Artificial Intelligence Chatbots can help you quickly clean up your presentation moments before important board meetings. However, these quick AI fixes can be responsible for a higher up than you are trying to impress.
While more employees use AI tools to help them complete work tasks and improve productivity, these tools are not approved by companies in most cases. When employees use fraudulent AI platforms and tools, it is called Shadow AI, creating the risk that workers will misdisclose sensitive internal data on these platforms, making them susceptible to cyberattacks or intellectual property theft.
In many cases, companies are slow to adopt the latest technology, allowing employees to seek third-party solutions, such as AI assistants, says Kareem Sadek, a partner in consulting practices at KPMG in Canada, specializes in technical risk.
This so-called shadow AI often permeates when users are looking for convenience, speed and intuition, Sadek said.
But these illicit tools are becoming a headache for Canadian businesses, big or small.
“Companies have a hard time ensuring that their intellectual property is maintained and that sensitive information about their business practices, customers and user base is not leaked,” said Robert Falzon, head of engineering at cybersecurity firm Checkpoint Software Technologies Ltd.
What many AI users don't understand is that every time they interact with a chatbot, conversations and data are stored and used to further train those tools, Falzon said.
For example, employees can generate infographics by sharing confidential financial statements or their own research on unauthorized chatbots. On the other hand, outsiders are unaware that when investigating the same subject on a chatbot, they can land on that data and should not be publicly available.
“There is a possibility that AI will dig into resources and training and find that information about the company that talks about the outcome.
And hackers use the same tools just like everyone else, Falson warned.
A July report from IBM and the Ponemon Institute, a US-based cybersecurity research center, found that 20% of companies surveyed had been data breached due to a security incident involving Shadow AI. This is 7% points higher than those who have experienced security incidents that include authorized AI tools.
The average cost of Canadian violations between March 2024 and February 2025 rose 10.4% to $6.98 million from $632 million the previous year, the report said.
According to KPMG's Sadek, governance regarding AI use in the workplace must be established.
“It's not necessarily the technology that will make you fail. It's a lack of governance,” he said.
That could mean establishing AI committees with people across departments like law and marketing, looking at the tools and encouraging adoption on the right guardrail, Sadek said.
GuardRails said it is based on an AI framework consistent with the company's ethics and will help answer difficult questions about security, data integrity and bias.
One example could be to adopt the zero trust idea, Falson said. This means that your company does not trust devices or apps that are not expressly permitted.
The Zero Trust approach reduces risk and limits whether devices can or will not allow employees to submit via chatbots, he explained. For example, Falzon said Checkpoint employees are not allowed to enter research and development data, and the system will limit and notify users of the risk.
“It helps you make sure your customers are educated and understand what risks they take, but even behind that, make sure those risks are alleviated by technology protection,” Falzon said.
Generating awareness is key to smoothing friction between employers and workers about AI tools, experts say.
Sadek said it would be helpful to hold hands-on training sessions and educate employees about the risks of using unauthorized AI tools.
“It will reduce usage significantly or hold users or employees accountable,” he said. “They feel accountable, especially when they are educated and have risk awareness sessions.”
To keep data within internal systems, some companies are beginning to deploy their own chatbots.
Sadek said it's a wise way to tackle fraudulent AI tools.
“It helps (companies) ensure the security and privacy of their corporate data and ensure that it is built within the guardrails they already have within their organization,” he said.
Still, internal tools cannot completely eliminate cybersecurity risks.
Researcher Ali Dehghantanha said it took only 47 minutes to break into the Fortune 500 company's internal chatbot and access sensitive client information during a cybersecurity audit. The company hired him to assess the safety of the internal chatbot and see if the system could be operated to reveal sensitive data.
Dehantanha, professor of cybersecurity and threat intelligence at the University of Guelph and Canada's research chair, said:
He said that major banks, law firms and supply chain companies rely heavily on internal chatbots for advice, email responses and internal communications, but many lack proper security and testing.
He added that companies need to secure budgets when adopting AI technology or deploying their own internal tools.
“When it comes to all technology, not just AI, but also the total cost of ownership,” Dehghantanha said. “Part of that cost of ownership is how we can secure it and protect it.
“At this point, that cost is important,” he said.
Falzon said employers need to provide employees with the tools they need, as businesses can no longer stop their staff from using AI.
At the same time, he said, “they want to make sure that nothing like data leaks or anything like that doesn't happen and that they are not creating greater risk than the benefits they provide.”
