Models & LabsUnited States
Why staff using ChatGPT, Claude and Gemini for work could create problems for employers

Cyber security experts have urged companies to be vigilant against the risks posed by employees using outside AI applications including Claude, ChatGPT and Gemini in the workplace.
The practice, known as using shadow AI, can lead to important data being leaked and, in some cases, malware and viruses being uploaded into companies' internal systems.
Firms are urged to ensure they are aware of what AI tools are being used by employees when it comes to sensitive company information, as it could lead to problems with customer information and intellectual property.
Pasting documents into an outside AI application, or even asking it to tidy up an email, means that sensitive information is being sent to a cloud tool outside the company. If the person's personal accounts are hacked, their company's data could end up in the wrong hands.
“Staff might see the benefits of completing work faster, but employers are likely to have no record of the systems they were using or the information those systems received,” said Vladislav Tushkanov, research and development group manager at the cyber security company Kaspersky. “You cannot send personally identifiable information in the cloud.”
This means employees will need to be educated on the need to ensure that only internal AI systems are used to process information, added Mr Tushkanov, who spoke to The National at the Ai Everything summit taking place this week in Abu Dhabi.
The rapid advancements in AI mean it is crucial that companies take a fresh look at business workflows and ensure security is built in from the start, said another expert, Premchand Kurup, chief executive of the cyber security firm ParamountAssure.
“Companies should first identify unapproved AI use that could expose customer information or intellectual property through external tools, then establish approved alternatives and clear access limits,” Mr Kurup said.
The scale of the risks companies face from data breaches was laid out in IBM’s 2026 Middle East Cost of a Data Breach Report, which found 26 per cent of malicious breaches were AI-enabled. The average breach cost in the region was $8 million. The research included organisations in the UAE and Saudi Arabia.
Monitoring the AI agents
Another challenge firms will face is keeping a closer eye on AI agents that play a more advanced role as technology improves. Agentic AI is likely to carry out more tasks with less human supervision, raising questions of who is accountable when something goes wrong.
“We can't put AI agents in jail, so ultimately it will always have to be a human [who is accountable],” said Costi Perricos, Deloitte’s global generative AI leader.
Businesses need to manage agents as a digital workforce, with performance checks and decisions about how much responsibility each system is given, said Mr Perricos.
Their behaviour could change over time as they pursue their goals, he said. Companies need to track what agents are doing, establish when they are ready for use and know when to switch them off.
An example of how quickly AI capability is increasing is provided by the UAE government, which has set a target to introduce agentic AI across 50 per cent of federal sectors and operations within two years, under a framework announced in April.
Companies should set access limits and require AI-assisted security investigations to draw on verified internal records, said Mr Kurup. He added that analysts need evidence they can check before approving sensitive actions.
“The same discipline should guide wider AI adoption, with employees trained to challenge outputs and records kept for review,” he said.
Ahmed Hafez, director of solution engineering for the Middle East, Turkey and Africa at the data company Snowflake, said businesses need trusted information and controls over what AI agents can access.
“Extensive testing in controlled environments, with governance and security built in from the ground up, becomes increasingly important as these systems take on more complex work,” he said.