Is Your Team Leaking Data to ChatGPT? What Indian CISOs Need to Know in 2025

Is Your Team Leaking Data to ChatGPT? What Indian CISOs Need to Know in 2025

Rahul
16-06-2026 04:02 PM Comment(s)

Generative AI tools are silently draining sensitive data from Indian enterprises. Learn the risks, the DPDP Act penalties, and how to build a GenAI-ready security posture.

The Breach No One Saw Coming

In early 2023, a group of engineers at Samsung pasted proprietary source code into ChatGPT. They were trying to work faster, debug more efficiently, and move a project forward. Within 20 days of the company allowing its staff to use the tool, three separate incidents had resulted in confidential source code, equipment diagnostics data, and internal meeting transcripts being fed into OpenAI’s model.

There was no hacker. No phishing email. No compromised password. Just employees doing what their instincts told them: use the best tool available to get the job done.

That data is now absorbed into a third-party AI model. There is no undo button.4


"The issue isn't malicious intent. It's contextual blindness.", Technology & Work Survey, 2025


If that can happen at Samsung, one of the world’s most sophisticated technology companies, the question we need to ask is straightforward: what is happening inside Indian enterprises right now?

We believe the answer is: more than most security leaders realise.



The Scale of the GenAI Data Leak Problem

Generative AI adoption is accelerating faster than security governance can keep pace. According to a 2025 Menlo Security report, 73% of organisations in India have already implemented GenAI tools, one of the highest adoption rates in the Asia-Pacific region. Web traffic to GenAI platforms jumped 50% in a single year, reaching 10.53 billion visits globally in January 2025 alone.

But the security infrastructure to govern that adoption is largely absent. Consider what the data tells us:

  • 86% of CISOs globally worry their employees are leaking sensitive data through GenAI platforms (Mimecast 2024 Data Exposure Report).
  • 48% of employees have admitted to uploading sensitive corporate data into public AI tools (Technology & Work Survey, 2025).
  • 1 in every 35 GenAI prompts carries a high risk of sensitive data leakage, affecting 87% of organisations that use GenAI regularly (Check Point, November 2025).
  • 68% of organisations have already experienced data leakage incidents related to employees sharing sensitive information with AI tools (Metomic, 2025 State of Data Security Report).
  • Shadow AI, the use of unauthorised AI tools outside IT oversight, now accounts for 20% of all enterprise breaches and adds an average of ₹4.74 million per breach compared to ₹4.07 million for standard incidents (IBM Cost of a Data Breach Report, 2025).

     

    Also, the trajectory is worsening. Gartner predicts that by 2027, 17% of all cyberattacks and data leaks will involve generative AI. By 2030, more than 40% of enterprises are expected to experience a security or compliance incident linked to unauthorised shadow AI usage.


    Rising enterprise adoption of generative AI tools increasing data security concerns.


    Why Indian Enterprises Face a Unique Exposure

    The Indian enterprise landscape carries specific characteristics that amplify GenAI data leak risk beyond what global benchmarks suggest.


    High AI adoption, low governance maturity

    India ranks among the fastest GenAI adopters in Asia, but governance is lagging dramatically. According to BW Businessworld’s 2025 cybersecurity analysis, shadow AI, prompt-based data leakage, and the misuse of public LLMs were identified as the most urgent governance blind spots of 2025 across Indian enterprises, particularly in BFSI, IT services, healthcare, and manufacturing sectors.


    A workforce optimised for productivity over process

    India’s digital workforce is young, fast-moving, and motivated to find efficiency gains. These are strengths, but they also mean that when a better tool exists, employees will find and use it. Gartner’s November 2025 survey of cybersecurity leaders found that 69% of organisations already suspect or have evidence that employees are using prohibited public GenAI tools.


    The DPDP Act 2023, and penalties that are now live

    India’s Digital Personal Data Protection Act (2023) received Presidential assent on 11 August 2023. The implementing DPDP Rules were notified on 13 November 2025, operationalising the full enforcement framework. Full Schedule 1 penalties are effective from May 2027, giving organisations a narrow window to achieve compliance.


