Skip to content
  • Home

  • Business growth

  • Business tips

Business tips

5 min read

79% of workers have entered sensitive info like logins into AI

By Lane Gillespie · July 29, 2026
Icon of a lock against a beige, dotted background.

As a species, we don't always approach workplace software with the cool diagnostic rigor of a Scandinavian TV detective. In the '90s, some companies learned the hard way that the photocopier they had just sold actually retained compressed images of every job it had ever done. More recently, I discovered that I'm not immune to suspicious email links, which was humbling for me and presumably delightful for the sender. But otherwise, I tend to assume that the tech I use at work has been thoroughly vetted by the higher-ups.

AI chatbots and related tools complicate that assumption. Corporate America has been gung-ho about AI, but it hasn't brought all employees up to speed on how to use it safely. The result is that many employees may be playing fast and loose with company data. 

Nearly all (89%) workers have entered company data into AI. Sometimes that's just a workplace address or phone number, but 79% have entered especially sensitive information, such as HR data, logins, and API keys, or customer/employee personally identifiable information (PII).

It's ok for some workers to enter some of this information into some types of AI tools. But doing that comes with certain risks that leadership teams and employees should be aware of. We surveyed 1,005 U.S. workers at companies with 500 or more employees to understand how business data is being handled in the age of AI.

Key findings:

  • 31% of workers say they enter login credentials or API keys into AI

  • 50% of workers have ignored their workplace's AI restrictions

  • 36% of workers aren't fully confident they know what's ok to share with AI

31% of workers say they enter login credentials or API keys into AI

Most of us know not to keep work passwords on a sticky note on our desks. And yet, the vast majority of people have entered sensitive information into AI. While not all that information is confidential, 79% of workers have entered everything from customer or client names to login credentials, financial data, and Social Security numbers. Here were the most common culprits:

  • Employee info, like performance reviews or salaries: 37%

  • Customer or employee PII, like IDs and Social Security numbers: 36%

  • Customer/client names, email, and contacts: 36%

  • Login credentials and API keys: 31%

The problem here is that this sensitive information is highly valuable to companies, customers, clients, and hackers. This is a known risk: hackers are using company-created AI agents to steal logins and other sensitive information. 

Nearly three-quarters (72%) of respondents said they were worried about their organization experiencing a problem—like data exposure, compliance problems, or improper use of sensitive information—due to employees' AI use. And those concerns are far from unfounded.

The point isn't that sensitive data can never be used with AI. Many employees need it to do normal, legitimate work. The point is that data shouldn't be poured into unsecured AI tools or accessed through AI under circumstances where access should be narrow, logged, and governed. Because "we had no idea this was happening" is generally a poor opening line in a compliance review.

Most compliance failures start with good intentions and poor tooling. When employees feel like they have to paste customer data or login credentials into an AI to get their job done, that's an infrastructure problem. Zapier gives your AI workflows a governed access layer: credentials stay out of the model entirely, permissions are scoped per connection, and you can see and revoke what your agents can access from one place.

50% of workers have ignored their workplace's AI restrictions

When companies provide AI licenses to staff, they should have clear governance policies explaining which tools to use, what's allowed, and what happens when people decide the rules are more of a suggestion than a requirement. If there aren't any consequences for ignoring company-provided accounts, some employees will predictably wander off into the wilderness of personal tools.

Around 1 in 4 (26%) workers say their organization restricts or blocks certain AI tools, but they've used a personal device or account to access the tools anyway. A similar percentage (24%) says they've tried to get around AI blockers with other workarounds, such as copying data into a personal tool or using a different browser. 

Not everyone using their own AI account for work is trying to perform a workplace heist. In many cases, they simply dislike the tools they were given. Among people using personal AI accounts for work:

  • 53% say they prefer their own tools' interfaces or experiences

  • 39% say it's too difficult or slow to get an employer-provided tool

  • 35% are infrequent AI users and don't see the need for a work account

  • 33% say their employer's AI tools don't fit their needs

But around 2 in 5 (43%) of people using personal accounts say they want to keep their AI usage private from their employer.

