Salary.com Compensation & Pay Equity Law Review

Is AI Sharing Your Trade Secrets?

Newsletter volume 3.21

Licensed and published by JD Supra

May 26, 2025

Editor's Note

Is AI Sharing Your Trade Secrets?

There are some eye-popping stats in this article about employees using free or unauthorized AI at work. I especially loved the 47% of employees who are willing to admit they used AI inappropriately, while 63% says they have observed other employees doing it. Humans are funny. And high five to the 47% who were honest on a survey. That may be the most surprising statistic of all.

But it was the data was being fed to AI systems that has me completely gobsmacked. Yikes. Finance, legal, employee records, and passwords. A kazillion yikes!

Once it's out there, there's no getting it back. And if the AI system has access to it over time through continual use, it's double kazillion yikes because there is so much to be gleaned by someone who knows what they're looking for.

Here's the thing about private or confidential data, there's almost no protections possible if you let it out or give it away, even if it's unauthorized by the employee who did it. Revealing confidential data can also come with significant liability for violating federal or state disclosure and privacy laws, not to mention the damage to the business because the recipe for your secret sauce just hit the internet.

While we know AI hallucinates and much of what it serves up is not trustworthy without analysis and verification, some of us are still pretty good at sussing out what's true and real and valuable. And we don't all have integrity or good intentions.

Employers, get on this. It's a big ducking deal.

- Heather Bussing

Employees using free or unauthorized AI tools at work?

by Laura Lemire, Jeff Liao, and Jim Vana

at Schwabe, Williamson & Wyatt PC

The rise of artificial intelligence has brought both opportunities and challenges to the workplace. However, a growing trend of employees using free or unauthorized AI tools poses significant risks, from security breaches to the loss of trade secrets. Recent reports indicate that some workers are engaging with AI in ways that are not authorized by the employer, highlighting the importance of establishing AI use policies and protocols that will enable responsible and deliberate adoption.

One report by Ivanti revealed:

  • 46% of office workers say some or all the AI tools they use are not provided by their employer.
  • 38% of IT workers are using unauthorized AI tools.
  • 32% of people using generative AI at work are keeping it a secret.

Another recent study out of the Melbourne Business School found that among those who use AI at work:

  • 47% say they have done so in ways that could be considered inappropriate.
  • 63% have seen other employees using AI inappropriately.

What could possibly go wrong?

Finally, in a report aptly named “From Payrolls to Patents,” Harmonic found that 8.5% of prompts into popular generative AI tools included sensitive data. Of those prompts:

  • 46% included customer data, such as billing information and authentication data.
  • 27% included employee data, such as payroll data and employment records.
  • 15% included legal and finance data, such as sales pipeline data, investment portfolio data, and M&A materials.
  • 12% included security policies and reports, access keys, and proprietary source code.

Inappropriate uses of AI in the workplace can result in a wide range of risks, including cybersecurity incidents, threats to national security, and the loss of IP protections.

How can business leaders minimize AI risks and encourage responsible AI adoption in the workplace?

In addition to applying technical solutions to address these risks, business leaders can implement a variety of organizational measures to support the responsible adoption of AI the workplace. Such measures may include, for example:

  • Adopting an AI policy. As a starting point, consider a policy that:
    • Prohibits the download and use of free AI tools without approval,
    • Prohibits sharing confidential, proprietary, and personal information with free AI tools,
    • Limits inputs, prompts, or asks of free AI tools, and
    • Limits the use and distribution of output from free AI tools.
  • Updating existing policies, such as IT, network security, and procurement policies, to account for AI risks.
  • Ensuring contracts for AI tools are reviewed prior to their use. AI developers often require disclosures or other measures in their terms and conditions, which may necessitate changes to users’ privacy statements or terms of use.
  • Developing a data classification strategy. Help employees spot and label confidential, proprietary, and personal information.
  • Training employees on AI risks and best practices.
  • Ongoing monitoring on the use of AI in your workplace. Monitoring may include regular review of contracts for AI tools (which can often change) or testing for accuracy, relevance, and bias in AI outputs.
  • Implementing an incident response plan that covers foreseeable AI scenarios.

Employers should take the initiative and actively communicate with employees about AI risks and acceptable use, adopt clear AI policies, update existing security protocols, and provide employee training. Such actions not only can protect sensitive data, but they can also empower employees to use innovate responsibly. By prioritizing preparedness, organizations can benefit from AI gains—from enhanced productivity to cost savings—while reducing risks.

Subscribe for free: compensation & pay equity law review

Are you concerned about pay gaps in your organization?

CompAnalyst® Pay Equity Suite can help you achieve and sustain pay equity

It's easy to get started

Transform compensation at your organization and get pay right — see how with a personalized demo.
See it in action