Opinion: The AI leak nobody is watching


Employees are pasting customer data into AI tools. Banning them won’t work; guardrails at the prompt will

Published Date – 30 September 2026, 10:31 PM

Opinion: The AI leak nobody is watching
Illustration: GuruG

By Vijay Kumar

Somewhere in an office in Mumbai, a customer service executive copied a complaint letter into a free AI chatbot and asked it to draft a polite reply. The letter carried the customer’s name, phone number, policy number and, as these letters often do, an Aadhaar number. The reply came back in seconds. The executive was pleased. The customer will never know that his or her personal details now sit on a server run by a company with which his or her bank or insurer has no contract.


This is not a story about a careless employee. It is a story about every Indian organisation that has not yet noticed how its people actually use artificial intelligence.

Quiet Habit

Generative AI has arrived in Indian workplaces faster than any technology before it. Staff use it to summarise documents, write emails, analyse spreadsheets and fix code. Most of this is harmless, and much of it is genuinely useful. But in the rush for productivity, a quiet habit has formed: people paste whatever is in front of them into whichever AI tool is open in their browser. Customer records, salary sheets, contracts, medical reports and, among software developers, the passwords and access keys to company systems.

The risk runs in both directions. Data leaks out through what employees type. It can also leak back through what AI systems say. Chatbots built on company data have, in reported cases around the world, surfaced one customer’s details in an answer to another.

For India, the stakes go beyond fines. Our technology services industry and global capability centres run on the trust of overseas clients. Those clients increasingly send security and privacy questionnaires that ask a direct question: how do your people use AI tools with our data? I have seen capable Indian firms lose contracts in Europe and North America not because of weak engineering, but because they could not answer questions like these convincingly. An uncontrolled AI habit is no longer just a compliance risk. It is a commercial one.

Law Catches Up

India’s law is catching up. The Digital Personal Data Protection Act, 2023, requires organisations to use personal data only for the purpose for which it was collected and to protect it with reasonable security safeguards. The penalty for failing to meet the safeguards can reach Rs 250 crore.

The DPDP rules, notified last November, bring the core obligations into force in May 2027, including a duty to report breaches to the Data Protection Board within 72 hours. A single paste into an unapproved AI tool could cause havoc. CERT-In, in its blueprint on AI-driven cyber threats released this May, has specifically warned about shadow AI, prompt injection, and data leaking through AI systems.

An agent running with a developer’s full access can reach far more than its task needs. These agents must be given only the permissions they need

The instinctive response of many entities is to ban public AI tools. It does not work. When the office network blocks a chatbot, employees simply use it on their personal phones, where the company sees nothing at all. A ban does not remove the risk. It only removes the visibility.

The smarter answer is to make the safe path the easy path. That starts with giving employees an approved AI tool, on an enterprise plan whose terms say the company’s data will not be used to train the provider’s models. It continues with a one-page policy, written in plain language, listing which tools may be used and for what kind of data.

The technical controls matter just as much. Traditional data loss prevention (DLP) tools were designed for email attachments and pen drives, not chat boxes. Organisations now need guardrails at the prompt itself: systems that check what is being sent to an AI tool, spot personal data or passwords, and mask them before they leave, so the employee still gets a useful answer and the customer’s identity stays protected.

The same checks should apply to what comes back. And they must work wherever AI is used, not only in the browser. Employees now reach AI through desktop apps, coding assistants that run inside developers’ terminals, browser extensions, and AI features built into everyday office software. A control that watches only websites misses most of that traffic.

People and Tools

People matter as much as tools. Most employees who paste sensitive data into a chatbot have simply never been told why it is risky. Short, practical training, built on real examples of what not to paste, changes behaviour faster than any policy document. Smaller firms and startups need not wait for large budgets either. An approved tool, a clear one-page rule and a monthly spot check of how AI is being used will close most of the gap at very little cost.

The next wave is already here. AI agents — software that can read files, call other tools and send emails on its own — are entering Indian companies through coding assistants and workflow automation. An agent running with a developer’s full access can reach far more than its task requires. These agents must be registered, given only the permissions they need, and stopped before they take actions that cannot be undone.

Companies should start asking three plain questions. Do we know which AI tools our employees are using today, including the ones we never approved? Can we see what data is being sent to them? And if a regulator or a customer asks us tomorrow how we protect personal data in AI tools, could we answer with evidence rather than intentions? If the answer to any of these is no, that is where the work begins.

None of this is exotic. It is the same discipline Indian companies already apply to email and cloud storage, now extended to a new channel. The organisations that act now will be ready when the DPDP obligations take effect. Those that wait will discover the problem the hard way, in a breach notice or a regulator’s letter.

The question is no longer whether your employees are using AI. They already are. The question is whether they are using it safely, and whether you would know if they were not. Artificial intelligence and privacy are not opposites. Indian companies can have both, but only if they put the guardrail where the risk begins: at the prompt.

(The author is Founder & CEO of DigiFortex Technologies. He is a CIPP/E & DSCI Certified Privacy Lead Assessor & serves as DPO & v-CISO for companies.  vijay@digifortex.com)



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *