Security Insights

Deep dives into Shadow AI, PII protection, and the future of secure LLM adoption.

Latest
5 min readSanitized AI Team

What a Partner Owes When an Articling Student Pastes a Client File Into AI

An articling student pastes a client file into ChatGPT to speed up a memo. The partner signs the work and carries the risk. Here is what supervisory duty actually requires when juniors use AI.

AI GovernanceRiskCompliance
Read
5 min readSanitized AI Team

What the Duty of Technological Competence Now Requires When Your Firm Uses ChatGPT

Law societies expect lawyers to understand the technology they use. When an articling student pastes a client's file into ChatGPT, that duty is no longer abstract — it's a disclosure you can't recall.

AI GovernanceComplianceData Privacy
5 min readSanitized AI Team

Why Banning ChatGPT Doesn't Work, and What Actually Reduces Shadow AI Risk

Blocking ChatGPT at the firewall feels decisive, but it just pushes AI use onto personal phones and accounts you can't see. Here's why bans backfire and what reduces Shadow AI risk instead.

Shadow AIAI GovernanceCISO
5 min readSanitized AI Team

Keeping PHI Out of LLM Prompts Under PHIPA and Bill C-27

Clinicians and researchers paste patient details into AI tools to save time, but PHI submitted to a public model can't be recalled. Here's how to keep it from leaving in the first place.

Data PrivacyCompliancePII
5 min readSanitized AI Team

Keeping Client Tax Returns Out of ChatGPT During Busy Season

During busy season, an overloaded associate pastes a client's return into ChatGPT to summarize it faster. The client's SIN and income just left your firm's control, and it can't be recalled.

Data PrivacyShadow AICompliance
5 min readSanitized AI Team

Your Valuation Is Your IP, and It Can Leave One Paste at a Time

For deep-tech and biotech companies, the balance sheet is the technology. When an engineer pastes source code or a draft claim into a public AI tool, the value backing your next round can quietly walk out the door.

Data SecurityAI GovernanceRisk
5 min readSanitized AI Team

How One Careless AI Prompt Can Waive Privilege

A single prompt pasted into a public AI tool can strip privilege or break confidentiality on a client's matter. Early court rulings show the disclosure is voluntary — and irreversible. Here's how firms are closing the gap.

AI GovernanceComplianceRisk
5 min readSanitized AI Team

How to Get Visibility Into Shadow AI Without Banning Every Tool

You can't govern what you can't see, and most organizations have no visibility into nearly 90% of their AI usage. Here's how to get that visibility without driving employees to personal accounts.

Shadow AIAI GovernanceCISO
4 min readSanitized AI Team

Your DLP Can't See the Prompt Box

Your DLP stack watches files, email, and downloads. The most revealing data in your company now leaves through a text box those controls were never built to read.

DLPData SecurityAI Governance
1 min readSanitized AI Team

Sanitized AI is Officially Live on Chrome and Edge

Sanitized AI is now available on the Chrome Web Store and Microsoft Edge Add-ons store. Get real-time visibility into what your employees are sharing with AI platforms.

AnnouncementProductSecurity
2 min readSanitized AI Team

Canada Just Told OpenAI Its Training Data Practices Broke Privacy Law. Here's What That Means for Every Organization Using AI.

Canada's privacy regulators found OpenAI's original ChatGPT training practices violated privacy laws. Learn why this finding matters for your organization and how to address the hidden risks of employee AI usage.

PrivacyComplianceAI Governance
2 min readSanitized AI Team

Why Your AI Acceptable Use Policy Probably Isn't Working

Most organizations rolled out an AI acceptable use policy sometime in the last 18 months. Most of them aren't working, and the reason isn't what people think.

SecurityGovernancePolicy
2 min readSanitized AI Team

The Opt-Out Illusion: Why Turning Off AI Training Doesn't Make Your Data Safe

Turning off AI training doesn't mean your data is safe. Understand why 'don't train on our data' is a narrow promise, and why you need upstream controls to prevent data leaks.

SecurityPrivacyCompliance
2 min readSanitized AI Team

US Cyber Defense Chief Falls Victim to Shadow AI

Even top cyber officials are not immune. Learn how a simple mistake led to a government data spill and how to protect your organization.

SecurityShadow AINews
3 min readSanitized AI Team

Shadow AI in 2026: The Insider Threat Draining Your Enterprise Data

75% of employees now use unauthorized AI tools, and 57% admit to inputting sensitive data. Discover the real cost of Shadow AI and how to prevent PII leakage before it breaches your organization.

Shadow AIPII LeakageData Security
1 min readSanitized AI Team

The Hidden Dangers of Shadow AI: How PII Leaks Through LLMs

Employees are using AI tools without approval. Here is how that leads to massive PII leakage and what you can do about it.

SecurityShadow AIcompliance