What is data leakage through AI prompts?
Data leakage through AI prompts occurs when someone submits confidential, personal, proprietary, or security-sensitive information to an AI system and that information is stored, processed, exposed, or reused outside the organization’s intended controls.
The prompt may be a question typed into a public large language model (LLM), a file uploaded for analysis, a message sent to an AI-enabled SaaS feature, or context automatically collected by an AI coding assistant. The user may not realize that the prompt contains sensitive information or understand what happens after submission.
An employee might ask an AI tool to summarize a customer complaint and include the entire ticket, internal notes, hostnames, and authentication logs. A developer might paste a code error containing an API key. An analyst might upload a security export to an online visualization service. The security question is not only what the AI produces. It is also where the input goes, who can access it, how long it is retained, and what systems the AI tool can reach.