    The penalties are substantial:

    • ₹250 crore for failure to implement reasonable security safeguards (Section 8(5))
    • ₹200 crore for failure to notify the Data Protection Board or affected Data Principals of a breach (Section 8(6))
    • ₹200 crore for non-compliance with provisions protecting children’s data

       

      An employee sharing customer PII, names, phone numbers, email addresses, financial records, through a public GenAI platform could constitute a reportable breach under the Act. The clock is ticking.



      Indian businesses facing increasing AI governance and compliance challenges.


      What Data Is Actually Being Leaked?

      It would be comforting to think that employees are only sharing harmless queries with GenAI tools. The data suggests otherwise.


      An analysis of over one million GenAI prompts and 20,000 uploaded files across more than 300 GenAI applications (Help Net Security, Q2 2025) found that:

      • 22% of uploaded files contained sensitive information, including source code, proprietary algorithms, M&A documents, customer records, and internal financial data.
      • 4.37% of prompts contained sensitive data, a figure that sounds small until it is applied to a workforce of thousands generating hundreds of prompts daily.
      • Customer data, including billing and authentication information, made up the largest share of leaked data at 46% (Harmonic Security, Q4 2024 analysis).
      • Employee PII and payroll data accounted for 27% of sensitive prompts.
      • Legal and financial data made up 15%.

         

        Among Mimecast’s tracked data, the most frequently shared data types by enterprise employees in ChatGPT per 10,000 users monthly include source code (158 instances), regulated data (18 instances), intellectual property (4 instances), and passwords and credentials (4 instances).A structured approach to information protection is the most direct way to close these leakage gaps.


        Four Business Risks Indian Security Leaders Cannot Ignore

        1. Loss of competitive advantage

        Your product roadmap, client pipeline, pricing strategy, and R&D plans are worth more than most organisations realise, until a competitor has access to them. GenAI platforms trained on even fragments of your confidential presentations or strategy documents can surface that intelligence in unexpected ways. In early 2025, a London-based pharmaceutical company suffered a significant IP breach when researchers used a public GenAI tool to analyse proprietary drug discovery data. Similar molecular structures and insights subsequently appeared in a competitor’s patent filings.


        2. DPDP, GDPR, and regulatory exposure

        India’s DPDP Act is now enforceable. For organisations with clients in the EU, HIPAA (US healthcare), or CCPA (California consumer data), the regulatory exposure compounds across jurisdictions. A single employee sharing customer PII through an unsanctioned GenAI tool can trigger a reportable breach across multiple frameworks simultaneously. Under GDPR alone, cumulative fines had reached approximately $6.17 billion by January 2025, with LinkedIn fined $326 million and Uber $305 million in 2024 for data handling violations.


        3. Reputational damage that outlasts the breach

        Trust, once broken, is extraordinarily expensive to rebuild in the enterprise context. India has seen high-profile breaches at Hathway (41.5 million customers, March 2024), boAt (7.5 million customers, February 2024), and BSNL. In each case, the reputational fallout extended far beyond the immediate incident. A data breach involving customer financial records or confidential business data can undo years of relationship-building in days, with social media amplifying the story faster than any PR team can respond.


        4. Fuelling the next generation of phishing attacks

        Leaked login credentials and internal communication patterns are extraordinarily valuable training data for adversarial AI. ChatGPT-themed phishing click rates rose from 1.2% to 6.8% in two years (Awareways Trend Report, 2025), a 467% increase. GenAI platforms trained on leaked credentials can generate hyper-personalised, contextually accurate phishing emails that traditional filters are not equipped to detect. In India alone, the first half of 2025 saw 23 lakh web-based attacks and 1.11 lakh password-stealing malware incidents (Kaspersky telemetry), with GenAI-powered attack methodologies playing an increasing role.


        DPDP Act compliance requirements and data protection penalties for Indian organizations.


        Why Traditional DLP Is Failing

        Most organisations in India currently rely on legacy Data Loss Prevention tools that were designed before generative AI existed. These tools were architected around a different threat model: email attachments, USB drives, and structured data egress. They were not built to monitor what an employee types into a browser tab.


