No items found.
  • Platform
  • Pricing
  • About
  • Resource Hub
  • News
  • Blog
  • Help
  • Login
  • Book Now

Solutions

Explore everything you need to protect your workforce.

Ai security

Shadow SaaS
Data Leakage
Real-Time User Guidance
Phishing Protection

Browser security

Browser Observability
Authentication Governance
Back to Blog
Security

When Big Law Can't Protect Your Data, What Chance Does Your AI Policy Have?

Shadow AI — the use of unsanctioned AI tools in the browser — is now a routine data governance risk. A 2025 Neon Cyber survey of 227 knowledge workers found that 68.7% admitted to pasting sensitive corporate data into AI tools in the last three months, often in breach of their own company's AI policy.

Mary Yang
Published on: 
Jun 29, 2026
On This Page
TOC Element
Share:

AI is blurring the lines between software, services, and corporate data even more.

Silicon Valley law giant Cooley recently announced a partnership with startup to launch Cooley GO Lab, an AI-powered online portal designed for s on Cooley’s vast repository of startup knowledge.

We’ve hit a fascinating milestone in tech and AI: a premium services firm productizing its expertise into software, targeted at startups and founders who may not be able to afford a full-scale engagement with a premier law firm.

But for security leaders — and tech founders — the headline hidden inside this announcement is a massive flashing red light.

According to reporting from BusinessInsider, Cooley explicitly warns that this AI tool is not protected b y attorney-client privilege. Founders must be incredibly careful about what they upload, because those materials are entirely discoverable and could be turned over in future litigation.

If a highly secure, firm-sanctioned legal portal built by Big Law doesn’t protect your data under privilege, what do you think is happening when employees paste corporate data into free, consumer-facing browser AI tools?

The Reality of "Shadow AI" in the Workplace

Cooley’s move highlights a massive macroeconomic shift: services firms and enterprise software vendors alike are rapidly leaning into AI to scale their delivery and add value. But this creates a distinct, highly sophisticated security challenge for the enterprise.

When a vendor adds a new AI feature or an online portal to an existing service, it rarely triggers a standard IT procurement or vendor risk assessment loop. Because it isn’t a brand-new application being explicitly purchased by the enterprise, it completely escapes security review. It is treated as an incremental feature update, flying entirely under the radar of traditional security architectures.

The danger of this "bolted-on" AI model is that it leaves organizations entirely blind to how corporate data is being processed, stored, or shared. It shifts the corporate attack surface directly into the browser session, introducing massive data governance gaps through trusted, legacy relationships.

And as these AI surfaces proliferate, employees aren’t waiting for corporate IT departments to vet or provision them. They are outrunning the rules. Neon Cyber just published findings from a survey assessing the behaviors of U.S. knowledge workers. The data reveals that the "unprivileged paste" into these unvetted surfaces isn't a rare mishap — it is an hourly corporate habit:

  • The Browser is the Workplace: 93.4% of knowledge workers do their work primarily through the browser, making it the primary vector where corporate data moves.
  • AI is Already Entrenched in Daily Work: 70.9% use AI tools daily or more often.
  • Enterprise Data is Leaking: A staggering 68.7% of workers admit to pasting internal, sensitive, or regulated corporate data into AI tools within the last three months alone.

The Regulatory Reality: The Paste Is the Breach

When that data enters a prompt field in the browser — whether it's a consumer chatbot or a newly added AI chat inside a previously approved application — what happens with that data is unclear. By leveraging unvetted AI tools to move faster, employees are inadvertently leaking data that could be used to train public models, exposed in a breach, or turned over in future litigation — completely stripped of corporate protections and legal privilege.

For those organizations operating under modern privacy frameworks, that exposure doesn't require a network breach to be catastrophic. Regulatory bodies like the FTC, state Attorneys General, and European data protection authorities increasingly treat the unauthorized transfer of customer or employee data to unvetted AI models as a reportable exposure event.

Under frameworks like Europe's GDPR, the newly rolled-out enforcement layers of the EU AI Act, and U.S. state privacy laws, a data breach doesn't require a malicious hacker. Regulatory bodies view the unauthorized transfer of personal, health, or financial data to an unvetted third-party AI vendor as an immediate data exposure event.

