Harmonic Security

53 stats5 reports

All Statistics

45.6% of employees' personal AI activity flows through enterprise tools their company is paying for.

AI UsageEnterprise Software

Go To Market accounts for 17.5% of AI minutes and runs 39% of its AI activity on enterprise plans.

SalesMarketingAI UsageEnterprise Software

64.5% of activity on personal and free-tier AI accounts is business use rather than personal use.

AI UsageShadow AIData Security

25% of all sensitive data disclosures involve technical data, with 65% of that consisting of proprietary source code copied into generative AI tools.

Gen AISensitive dataTechnical dataProprietary source code

12% of all sensitive data exposures originate from personal accounts, including free versions of generative AI tools.

Gen AISensitive dataPersonal Gen AI account

The average organization used 27 distinct AI tools in Q3 2025, down from 23 new tools introduced in Q2 2025.

Gen AIAI tools

15% of Google Gemini use by employees was via personal accounts.

AIGen AIGoogle Gemini

Of these incidents involving Chinese GenAI tools, the exposed data types included: 32.8% involving source code, access credentials, or proprietary algorithms; 18.2% including M&A documents and investment models; 17.8% exposing PII such as customer or employee records; and 14.4% containing internal financial data.

AIGen AIChinese Gen AISensitive data

26.3% of ChatGPT use by employees was via personal accounts.

AIGen AIChatGPT

1 in 12 employees, or 7.95%, used at least one Chinese GenAI tool at work.

AIGen AI

Among the 1,059 users who engaged with Chinese GenAI tools, there were 535 incidents of sensitive data exposure.

AIGen AISensitive data exposure

The majority of sensitive data exposure (roughly 85%) due to the use of Chinese GenAI tools occurred via DeepSeek, followed by Moonshot Kimi, Qwen, Baidu Chat and Manus.

AIGen AISensitive data exposureDeepSeek

63.8% of ChatGPT users used the free tier, with 53.5% of sensitive prompts entered into it.

Gen AIChatGPTSensitive information

8.5% GenAI prompts contain sensitive information.

Gen AISensitive information

45.77% of sensitive data input into GenAI tools was customer data, such as billing information, customer reports, and customer authentication data.

Gen AISensitive informationCustomer data

Legal and Governance departments account for 19.5% of all AI hours, with 81% of that use occurring on enterprise plans.

ComplianceLegalAI UsageEnterprise Software

Operations runs just 18% of its AI activity on enterprise plans.

OperationsAI UsageEnterprise Software

74.6% of all AI use at work has a clear business purpose.

AI Usage

The average enterprise uploaded more than three times as much data to generative AI platforms in Q3 2025, with 4.4GB compared to 1.32GB in Q2 2025.

Gen AI

57% of sensitive data uploaded to generative AI tools is classified as business or legal data, with 35% of that involving contract or policy drafting.

Gen AISensitive dataBusiness dataLegal data

26.4% of all file uploads to generative AI tools contained sensitive data between July and September 2025, an increase from 22% in Q2 2025.

Gen AISensitive data

15% of all sensitive data uploaded to generative AI tools involves personal or employee data, including identifiers such as names and addresses.

Gen AISensitive dataPersonal dataEmployee dataPII

2.1% of all sensitive prompts analysed in Q2 originated in Poe.

AIGen AIPoeSensitive prompts

72.6% of all sensitive prompts analysed in Q2 originated in ChatGPT.

AIGen AIChatGPTSensitive prompts

1.8% of all sensitive prompts analysed in Q2 originated in Perplexity.

AIGen AIPerplexitySensitive prompts

Of analyzed prompts and files submitted to 300 GenAI tools and AI-enabled SaaS applications between April and June, 22% of files (totaling 4,400 files) and 4.37% of prompts (totaling 43,700 prompts) were found to contain sensitive information.

AIGen AISensitive data

The average enterprise uploaded 1.32GB of files (half of which were PDFs) to GenAI tools and AI-enabled SaaS applications in Q2. A full 21.86% of these files contained sensitive data.