        The limitations are structural, not incidental:

        • No browser visibility: Legacy DLP cannot intercept or monitor prompts entered into web-based AI tools like ChatGPT or Gemini.
        • Alert fatigue: Traditional tools require constant tuning, generate enormous alert volumes, and drain analyst bandwidth, in an industry already experiencing critical talent shortages.
        • Months-long deployments: Legacy platforms can take six months or more to configure before they provide meaningful protection, by which time the threat landscape has shifted.
        • Policy-first architecture: They require organisations to know exactly what they are looking for before they can find it, a fundamental mismatch with the emerging, unclassified nature of GenAI data leakage.

           

          Organisations have responded with blunt instruments. According to Cisco’s 2024 Data Privacy Benchmark Study: 63% have set restrictions on data input into AI platforms, 61% limit which AI tools employees can use, and 27% temporarily banned GenAI applications entirely. The problem with the ban approach is well-documented: it does not stop usage; it pushes it underground. Shadow AI use grows when restrictions are imposed without an approved alternative.


          Shadow AI is not traditional shadow IT. It requires only a browser and a deadline, not coding skills, enabling any employee to leak data without realising it. Existing DLP, logging, and access tools were never designed to monitor prompts.


          Sensitive enterprise information being exposed through AI tools.


          A Modern Framework for GenAI Data Security

          The answer to GenAI data risk is not to ban AI, it is to build a security posture that moves with how your teams actually work. We recommend a five-pillar approach for Indian enterprises:

          1. Detect without disrupting. Deploy solutions that provide visibility into data movement across cloud, endpoint, browser, and GenAI channels without requiring months of policy configuration. The goal is to surface both known and unknown risks from day one. Solutions like Mimecast Incydr provide this visibility across Git activity, Salesforce downloads, cloud syncs, Airdrops, and browser-based AI tool usage in a single view.

          2. Educate at the moment of risk. Quarterly awareness training is insufficient. When an employee attempts to paste source code into ChatGPT, the most effective intervention is a real-time micro-training triggered at that exact moment, not a session they completed six months ago. Integrated micro-training tools, including Mimecast Instructor, automate responses to low-severity risk events and reduce event volume over time.

          3. Contain and investigate fast. User error is inevitable. When an incident occurs, speed of containment determines the scale of damage. Security teams need tools with swift containment controls that enable rapid investigation and closure. Mimecast Incydr enables 50% faster incident closing, per a commissioned Forrester Research report.

          4. Block selectively for high-risk users. Real-time blocking is not appropriate for the entire organisation, that path leads to shadow IT. But for employees working directly with intellectual property, source code, or regulated customer data, real-time blocking tied to behavioural risk scoring is a proportionate and necessary control.

          5. Upgrade your DLP infrastructure. Modern Data Loss Prevention solutions purpose-built for the GenAI era provide complete visibility into cloud exfiltration, validate actual file contents to determine sensitivity, and deploy in days rather than months. The ROI is measurable: organisations deploying Mimecast Incydr see an average 172% return on investment, including data loss savings exceeding $680,000 and a 50% reduction in incident closure time.


          Business consequences of AI-driven data leakage and compliance failures.


          The Shadow AI Problem Is Already Inside Your Organisation

          Shadow AI is not a future risk. It is operating inside Indian enterprises today.


          Over 80% of employees globally use unapproved AI tools. 665 distinct generative AI applications have been tracked across enterprise environments (Vectra AI, 2025). In India specifically, 68% of employees use free-tier AI tools that bypass enterprise controls (Menlo Security, 2025). The WEF Global Cybersecurity Outlook 2026 found that CEOs now rank GenAI data leaks as their number one security concern, ahead of ransomware, ahead of nation-state actors.

          We are not raising this to cause alarm. We raise it because the window to act is open and closing. The DPDP Rules are now in force. The Data Protection Board of India is operational. The enforcement calendar is set.

          Legacy data loss prevention tools struggling against modern AI threats.


          How Delphi Infotech Can Help

          As an authorised Value-Added Distributor (VAD) for Mimecast in India, we work with security teams across Indian enterprises to evaluate, pilot, and deploy Mimecast’s data security solutions, including Mimecast Incydr, the cloud-native insider risk and data loss protection platform.

          Our engagements typically begin with a GenAI Data Risk Assessment, a structured 30-minute conversation to help your team understand your current exposure, identify the highest-risk data flows in your environment, and map a practical path to remediation. There is no obligation and no lengthy sales process.

