To work faster and better, employees often put business information into AI tools, invariably sending sensitive data outside an organisation's controlled environmentImagine accounting employees at a listed company who have to extract insights from quarterly financial statements. Instead of manually analysing the numbers, they upload the file to an AI tool and ask it to identify the key trends.Similarly, customer support executives who have, say, numerous complaints in a folder and want to identify recurring issues upload the files to an LLM and ask it to categorise them. Now, that file may have customers’ names, purchase information, addresses and phone numbers too.In their minds, the executives are being efficient and productive by reducing the turnaround time. Rishi Agrawal, co-founder and CEO of TeamLease Regtech, a leading regulatory technology company, however, cautions that this practice could turn into a huge compliance problem for firms.In the chase to work faster and better, employees often put a lot of business information into AI tools to summarise/analyse, without realising that in the process a lot of sensitive information goes outside their organisation's controlled environment, explains Agrawal. “What looks like a simple productivity shortcut can, therefore, create a data protection, confidentiality, intellectual property, cybersecurity or regulatory exposure, creating data governance risk for organisations,” he says.Organisations usually have strict controls around how company’s information in email, cloud storage, USB drives and third-party vendors moves, but AI tools are outside them all. In fact, a single prompt in AI by an employee can become a new route for information to go outside the organisation.The information being uploaded could be personal data, unpublished financial information, a customer's confidential information, source code, a trade secret, a board paper, an acquisition plan or a draft regulatory response. Moreover, companies don’t have any visibility into what information the employee has submitted, where it was processed, how it was retained or who could access it.THE STAKES ARE HIGHUnder the Digital Personal Data Protection Act, 2023, for instance, personal data may be processed only for a lawful purpose and based on consent or a specified legitimate use. There is also a requirement of reasonable security safeguards to prevent a personal data breach. Otherwise, there are stricter penalties of up to Rs 250 crore in case of the company’s failure to take reasonable security safeguards.But, for instance, if an HR employee, say, uploads a provident fund challan, which usually contains an employee's name, salary, UAN (Universal Account Number), PAN (Permanent Account Number), bank details or other identifiers, onto an external AI tool, the organisation has potentially created a new processing activity involving personal data.The risk gets even more serious when the information is not personal data but unpublished price-sensitive information and has been uploaded to an AI system. The Prohibition of Insider Trading Regulations of the Securities and Exchange Board of India (SEBI) restricts an insider from communicating, providing or allowing access to unpublished price-sensitive information, except where utmost necessary.Further, if this information is communicated outside the permitted framework, it can create exposure under the insider-trading regime. If the information is subsequently traded upon in circumstances covered by the law, the consequences become much more serious.Agrawal says that in such cases, “the employee uploaded it” is not, by itself, a defence. It raises various compliance questions for the company. Was this AI service authorised? Was the processing permitted? Were appropriate contractual and security controls in place?If an organisation has no approved arrangement governing that AI provider, no clear purpose for the additional processing, no security controls and no way of knowing what happens to the information after it is submitted, the employee has effectively created an external data-processing workflow without the organisation necessarily having designed or approved one. This is the uncomfortable gap between AI adoption and AI governance, explains Agrawal.The result could be a claim for damages, an indemnity claim, termination of a commercial relationship or an injunction. For source code or proprietary technology, the exposure could primarily be around intellectual property and confidentiality. For customer information inside the contract, digital personal data protection (DPDP) obligations may be added to the mix. One document can, therefore, trigger several compliance regimes at once.WHAT SHOULD ORGANISATIONS DO?Prohibiting employees from using public AI tools may not work as AI is becoming part of everyday knowledge work, and a blanket prohibition could simply push usage underground, making it harder for organisations to see, control or investigate. What organisations need, says Agrawal, is a formal AI usage policy with practical guardrails. It should answer a simple question for employees before they press enter: can I put this information into this AI tool?Agrawal has some key recommendations for organisations:* Create a simple ‘green-amber-red’ data frameworkOrganisations can create different categories so employees are able to decide in seconds whether they can use AI for a particular purpose or not.Green (permitted): Public information, publicly available regulatory documents, generic brainstorming and non-confidential content.Amber (restricted): Internal business information, internal presentations and aggregated or anonymised datasets. These should only be used through approved enterprise AI tools and subject to defined controls.Red (prohibited): Personal data, customer and employee records, UPSI (unpublished price sensitive information), unpublished financial information, credentials, source code, trade secrets, confidential contracts, regulatory inspection material and sensitive M&A (mergers and acquisitions) information.* Define approved AI tools and use casesCompanies should specify which AI tools employees can use. This should sit alongside existing data-security and third-party vendor controls. An employee should not have to decide independently whether a public AI service is appropriate for handling company information.* Distinguish between free, paid and enterprise AI versionsAI usage should happen within an organisationally controlled environment rather than through individual, unmanaged accounts. Hence, the approved tool framework should specify not only which AI platforms are permitted but also which version, account type or deployment is authorised for each category of information.For example, an organisation could permit:Free/consumer AI: Only for publicly available-category information and generic brainstorming.Paid/professional AI: Only where the organisation has assessed the provider's terms and controls and expressly approved the use case.Enterprise/business deployment: For approved internal information, subject to access controls, data classification, retention and monitoring requirements.Prohibited-category information: Prohibited from being entered into external AI platforms altogether, irrespective of whether the account is free, paid or enterprise.* Build awareness around real decisionsTraining shouldn’t simply tell employees to “use AI responsibly”. It should put them in situations they actually encounter.* Keep human accountability around AI use and outputsAI can assist but employees should remain accountable for what they submit or act upon. Organisations should define when human review is mandatory, particularly for regulatory filings, financial analysis, legal documents, HR decisions and customer communications.* Create a simple process for mistakesOrganisations should assume that employees will occasionally upload something they should not. The policy should, therefore, provide a clear escalation mechanism: stop, report, contain, assess and remediate. The organisation should be able to determine what information was shared, which tool received it, whether personal data, UPSI or confidential information was involved, and whether any regulatory or contractual action is required.Subscribe to India Today Magazine- EndsPublished By: Shyam BalasubramanianPublished On: Sep 2, 2026 19:09 IST
How AI prompts are becoming a compliance risk for companies
Full Article
Original Source
Read the full article at Indiatoday →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.