases, internal reports, and business strategies without any idea where this data ultimately goes.
What are the specific risks of using Chinese AI tools like DeepSeek?
DeepSeek, which became the most downloaded app on Apple's U.S. store in January 2025, operates under China's National Intelligence Law, which requires companies to cooperate with government security investigations. In the article, this geopolitical dimension is highlighted: if you think your data cannot end up in the wrong hands through a Chinese AI tool, it is time to wake up. The combination of rapid adoption and minimal user awareness creates a significant data exposure risk.
Can sharing data with AI violate GDPR?
Yes. The European Data Protection Board has confirmed that GDPR applies to AI models trained on personal data. Italy fined OpenAI 15 million euros for GDPR violations in December 2024. In the article, the concern is that many employees do not realise they may be violating data protection regulations through a single thoughtless action, exposing their company to significant fines and creating problems that jeopardise both the organisation and their own job security.
What do AI tools learn from our interactions?
Every question and conversation reveals patterns about how we think, what we know, what problems we are trying to solve, and how we approach them. In the article, this is described as creating a database of the intelligence of the entire human population. These insights go beyond individual queries. They map thinking patterns, knowledge gaps, and decision-making processes that could be exploited for advertising targeting, political manipulation, or purposes not yet imagined.
How can employees protect sensitive data when using AI?
In the article, four practical steps are recommended. Think before sharing. Evaluate whether data truly needs to be processed by an external AI. Consult company policies, or push for their creation if they do not exist. Use internal AI solutions managed by the company instead of public chatbots whenever possible. And improve digital literacy. The more employees understand how AI works, the better they can protect sensitive information.
Why should individuals care about AI data privacy?
Because the data is not just corporate. In the article, personal interactions with chatbots are identified as equally concerning. Our conversations reveal our values, interests, and cognitive patterns. The probability that someone will use this information against certain groups of people in the future is described as very high. If we do not start acting responsibly now, it may soon be too late.
What is shadow AI?
Shadow AI is the use of unsanctioned, public AI tools such as ChatGPT, Gemini or DeepSeek by employees without the knowledge or approval of their employer. It is a form of shadow IT applied specifically to AI. In the article, this is exactly the behaviour described: staff paste customer databases, internal reports and business strategies into public chatbots outside any company policy or security review. Because it bypasses IT governance, shadow AI has become one of the leading channels through which sensitive data leaves an organisation.
What is data leakage in the context of AI?
Data leakage, also called data exfiltration when information deliberately leaves the organisation, is the uncontrolled exposure of sensitive data when it is shared with an external system. With AI tools it happens when employees upload spreadsheets, source code or customer records into a public chatbot, where the data may be retained, used to train future models, or exposed through a security flaw. In the article, the core warning is that people copy entire databases into these tools without any idea where the data ultimately goes.
Is DeepSeek safe to use for work?
DeepSeek is a Chinese AI chatbot that became the most downloaded app on the Apple US store in January 2025. It operates under the National Intelligence Law of China, which can require companies to cooperate with state security requests, so uploading corporate or personal data to it carries a real data sovereignty risk. In the article, this is the central geopolitical warning: if you assume your data cannot end up in the wrong hands through a Chinese AI tool, it is time to wake up.
Does ChatGPT store and retain the data I share with it?
On consumer tiers, inputs can be retained and used by default to help improve the models, and deleted conversations are typically held for a period before removal. This is why the article warns against assuming an AI simply forgets what you provide: data can become part of its knowledge base. Business and enterprise tiers usually exclude inputs from training, which is why internal, company controlled AI solutions are safer for sensitive work.
What personal data should you never share with an AI chatbot?
You should never share personally identifiable information (PII) such as names, addresses, identification numbers, financial or health details, passwords, or confidential client and customer data. In the article, the deeper concern is that even ordinary questions reveal your knowledge, values and thinking patterns, building a profile that could later be used for advertising targeting or political manipulation.
Richard Golian

If you have any thoughts, questions, or feedback, feel free to drop me a message at mail@richardgolian.com.

NEWSLETTER
What I write about, what I am working on, what I learned.
Sent the first Sunday of the month. Unsubscribe anytime.

Related articles

Open Source Intelligence and AI Crime Detection

The more I think about it, the more I realize what a fundamental issue this is.

