Your employee just pasted the client contract into ChatGPT. Now what?
Key takeaways
- In 2025, 34.8% of the corporate data employees paste into AI tools is classified as sensitive, up from 10.7% two years earlier (Cyberhaven).
- Network DLP and firewalls cannot see prompt content: traffic to ChatGPT is encrypted and the leak leaves no trace.
- Every prompt with real data can be a transfer to a third-party data processor without a DPA, a concrete risk under the GDPR.
- Effective defense acts in the browser, before sending: it intercepts and masks sensitive data with local, on-device analysis.
The short answer: that contract has already left the corporate perimeter, and no system flagged it. According to Cyberhaven's 2025 AI Adoption and Risk Report, 34.8% of the corporate data employees paste into AI tools is classified as sensitive, more than triple the 10.7% of two years earlier. It does not vary by industry or company size. It happens everywhere, every day.
It is not an attack. It is an ordinary morning.
The problem is not ChatGPT. The problem is that you probably do not know it is happening.
Do you know? Probably not.
No security system generated an alert. No log recorded the event. No ticket was opened. And yet, right now, as you read this, one of your employees is using an AI tool with data that should never have left the company.
You cannot know because no tool available today is positioned at the right moment: between the click that opens the chat window and the Enter key. Traffic to ChatGPT is encrypted. Perimeter DLP cannot see the content. The firewall only knows that a connection was made to openai.com.
By the time you find out, it will already have happened.
Three moments. Every day.
No hypothetical scenarios needed. These happen every day in companies of every size, in a perfectly natural way:
The lawyer who wants to improve a text
Copies the clauses from a newly received NDA, pastes them into ChatGPT, and asks for a cleaner, more concise version. The contract includes the client's name, financial terms, and references to confidentiality clauses. All of this is now on OpenAI's servers.
The analyst who needs to deliver a report
In a hurry. Copies the client's quarterly financial table and asks Gemini to summarize it in three bullet points. The document includes projections, margins, and counterparty names. It did not occur to them that this was a problem.
The HR manager writing a difficult letter
Needs to draft a termination notice. Uses Claude as a writing assistant and includes the employee's name, role, start date, and reason for termination. The letter comes out well. The employee's data has left the corporate perimeter.
In none of these cases is there malicious intent. There is only a path of least resistance and no moment in which anyone or anything said: wait.
The paradox you already know
You could block access to AI services at the corporate perimeter. Some organizations do. The result is predictable: employees use their phones, their home network, a personal VPN. The problem does not disappear, it just becomes invisible.
You could do nothing. But every prompt sent with real data is a potential transfer to a third-party data processor without a Data Processing Agreement. Under the GDPR, this is not a theoretical risk.
The numbers show the cost. According to the IBM Cost of a Data Breach Report 2025, shadow AI (the use of unapproved AI tools) adds an average of USD 670,000 to the cost of a breach, and one in five organizations has already suffered a breach linked to these tools. In 97% of cases, proper AI access controls were missing.
You could write a policy. Many companies already have. Policies get read during onboarding and forgotten the next day, in the rush to deliver a presentation by 6 pm.
There is no policy that works in the moment when someone is under pressure and needs a fast answer.
The way out
Control needs to move to where it matters: in the browser, before the prompt is sent. Not upstream in the network. Not in post-hoc logs. Exactly there, at that moment.
That is what Talmur does. It does not block access to AI tools. It does not surveil employees. It positions itself at the only useful instant and analyzes the text locally, on the device, without transmitting anything to external servers. If it finds sensitive data, it replaces it with a neutral placeholder and explains to the employee what it found and why.
It is not a punishment. It is a learning moment. The version of the prompt that reaches ChatGPT contains nothing that should not have left the company. The organization keeps control. The employee understands. No one is blocked from doing their work.
Protect AI usage in your organization.
See how Talmur masks sensitive data before it leaves the browser.
Book a Demo