Shadow IT thrives when official tools feel like a punishment. By giving people AI that actually works, inside a governance layer IT can trust, everyone wins. With Zapier, you connect your AI tools to the apps your org already runs on: permissions are scoped per connection, access is revocable from one place, and no credentials are floating through personal chat threads. That means employees won't have to choose between doing their job well and following the rules.

36% of workers aren't fully confident they know what's ok to share with AI

The majority (85%) of employees say they usually consider whether information is safe before entering it into AI, which suggests most people aren't blindly firing off Social Security numbers into ChatGPT. More likely, many simply don't know what's safe, what's risky, and what their company would like them to stop doing immediately. Someone who doesn't know what an API key even is probably won't hesitate to drop it in an AI chat.

36% of workers aren't fully confident they know what's acceptable to share with AI at work, and—as we saw—even more are sharing sensitive information with AI tools that may not be safe. 

The good news: training helps. The majority (82%) of people who feel fully confident about what's ok to share with AI tools received formal training on AI use for work. That's compared to only 46% of people who aren't very sure—a pretty stark difference.

But training alone isn't enough if people continue to share unsafe information or actively work around AI restrictions. Organizations need governance baked into their AI systems from the start, not smeared on later like decorative frosting over a structural crack. That means policies, approved tools, access controls, monitoring, guardrails, and workflows that make the safe path the easy path.

How companies can build strong AI governance

It's easy to say "build an AI governance system" with the confidence of someone who won't personally attend the implementation meetings. Creating new guidelines takes time and effort. But companies can start improving governance now with a few practical moves.

  • Don't assume your staff completely understands AI governance and safety. Start with the basics when hiring new employees and building training procedures. Explain how your team uses AI, which tools are approved, and exactly what kinds of data can and cannot be used. ("Use your judgment" is not a policy.)

  • Learn how your staff uses AI and ask if they have the right tools to do their jobs. Audit AI usage where appropriate, or simply ask employees how they use AI day-to-day. What works? What slows them down? What are they solving with personal tools that the company should probably know about? The shadow workflow is often just an unmet need with a burner account.

  • Look for guardrails you can add to your existing workflow before building everything from scratch. There are likely checks and balances you can introduce into the tools employees already use. Zapier's AI Guardrails, for example, can analyze text in real time and evaluate it for common security risks, including PII, prompt injections, or toxic content. And because it's built into Zapier, teams can create safeguards quickly rather than waiting for a 12-month governance odyssey.

Humans are going to be human, so there's no way to eliminate every possible security risk on your team. But you can make the secure path the easy path. When AI workflows are built on a governed infrastructure like Zapier, employees don't have to choose between the tool that works and the tool IT approved. Credentials stay out of the model, permissions are scoped and revocable, and the workflows your team uses are the ones your organization can see. Zapier makes it easier to grow AI capabilities with security and guardrails in place, so teams can do better work without accidentally producing a PR incident.

Try Zapier
Methodology

The survey was conducted by Centiment for Zapier. The survey was fielded between May 13, 2026, and May 21, 2026. The results are based on 1,005 completed surveys. To qualify, respondents were screened to be U.S. workers at companies with 500 employees or more. All work at companies that have provided employees with paid plan access to AI tools or services for business tasks (including but not limited to ChatGPT Enterprise, Claude for Business, OpenAI/Anthropic/Google Cloud APIs, etc.). Data is unweighted, and the margin of error is approximately ±3% for the overall sample with a 97% confidence level.

Related reading:

  • AI governance: What it is and why it's important

  • How to build safe and trustworthy AI agents with Zapier

  • AI transformation is a problem of governance. Here's how to address it

  • AI security risks: 7 threats and how to manage them

Get productivity tips delivered straight to your inbox

We’ll email you 1-3 times per week—and never share your information.

tags

Related articles

Improve your productivity automatically. Use Zapier to get your apps working together.

Sign up
See how Zapier works
A Zap with the trigger 'When I get a new lead from Facebook,' and the action 'Notify my team in Slack'