>gabes/the letter
warningthursday2026-07-09

the biggest data leak in your company this year has no attacker in it.

it is your own people, pasting the confidential parts into a chatbot on a personal login.

the dangerous data movement inside your company is not a hacker. it is your own team pasting client lists, contract terms, and half-written strategy into whatever chatbot is open: seventy-seven percent of employees do it, and eighty-two percent of those pastes run through personal logins your company cannot see, review, or wipe. that is why security teams now rank general ai as the single largest channel for corporate data leaving the building, ahead of email and file storage. the linkedin expert's answer is a ban and a policy template he will sell you for nineteen dollars: block the domain, send the memo, add a line to the handbook nobody reads. the ban does exactly one thing: it moves the same paste to a phone, where you have less visibility than when you started. a policy is not a control; it is a paragraph. do this instead: give people one sanctioned account with a short, literal rule about what never gets typed in, covering client identifiers, credentials, anything under nda, and route the work that actually needs company data through a system you control, so the useful part does not depend on someone remembering a handbook at 5pm on a friday.