The rise of AI tools has inadvertently turned employee experience into a security issue when it comes to protecting customer data.
The applications employees use to solve everyday problems are data processing environments as much as they are productivity applications. Every interaction with AI, whether a prompt, uploaded file, pasted transcript, spreadsheet extract, customer record, internal policy, or meeting note, can become a point of exposure that the enterprise may not see, control, retain or govern.
Employees will use AI wherever it is easiest. If the tools approved by an enterprise are slow, unavailable, poorly integrated, or locked behind approval processes, they will turn to personal AI accounts.
As Patricia Egger, Co-Founder of Women in Cyber Switzerland and Head of Security at encrypted business cloud storage provider Proton, told CX Today:
“The first issue is that a chat window feels like a private conversation (it’s just you and the machine) so employees can forget there’s a company, infrastructure, logs and settings behind it.”
A sense of familiarity when interacting with AI tools can cause employees to become comfortable sharing information that should stay within the company.
“The second problem is everything happening outside official channels, people using AI in their personal lives, or at work regardless of what the policy says. We usually call this shadow IT, but we could call it shadow AI,” Egger said.
And with new functionalities emerging at a rapid pace, hidden AI is a moving target.
“New AI tools are popping up literally every day, so knowing what’s out there, what people are using, what they’re playing around with, it’s not easy to keep track. In a business without a dedicated security function, nobody is even trying to keep track, and that’s where the exposure builds up,” Egger added.
The result is a growing gap between where organizations think AI is being used and where work is actually happening.
Personal AI Use Has Become an Enterprise Blind Spot
Despite all the discussion around AI security, nearly half of enterprise AI consumption still happens through personal accounts.
According to the State of AI Usage Report 2026 by secure enterprise browser (SEB) technology provider Layer X Security, 47 percent of enterprise AI conversations are conducted through personal identities rather than corporate accounts. These interactions sit outside the normal scope of enterprise AI security, making them difficult to monitor as they are often disconnected from corporate data retention and compliance policies.
Employees are not trying to create risk. In many cases, they are trying to get work done. They may be drafting emails, summarizing documents, analyzing customer feedback, preparing meeting notes, troubleshooting technical issues or rewriting support responses. The risk emerges when those tasks are carried out in environments the business cannot see.
Even corporate identity does not fully solve the problem. The data also shows that more than 14 percent of conversations carried out using a corporate identity are happening via personal AI licenses. While an employee may appear to be operating within a business context, the underlying license may still allow data to be used for model training or sit outside enterprise-grade protections.
The organization may believe employees are using AI safely because they are signing in with work credentials. But in reality, the data may still be leaving the confines of its environment.
Sensitive Data Exposure Is Already Happening
AI chatbot users recently found that conversations in Claude, Grok and Meta AI can show up in Google search results via share links, exposing sensitive data, including names, addresses, work notes and cryptocurrency wallet keys to the public web.
More than six percent of enterprise AI conversations contain sensitive data, according to the Layer X report. ChatGPT, in particular, has a sensitive data exposure rate of 8.38 percent, making it the largest enterprise AI data exposure channel.
Sensitive data exposure can take many forms. An employee might paste a customer complaint containing contact details into an AI tool to generate a response. A sales manager might upload pipeline notes to summarize account risks. A support leader might analyze call transcripts that include personal information. A product team might use AI to review bug reports containing internal system details. Or a finance employee might ask AI to explain a spreadsheet containing commercial information.
In each case, the employee’s intent to save time or improve quality may be reasonable, but the data protection risk depends on the environment in which that task takes place.
In an interview with CX Today, Adam Spearing, EMEA Head of AI Innovation at ServiceNow, cited an unnamed customer that
“found 20,000 AI agents, what we call shadow AI, that have been built by people for all good reasons, with all good intention, doing stuff that the IT organization had no clue about.”
A lack of visibility has implications for governance and compliance, because if a business cannot see which AI tools are being used, which identities are being used to access them, what data is being shared, or how that data is handled, it cannot make credible claims about control.
The Workforce Experience Problem Behind AI Risk
Contact center agents, sales teams, customer success managers, marketers and service leaders under pressure to respond quickly to customers in personalized interactions and extract insight from unstructured data are likely to experiment with personal AI tools that they find to be fast and flexible.
Enterprise tools, by contrast, can be fragmented. Access may be limited to certain teams and approved AI assistants may not connect to the systems employees actually use. Some platforms may be available but poorly communicated.
