Security Insights

Deep dives into Shadow AI, PII protection, and the future of secure LLM adoption.

Latest
5 min readSanitized AI Team

AI Data Loss Prevention: A Practical Guide for Security Teams

A practical guide to AI data loss prevention, including what to monitor, what to block, and how security teams can protect sensitive data at work.

DLPData SecurityAI Governance
Read
6 min readSanitized AI Team

AI in Auditing: Where It Helps and Where It Creates Risk

Explore where AI can improve audit work, from data analysis to planning, and where it creates risks involving evidence, bias, confidentiality, and oversight.

AI GovernanceData SecurityCompliance
6 min readSanitized AI Team

Does ChatGPT Train on Company Data? A Plain-English Guide

Does ChatGPT train on company data? Learn how business and personal accounts differ, what “no training” really means, and what employees should check.

Shadow AIData PrivacyAI Governance
6 min readSanitized AI Team

AI in Accounting: Real Benefits, Real Privacy Risks

Explore the real benefits of AI in accounting and the privacy risks firms need to manage when using client data, financial records, and AI-generated output.

Data PrivacyAI GovernanceCompliance
5 min readSanitized AI Team

AI Data Privacy: What Companies Need to Know Before Employees Use AI Tools

A practical guide to AI data privacy, including what employees should avoid sharing, how to evaluate AI tools, and how to build safer workplace rules.

Data PrivacyAI GovernancePII
5 min readSanitized AI Team

Quebec Law 25 and Generative AI: Where Prompt Data Quietly Creates Liability

Every prompt that carries a client's name, a SIN, or a health detail into a public AI tool is a disclosure of personal information. Under Quebec Law 25, that disclosure can carry consequences most organizations never planned for.

ComplianceData PrivacyAI Governance
6 min readSanitized AI Team

ChatGPT for Law Firms: Useful Tool or Confidentiality Risk?

Learn how law firms can use ChatGPT more safely while protecting client confidentiality, privilege, sensitive documents, and professional obligations.

AI GovernanceComplianceData Privacy
5 min readSanitized AI Team

The AI Controls Investors Now Probe in Technical Diligence

Technical diligence used to stop at your codebase and cloud posture. Now investors ask how your engineers use AI, because an uncontrolled prompt can quietly move your crown-jewel IP outside your control before the deal closes.

Data SecurityAI GovernanceLLM Security
6 min readSanitized AI Team

What Is Shadow AI, and Why Are Security Teams Worried About It?

Learn what shadow AI is, why employees use unapproved AI tools, what risks it creates, and how organizations can respond without simply banning AI.

Shadow AIAI GovernanceData Security
5 min readSanitized AI Team

AI in Patent Prosecution: Keeping Pre-Filing Inventions Out of Public LLMs

Pasting a pre-filing invention into ChatGPT can put the novelty a patent depends on at risk — and it can't be undone. Why bans fail and what a prosecution practice should control instead.

AI GovernanceData PrivacyCompliance
5 min readSanitized AI Team

What IBM's 2025 Breach Data Says About the Real Cost of Shadow AI

IBM's 2025 breach report puts a number on Shadow AI: breaches involving it cost roughly $670K more, and almost no affected organization had controls to stop sensitive data at the point of entry. Here is what that means for the board.

Shadow AICISOData Security
5 min readSanitized AI Team

Shadow AI in Clinical Workflows: The Blind Spot EMR Security Misses

Your EMR is locked down, audited, and access-controlled. But the browser tab beside it isn't. When clinicians and admins paste PHI into public AI tools, patient data leaves through a door your health IT security never watched.

Shadow AIData PrivacyCompliance
5 min readSanitized AI Team

What the CPA Confidentiality Duty Means When Client Data Meets Generative AI

Your professional code binds you to keep client financial information confidential. But the moment a staff accountant pastes a return into a public AI tool, that duty is already in jeopardy.

ComplianceData PrivacyAI Governance
5 min readSanitized AI Team

Let Your Engineers Keep AI Velocity Without Leaking Source Code

The engineers closest to your crown-jewel IP are the ones most likely to paste source code into AI. Here's how to keep their velocity without letting a single prompt weaken your trade-secret position.

Shadow AIData SecurityAI Governance
5 min readSanitized AI Team

Answering the Client AI-Security Questionnaire: What Outside Counsel Needs to Show

Clients now send law firms AI-security questionnaires before handing over sensitive matters. The ones asking how you protect their data in AI tools want evidence, not assurances. Here's what a credible answer looks like.

