ChatGPT, Microsoft Copilot, Google Gemini, Claude. Your employees are already using them - at their desks, on their phones, sometimes on their personal accounts. According to data published on amithos.com, over 70% of employees use unsanctioned AI tools at work. That number isn't a projection. It's the baseline.
The question isn't whether AI is being used. It's whether sensitive data is going with it.
Can employees paste confidential data into ChatGPT?
Yes - and they do. There is no technical barrier between an employee's clipboard and an AI chat window. A customer record, a contract draft, an internal financial model, a support ticket containing social security numbers. All of it can be pasted into a prompt in a few keystrokes.
Most employees aren't doing this to be reckless. They're trying to work faster. They don't think of it as "sending data to a third party" - they think of it as using a tool. That's the gap security policies alone can't close.
Once that data is submitted to the AI tool, it has left your environment. It's on the AI provider's servers. What happens next depends on their data handling policies, your enterprise agreement, and factors outside your control.
AI data leakage risk: what the numbers show
The exposure window is smaller than you might think - which is exactly what makes it hard to manage. Data published on amithos.com shows the average time to paste sensitive data into an AI prompt is under 3 seconds. There's no alarm, no warning, no visible moment where something goes wrong. It just happens.
Multiply that across a team of 50 people using AI tools every day and you have a data exposure problem that scales invisibly.
Common categories of data that end up in AI prompts:
- Customer names, emails, and account numbers (PII under GDPR, CCPA)
- Internal financial projections and M&A detail
- Employee records and HR notes
- Source code and technical architecture
- Legal documents and contracts
- Credentials and API keys pasted for debugging help
Is ChatGPT GDPR compliant? The question you're actually asking
If your legal or compliance team has flagged AI tools, this is usually the underlying concern. The answer is complicated.
OpenAI's Enterprise tier offers data processing agreements that can satisfy some GDPR requirements. Microsoft Copilot for Microsoft 365 has additional controls through the Microsoft compliance ecosystem. But none of those agreements change one fundamental fact: if personal data reaches the AI provider's servers, you've already created a GDPR exposure event, regardless of the contractual protections in place.
The stronger compliance posture isn't a better DPA. It's ensuring personal data never leaves the browser in the first place.
That's the approach Amithos EverShade takes: detect sensitive data before the prompt is submitted, replace it with safe tokens, let the AI process the anonymized version, then restore the real values in the response. No sensitive data ever reaches the AI provider's servers - no GDPR exposure, no data processing agreement required for the protected prompt content.
Blocking AI tools doesn't work - here's what does
The instinct to block ChatGPT at the firewall is understandable. It doesn't work. Employees switch to personal devices, personal accounts, or less-visible tools. Blocking AI just pushes it underground - and underground AI use is harder to govern than visible AI use.
Effective AI governance doesn't look like a policy. It looks like a protection layer that runs automatically, without asking employees to change how they work.
See how EverShade addresses this - automatic sensitive data protection for every AI tool your team uses, with zero workflow changes.
See How EverShade WorksFrequently asked questions
Related reading: How EverShade's Detect, Protect, Restore process works | EverShade product overview | Pricing