Safety

AI-generated text

Companies urged to use local or hybrid AI as public tools risk leaking sensitive data

A Cyberhaven telemetry study found 39.7% of data uploaded to public AI tools contains sensitive information, raising security and compliance concerns for firms.

Companies urged to use local or hybrid AI as public tools risk leaking sensitive data

A Cyberhaven telemetry study found that 39.7% of data uploaded to public AI tools contains sensitive information. SeaCon Europe experts warn this uncontrolled use of public AI creates both significant cybersecurity risks and potential legal and compliance issues as the EU's AI Act tightens requirements.

What risks do companies face?

Gábor Berkovich, CEO of SeaCon Europe, says employees often assume provider privacy settings and guarantees are sufficient protection. In practice, uncontrolled sharing of corporate data can lead to strategic disadvantages or the leakage of trade secrets.

Berkovich notes that if personal data has already been exposed through security failures, protecting companies' strategic information requires at least as much caution. He argues that policies alone are not enough and that data protection must be enforced at the technological level.

Regulatory expectations and compliance

The European Union's AI Act establishes a comprehensive framework for developing and deploying artificial intelligence and is being phased in. Berkovich highlighted that an AI-literacy obligation took effect in February of last year, requiring employees who use AI to have appropriate knowledge of how the technology works and its risks.

Companies must be able to document and demonstrate that AI usage is controlled from organizational and technical perspectives. Transparency is a key element: firms need to track what data the AI uses, who has access, what operations the system performs, and which sources underpin particular outputs.

Local and hybrid AI infrastructure as a solution

SeaCon Europe recommends local or hybrid infrastructure as a mitigation strategy. In a local model, the AI runs on the company’s internal network on GPU-equipped hardware, allowing sensitive data to be processed without internet connectivity. In a hybrid approach, cloud services can still be used for non-sensitive tasks while confidential processing remains on closed infrastructure.

A validated internal knowledge base is central to this approach. SeaCon gives the example that producing a 1,000-page software documentation set once required weeks of manual engineering work, whereas a local AI can generate such documentation in hours without the data leaving the corporate environment.

Use cases and benefits

Local AI can also correlate internal system logs quickly: for example, it can match VPN logins with file movements and flag unusual remote downloads within minutes. Managers can query their databases in natural language to get rapid insights into process trends, and source-code optimization or vulnerability scanning can be performed without the code leaving company servers.

SeaCon IntrAI is presented not as a simple chatbot but as a controlled enterprise AI environment that relies on a validated knowledge base built from the company’s own documents. The AI does not receive automatic administrator privileges and can only access data a given user is authorized to view. All data movements and operations can be logged and audited, enabling verification of which sources contributed to a given answer while reducing dependence on external cloud AI providers and their changing terms.

Human oversight and economic return

Alongside technological controls, human oversight remains important: AI should automate repetitive, time-consuming tasks, while final professional and critical decisions should stay with human experts.

Szabolcs Varga, SeaCon Europe’s business development director, says local AI infrastructure can be attainable for SMEs. For companies with annual revenue around HUF 100 million or with 10–50 employees — such as accounting firms, law offices, or engineering firms — a well-implemented investment can pay back quickly. Such systems can typically free up the equivalent of 0.5–2 full-time employees by automating administrative processes.

Final thoughts

SeaCon Europe’s leadership stresses that the coming period will be defined by the quality and auditability of the knowledge used by corporate AI systems. Their aim is for Hungarian companies to use controlled AI tools built on verified corporate knowledge, keeping sensitive information as secure as possible within their own environments.