As Simon Morris, Senior Director of Solution Engineering for Freshworks, put it in a CX Today roundtable discussion:
“Everyone in the CX industry is asking the question, ‘how can I give my customers a five-star experience?’ Well, I think it starts by not giving your agents a two-star experience where things are really complicated.”
The key to improving the employee experience while protecting customer data is to make access to AI productivity tools easier, demonstrating an understanding of those pressures.
“I try very hard not to be the person who tells people they can’t do the things that makes them effective at work,” Egger said. “My job is to help people do what they want to do without creating security risk, and that principle should shape the employee experience. If the secure path is slower or clunkier than the insecure one, people will take the insecure one, not out of malice but because they have deadlines.”
AI Governance Cannot Rely on Policy Alone
Many organizations have responded to AI risk by publishing usage policies. These are important, but they are not enough.
A policy that tells employees not to paste sensitive data into AI tools will not work if employees do not understand what counts as sensitive data, cannot access a safe alternative or face pressure to move faster than existing processes allow.
A survey of professionals carried out by compliance services firm VinciWorks earlier this year found that 19 percent pointed to staff awareness and training as the most challenging issue in compliance with General Data Protection Regulation (GDPR), with 43 percent selecting AI and automated decision making. Approximately 11 percent said their training was not very effective, while nine per cent said their organization had no data protection training at all.
“The danger with AI tools is laziness,” Egger warned. “They’re so convenient and so everywhere that people let themselves slip into a vicious cycle of ‘it already knows everything about me, so it might as well know more,’ and suddenly they’re handing over things they’d never have shared on day one.”
“Leaders need to interrupt that drift with clear, concrete norms about what goes into which tool, and with sanctioned tools that are secure by default, so people don’t need a security mindset just to do their jobs safely.”
What Organizations Should Do Now
Enterprises can reduce the risk of employees exposing customer data through AI tools by making secure behavior the easiest behavior, designing AI governance around how work actually gets done.
Classifying AI use cases by risk can help to identify where sensitive, regulated, or commercially confidential data is likely to appear. Asking AI to rewrite a public-facing paragraph is very different from uploading customer transcripts or employee records.
Giving employees easy, role-based access to the tools and data they need can help to avoid risky workarounds such as personal apps or unsanctioned AI tools.
“The most important move would be to provide a sanctioned AI tool that’s genuinely good and convenient, so nobody needs to go looking elsewhere,” Egger said. “Configure it according to company policies, as much as that’s possible, and set up any additional security controls you are able to, in order to feel comfortable with employees using the tool.”
Even an approved tool should have restricted access to customer data. As Egger explained:
“Before committing to a tool, companies need to look at the options available and figure out what exactly does this tool access, and can we narrow it? What can it see, what can it do, and what happens to that access when an employee leaves or the contract ends? A tool that only needs a transcript should never be connected to an entire inbox or customer database.”
That means engaging with vendors to understand how their AI tools handle data.
“Leaders should also ask vendors about the data: what they retain, for how long, and is anything used for model training or advertising? Get it contractually, as legal guarantees matter,” Egger advised. “But then go further, because a contract doesn’t prevent a breach, and if the provider is compromised, your data is out there regardless of what the paperwork said.”
Once sanctioned tools are in place, data protection training should become specific. Rather than relying on compliance training, start by showing employees how to handle customer data in real situations they encounter. Employees need practical examples, such as what they can copy and paste, what they should redact, which tools are approved, when they need human review and what to do if they are unsure.
“My rule is simple: if you wouldn’t tell it to a random person at the grocery store, don’t tell it to the Internet, and that includes chatbots,” Egger said.
Integrating security protections and governance into the background of existing workflows rather than adding layers of manual checks further reduces friction. The more governance depends on employees remembering every rule in the moment, the more likely it is to fail.
“People shouldn’t need any particular knowledge of security or encryption to be protected; it should come with the product. And don’t demand perfection or overnight change. The same applies inside a company: baby steps that people will really take beat a perfect policy that everyone routes around,” Egger said.
Employees should also be able to report mistakes, suspicious activity or insecure processes without fearing blame.
The New Standard for Workforce Experience
Workforce experience is about shaping the environment in which work happens and decisions are made.
Enterprises that provide employees with tools that match the speed and convenience of consumer AI while maintaining enterprise-grade controls over identity, data, retention and governance will be able to balance employee experience with customer data protection.
If nearly half of enterprise AI conversations are taking place through personal identities, the problem is not only that the enterprise has not yet made the right tools easy enough to use.
The underlying principle is that better employee experiences can support stronger data protection when security is designed around how people actually work.