GenAI is reshaping how employees work, but it’s also changing the risk profile for data security teams. Employees are eager to use AI to boost productivity, often faster than governance can keep up.
According to the 2025 Work Trends Index, the majority of global knowledge workers surveyed report using AI, and more than 70% say they are bringing their own AI tools to work. This “bring your own AI” trend means employees frequently turn to consumer-grade tools or log in with personal accounts, outside corporate controls.
The impact on security is already visible:
- 32% of data security incidents reported by surveyed organizations involve the use of GenAI tools.
- 35% of organizations expect incident volumes to rise in the coming year due to GenAI usage.
- Use of personal credentials for GenAI at work has increased by 5 percentage points year over year.
- Use of personal devices to access GenAI for work has grown by 9 percentage points year over year.
Security leaders are less worried about GenAI as a technology and more about where and how employees use it. Unsanctioned tools and personal accounts can expose confidential data to external systems, with little visibility into where that data goes.
In response, nearly half of surveyed organizations are tightening controls. 47% are implementing specific GenAI controls in 2025, up from 39% the previous year. Their top priorities include:
- Preventing sensitive data from being uploaded into GenAI tools.
- Training employees on secure GenAI usage.
- Detecting anomalous user activity and identifying risky users.
- Identifying sensitive data being uploaded to or generated by GenAI tools.
The goal isn’t to slow down AI-driven productivity. Instead, organizations are steering employees toward sanctioned AI tools, reinforcing safe practices, and building clear approval processes so they can enable GenAI use while keeping data protected.