Editorial

VIDEO: Staff aren't villains, but their use of AI opens the door

Rethinking insider threats in the age of AI

Saturday, July 12, 2025 | 5 MINS

Video: Staff aren't villains, but their use of AI opens the door

Rethinking insider threats in the age of AI

Staff are not necessarily villains, but their unguarded and unmonitored use of artificial intelligence (AI) tools opens the door for cyberattacks, according to Rob Dartnall from Netskope, who spoke at CyberSync 2025 about how businesses can rethink insider threats in the age of AI.

AI tools like ChatGPT, Gemini, Claude, and Copilot are becoming embedded into daily workflows, and while they promise productivity and innovation, they also bring new risks — particularly when sensitive data is involved. Most employees use personal accounts on shared devices, and this creates vulnerabilities.

Usage is widespread — and largely unmonitored

Dartnall shared that 97% of organisations now see AI traffic through their networks, and use is growing at over 500% year on year. The problem? Most businesses have little to no visibility into what data is being shared, pasted, or uploaded into these tools. Over 10% of employees are uploading content weekly — and some are doing it daily — with little thought to whether it contains confidential or sensitive information.

For context, a typical company of 10,000 employees using Microsoft 365 might have 2,100 users regularly interacting with AI apps. That scale of exposure is significant, especially when many of those interactions are happening via personal accounts that organisations can't monitor or control.

The problem with prompts

The real risk lies in what employees are inputting. Dartnall described prompts as the "insider threat of the AI era". Unlike traditional data loss prevention (DLP) systems that scan files and emails, most organisations have no equivalent safeguards for prompts entered into generative AI tools.

Take a scenario where an employee pastes a company's strategic plan into ChatGPT to summarise it. That prompt — and the data it contains — has left the organisation, been processed by a third party, and could potentially be stored, logged, or used to train the model. That's a breach of confidentiality, whether intentional or not.

He noted that over 4% of prompts analysed in his research contained some form of sensitive data: source code, credentials, regulated information, or intellectual property. In high-risk environments — think financial services or healthcare — that could mean patient records, payment details, or proprietary algorithms being exposed without oversight.

Policy, visibility, and control

So what can businesses do? Dartnall outlined a three-part approach:

  1. Policy: Start by defining acceptable use. Which AI tools are permitted? Under what conditions? Who is authorised to use them, and for what purpose?
  2. Visibility: Deploy tools that give you real-time insight into AI usage across your estate. Who's using what? How often? And critically — what are they uploading or prompting?
  3. Control: Implement guardrails. That might mean blocking certain apps, restricting uploads in others, or using DLP-like rules to scan prompts for sensitive content before they're sent

He also highlighted the growing trend of enterprise AI agreements, where organisations negotiate directly with providers like OpenAI, Google, or Anthropic for managed instances with stronger data protections, audit trails, and contractual guarantees around data usage and retention.

Moving from reaction to prevention

The session reinforced a key message: ignoring AI usage won't make the risks go away. Employees are already using these tools — the question is whether your organisation has the visibility and controls in place to manage that use safely.

Dartnall's advice? "Assume your staff are not malicious, but are human. They will take shortcuts. They will use the tools that make their job easier. Your job is to give them a safe way to do that."

As AI becomes further embedded into workplace tools, businesses that treat it as just another SaaS application — rather than a distinct risk category — will likely find themselves exposed. The insider threat in 2025 isn't the disgruntled employee stealing files. It's the well-meaning one copy-pasting them into a chatbot.

Also in this section

}());