In short: the moment the employee clicks "enter" in an unapproved AI tool with sensitive data, the compliance violation has already occurred.

Policy is Not the Problem. Enforcement Is.

Most companies have policies in place to prevent the use of unauthorized AI tools. Enterprises are building these into annual security training for employees.

But our research proves that this does not work: 63.0% of employees state they have a clear AI policy at work that they fully understand. Yet, 48.3%of those exact same policy-aware workers admit to knowingly breaching the policy anyway because they need to get their work done.

It’s clear that the problem isn't a lack of awareness; it's a lack of enforcement at the point of action. Legacy security stacks, relying on traditional DLP or network firewalls, were not built to see what happens inside a browser prompt field.

How Prepared Organizations Respond

As professional service firms like law practices deploy specialized AI tools, enterprise risk will only multiply. To protect corporate data without killing workforce productivity, security leaders must shift their control point to the browser.

  1. Gain Complete Surface Visibility: You cannot protect what you cannot see. Organizations need to monitor all AI and SaaS tools running inside the browser—not just the ones explicitly sanctioned.
  2. Enforce Controls in Real-Time: Security must intervene at the exact moment of risk—blocking the paste of sensitive data or credentials into unapproved surfaces before the data leaves the endpoint.
  3. Quantify Your Real Exposure: Move from guessing to knowing by auditing real-world user behavior against compliance and legal benchmarks.

Review Your AI Risk Exposure Today

Is your workforce exposing corporate data to discoverable, unprivileged AI surfaces?

Download the full Quantifying Shadow AI Risk Report to see the hard numbers on workforce behavior, or take our AI Exposure Assessment to map your organization's shadow AI risk today.

‍

‍

FAQs

Q: Does attorney-client privilege protect data uploaded to AI-powered legal tools?

‍A: Not necessarily. As highlighted by Cooley's own warnings about Cooley GOLab, even firm-sanctioned AI portals built by top-tier law firms may not extend attorney-client privilege to uploaded materials. Any documents submitted to these tools could be discoverable in future litigation, regardless of the firm's reputation or the sophistication of the platform.

Q: What types of corporate data are employees most commonly pasting into AI tools?

‍A: Knowledge workers frequently paste internal communications, contracts, financial data, customer records, and HR materials into browser-based AI tools— often without realizing these inputs may be stored, used for model training, or exposed in a breach. The sensitive nature of this data makes each paste a potential compliance event under frameworks like GDPR, HIPAA, or state-level privacy laws.

Q: How is Shadow AI different from traditional shadow IT?‍

A: Traditional shadow IT involved employees installing unapproved software or using unauthorized devices. Shadow AI is harder to detect because it operates entirely within the browser — often inside already-approved applications that have quietly added AI features. There's no new application to flag, no procurement trigger, and no network anomaly to catch. The risk surface is invisible to legacy security tools.

Q: What regulations apply when an employee pastes sensitive data into an unapproved AI tool?

‍A: Depending on the data type and jurisdiction, several frameworks may apply —including GDPR, the EU AI Act, CCPA, HIPAA, and a growing body of U.S. state privacy laws. Regulators increasingly treat the unauthorized transfer of personal, financial, or health data to an unvetted third-party AI vendor as are portable exposure event, even without a network breach or malicious actor involved.

Q:What's the difference between an AI acceptable use policy and browser-level enforcement?

A: An AI acceptable use policy defines what employees are permitted to do — but it relies entirely on voluntary compliance. Browser-level enforcement intercepts risk at the moment of action, blocking sensitive data from being pasted or uploaded into unapproved AI tools. Given that nearly half of policy-aware employees admit to knowingly violating their company's AI policy, enforcement at the point of click is the only reliable control.

 

Protect the people that power your business

Subscribe to the Neon Glow-Up

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Follow Us

Company

Platform
About us
News
Blog

Platform

Browser Observability for SecOps & GRC
AI & Shadow SaaS Visibility and Control
AI Data Leakage & Insider Risk
AI Guardrails & Real-time User Guidance
AI-Powered Phishing & Social Engineering Defense
Authentication & Identity Hygiene
© {{year}} Copyright. All Rights Reserved.
Privacy Policy
Terms and Conditions