JUNE 25, 2026 - 3 MIN READ
AI adoption has an insider problem
One 8-K filing changed how enterprises should think about data protection in the era of AI.
- Data Security
- Artificial Intelligence
- Tokenization
- Data Management for AI
Alexa SlingerSenior Manager, Product Marketing, Capital One Software
Last month, a public company filed what is believed to be the first material cybersecurity incident caused by the unauthorized use of an AI application.
This landmark 8-K disclosure is significant because, unlike traditional cyberattacks, there was no system intrusion, malware, ransomware or external threat actor involved. Instead, sensitive customer information was reportedly entered into an unauthorized AI tool by an employee performing routine business tasks.
The incident highlights the growing risks associated with AI and demonstrates how AI-related data exposure can become a material business issue even in the absence of a traditional breach. As organizations accelerate AI adoption, protecting sensitive data before it reaches AI systems is becoming just as important as protecting it from external attackers.
What is Shadow AI?
Shadow AI refers to the unauthorized use of artificial intelligence tools, models or applications by employees within an organization without the explicit approval or oversight of the IT and security teams.
It is the modern evolution of Shadow IT, the long-standing practice of employees downloading unapproved software or using personal cloud accounts to get their work done faster.
But the stakes with AI are exponentially higher.
When a well-meaning employee copies a proprietary data set or customer spreadsheet and pastes it into a consumer-grade chatbot to build a presentation or write code, that data leaves the company’s secure perimeter. In many cases, organizations have limited visibility into what happens to their data after it's ingested by consumer-facing AI tools, which means it's no longer subject to the same governance or security controls that exist within the business.
The challenge isn’t malicious intent. Most employees engaging in Shadow AI are simply trying to do their jobs more effectively. The challenge is that the speed of AI adoption has outpaced the development of safe, governed pathways to use it.
The AI Trust Paradox
This surge in Shadow AI has created what data and security leaders are beginning to call the AI Trust Paradox.
On one side are rank-and-file employees.
The employee perspective: They see the immense capability of generative AI and autonomous agents, and they are rushing ahead to adopt them to eliminate friction in their daily tasks. To them, AI is a massive productivity unlock. They use it to summarize information, generate content, analyze data and deliver faster. And adoption is happening faster than most organizations can govern.
On the other side are CDOs and CISOs.
The leadership perspective: They understand something employees don’t: AI is only as trustworthy as the data foundation beneath it. Every AI model, agent or workflow introduces new questions around data access, privacy, governance and compliance. A model trained on or exposed to improperly handled PII doesn’t just create a compliance problem—it creates a liability that can be nearly impossible to unwind.
The result is a high-stakes tug-of-war. Employees lean into AI for maximum speed. Security and data leaders pull back to enforce maximum caution. And organizations get stuck in between.
The paradox is this: If organizations institute outright bans on AI tools, they risk stalling innovation and driving employees further into the shadows. But if they grant total freedom, they risk exactly the kind of data exposure that ends up in an 8-K filing.
To solve the paradox, organizations must shift from a mindset of absolute restriction to one of continuous governance—implementing guardrails that allow employees to leverage the power of AI safely, without compromising the enterprise's crown jewels.
Solving the paradox at the data layer
Many conversations about AI governance focus on access controls—who can use which tools, what gets approved, how usage gets monitored. Although access controls are important, they address the problem at the wrong layer by assuming the goal is to control behavior. The more durable control is to protect the data at the data layer, so protection travels with the data, regardless of where it flows. This is where tokenization can fill the gap.
Tokenization is the process of replacing sensitive data, like social security numbers, account numbers or medical identifiers, with non-sensitive values called tokens. The tokens retain the format and structure of the original data, so they can still be used in essential business workflows, but reduce the potential of unintended exposure or feeding an AI model with protected data. The exposure risk is neutralized at the source—before it ever reaches an AI system, approved or otherwise.
What this means for security and data leaders
For data leaders, tokenization offers a path to enabling AI adoption without sacrificing data integrity. When sensitive data is tokenized at the point of ingestion or storage, it can flow freely through AI pipelines or analytics environments, because the risk of exposure has already been addressed. This enables teams to move faster while maintaining the governance posture that regulators and auditors expect.
For security leaders, tokenization reduces the blast radius of Shadow AI incidents. You cannot eliminate human behavior—employees will continue to find and use tools that help them work faster. But you can ensure that the data they have access to is structurally protected at the data layer, so that even unauthorized use doesn’t necessarily result in a material disclosure.
Together, this represents a shift in mindset that the AI Trust Paradox demands, from absolute restriction to continuous governance that supports AI innovation.
The incident is a signal, not an outlier
Ultimately, the recent 8-K filing is not an isolated cautionary tale. It’s a signal about where enterprise risk is moving. According to a 2026 global study by the World Economic Forum (opens in new tab), 87% of technology and risk leaders stated that AI-related vulnerabilities were the fastest-growing cyber risk in 2025.
As AI tools become more capable, more embedded in daily workflows and more accessible to non-technical users, the attack surface for unintentional data exposure grows. And as regulators become more attuned to AI-related risk, regulatory oversight and governance standards will only become more stringent.
The threat is no longer just coming from outside the perimeter. In the age of AI, it’s coming from the inside, from well-intentioned employees with powerful tools and no guardrails. The answer isn’t to remove the tools. It’s to make sure the data that reaches those tools is already protected.
For organizations serious about securely accelerating AI adoption, this is the time to rethink their data foundation because the most effective way to secure the future of AI is to protect the data that feeds it.
How Databolt can help you build a secure AI foundation
Databolt helps organizations secure sensitive data at the foundational level, so your teams can securely train AI models, share data with third parties and feed powerful analytics tools, unlocking greater business value without increasing risk.
Ready to neutralize Shadow AI risk and scale your AI initiatives with confidence? Book a demo today.
Alexa Slinger
Senior Manager - Product Marketing, Capital One Software
Alexa Slinger is Senior Manager of Product Marketing at Capital One Software, where she leads strategy, storytelling and programs for the company’s data security solutions. With over 10 years of experience in cybersecurity and SaaS, she’s known for creating clear, compelling narratives that drive results. Alexa also serves as a Capital One Community Champion and is an active volunteer, passionate about helping others and building connections.
Footnotes
DISCLOSURE STATEMENT: © 2026 Capital One. Opinions are those of the individual author. Unless noted otherwise in this post, Capital One is not affiliated with, nor endorsed by, any of the companies mentioned. All trademarks and other intellectual property used or displayed are property of their respective owners.