AI GovernanceComplianceRisk
5 min readSanitized AI Team

What a Partner Owes When an Articling Student Pastes a Client File Into AI

An articling student pastes a client file into ChatGPT to speed up a memo. The partner signs the work and carries the risk. Here is what supervisory duty actually requires when juniors use AI.

AI GovernanceRiskCompliance
5 min readSanitized AI Team

What the Duty of Technological Competence Now Requires When Your Firm Uses ChatGPT

Law societies expect lawyers to understand the technology they use. When an articling student pastes a client's file into ChatGPT, that duty is no longer abstract — it's a disclosure you can't recall.

AI GovernanceComplianceData Privacy
5 min readSanitized AI Team

Why Banning ChatGPT Doesn't Work, and What Actually Reduces Shadow AI Risk

Blocking ChatGPT at the firewall feels decisive, but it just pushes AI use onto personal phones and accounts you can't see. Here's why bans backfire and what reduces Shadow AI risk instead.

Shadow AIAI GovernanceCISO
5 min readSanitized AI Team

Keeping PHI Out of LLM Prompts Under PHIPA and Bill C-27

Clinicians and researchers paste patient details into AI tools to save time, but PHI submitted to a public model can't be recalled. Here's how to keep it from leaving in the first place.

Data PrivacyCompliancePII
5 min readSanitized AI Team

Keeping Client Tax Returns Out of ChatGPT During Busy Season

During busy season, an overloaded associate pastes a client's return into ChatGPT to summarize it faster. The client's SIN and income just left your firm's control, and it can't be recalled.

Data PrivacyShadow AICompliance
5 min readSanitized AI Team

Your Valuation Is Your IP, and It Can Leave One Paste at a Time

For deep-tech and biotech companies, the balance sheet is the technology. When an engineer pastes source code or a draft claim into a public AI tool, the value backing your next round can quietly walk out the door.

Data SecurityAI GovernanceRisk
5 min readSanitized AI Team

How One Careless AI Prompt Can Waive Privilege

A single prompt pasted into a public AI tool can strip privilege or break confidentiality on a client's matter. Early court rulings show the disclosure is voluntary — and irreversible. Here's how firms are closing the gap.

AI GovernanceComplianceRisk
5 min readSanitized AI Team

How to Get Visibility Into Shadow AI Without Banning Every Tool

You can't govern what you can't see, and most organizations have no visibility into nearly 90% of their AI usage. Here's how to get that visibility without driving employees to personal accounts.

Shadow AIAI GovernanceCISO
4 min readSanitized AI Team

Your DLP Can't See the Prompt Box

Your DLP stack watches files, email, and downloads. The most revealing data in your company now leaves through a text box those controls were never built to read.

DLPData SecurityAI Governance
1 min readSanitized AI Team

Sanitized AI is Officially Live on Chrome and Edge

Sanitized AI is now available on the Chrome Web Store and Microsoft Edge Add-ons store. Get real-time visibility into what your employees are sharing with AI platforms.

AnnouncementProductSecurity
2 min readSanitized AI Team

Canada Just Told OpenAI Its Training Data Practices Broke Privacy Law. Here's What That Means for Every Organization Using AI.

Canada's privacy regulators found OpenAI's original ChatGPT training practices violated privacy laws. Learn why this finding matters for your organization and how to address the hidden risks of employee AI usage.

PrivacyComplianceAI Governance
2 min readSanitized AI Team

Why Your AI Acceptable Use Policy Probably Isn't Working

Most organizations rolled out an AI acceptable use policy sometime in the last 18 months. Most of them aren't working, and the reason isn't what people think.

SecurityGovernancePolicy
2 min readSanitized AI Team

The Opt-Out Illusion: Why Turning Off AI Training Doesn't Make Your Data Safe

Turning off AI training doesn't mean your data is safe. Understand why 'don't train on our data' is a narrow promise, and why you need upstream controls to prevent data leaks.

SecurityPrivacyCompliance
2 min readSanitized AI Team

US Cyber Defense Chief Falls Victim to Shadow AI

Even top cyber officials are not immune. Learn how a simple mistake led to a government data spill and how to protect your organization.

SecurityShadow AINews
3 min readSanitized AI Team

Shadow AI in 2026: The Insider Threat Draining Your Enterprise Data

75% of employees now use unauthorized AI tools, and 57% admit to inputting sensitive data. Discover the real cost of Shadow AI and how to prevent PII leakage before it breaches your organization.

Shadow AIPII LeakageData Security
1 min readSanitized AI Team

The Hidden Dangers of Shadow AI: How PII Leaks Through LLMs

Employees are using AI tools without approval. Here is how that leads to massive PII leakage and what you can do about it.

SecurityShadow AIcompliance