Report by Harmonic Security

GenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises

17 FINDINGSPublished Jul 31, 2025
View Original Report →

Key Findings

15% of Google Gemini use by employees was via personal accounts.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIGoogle Gemini

26.3% of ChatGPT use by employees was via personal accounts.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIChatGPT

13.7% of all sensitive prompts analysed in Q2 originated in Microsoft Copilot.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIMicrosoft CopilotSensitive prompts

72.6% of all sensitive prompts analysed in Q2 originated in ChatGPT.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIChatGPTSensitive prompts

1.8% of all sensitive prompts analysed in Q2 originated in Perplexity.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIPerplexitySensitive prompts

Of these incidents involving Chinese GenAI tools, the exposed data types included: 32.8% involving source code, access credentials, or proprietary algorithms; 18.2% including M&A documents and investment models; 17.8% exposing PII such as customer or employee records; and 14.4% containing internal financial data.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIChinese Gen AISensitive data

Of analyzed prompts and files submitted to 300 GenAI tools and AI-enabled SaaS applications between April and June, 22% of files (totaling 4,400 files) and 4.37% of prompts (totaling 43,700 prompts) were found to contain sensitive information.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AISensitive data

The average enterprise uploaded 1.32GB of files (half of which were PDFs) to GenAI tools and AI-enabled SaaS applications in Q2. A full 21.86% of these files contained sensitive data.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AISensitive data

Code leakage was the most common type of sensitive data sent to GenAI tools.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AISensitive dataCode

7.95% of employees in the average enterprise used a Chinese GenAI tool.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIChinese Gen AI

535 separate incidents of sensitive exposure were recorded involving Chinese GenAI tools.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIChinese Gen AISensitive data

Sensitive data in files sent to GenAI tools showed a disproportionate concentration of sensitive and strategic content compared to prompt data, with files being the source of 79.7% of all stored credit card exposures, 75.3% of customer profile leaks, 68.8% of employee PII incidents, and ◦ 52.6% of total exposure volume in financial projections.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AISensitive data

47.42% of sensitive employee uploads to Perplexity were from users with standard (non-enterprise) accounts.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIPerplexity

In Q2, the average enterprise saw 23 previously unknown GenAI tools newly used by their employees.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AI

5.0% of all sensitive prompts analysed in Q2 originated in Google Gemini.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIGoogle GeminiSensitive prompts

2.5% of all sensitive prompts analysed in Q2 originated in Claude.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIClaudeSensitive prompts

2.1% of all sensitive prompts analysed in Q2 originated in Poe.

Harmonic SecurityGenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises·Jul 31, 2025
AIGen AIPoeSensitive prompts