Back to blog

AI Data Leaks in Small Business: What Happens to the Data Your Team Pastes Into ChatGPT

77% of employees paste company data into AI tools, mostly via personal accounts. Here's what that means for a small business, and how to fix it fast.

One of your staff has a customer list open and a deadline closing in. They paste the whole thing into ChatGPT and ask it to write a friendly follow-up email for each name. Thirty seconds later they have the emails. It felt like a shortcut. What actually happened is that a list of your customers, with their contact details, just left your business and landed on a server you don't own, under an account you can't see. Nobody meant any harm. That is exactly why it keeps happening.

This is the quiet version of a data breach. No hacker, no ransom note, no locked screen. Just helpful people using a helpful tool, one paste at a time. And it is now the most common way company data walks out the door. A report from security firm LayerX, covered again in industry press on 20 August 2026, found that 77% of employees paste company data into generative AI tools like ChatGPT. Most of that, 82%, happens through personal accounts your business has no visibility into. Generative AI has quietly become the single biggest channel for company data leaving the building, ahead of email and file sharing.

For a business with 1 to 10 staff, this matters more than the headlines suggest. You probably don't have a security team watching for it. You may not even have a rule about it. And your team is adopting AI faster than almost anyone. This is what is actually happening, why it is a real risk rather than a scare story, and the short list of things you can do about it this week.

Your team is already using AI, whether you set it up or not

Start with the reality on the ground. 58% of small businesses used generative AI in 2025, up from 40% the year before, according to US Census Bureau business survey data. The smallest firms, those with 1 to 4 people, are among the fastest adopters of all. Solo operators and tiny teams have worked out that AI is a cheap extra pair of hands, and they are using it for real work: writing quotes, cleaning up spreadsheets, drafting contracts, answering customers.

That is a good thing. AI genuinely helps a small team punch above its weight. The problem is not the tool. The problem is that adoption has raced ahead of any thought about what data goes into it. This is shadow AI in its plainest form: useful tools arriving through the side door, faster than anyone can keep track of them. IBM found that 77% of organisations say AI adoption is already outpacing their ability to govern it. In a big company that gap gets papered over by a security team and a written policy. In a 10-person business, there is usually nothing in between the employee and the paste button.

So the honest starting point is this. Your team is using AI. You did not sign off on most of it. You cannot see most of it. And some of what they are feeding it is data you would never email to a stranger.

What "data leak" actually means here

It helps to be specific, because "AI data leak" sounds abstract until you picture the real files. Based on the LayerX findings, here is what people actually paste into AI tools at work:

  • Customer records and contact lists, to summarise or write outreach
  • Source code and technical notes, to debug or review
  • Internal financial numbers and projections, to draft an update or investor note
  • HR and pay information, to write a review or a policy
  • Contracts and NDA terms, to summarise the tricky clauses

Notice the pattern. This is not junk data. It is the most sensitive material in your business, handed to a third party in the course of doing genuinely useful work. The share of data going into AI tools that counts as sensitive has more than tripled in two years, from 10.7% to 34.8%. In other words, AI use is not just growing. It is getting riskier per use, because people trust it with more.

Now add the account problem. When 82% of that activity runs through personal ChatGPT or personal AI accounts, the data is no longer inside anything your business controls. You cannot audit it. You cannot delete it. If that employee leaves, their chat history, and everything they pasted into it, leaves with them. That is the same blind spot that makes offboarding harder than switching off an email account. On a free consumer AI plan, that content can also be used to train future versions of the model, depending on the settings the employee never checked.

Why this is a breach, even when nothing gets "hacked"

Owners tend to file breaches under one mental heading: someone broke in. Under privacy law, and under plain common sense, a breach is simpler than that. It is your data ending up somewhere it should not be, in the hands of someone who should not have it. Pasting a client list into a personal AI account clears that bar comfortably. It is the same exposure that shows up in the breaches small businesses actually have, just without the drama.

