By Danielle Barbour
Organizations face an unprecedented security dilemma as they rush to harness the transformative potential of artificial intelligence (AI). According to the Kiteworks AI Data Security and Compliance Risk Report, a staggering 83% of companies surveyed operate without basic technical controls to prevent employees from uploading sensitive data to AI tools. These organizations rely on training sessions, warning emails, or nothing at all to prevent data exposure to AI tools. This means that only 17% can automatically stop employees from uploading confidential data to public AI tools. Meanwhile, employees routinely paste customer records, financial data, and trade secrets into ChatGPT and similar AI services – often from personal devices the company can’t even see.
The persistence of AI-generated data creates particularly insidious risks. Once confidential information enters an AI model, organizations lose effective control over its storage, use, and potential retrieval. This data might resurface in responses to other users’ queries or become permanently incorporated into the model’s training data.
Something needs to change.
The emergence of ‘private’ AI environments, such as custom GPTs in ChatGPT or private instances in Gemini, represents a halfway solution that many organizations are exploring but a surer solution is a private data network (PDN). This can address the fundamental challenges associated with GenAI use by creating a secure, governed channel for AI interactions while maintaining complete organizational control.
Rather than sending data to external AI platforms – even private ones – a PDN acts as an intelligent intermediary that enforces governance policies on every AI-data interaction. It provides end-to-end encryption for data both at rest and in transit, implementing the secure infrastructure requirements necessary for private AI deployment, including network segmentation, encrypted storage, and zero-trust architectures.
The platform automatically scans and classifies data before any AI interaction takes place.
A PDN also provides the comprehensive audit trails required by frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001. It maintains continuous monitoring capabilities that can identify unauthorised data sharing, detect potential breaches, and ensure compliance with established policies.
By unifying these controls through a centralised governance framework, organizations can finally achieve what only 17% currently have: comprehensive data protection policies and controls for AI applications. This transforms AI from an uncontrolled risk into a governed business capability, allowing organizations to innovate confidently while meeting their security and compliance obligations.
The author
Danielle Barbour is Senior Director of Product Marketing ‑ Compliance, Kiteworks






