logo

Almost 10% of GenAI Prompts Include Sensitive Data: Study

ID: ac851fcf-c6ab-516c-8ea6-bb5773d1fa52

STIX ID: report--ac851fcf-c6ab-516c-8ea6-bb5773d1fa52

Feed Name: Security Boulevard

Threat Score
30/100

Date Published: 2025-01-21

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Harmonic Security analyzed tens of thousands of enterprise prompts to ChatGPT, Copilot, Gemini, Claude and Perplexity and found 8.5% contained sensitive information—primarily customer (45%+) and employee (~27%) data, plus legal/financial, security, and code-related content. The report highlights that a large share of these sensitive prompts were submitted via free-tier AI services (which often lack enterprise protections and may train on submitted data), and recommends real-time monitoring of data sent to GenAI, enforcing paid enterprise plans, departmental usage workflows, and ongoing user education to reduce leakage risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.