The rapid adoption of artificial intelligence in workplaces is creating a growing risk of sensitive information being exposed, according to an Icelandic cybersecurity specialist.
Employees across both the public and private sectors are increasingly relying on AI tools to assist with their work, often without fully understanding what happens to the information they upload. That can result in confidential, commercially valuable, or even nationally sensitive data leaving secure environments and becoming accessible to third-party AI providers.
What’s the Story?
Original source: RÚV
- AI use in workplaces is growing rapidly, with experts estimating that around two-thirds of employees now use AI tools in some capacity.
- Cybersecurity specialists warn that staff may inadvertently upload sensitive information to external AI platforms.
- The practice, known as “shadow AI” when employees use personal accounts rather than approved workplace systems, is becoming a widespread concern.

“Shadow AI” Risks
Ýmir Vigfússon, who holds a doctorate in computer science and serves as Chief Technology Officer at Keystrike, said many workers are unaware that information entered into AI systems may be stored and used beyond its original purpose.
“Once the data has been entered into an AI application, the danger begins,” he said.
Ýmir noted that many people interact with AI without even realising it, citing search engines that increasingly generate AI-powered responses. Documents uploaded to AI platforms can be retained by technology companies and potentially used to improve future models.
He warned that information intended to remain confidential could later appear in unexpected contexts, creating what amounts to a data leak.
Microsoft estimates that around 75% of employees use AI at work, while 78% access AI tools through personal rather than employer-managed accounts, according to Ýmir. This use of unauthorised platforms is commonly referred to as shadow AI.
Security Struggling to Keep Pace

While AI adoption continues to accelerate, Ýmir argues that security measures and governance frameworks are lagging behind.
“Employees are not going to stop using AI,” he said. “We simply need to find ways to ensure that it is used safely.”
He also warned that criminals are increasingly exploiting AI technologies for fraud, cyberattacks, and other malicious purposes. Rather than attempting to halt development, he said organisations must focus on using the technology responsibly while protecting sensitive information.
Asked whether AI possesses a moral compass, Ýmir was sceptical.
“AI can pretend to have morals by imitating the material it has been trained on, but it is a very thin mask,” he said.
Read more stories covering Icelandic society, politics, business, and culture at Iceland Review News.