The consequences are the same as any other exposure. If that data includes personal information about your customers or staff, you may have a notification obligation. In Australia, businesses covered by the Privacy Act have to consider whether an exposure is likely to cause serious harm and, if so, report it. "An employee pasted it into ChatGPT" is not a defence anyone wants to test. One in five organisations has already had a data incident tied to unsanctioned AI use, so this is not a rare edge case. It is a common one that simply does not make the news, because there is no dramatic ransom note attached.

There is a reputational angle too, and small businesses feel it harder. Nearly half of small-business workers in a 2026 survey said they worried that leaning too heavily on AI could damage their company's reputation. Your customers gave you their information on the understanding that you would look after it. "We fed it to an AI to save ten minutes" is not the story you want to explain to them later. And unlike a big brand, a small local business does not have a reputation buffer to absorb the hit. Trust is often the main thing you are selling, and it is the one thing this kind of quiet leak spends fastest.

The fix is not banning AI. It is giving it a lane

Here is the trap. The instinct, once an owner understands the risk, is to ban AI outright. That fails for the same reason banning personal phones failed. People will use it anyway, just more quietly, and now you have no visibility at all. Prohibition pushes the problem into the shadows instead of solving it.

The better move is to give AI a lane: a clear, simple path for using it safely, so the risky version stops being the easy version. For a small team, that comes down to four practical steps you can start this week.

1. Move the team onto business AI accounts

The single biggest lever is the account. A business or team tier of ChatGPT, Microsoft Copilot, or Google Gemini gives you two things a personal account never will: your data is excluded from model training by default, and you keep some control over the account when the person leaves. If your team is going to use AI, and they are, this is the difference between an exposure you can manage and one you cannot see. It usually costs less than one unused software subscription you are already paying for, so the money is rarely the real blocker. The blocker is that nobody has decided to make it the standard, so everyone quietly defaults to whatever they signed up for at home.

2. Write one page on what not to paste

You do not need a formal AI policy with legal review. You need one page AI Usage Policy, in plain language, that everyone actually reads. Name the specific things that must never go into any AI tool: customer personal details, staff pay and HR records, passwords and access keys, signed contracts, anything covered by a client confidentiality agreement. Then name the safe stuff people can use it for freely: drafting generic copy, summarising public information, brainstorming, fixing their own writing. People follow rules they understand. Give them the line, not a lecture.

3. Make the safe path the easy path

Rules only stick when the compliant option is also the convenient one. If the approved AI account is slower to reach than the personal one, people will drift back to personal. Put the business account login where they work. Show them once how to use it for the tasks they were already doing on the side. The goal is that the safe tool is the one sitting right there when the deadline hits.

4. Know which AI tools your team actually uses

You cannot manage what you cannot see. Most owners would struggle to name every AI tool their staff have signed up for, and that blind spot is the whole problem. Shadow AI is just the newest form of shadow IT, the same habit that quietly produces SaaS sprawl: tools brought in without anyone tracking them. Spend twenty minutes asking the team, plainly and without blame, which AI tools they use and what for. You will almost always find one or two you had no idea about. That list is the foundation for every other step.

Where this fits into the bigger picture

Notice that three of those four steps come back to the same thing: knowing what is actually in use across your business. Which tools your team has adopted. Which accounts hold your data. Which subscriptions you are paying for and which have quietly gone stale. AI data leaks are a new symptom of an old problem, the fact that most small businesses have no single place that shows them their own IT.

This is the gap Vera was built to close. Vera is a simple dashboard that gives a small business the kind of IT visibility that used to require hiring a managed provider. It keeps a live record of your team, your devices, and the software and subscriptions in use across the business, so the tools your staff sign up for stop being invisible. When you can see the full picture in one place, shadow AI stops being a surprise and starts being just another thing you manage, on purpose, before it turns into an incident.

You do not need a security team to get ahead of this. You need to know what your team is using, give them a safe way to use it, and write down the handful of things that must never be pasted anywhere. AI is one of the best things to happen to small business productivity in years. It is worth the ten minutes it takes to make sure the shortcut your team loves does not quietly become the leak you did not see coming.

If you want a quick read on where your setup stands right now, the free IT health checkup takes about five minutes. And if you want to see what your business is actually running, from the software your team uses to the accounts holding your data, Vera gives you that view in one place. Knowing beats hoping nobody pasted the wrong thing today.