Every copy-and-paste into an AI tool carries the risk of compromising company’s security: Forum
Source: Straits Times
Article Date: 30 Sep 2026
The core challenge is not simply employee negligence. It is whether organisations have given employees a safe and practical way to use AI, says the writer.
Every morning, employees across the world open a browser tab and quietly paste valuable corporate data into public AI tools.
They aren’t bad actors. They are overstretched staff summarising presentation slides, developers entering proprietary code to diagnose bugs, and managers drafting sensitive documents. In the relentless pursuit of productivity, the simple copy-and-paste command has become an unmonitored exit point for confidential information.
This reality frequently comes up at Kopi Meet Up, a monthly gathering I founded for security professionals to exchange insights. While organisations race to harness generative AI, many are still struggling to manage its underlying security implications.
The core challenge is not simply employee negligence. It is whether organisations have given employees a safe and practical way to use AI. They must move beyond dense policy documents that sit unread on intranets. Secure AI usage must become an intuitive, frictionless part of everyday work.
Three shifts are required.
First, staff need context, not generic prohibitions. They need clear examples of what may be entered into an AI tool, when identifying details must be removed, and when they should seek approval.
Second, organisations should provide sanctioned platforms with appropriate access controls, supplier assessments and safeguards for sensitive data. These tools must be sufficiently useful and accessible for employees to choose them over public alternatives.
Third, AI risk cannot belong solely to the chief information security officer. Legal, human resources, procurement and business leaders must share responsibility. If employees feel compelled to bypass security controls to meet a key performance indicator, that signals a wider organisational problem, not merely an IT failure.
As Singapore strengthens its position as a trusted global digital hub, its advantage will not be defined by how quickly we adopt AI, but by how securely we govern it. Trust is earned in the space between innovation and oversight.
Before an employee hits “Enter” on a public AI prompt window, leaders need to ask: When that data crosses the threshold, who is accountable for protecting it? Without that clarity, every copy-and-paste carries the risk of compromise.
Ong Wei Yuan
Source: The Straits Times © SPH Media Limited. Permission required for reproduction.
2