The short answer
The risks of AI in the workplace fit into seven. The first three happen every day, with no attack at all, simply because someone had a problem and a tool within reach: company data goes into a tool nobody approved, the data is used to train another company’s model, or personal data crosses a border. The next four depend on how the company adopts AI: unsupervised agents, errors turning into decisions, a lack of evidence for the regulator, and dependence on tools that disappear.
For each risk below you will find what it is, a verifiable fact, the control that reduces it and how to tell whether it is happening in your company. The common thread is one: you cannot control what you cannot see. That is why the first step of any program is the inventory.
43%
of the security incidents analyzed in the 2026 report involved Shadow AI, the use of AI outside IT’s approval and view. Incidents involving Shadow AI cost US$ 5.39 million on average, against US$ 4.99 million for the global average. These are averages across organizations that suffered a breach, not a forecast for yours.
1. Company data in a tool nobody approved
What it is. An employee pastes a contract, a customer spreadsheet or a piece of code into an AI tool the company never assessed. There is no bad faith: there is a deadline and a free tool.
A fact. In May 2023, TechCrunch reported that Samsung restricted the use of generative AI after sensitive internal data was sent to ChatGPT. The episode does not prove the tool is unsafe; it proves that, without a clear rule, data leaves by the most convenient path. According to Gartner, 69% of organizations already suspect or have evidence that employees use prohibited public generative tools.
The control. A continuous inventory, classification of each tool as allowed, restricted or prohibited, and a usage policy that says what kind of data goes into each category.
How to tell if it is happening. Asking does not answer: most use is not declared. Only technical discovery answers, and the guide What is Shadow AI shows the paths.
2. Data used to train another company’s model
What it is. In some tools, what the user types can be used to improve the vendor’s model. Some offer an option to turn it off, and the default depends on the plan.
A fact. OpenAI documents that, on personal accounts, content can be used to improve its models, with the possibility of opting out, and treats business plans differently, in the contract and in the policy. The same tool, on two plans, has two risk profiles. That is why the useful question is “which plan is my team on?”, not “is this tool safe?”. We cover the case in the guide Is ChatGPT safe to use at work?.
The control. Record, per tool, whether the free version trains on the data and whether the company has a plan with different terms. This field exists on the pages of our public catalog, for the tools already assessed; the assessment is progressive.
3. Personal data leaving the country
What it is. When there is personal data in what is sent to a foreign vendor’s tool, the sending is an international data transfer.
Our own data. Of the 4,156 active AI tools in our catalog with an identified home country, 98.9% are headquartered outside Brazil; only 45 are Brazilian. In practice, almost every AI adoption by a Brazilian company that involves personal data is an international transfer, subject to article 33 of the LGPD and to the regime of Resolution CD/ANPD No. 19/2024, whose transition period for the standard clauses ended on 23 August 2025.
The control. Know the country of each vendor, have the legal basis and the contractual instrument for the transfer where personal data is involved, and keep personal data out of tools that do not have them. Each tool’s origin is on its page in the catalog, and the full analysis is at /pesquisa. For the legal framing, see the LGPD and AI tools.
4. Agents that act without supervision
What it is. An AI agent does not only answer: it carries out actions, such as sending email, editing files, calling systems and buying things. The risk changes in nature: it stops being what the tool says and becomes what it does, with the credentials of whoever configured it.
A fact. NIST’s generative AI profile (AI 600-1, 2024) is the companion to the AI RMF dedicated to the risks specific to generative AI. Our catalog already records more than 500 active tools in the agent category, and each one is a decision point: which systems it reaches and with what credentials.
The control. Treat an agent as an identity: least-privilege permissions, human approval for irreversible actions and a record of what was done. When assessing one, ask which systems the agent has access to and who answers for what it does.
5. An AI error becoming a decision
What it is. Generative AI produces text that sounds right and may be wrong. The risk appears when the text becomes a contract, an opinion, a customer reply or a decision without anyone reviewing it.
The control. A human-review rule proportional to impact: whatever leaves the company, or decides something about a person, goes through someone who answers for the result. The policy should say so in writing, with everyday examples, and attribute generated content to a person.
6. Regulatory accountability without evidence
What it is. The LGPD, the EU AI Act and sector rules do not ask the company to say it controls AI: they ask it to be able to show that it does. A rule with no record that it was followed does not survive an audit.
68%
of organizations that suffered a breach had no AI governance in place to manage AI or detect shadow AI, according to the 2026 report. It is a figure about organizations that were breached, not a forecast for yours.
The control. Keep the evidence with the decision: the inventory, the classification, the policy acknowledgement from the people who use it and the handling of each deviation, with an owner and a deadline. The EU AI Act, for instance, imposes obligations by risk category and can reach companies outside Europe; see when it applies to a company outside the EU.
7. Dependence on a tool that disappears
What it is. The AI market moves faster than a company’s purchasing cycle: tools appear, change terms and disappear. A process built on a tool that goes offline is an operational risk, and the record of what was done in it, an audit risk.
