In October 2025, security firm LayerX published the Enterprise AI and SaaS Data Security Report 2025, built from monitoring corporate browsers. The central finding: 77% of professionals who use AI assistants paste company information straight into the text box, and 82% of those pastes come from a personal account, outside any company control.

This isn't a careless minority. According to the same study, each person pastes an average of 14 times a day into non-corporate accounts, and at least three of those pastes carry some sensitive data. The gesture is so routine it no longer feels risky: in the middle of a task, pasting a spreadsheet excerpt or a contract paragraph into an AI assistant is today as automatic as pasting into a personal chat.

That changes the question security leaders should be asking. It's no longer "which sites are blocked" — it's "what is our team pasting, from which account, and who can reconstruct it afterward."

What Actually Leaves Through Ctrl+V

The Cloud and Threat Report: Generative AI 2025, from Netskope, measured the same phenomenon from the network side and arrived at a similar picture: 72% of enterprise users access generative AI tools through a personal account while working. The volume of data sent to these tools grew 30-fold in a year — not because AI use multiplied at the same rate, but because each use started carrying more company information inside the text.

What gets pasted varies by team, but the Netskope report lists the most recurring types: source code snippets, regulated data, passwords and access keys, intellectual property. Nobody is stealing this information. Whoever is stuck on a problem pastes the snippet that broke the system, pastes the key "just to test", pastes the contract clause "to summarize quickly".

LayerX's report breaks down what gets pasted: 22% of the pasted text carried personal or payment information, and 40% of the files uploaded to these tools carried the same kind of data. Cyberhaven, in a report published in February 2026, measured that 39.7% of all AI interactions involve some sensitive data — almost four in ten.

None of these numbers describe an attack. They describe an ordinary work routine that crosses the company's perimeter one paste at a time, with nobody needing to break in.

Why Website Blocking Doesn't See This Paste

Why Website Blocking Doesn't See This Paste

The most common answer is still technical: block the AI assistant's address on the company network, or point the data-loss prevention tool at email attachments. Both controls were built for a different problem than the one happening now.

Website blocking depends on the tool being on a banned list — and the list of AI assistants changes every week. Even when the target is blocked on the company network, the same person accesses it from a personal phone, from another network, or from a new tool that hasn't made any list yet.

Data-loss prevention was designed to catch a file leaving by email or upload, not text typed into a chat box, in an ordinary browser tab, on an account that isn't even the company's. From the network's point of view, that traffic is indistinguishable from any other visit to a legitimate site: a secure connection, a known domain, a person authenticated with their own personal email. There's no file to inspect, no attachment to scan.

The result is a double blind spot: the company doesn't see what was pasted, and doesn't see who pasted it, because the account used was never under corporate identity. The 82% of pastes from personal accounts, measured by LayerX, and the 72% of access from personal accounts, measured by Netskope, describe the same gap through two different paths.

Copying and pasting into AI assistants is already the primary way company data leaves, ahead of file transfers.

LayerX, 2025

What Has to Be in Place

A governed AI environment replaces the individual decision — paste or don't paste — with a structure that already decides it for the person, before the text leaves the screen.

Corporate identity, not a personal account. Access comes through the same company network login, with the same lifecycle: whoever is let go loses AI access the same instant, without depending on someone remembering to revoke a stray account.

Access according to each person's role. Each person and each agent see only what their own role authorizes inside a connected tool, not the entire tool because that was the only way to unlock one specific function.

Human approval before a sensitive action. An action that moves money, changes a record, or exposes information outside the company asks a person to confirm before it proceeds, inside the conversation itself, not in a separate step nobody revisits later.

Approved knowledge with sources. Instead of pasting the latest version of a contract or a spreadsheet "to see what the AI thinks", the question gets answered from content the company has already reviewed and recognizes as official.

An audit trail. Every question asked from company knowledge, every approval, and every permission change gets logged — the opposite of the personal history that disappears along with the account.

This is how Skyller was designed: identity coming from the company directory, role-based access, and human approval as the default, not a setting someone has to remember to turn on.

The Payoff of Closing the Shortcut

The Payoff of Closing the Shortcut

Closing the personal-paste shortcut isn't only about reducing risk, it's about recovering the work that gets lost inside it today. When the same question about a contract clause gets answered thirty times by thirty different people, each one pasting the same snippet into a personal assistant, the company pays the risk thirty times and gets nothing back for it: none of those answers becomes reusable knowledge for the next person with the same question.

In an environment with approved knowledge and permission-based reuse, the right answer is found once and stays available, under the same access controls, for whoever needs it next — without each person having to repeat the same risky paste.

There's also an effect on security's time. Today, much of the effort after an incident goes into reconstructing what happened: which information left, through which account, headed where. With corporate identity and an audit trail from the start, that reconstruction stops being detective work and becomes a records lookup.

For whoever leads a team, the most direct payoff tends to be a different one: no longer finding out, only after the fact, that sensitive data left through someone's screen. Instead of chasing every new AI tool the team discovers, the conversation shifts to whether the official path covers what people actually need to get their work done.

A Starting Roadmap

Before buying yet another blocking tool, these steps help measure the real size of the problem and decide where to start.

  1. Measure what's already happening. Find out how many personal AI accounts the team already uses for work — most companies have never asked their own teams this directly.
  2. Pick one high-volume area to start with. Teams handling contracts, customer support, or financial data tend to paste sensitive information more often; start there, not across the whole company at once.
  3. Offer the official path before tightening the ban. A place with corporate identity, role-based access, and approval, where the same task is easier to do, cuts risky pasting more than any site block does.
  4. Define with security what "sensitive" means here. Contracts, customer data, passwords, and source code call for different handling; agreeing on this upfront keeps the audit trail from turning into noise nobody reviews.
  5. Revisit the roadmap in three months. The list of AI tools a team uses changes fast; what was measured once doesn't stay accurate for long without a recheck.

Discover Skyller