20 AUGUST 2026 - Shadow AI incidents more than doubled in a year, while widespread use of AI tools leaves organisations increasingly exposed to sensitive data being shared with external platforms, SearchInform Malaysia warns.

Malaysian organisations could be facing a growing cybersecurity risk from within their own workforce as employees increasingly turn to public artificial intelligence (AI) tools to complete everyday business tasks.

SearchInform Malaysia has warned that so-called Shadow AI — the use of AI tools without the knowledge or oversight of an organisation — is creating new opportunities for sensitive corporate data to leave company systems undetected.

The warning comes as 91% of Malaysian organisations have adopted business AI tools, according to the company, with many organisations lacking visibility into how employees use these platforms.

Employees may inadvertently expose sensitive information by pasting source code, customer databases, payment card details or unreleased financial information into public AI chatbots to complete reports, analyse information or perform other tasks more quickly.

Shadow AI incidents more than double

The risk is reflected in findings from IBM’s 2026 Cost of a Data Breach Report, which found that Shadow AI incidents more than doubled over the past year, rising from 20% to 43% of breached organisations.

These incidents averaged US$5.39 million in costs, highlighting the potential financial consequences of unmanaged AI use.

Unlike conventional cyberattacks, Shadow AI activity can be difficult for organisations to identify because traffic to AI platforms can appear similar to ordinary web browsing.

While firewalls may allow such traffic through, information entered into external AI platforms could potentially be retained on external servers or used to train future models, depending on the service and its terms.

This creates a challenge for organisations seeking to protect confidential information while allowing employees to benefit from AI technology.

Employees can create risks without malicious intent

SearchInform Malaysia said the issue does not necessarily stem from employees deliberately attempting to compromise corporate security.

Even responsible employees may share sensitive information with a chatbot simply because they are looking for a faster way to complete a business task.

Francis Yeoh, Country Director at SearchInform Malaysia, said organisations need greater visibility over the data being transferred to AI services.

“You cannot protect data you cannot see, and right now numerous organisations are blind to this,” Yeoh said.

He said an employee could unintentionally move sensitive information outside the organisation the moment it is entered into a public AI prompt.

“The goal is to see what data is being transferred and whether this operation poses a risk to corporate security. If so, the operation should be blocked before a leak happens,” he said.

How businesses can manage AI data security

As AI adoption continues to expand, SearchInform Malaysia recommends that organisations take a more proactive approach to controlling how corporate information is shared with AI services.

Know your data

Businesses should classify their data assets and identify information that is sensitive or restricted.

Clear data classification can help organisations determine what information employees must not share with external AI services.

Apply technical controls

SearchInform Malaysia recommends using Next-Generation Data Loss Prevention (DLP) systems capable of monitoring data transfer operations involving AI services.

Such systems can identify and block potentially risky transfers before sensitive information leaves the organisation, providing an additional safeguard against AI-related data leaks.

Train employees regularly

Technology alone cannot eliminate the risks associated with Shadow AI.

Organisations should regularly train employees on responsible AI use and make clear what information must never be shared with AI tools.

This should cover both standalone public AI platforms and AI features embedded within existing business applications.

PDPA increases the stakes for Malaysian organisations

For Malaysian businesses, the growing use of AI also creates data protection and regulatory considerations under the Personal Data Protection Act (PDPA).

SearchInform Malaysia warned that once regulated personal data enters an ungoverned external AI model, demonstrating compliance can become significantly more difficult.

The organisation, rather than the AI tool itself, remains responsible for managing the data and meeting its regulatory obligations.

As Malaysian businesses continue adopting AI to improve productivity and efficiency, the challenge will increasingly be to balance innovation with AI governance, data protection and cybersecurity.

With Shadow AI becoming harder to detect and employees increasingly incorporating AI into everyday workflows, organisations will need greater visibility over how data moves between internal systems and external AI platforms to prevent an inadvertent data leak from becoming a costly breach.