AI is blurring the lines between software, services, and corporate data even more.
Silicon Valley law giant Cooley recently announced a partnership with startup to launch Cooley GO Lab, an AI-powered online portal designed for s on Cooley’s vast repository of startup knowledge.
We’ve hit a fascinating milestone in tech and AI: a premium services firm productizing its expertise into software, targeted at startups and founders who may not be able to afford a full-scale engagement with a premier law firm.
But for security leaders — and tech founders — the headline hidden inside this announcement is a massive flashing red light.
According to reporting from BusinessInsider, Cooley explicitly warns that this AI tool is not protected b y attorney-client privilege. Founders must be incredibly careful about what they upload, because those materials are entirely discoverable and could be turned over in future litigation.
If a highly secure, firm-sanctioned legal portal built by Big Law doesn’t protect your data under privilege, what do you think is happening when employees paste corporate data into free, consumer-facing browser AI tools?
The Reality of "Shadow AI" in the Workplace
Cooley’s move highlights a massive macroeconomic shift: services firms and enterprise software vendors alike are rapidly leaning into AI to scale their delivery and add value. But this creates a distinct, highly sophisticated security challenge for the enterprise.
When a vendor adds a new AI feature or an online portal to an existing service, it rarely triggers a standard IT procurement or vendor risk assessment loop. Because it isn’t a brand-new application being explicitly purchased by the enterprise, it completely escapes security review. It is treated as an incremental feature update, flying entirely under the radar of traditional security architectures.
The danger of this "bolted-on" AI model is that it leaves organizations entirely blind to how corporate data is being processed, stored, or shared. It shifts the corporate attack surface directly into the browser session, introducing massive data governance gaps through trusted, legacy relationships.
And as these AI surfaces proliferate, employees aren’t waiting for corporate IT departments to vet or provision them. They are outrunning the rules. Neon Cyber just published findings from a survey assessing the behaviors of U.S. knowledge workers. The data reveals that the "unprivileged paste" into these unvetted surfaces isn't a rare mishap — it is an hourly corporate habit:
The Regulatory Reality: The Paste Is the Breach
When that data enters a prompt field in the browser — whether it's a consumer chatbot or a newly added AI chat inside a previously approved application — what happens with that data is unclear. By leveraging unvetted AI tools to move faster, employees are inadvertently leaking data that could be used to train public models, exposed in a breach, or turned over in future litigation — completely stripped of corporate protections and legal privilege.
For those organizations operating under modern privacy frameworks, that exposure doesn't require a network breach to be catastrophic. Regulatory bodies like the FTC, state Attorneys General, and European data protection authorities increasingly treat the unauthorized transfer of customer or employee data to unvetted AI models as a reportable exposure event.
Under frameworks like Europe's GDPR, the newly rolled-out enforcement layers of the EU AI Act, and U.S. state privacy laws, a data breach doesn't require a malicious hacker. Regulatory bodies view the unauthorized transfer of personal, health, or financial data to an unvetted third-party AI vendor as an immediate data exposure event.
In short: the moment the employee clicks "enter" in an unapproved AI tool with sensitive data, the compliance violation has already occurred.
Policy is Not the Problem. Enforcement Is.
Most companies have policies in place to prevent the use of unauthorized AI tools. Enterprises are building these into annual security training for employees.
But our research proves that this does not work: 63.0% of employees state they have a clear AI policy at work that they fully understand. Yet, 48.3%of those exact same policy-aware workers admit to knowingly breaching the policy anyway because they need to get their work done.
It’s clear that the problem isn't a lack of awareness; it's a lack of enforcement at the point of action. Legacy security stacks, relying on traditional DLP or network firewalls, were not built to see what happens inside a browser prompt field.
How Prepared Organizations Respond
As professional service firms like law practices deploy specialized AI tools, enterprise risk will only multiply. To protect corporate data without killing workforce productivity, security leaders must shift their control point to the browser.
- Gain Complete Surface Visibility: You cannot protect what you cannot see. Organizations need to monitor all AI and SaaS tools running inside the browser—not just the ones explicitly sanctioned.
- Enforce Controls in Real-Time: Security must intervene at the exact moment of risk—blocking the paste of sensitive data or credentials into unapproved surfaces before the data leaves the endpoint.
- Quantify Your Real Exposure: Move from guessing to knowing by auditing real-world user behavior against compliance and legal benchmarks.
Review Your AI Risk Exposure Today
Is your workforce exposing corporate data to discoverable, unprivileged AI surfaces?
Download the full Quantifying Shadow AI Risk Report to see the hard numbers on workforce behavior, or take our AI Exposure Assessment to map your organization's shadow AI risk today.
FAQs
Q: Does attorney-client privilege protect data uploaded to AI-powered legal tools?
A: Not necessarily. As highlighted by Cooley's own warnings about Cooley GOLab, even firm-sanctioned AI portals built by top-tier law firms may not extend attorney-client privilege to uploaded materials. Any documents submitted to these tools could be discoverable in future litigation, regardless of the firm's reputation or the sophistication of the platform.
Q: What types of corporate data are employees most commonly pasting into AI tools?
A: Knowledge workers frequently paste internal communications, contracts, financial data, customer records, and HR materials into browser-based AI tools— often without realizing these inputs may be stored, used for model training, or exposed in a breach. The sensitive nature of this data makes each paste a potential compliance event under frameworks like GDPR, HIPAA, or state-level privacy laws.
Q: How is Shadow AI different from traditional shadow IT?
A: Traditional shadow IT involved employees installing unapproved software or using unauthorized devices. Shadow AI is harder to detect because it operates entirely within the browser — often inside already-approved applications that have quietly added AI features. There's no new application to flag, no procurement trigger, and no network anomaly to catch. The risk surface is invisible to legacy security tools.
Q: What regulations apply when an employee pastes sensitive data into an unapproved AI tool?
A: Depending on the data type and jurisdiction, several frameworks may apply —including GDPR, the EU AI Act, CCPA, HIPAA, and a growing body of U.S. state privacy laws. Regulators increasingly treat the unauthorized transfer of personal, financial, or health data to an unvetted third-party AI vendor as are portable exposure event, even without a network breach or malicious actor involved.
Q:What's the difference between an AI acceptable use policy and browser-level enforcement?
A: An AI acceptable use policy defines what employees are permitted to do — but it relies entirely on voluntary compliance. Browser-level enforcement intercepts risk at the moment of action, blocking sensitive data from being pasted or uploaded into unapproved AI tools. Given that nearly half of policy-aware employees admit to knowingly violating their company's AI policy, enforcement at the point of click is the only reliable control.