          Incydr is FEDRAMP-authorised and can be configured for DPDP, GDPR, HIPAA, PCI, and other compliance frameworks, making it well-suited for Indian enterprises operating across regulatory jurisdictions. For enterprises that need to maintain operations during security incidents, email continuity ensures business communication is never interrupted, making it well-suited for Indian enterprises operating across regulatory jurisdictions.

          Delphi Infotech helping organizations secure generative AI adoption and prevent data leaks.


          Key Takeaways

            • 73% of Indian enterprises have implemented GenAI tools, but governance and security controls have not kept pace with adoption.
            • Sensitive data is already flowing into public AI platforms daily: source code, customer PII, financial records, credentials, and intellectual property.
            • India’s DPDP Rules (November 2025) impose penalties of up to ₹250 crore for failure to maintain reasonable data security safeguards.
            • Legacy DLP tools have no visibility into browser-based AI tool usage, the most common vector for GenAI data leakage.
            • Banning AI drives usage underground, creating shadow AI and worsening the risk picture. The solution is governed, secure AI adoption.
            • Modern solutions like Mimecast Incydr deploy in days, provide cross-channel visibility, and deliver measurable ROI, including 50% faster incident closure and 172% average ROI.
            • Delphi Infotech offers a complimentary GenAI Data Risk Assessment for Indian enterprises. Reach out at info@delphiinfo.com or visit delphiinfo.com.


          Frequently Asked Questions

          Q: What types of data are most commonly leaked through GenAI tools in enterprise environments?

          A: Based on analysis of enterprise GenAI usage, the most frequently leaked data types include source code (the single largest category), customer data including PII and billing information (46% of sensitive prompts), employee data and payroll information (27%), and legal and financial data (15%). In ChatGPT specifically, Mimecast data shows 158 source code sharing instances per 10,000 enterprise users monthly.


          Q: Does India’s DPDP Act apply to employee data shared through ChatGPT?

          A: Yes. The DPDP Act 2023, now fully operationalised with the DPDP Rules notified in November 2025, applies to the processing of personal data of individuals in India. If an employee shares customer names, phone numbers, addresses, email addresses, or any other personal data through a public GenAI platform, this likely constitutes processing of personal data outside an approved, governed environment, creating compliance exposure under the Act. Penalties can reach ₹250 crore for failure to maintain reasonable security safeguards.


          Q: Is banning GenAI tools an effective security measure?

          A: Banning AI tools rarely works in practice. Research consistently shows that employees continue using prohibited tools, simply through personal accounts and unapproved channels, creating shadow AI that is invisible to security teams. Cisco’s 2024 Benchmark Study found 27% of companies have temporarily banned GenAI, but Menlo Security data shows 68% of employees still use free-tier AI tools despite restrictions. The more effective approach is building a governed, secure framework for AI usage that enables productivity within appropriate guardrails.


          Q: What is shadow AI, and why is it more dangerous than traditional shadow IT?

          A: Shadow AI refers to the use of generative AI tools by employees outside of IT-approved and security-monitored channels. It is more dangerous than traditional shadow IT because it requires no technical skill to implement, just a browser and an internet connection, and because the nature of GenAI interaction (pasting documents, entering queries, uploading files) directly exposes sensitive data. Shadow AI now accounts for 20% of enterprise breaches and adds ₹52 lakh on average to breach costs, according to IBM’s 2025 Cost of a Data Breach Report.


          Q: How quickly can a modern data security platform like Mimecast Incydr be deployed?

          A: Mimecast Incydr deploys in approximately two weeks, compared to the six-month-plus timelines typical of legacy DLP platforms. It requires no complex policy management or lengthy configuration. Per a commissioned Forrester Research report, the solution pays for itself within six months of deployment, with an average 172% return on investment and data loss savings exceeding $680,000. Incident closure time improves by 50% compared to pre-deployment baselines.

          Q: What is a GenAI Data Risk Assessment, and how do we get one?

          A: A GenAI Data Risk Assessment is a structured 30-minute consultation with our team at Delphi Infotech to help you understand your current exposure, specifically, what data may be flowing through unsanctioned AI channels in your organisation, where your highest-risk data flows are, and what a practical remediation roadmap looks like. There is no cost and no obligation. To schedule an assessment, contact us at info@delphiinfo.com or visit delphiinfo.com/contact.




          Rahul