Every employee carries a piece of what your company knows. AI tools make it easier than ever to copy that knowledge somewhere you can’t see — a little at a time, or all at once on the way out the door.
A joint educational white paper by NetApp® and Iterate.ai.
In March 2025, the payroll platform Rippling filed suit alleging that an employee at competitor Deel — hired into a global payroll compliance role with ordinary access to Slack, Salesforce, and Google Drive — used that access to pull customer lists, pricing details, and competitive intelligence out of the company. No password was cracked. No firewall was breached. The access was already there, granted on day one, and the activity blended into a normal workday for four months before anyone noticed.
Call this the burst pipe: a short, predictable window where a career’s worth of institutional knowledge can leave through channels no security tool is watching, because the person leaving already had permission to be there. It’s the dramatic half of this problem. The other half never makes the news.
Most institutional knowledge doesn’t leave in a burst. It leaves in a drip — one prompt at a time, from employees who have no intention of taking anything anywhere. According to LayerX Security’s Enterprise AI and SaaS Data Security Report 2025, 45% of enterprise employees now use generative AI tools at work, and most of them are pasting company information directly into the chat window.
The burst pipe gets attention because it looks like theft. The slow leak rarely does — it looks like someone doing their job a little faster.
When Harmonic Security analyzed a sample of enterprise AI prompts flagged as risky in late 2024, the contents weren’t exotic. They were the ordinary paperwork of running a business.
Separately, a CybSafe/National Cybersecurity Alliance survey found that 38% of employees admit to sharing sensitive work information with an AI tool without their employer’s permission — not to leak anything, but because the AI tool was the fastest way to get an answer.
IBM’s 20th annual Cost of a Data Breach Report, produced with the Ponemon Institute, put a number on both leaks at once. Breaches involving a high level of shadow AI — unsanctioned tools employees adopt without security sign-off — cost organizations measurably more, and happen more often than most security teams assume.
The gap is a governance gap, not a technology gap: 97% of organizations with an AI-related breach lacked proper access controls. And shadow-AI breaches don’t expose a random slice of the business — customer PII shows up in 65% of them, versus 53% industry-wide, and stolen intellectual property carries the highest cost per record of anything in the report.
Day-to-day risk looks different depending on what a person’s job actually touches. The same chatbot window that’s harmless for one role is a live wire for another.
None of this is a reason to ban AI tools — every one of these roles has legitimate, valuable uses for them. It’s a reason to control where the prompt goes, so the answer to “can I use AI for this?” can stay yes. Just use AI that resides behind your firewalls. It’s why NetApp and Iterate provide AI chat, agents, and projects — privately — via the AIPod Mini.

A Ponemon Institute study for Symantec found that 59% of departing employees take confidential information with them on the way out. Cyberhaven’s more recent analysis of exfiltration incidents found that generative AI tools now account for 13.1% of the channels used to move that data — behind only personal cloud storage and removable media, and the fastest-growing of the group.
Once something is pasted into a public AI tool, a company’s own data-handling policy is no longer the only document that matters — the vendor’s terms of service are. An analysis of AI vendor contracts by TermScout, conducted with Stanford Law School’s CodeX center, found that 92% of AI contracts claim data usage rights beyond what’s necessary to deliver the service, compared with 63% for software contracts generally.
Many of those contracts allow the vendor to use customer prompts and data for retraining models or other purposes well beyond answering the question that was asked. Once a prompt is sent, the company that typed it no longer decides what happens to it next. Private, governed infrastructure changes that equation at the source: the data never leaves an environment a company’s own contract governs in the first place.
That NDA your company signed? An employee may breach it with a single prompt—by pasting a partner’s confidential information into a public AI model.
Every company already has both problems: a slow, constant leak from everyday AI use, and a burst risk sitting in every resignation on the calendar. Neither requires an attacker. Both just require a pipe nobody is watching. The fix isn’t banning AI — every role in this paper has a legitimate reason to use it. The fix is making sure the pipe belongs to the company, not to whichever chatbot happened to be open.
A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.

Plain-language definitions for the governance and security terms in this paper.