Our own data. When re-verifying the catalog, we found that 18.7% of the AI tools we have cataloged have ceased to exist: the domain went offline, was abandoned or started serving something else. The figure excludes tools we removed by our own scope decision. Methodology and limitations at /pesquisa.
The control. An inventory that updates itself, instead of a list built once a year, and a record of each tool’s risk that stays valid after the tool disappears, so an old event remains auditable.
The map in one table
| Risk | Where it shows up | Main control | How to tell if it is happening |
|---|---|---|---|
| 1. Unapproved tool | Any department | Policy and classification | Technical discovery |
| 2. Data trains a third party's model | Free and personal plans | A record per tool and plan | A catalog with each plan's terms |
| 3. Personal data leaves the country | Foreign vendors' tools | Vendor country and legal basis | Country recorded per tool |
| 4. Unsupervised agent | Automation and productivity | Least privilege and human approval | Inventory of agents and access |
| 5. Error becomes a decision | Contracts, opinions, support | Proportional human review | Sampling and a written rule |
| 6. No regulatory evidence | Audit and inspection | A record kept with the decision | Evidence per control, dated |
| 7. A tool disappears | Processes that depend on it | A live inventory and recorded risk | Continuous re-verification |
51%
of organizations that use AI have already had at least one negative consequence from it, according to McKinsey’s 2025 survey (1,993 respondents in 105 countries). It is the backdrop against which these seven risks stop being hypothetical.
Where to start: the first 30 days
- Week 1: discover. Survey what is in use with technical data, not a questionnaire. The free assessment at /diagnostico shows, in nine questions, where your company stands.
- Week 2: classify. Place each tool as allowed, restricted or prohibited, and note the reason and the plan in use.
- Week 3: regulate. Publish a short policy with data examples and collect acknowledgement from the people who use it.
- Week 4: monitor. Turn each deviation into a task with an owner and a deadline, and close the loop with evidence.
How to measure a tool’s risk
Four questions settle most cases: what the tool does with what goes in (trains, stores, shares), where the data lives and who the vendor is, which terms apply to the plan your team uses, and what the track record of the company behind it is. The page for each tool in our catalog records the vendor’s country, the classified risk with the reason and, for tools already assessed, whether the free version trains on the data. If a vendor cannot answer these questions, that is the answer.
Frequently asked questions
What are the main risks of AI in the workplace?
Seven, in practice: company data in an unapproved tool (Shadow AI); data used to train a third party's model; personal data leaving the country; autonomous agents acting without supervision; an AI error becoming a decision; regulatory accountability without evidence; and dependence on a tool that ceases to exist. The first three happen every day, with no attack at all.
Does generative AI leak company data?
The tool itself does not "leak": the data leaves when someone pastes or uploads it. The risk depends on who uses it, with what data, on which plan and under what terms. On free plans, some tools' terms allow content to be used to improve the model; on business plans the contract usually says the opposite. That is why the useful rule is to classify tools and data, not to ban the category.
Does banning AI use solve it?
Rarely. A ban in a company where people already use AI takes the use out of sight of the people who should see it and creates a contradiction between the document and the practice. It is more defensible to classify tools as allowed, restricted or prohibited, define what kind of data goes into each, and monitor compliance.
How does the LGPD apply to the use of AI tools?
If there is personal data in what is sent to the tool, sending it is data processing and, when the vendor is abroad, it is also an international transfer, subject to article 33 of the LGPD and to Resolution CD/ANPD No. 19/2024. That holds even when the employee used the tool on their own: the company remains responsible for the data it was processing.
How do I find out which AI tools my company uses?
Asking is not enough: most use is not declared. You need technical discovery, through an agent on workstations or through firewall, SSE and SIEM logs, compared against a catalog of tools with classified risk. The first inventory tends to be a surprise, and it is what turns the policy from theory into practice.
Sources
- IBM / Ponemon Institute — Cost of a Data Breach Report 2026 (2026). https://www.ibm.com/reports/data-breach
- Gartner — Previsão sobre incidentes de Shadow AI até 2030 (2025). via Infosecurity Magazine. https://www.infosecurity-magazine.com/news/gartner-40-firms-hit-shadow-ai/
- McKinsey & Company — The State of AI: Global Survey (2025). https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
- NIST — NIST AI 600-1 — AI RMF: Generative Artificial Intelligence Profile (2024). https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
- TechCrunch — Samsung bans use of generative AI tools like ChatGPT after April internal data leak (2023). https://techcrunch.com/2023/05/02/samsung-bans-use-of-generative-ai-tools-like-chatgpt-after-april-internal-data-leak
- OpenAI — How your data is used to improve model performance (2026). https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance
- Presidência da República — Lei n.º 13.709/2018 (LGPD) (2018). https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
- ANPD — Resolução CD/ANPD n.º 19/2024 — transferência internacional e cláusulas-padrão (2024). https://www.gov.br/anpd/pt-br/assuntos/assuntos-internacionais/transferencia-internacional-de-dados
- União Europeia — Regulamento (UE) 2024/1689 — EU AI Act (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/oj