77% of employees who use generative AI tools paste data into GenAI prompts, according to LayerX Security's Enterprise AI and SaaS Data Security Report, published in October 2025 from browser telemetry gathered across dozens of global enterprises. That is not a fringe habit: 45% of enterprise employees already use some form of generative AI, and more than four in five of the resulting pastes flow through personal accounts the employer cannot see or audit. Separate telemetry studies from Harmonic Security and Cyberhaven put the narrower, strictly-confidential slice of that data anywhere from 2.6% to 39.7% of all AI interactions, depending on how each vendor defines "sensitive."
What percentage of workers paste data into AI tools?
77% of employees who already use a generative AI tool paste data directly into its prompt box, based on real browser telemetry LayerX Security collected across dozens of enterprise customers for its Enterprise AI and SaaS Data Security Report. That figure describes behavior among adopters, not the whole workforce: LayerX separately measured GenAI adoption itself at 45% of enterprise employees, meaning roughly a third of the entire workforce has pasted something into an AI tool, whether or not their employer sanctioned it.
The paste habit is frequent, not occasional. LayerX's telemetry shows employees averaging 14 paste actions per day into personal, unmanaged AI accounts, with at least three of those daily pastes containing data flagged as sensitive. Two smaller shares of the same paste activity carry outsized risk: 22% of paste operations include personally identifiable or payment card information, and 40% of files uploaded to GenAI tools contain the same category of data.
Figure 1: Five separate LayerX metrics on the same underlying paste behavior. Source: LayerX Security, Enterprise AI and SaaS Data Security Report 2025.
That behavior pattern matches the wider AI-and-privacy picture: adoption is outrunning oversight across nearly every metric researchers track. Our broader look at AI and privacy statistics for 2026 covers how that gap shows up outside the workplace too.
Take that combination, near-universal pasting among adopters plus heavy personal-account use, as the baseline the rest of this post breaks down.
How much of the data workers paste into AI tools is sensitive?
Estimates split depending on the measurement window and what counts as "sensitive." Harmonic Security's full-year analysis of 22,458,240 prompts and file uploads submitted to 665 different AI applications during 2025 found 579,113 sensitive instances, a rate of 2.6% of total volume. ChatGPT accounted for 71.2% of those exposures despite representing 43.9% of prompt volume overall, meaning sensitive material concentrates disproportionately in the single most-used tool.
A narrower quarterly snapshot from the same vendor tells a starker story. Harmonic Security's "From Payrolls to Patents" report, covering Q4 2024 specifically, found sensitive information in 8.5% of employee prompts across ChatGPT, Microsoft Copilot, Gemini, Claude, and Perplexity. Customer data such as billing and authentication details made up 46% of those flagged prompts, employee data like payroll and personal identifiers made up 27%, legal and finance material made up 15%, and security-related information made up another 6.9%, with the remainder spread across smaller categories.
Figure 2: Breakdown of the 8.5% of Q4 2024 prompts Harmonic Security flagged as sensitive. Source: Harmonic Security, "From Payrolls to Patents" report.
Cyberhaven's own measurement runs even higher: its 2026 AI Adoption and Risk Report, built on telemetry from 222 companies, found that 39.7% of all AI data movements, prompts, pastes, and file uploads combined, involved sensitive information. The gap between Harmonic's 2.6% and Cyberhaven's 39.7% comes down to scope: Harmonic counts confirmed sensitive-data instances flagged by content classifiers, while Cyberhaven's figure covers any data movement its platform tags as touching a sensitive category, a broader net.
Whichever number is used, sensitive data is a meaningful and growing share of what leaves the browser toward an AI tool, not an edge case. It is not just a browser-paste problem, either: our post on how many AI apps share data with third parties covers the same pattern showing up in mobile apps that quietly route data to a remote AI endpoint.
Which accounts do employees use to paste data into AI tools?
82% of GenAI pastes come from personal, unmanaged accounts rather than corporate-issued ones, according to LayerX's October 2025 telemetry, meaning the bulk of this activity happens entirely outside an employer's visibility, audit trail, or data-processing agreement. Only 18% of paste activity runs through accounts an IT or security team actually manages.
Harmonic Security's full-year 2025 dataset backs up the personal-account pattern from a different angle: of the 579,113 sensitive exposures it recorded, 16.9% flowed through personal free-tier accounts specifically, separate from the corporate-account share of the same tool. Free-tier and personal accounts typically carry the weakest contractual protection against a vendor using submitted content for future model training, which is precisely the account type carrying most of the paste volume this post is built around.
That gap between the accounts workers actually use and how much they say they trust AI systems with their data is worth reading alongside our post on how many people trust AI with their data, which covers the same disconnect from the consumer-trust side.
The account type someone uses to reach an AI tool, not just whether they use one at all, is the strongest single predictor of how much oversight that pasted data receives.
How often do employees paste data into AI tools?
Employees who paste data into GenAI tools do it multiple times a day, not as a rare event. LayerX's telemetry puts the average at 14 paste actions per day into personal, unmanaged accounts alone, with at least three of those daily pastes containing sensitive material. Cyberhaven's 2026 report frames a related but distinct measurement: across its full monitored population, the average employee inputs proprietary information into an AI tool once every three days.
The two figures are not directly comparable, LayerX counts paste events into personal accounts specifically, while Cyberhaven averages proprietary-data submissions across every account type and every AI interaction method, but both point to the same conclusion: this is routine, repeated behavior rather than an occasional lapse.
