Home
Blog
MSP Tips

Our Daily Habits: The Weak Link in Cybersecurity in the Age of AI

Elvira ZaltaneSeptember 29, 2026

Data from Cert.lv shows that cybersecurity threats in Latvia remain high. In the second quarter of this year, the number of processed cyber incidents and compromised devices significantly exceeded the average levels for 2022–2024. Today, the greatest cybersecurity risk is no longer just external hacker attacks, but rather the daily decisions made by employees - such as pasting company data into a public artificial intelligence (AI) tool, connecting an unapproved app, or using a personal account for work purposes.

At first glance, situations that can create significant risks seem completely ordinary and can be found in almost any organization: A marketing specialist rushes to prepare a client report, opens a free AI tool, and pastes the client's data. An HR manager uses AI to quickly draft an employment contract or an employee performance summary, uploading a document containing personal data into the tool, or a project manager asks AI to summarize meeting minutes, failing to notice that they contain confidential information about company plans, clients, or financial metrics.

Without Hacking, Just by Copying Text

Traditionally, cybersecurity has focused on malicious code, phishing emails, and system breach attempts. However, with the rapid spread of AI tools, their uncontrolled use has introduced equally significant risks.

According to the IBM Cost of a Data Breach Report 2026 -in which the research organization Ponemon Institute analyzed 602 organizations across 17 industries - the proportion of security incidents related to unauthorized AI tool usage reached 43%, more than doubling compared to 20% in 2025.

Employees often use generative AI out of a desire to be more productive - writing client emails, summarizing meeting notes, or analyzing sales data. The problem begins the moment these texts include confidential client data.

A study by LayerX on data security for AI and SaaS solutions in enterprises reveals that: 77% of employees copy data into AI queries, 82% do so using personal accounts, 34% have shared client data (first and last names), 31% have shared financial or other confidential documents with public AI tools.

As a result, data slips outside the organization's control. Furthermore, many free AI service providers retain entered information and may use it to train their models. This means client data could theoretically appear in the AI responses generated for another company.

The Risk Goes Beyond External, Unapproved Tools

Even if an organization bans external AI tools, many officially approved SaaS solutions - such as Microsoft 365 Copilot, Slack AI, Salesforce Einstein, and Google Workspace AI - have built-in generative AI features that bring their own risks.

These features can read data from multiple sources in a single query, even if the user would not normally have access to all of that data. Moreover, AI-generated content (emails, documents, and records) is often not automatically classified as confidential, creating an additional security layer risk.

Another aspect is process automation using AI agents, which can automatically create CRM records, send emails to clients, or update documents without human approval. This means the risk does not lie solely in external, unapproved tools, but also inside the official ecosystem approved by the IT department. According to a 2026 study by the Cloud Security Alliance, 89% of enterprise AI usage remains invisible to security teams.

Why Do Employees Do It?

Employees turn to unauthorized AI tools for several reasons. In today's workplace, employees are expected to work more and faster, and AI promises to help them achieve these goals -writing text, summarizing data, building presentations, and more.

In many companies, purchasing and implementing official AI tools takes months, whereas an employee can sign up for a free ChatGPT account in two minutes. Additionally, many employees simply don't see the harm, thinking, "It's just text" or "I'm not giving them passwords." They fail to realize that text can contain confidential information, a client's name, a project title, or financial figures.

The 2026 Voice of the CISO report by Proofpoint indicates that 79% of surveyed Chief Information Security Officers (CISOs) view the human factor as the single greatest source of vulnerability for organizational cybersecurity. This proves that technological security solutions alone are not enough - employee awareness, habits, and organizational security culture are just as critical.

Practical Steps to Take Today

We cannot stop the wave of AI, as these solutions are already embedded in our emails, documents, and meetings. However, we can choose how to use them responsibly. To mitigate these risks, cybersecurity experts and industry associations recommend three practical steps:

  1. Establish a clear and understandable AI usage policy: This shouldn't ban everything, but rather precisely define which tools are approved, what data must never be entered into AI, and what the consequences are for breaking the rules.
  2. Provide secure alternatives: Give employees official AI tools backed by contractual data protection guarantees, accompanied by regular training on how to use them safely.
  3. Implement technical solutions: Deploy tools that monitor data flows to external AI services and alert employees if they attempt to input confidential information.

The most important shift is cultural: rather than punishing mistakes, organizations must foster an environment where employees understand the risks and feel comfortable asking questions about proper AI usage.

This tex is a translated text from an opinion piece published in Dienas Bizness news outlet, original text is accessible in Latvian here: Mūsu ikdienas paradumi - kiberdrošības vājais posms MI laikmetā