AIGen AISensitive data

Sensitive data in files sent to GenAI tools showed a disproportionate concentration of sensitive and strategic content compared to prompt data, with files being the source of 79.7% of all stored credit card exposures, 75.3% of customer profile leaks, 68.8% of employee PII incidents, and ◦ 52.6% of total exposure volume in financial projections.

AIGen AISensitive data

535 separate incidents of sensitive exposure were recorded involving Chinese GenAI tools.

AIGen AIChinese Gen AISensitive data

In Q2, the average enterprise saw 23 previously unknown GenAI tools newly used by their employees.

AIGen AI

5.0% of all sensitive prompts analysed in Q2 originated in Google Gemini.

AIGen AIGoogle GeminiSensitive prompts

2.5% of all sensitive prompts analysed in Q2 originated in Claude.

AIGen AIClaudeSensitive prompts

Code leakage was the most common type of sensitive data sent to GenAI tools.

AIGen AISensitive dataCode

13.7% of all sensitive prompts analysed in Q2 originated in Microsoft Copilot.

AIGen AIMicrosoft CopilotSensitive prompts

47.42% of sensitive employee uploads to Perplexity were from users with standard (non-enterprise) accounts.

AIGen AIPerplexity

7.95% of employees in the average enterprise used a Chinese GenAI tool.

AIGen AIChinese Gen AI

Code and development artifacts made up 32.8% of sensitive data exposed through employee use of Chinese GenAI tools at work.

AIGen AISensitive data exposure

Financial information accounted for 14.4% of sensitive data exposed through employee use of Chinese GenAI tools at work.

AIGen AISensitive data exposure

Customer data represented 12.0% of sensitive data exposed through employee use of Chinese GenAI tools at work.

AIGen AISensitive data exposure

Legal documents made up 4.9% of sensitive data exposed through employee use of Chinese GenAI tools at work.

AIGen AISensitive data exposure

Mergers & acquisitions data accounted for 18.2% of sensitive data exposed through employee use of Chinese GenAI tools at work.

AIGen AISensitive data exposure

Organisations that implement light-touch guardrails and nudges, rather than blanket blocking of Chinese GenAI tools, have seen up to a 72% reduction in sensitive data exposure, while increasing AI adoption by as much as 300%.

AIGen AI

Personally identifiable information (PII) comprised 17.8% of sensitive data exposed through employee use of Chinese GenAI tools at work.

AIGen AISensitive data exposure

When asked if they agree with the statement "My organization has blocked/is blocking access to one or several GenAI sites," 44% of organizations surveyed said they strongly agree, 42% said they agree, 6% said they neither agree nor disagree, 5% said they disagree, 2% said they strongly disagree.

Gen AI

When asked if they agree with the statement "We are concerned about data leakage as employees increasingly use GenAI tools," 43% of organizations surveyed they strongly agree, 39% said they agree, 10% said they neither agree nor disagree, 5% said they disagree, and 3% said they strongly disagree.

Gen AIData leakage

5.64% of sensitive data input into GenAI tools was sensitive code, like Access Keys and proprietary source code.

Gen AISensitive informationCode

When asked if they agree with the statement "We aren't sure if any employees are currently accessing GenAI sites today or what they are doing on these sites," 42% of organizations surveyed said they strongly agree, 40% said they agree, 7% said they neither agree nor disagree, 5% said they disagree, 5% said they strongly disagree.

Gen AI

When asked if they agree with the statement "My organization has blocked/is blocking access to one or several GenAI sites," 44% of organizations surveyed said they strongly agree, 42% said they agree, 6% said they neither agree nor disagree, 5% said they disagree, 2% said they strongly disagree.

Gen AI

When asked if they agree with the statement "We are concerned about data leakage as employees increasingly use GenAI tools," 43% of organizations surveyed they strongly agree, 39% said they agree, 10% said they neither agree nor disagree, 5% said they disagree, and 3% said they strongly disagree.

Gen AIData leakage

14.88% of sensitive data input into GenAI tools was legal and finance data, such as information on Sales Pipeline Data, Investment Portfolio Data, and Mergers and Acquisitions.

Gen AISensitive informationLegal dataFinance data