Figure 3: Four snapshots of the same underlying trend across three research vendors. Sources: Cyberhaven (2023, 2026), Harmonic Security (2024 data, reported 2025), LayerX Security (2025).
Frequency matters for risk exposure in a way a single incident does not: a workforce pasting data multiple times daily gives a policy gap far more opportunities to turn into an actual leak than a workforce that touches an AI tool once a month.
How has AI data-pasting risk changed since 2023?
Cyberhaven's earliest published analysis, based on telemetry from 1.6 million workers and first published in February 2023, found that 8.6% of employees had pasted company data into ChatGPT since its launch, and that 11% of everything employees pasted into the tool was confidential material. By the time Cyberhaven published its 2026 AI Adoption and Risk Report, built on telemetry across 222 companies, the sensitive-data share of all AI data movements had risen to 39.7%, more than a threefold increase in three years.
Two forces likely drive that growth: broader AI adoption means more total volume flowing toward these tools, and workers appear to be trusting AI tools with more sensitive categories of work than they did in 2023, when usage was still concentrated on lower-stakes tasks like drafting and summarizing. Free-tier AI tools generally reserve the right to use submitted prompts for model training unless a user opts out or a business signs an enterprise agreement that excludes training use, which is exactly the gap a current privacy policy needs to disclose if a business's own staff, contractors, or the tools embedded in its product route customer data toward a third-party AI vendor. A privacy policy generator that covers third-party data sharing and AI vendor disclosures keeps that gap from becoming an unstated one.
Figure 4: What happens to a pasted prompt depends almost entirely on the account type and vendor terms behind it. Source: LayerX Security, Enterprise AI and SaaS Data Security Report 2025, general vendor free-tier terms.
Enforcement of AI usage policy has not kept pace with adoption. Growth in the sensitive-data share of AI activity is the clearest single sign of that gap.
How do the major AI data-risk studies compare?
| Source | Metric | Figure | Year |
|---|---|---|---|
| LayerX Security | Share of GenAI users who paste data into prompts | 77% | 2025 |
| LayerX Security | Share of pastes from personal, unmanaged accounts | 82% | 2025 |
| Harmonic Security | Share of full-year prompts/uploads containing sensitive data | 2.6% | 2025 |
| Harmonic Security | Share of Q4 2024 prompts containing sensitive data | 8.5% | 2024 |
| Cyberhaven | Share of all AI data movements involving sensitive data | 39.7% | 2026 |
| Cyberhaven | Baseline share of ChatGPT pastes that were confidential | 11% | 2023 |
Source: LayerX Security (2025), Harmonic Security (2024-2025), Cyberhaven (2023, 2026).
The Bottom Line
Every study measures a slightly different slice of the same behavior, but they agree on direction: employees who use generative AI tools paste data into them constantly, most of that activity runs through personal accounts an employer cannot see, and the sensitive-data share of that traffic has grown sharply since 2023. The 77% paste rate LayerX measured among GenAI adopters is the clearest single number for the scale of the habit, and the 82% personal-account share explains why so little of it shows up in any corporate audit log. For a business handling customer data, the practical takeaway is that AI vendor usage, by staff, contractors, or embedded product features, is now a disclosure question a privacy policy needs to answer directly, not an edge case to leave out.
Frequently Asked Questions
What percentage of workers paste data into AI tools? 77% of employees who use generative AI tools paste data into GenAI prompts, according to LayerX Security's Enterprise AI and SaaS Data Security Report, published in October 2025 from telemetry across dozens of global enterprises.
How much of the data pasted into AI tools is sensitive? Estimates vary by methodology: Harmonic Security found sensitive information in 2.6% of the 22.4 million prompts and file uploads it analyzed across 2025, while Cyberhaven's 2026 AI Adoption and Risk Report put the sensitive-data share of all AI data movements at 39.7%.
What accounts do employees use to paste data into AI tools? 82% of GenAI pastes come from personal, unmanaged accounts rather than corporate-issued ones, per LayerX's October 2025 report, and Harmonic Security separately found that 16.9% of the sensitive exposures in its 2025 dataset flowed through personal free-tier accounts.
How has AI data-pasting risk changed since 2023? Cyberhaven's earliest tracking in 2023 found 11% of data pasted into ChatGPT was confidential; by its 2026 AI Adoption and Risk Report, 39.7% of all AI data movements involved sensitive information, more than a threefold increase in three years.
Where the Numbers Come From
- LayerX Security. (2025). "Enterprise AI and SaaS Data Security Report 2025." 77% of GenAI users paste data into prompts, 82% from personal accounts, telemetry across dozens of global enterprises, published October 2025.
- Harmonic Security. (2026). "What 22 Million Enterprise AI Prompts Reveal About Shadow AI in 2025." 579,113 sensitive instances across 22,458,240 prompts and file uploads analyzed through 2025, published January 2026.
- CSO Online, citing Harmonic Security's "From Payrolls to Patents" report. 8.5% of Q4 2024 employee prompts contained sensitive data, with a breakdown by category, published January 2025.
- Cyberhaven. (2026). "2026 AI Adoption and Risk Report." 39.7% of AI data movements involve sensitive data, telemetry across 222 companies, published February 2026.
- Cyberhaven. (2023). Baseline ChatGPT analysis of 1.6 million monitored workers: 8.6% had pasted company data into ChatGPT, 11% of pasted data was confidential, published February 2023, updated June 2023.
Note: All figures verified as of August 2026. Harmonic Security's Q4 2024 and full-year 2025 figures use different measurement windows and are not directly comparable to each other. This post's headline figures will be refreshed at least twice a year as newer vendor reports publish.