Key findings:
Everyone is a developer now.
HR, marketing, sales, and operations teams are building automated workflows and lightweight apps with AI, without traditional security review.
Five well-intended prompts, five real exposures.
Common prompts that quietly expose employee data, customer records, source code, and access to connected systems.
Shadow AI becomes shadow risk.
82% of organizations report unknown or unmanaged AI usage (Cloud Security Alliance).
A safer approach for each.
Least-privilege access, PII sanitization, secret/token removal, and security gating before prompts reach production.
If your teams are building with AI faster than security can review, this cheat sheet is for you.
Most employees aren’t trying to bypass controls, they’re solving problems quickly with powerful new AI capabilities. But AI tools make it easy to connect systems, upload information, and create workflows at a speed most security processes weren’t designed to handle. The question is no longer “Are employees using AI?” It’s “Do we understand what those AI workflows can access?”
Inside the cheat sheet: the five prompts
- “Connect our AI assistant to Slack, Google Drive, email, and our CRM.” Broad, ungoverned visibility across systems and data sources. Risk: excessive permissions, lateral exposure across business systems, unclear data-access scope.
- “Summarize these customer contracts and highlight any important terms.” Confidential agreements and customer information uploaded into external systems. Risk: exposure of legal language and sensitive data.
- “Build me a quick HR portal that pulls employee information from our systems.” Employee records, compensation, and performance data flow into an AI system. Risk: PII exposure, privacy/regulatory concerns, long-term retention uncertainty.
- “Paste this code and tell me why it isn’t working.” Internal APIs, credentials, architecture details, and proprietary code become part of prompts or apps. Risk: source code and API leakage, exposure of secrets, IP risk.
- “Connect this AI tool to all of my accounts so it can access everything it needs.” Overprivileged access far beyond the task. Risk: expanded attack surface, unauthorized access and escalation.
By the numbers:
82% of organizations report unknown or unmanaged AI usage (Cloud Security Alliance).
5 well-intended prompts analyzed, each with a real, unintended exposure path.
1 cautionary tale: an over-eager HR vibe coder who exposed all co-workers’ sensitive data.
4 safer-approach controls: least privilege, PII sanitization, secret removal, and security gating.