16 March 2025·2 738 reads
Autonomous Weapons and Military AI: How AI Warfare Threatens Our Security

You might say I am being too pessimistic, that I am fearmongering. Fear is useful.

15 March 2025·2 963 reads
AI, Wealth Inequality, and the Singularity We Cannot Predict

No matter how I look at the future, I see very few answers and far too many questions and problems.

25 February 2025·3 153 reads

More articles

I Ran Object Detection on My Laptop, and Saw Everything Is Possible

A few weeks ago I installed a small local AI model on my laptop that watches a live camera feed. I turned the webcam on in the dark, and in near total darkness it recognised me and the objects in the room. That such things exist, I have known for a long time. What opened my eyes was the accessibility. I installed it in one prompt, free, and it runs entirely on my machine, sending data nowhere.

15 July 2026·84 reads
Dependent on AI: Are We Still Masters, or Slaves?

I have Heidegger and my notebook beside me. I am asking where all of this is heading, where artificial intelligence is taking us.

21 June 2026·551 reads
Which Work Will AI Not Replace?

Seventy per cent. That is where the first AI output begins, even when you give it the full company context and the best examples from the past. We are talking about the kind of output that cannot be defined programmatically. It is more complex. Often it is creative work. On one repeated type of output I reached eighty per cent within a week. Every further percentage point is harder than the one before.

10 June 2026·521 reads
What is the dead internet theory? Will we return offline?

For a long time we treated the internet as the main road. The place where work and relationships happen. Yet most of what we see on it today is, or soon will be, AI-generated: text, images, profiles and comments. The internet is turning into an online game full of bots, where you cannot be sure that a human is on the other side of anything. So I ask: was the online world the main road, or only a temporary detour that part of us will return from, back offline?

7 June 2026·665 reads
The Gap Between Professionals in the AI Era

A few days ago I interviewed a senior marketer. An experienced man, years of practice. I asked him about AI. He said he barely uses it. He had one bad experience with the output and decided he was too senior for it to add value when it is not perfect. I know the other side too: professionals who automate everything that can be automated.

6 June 2026·627 reads
Europe Is Not Ready for Drone Warfare

Europe does not have the capacity to face a full-scale, mass drone war of the kind we see in Ukraine. Three dependencies weaken it: China supplies the physical material for defence systems, the United States supplies capabilities Europe does not have, and twenty-seven states cannot agree how fast, or who pays. Rearmament plans exist, but they are being carried out slowly.

31 May 2026·591 reads
Can AI Replace Human Judgement?

AI produces the graphic, the newsletter and the product page faster than a person. What is left for the one who used to do it is the judgement, knowing whether the output is good. But most people have worse judgement than AI. And whoever cannot judge quality cannot delegate either. How do you tell whether yours is the judgement a company relies on, or the kind it can replace?

30 May 2026·595 reads
What Determines a Stock Price?

In April, in the first part of this series, I wrote about an AI prediction system I had started building on my own machine. At the time the software was a few hours old and the prediction record was empty. The record since then has shown one thing: the system does not yet understand the market it is being asked to forecast. It can pull macro context, book value, earnings. But it cannot put those together into something that helps it understand the price.

23 May 2026·626 reads
Where the Money Goes When AI Takes the Work: Mapping the AI Economy

Prague, 13 May 2026. On my way to work I started thinking about something that stayed with me for days. If most routine work on a computer disappears in the next ten years, and a large share of repetitive manual work disappears with it, what happens to the flow of money? Who pays whom for what? Which economic layers will exist, how large will they be, and what relationships will run between them? This is the six-layer map I sketched as an answer.

15 May 2026·1 254 reads
Can AI Predict the Stock Market? Building a Calibrated System

I am building an AI system to predict the S&P 500. It runs on my own machine, uses free public data (yfinance, FRED, the Shiller dataset), and grades every forecast against reality. This series documents the build itself: the decisions, the methodology, the mistakes. What I will eventually share from the running system is a separate question, and an honest one.

26 April 2026·2 002 reads
All in on AI agents, or an analogue life.

Four days in Catalonia. No computer, no AI, almost no social media. I bought this notebook so that I could write down what I would think about, and what I would come across and learn on the trip.

10.5.2026·1 099 reads
NEWSLETTER
What I write about, what I am working on, what I learned.
Sent the first Sunday of the month. Unsubscribe anytime.