AGP Picks
View all

Security Leaders Underestimate AI Data Leaks by Nearly 3X, New Research Finds

Neon Cyber survey of U.S. security and IT leaders finds financial data leaking into AI tools nearly three times more often than security teams estimate

DALLAS, Aug. 31, 2026 (GLOBE NEWSWIRE) -- Neon Cyber, the AI-native browser security platform purpose-built to govern how today's workforce uses AI and SaaS, today published From Concern to Control: The Shadow AI Blind Spot, a research report based on a survey of 169 U.S. IT and security leaders fielded in May 2026. The report is a companion volume to Neon's earlier study, Quantifying Shadow AI Risk in the Browser, which surveyed more than 200 U.S. knowledge workers on their AI use.

One key finding is the gap between what security leaders believe workers are putting into AI tools and what workers admit to. Comparing the two surveys directionally:

  • 25.6% of knowledge workers reported pasting or uploading financial information into an AI tool, while security leaders estimated that only 8.9% of workers do so — a gap of nearly three times.
  • 20.3% of workers reported sharing sensitive or regulated data versus a 14.2% security estimate.
  • 13.2% reported sharing source code or scripts versus an 8.3% estimate.

The gap narrowed to roughly zero for credentials and API keys (11.0% reported by workers vs. 11.8% estimated by security and IT). As the one data category security teams instrument directly, any potential leakage would require their support in updating or rotating credentials and keys — giving them direct insight into how often that data is exposed.

"The categories where security is most wrong are the categories where being wrong costs the most," said Cody Pierce, CEO and Co-Founder of Neon Cyber. “Credentials are the one category where the estimate holds up, because it's the one category where security already has direct visibility. Financial data and source code don't have an equivalent. Closing that gap means putting that same kind of instrumentation where the activity actually happens: in the browser, at the moment of the paste."

That same blind spot shows up in how security leaders view their own visibility. Neon found that 69.8% of surveyed leaders claim event-level visibility into the AI tools their employees use. But among the leaders who hold that belief most strongly, three-quarters or more also believe employees are using AI tools anonymously — activity their own tools have no way of monitoring. 92.9% of all respondents acknowledged at least one blind spot in their AI observability.

"Security leaders aren't wrong about what their tools show them — they're wrong about what that coverage means," said Mark St. John, COO and Co-Founder of Neon Cyber. "Identity-based visibility can only ever show you sanctioned, authenticated activity. The moment an employee opens an incognito window or a personal account, that visibility disappears — and the data in this report shows most leaders already suspect that's happening, even while they report high confidence in their own coverage."

59% of surveyed leaders confirmed their organization has already handled an AI-related security incident in the past 12 months. Asked where they plan to invest over the next 12 to 18 months, security leaders named browser security as their top priority by a wide margin — 32.5%, ahead of AI gateways at 26.6% and every other category below 21%.

The Shadow AI Blind Spot is available now at neoncyber.com/reports/concern-to-control-the-shadow-ai-blind-spot.

About Neon Cyber

Neon Cyber is the AI-native browser security platform purpose-built to secure how today's workforce uses AI and SaaS: in the browser, where modern work happens. Neon delivers real-time visibility for the browser — every credential used, prompt input, link click and file upload — and enforces intelligent guardrails without disrupting productivity. Deployed in minutes, Neon gives security leaders the confidence to say "yes" to AI — without leaking customer or company data. Learn more at www.neoncyber.com.

Media Contact

Michelle Schafer
schafer@merrittgrp.com


Primary Logo

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

New Products Watch

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.