-

1 in 12 Employees Use at Least One Chinese GenAI Tool at Work Reveals New Analysis of 14,000 End Users

Harmonic Security identifies widespread, unsanctioned use of high risk GenAI tools including DeepSeek, Moonshot Kimi, Manus, Baidu Chat, and Qwen

LONDON & SAN FRANCISCO--(BUSINESS WIRE)--Harmonic Security has today released new research revealing widespread use of Chinese-developed generative AI (GenAI) applications within the workplace. The behavioral analysis, conducted over 30 days across a sample of approximately 14,000 end users in the United States and United Kingdom finds that 7.95%, or nearly one in 12 employees used at least one Chinese GenAI tool.

Among the 1,059 users who engaged with Chinese GenAI tools, Harmonic Security detected 535 incidents of sensitive data exposure. The majority of exposure occurred via DeepSeek, which accounted for roughly 85% of the total, followed by Moonshot Kimi, Qwen, Baidu Chat and Manus.

In terms of what sensitive data was exposed, code and development artifacts represented the largest category, making up 32.8% of the total. This included proprietary code, access keys, and internal logic. This was followed by mergers & acquisitions data (18.2%), personally identifiable information (PII) (17.8%), financial information (14.4%), customer data (12.0%), and legal documents (4.9%). Engineering-heavy organizations were found to be particularly exposed, as developers increasingly turn to GenAI for coding assistance, potentially without realizing the implications of submitting internal source code, API keys, or system architecture into foreign-hosted models.

Alastair Paterson, CEO and co-founder Harmonic Security comments: “All data submitted to these platforms should be considered property of the Chinese Communist Party given a total lack of transparency around data retention, input reuse, and model training policies, exposing organizations to potentially serious legal and compliance liabilities. But these apps are extremely powerful with many outperforming their US counterparts, depending on the task. This is why employees will continue to use them but they’re effectively blind spots for most enterprise security teams.”

Paterson continues: “Blocking alone is rarely effective and often misaligned with business priorities. Even in companies willing to take a hardline stance, users frequently circumvent controls. A more effective approach is to focus on education and train employees on the risks of using unsanctioned GenAI tools, especially Chinese-hosted platforms. We also recommend providing alternatives via approved GenAI tools that meet developer and business needs. Finally, enforce policies that prevent sensitive data, particularly source code, from being uploaded to unauthorized apps. Organizations that avoid blanket blocking and instead implement light-touch guardrails and nudges see up to a 72% reduction in sensitive data exposure, while increasing AI adoption by as much as 300%."

The data for this analysis was collected using insights from Harmonic Security Protect, which monitors user behavior around SaaS-based GenAI apps. All data was anonymized and sanitized prior to analysis. The dataset included file upload volumes, app usage frequency, and prompt-level detections of sensitive content exposure.

To read the full report, please go to: http://www.harmonic.security/resources/code-red-analyzing-chinese-based-app-use

About Harmonic

Harmonic Security lets your teams adopt AI tools safely by protecting sensitive data in real time with minimal effort. It gives you full control and stops leaks so your teams can innovate confidently.

For more information, visit https://www.harmonic.security/

Contacts

Harmonic Security


Release Versions

Contacts

More News From Harmonic Security

UK Industry, Government and Tech Leaders To Gather for the Inaugural UK Cyber Flywheel Event

LONDON--(BUSINESS WIRE)--Harmonic Security today announced the launch of UK Cyber Flywheel, a one-day event dedicated to boosting the UK’s cyber security startup sector. Taking place 9 October at the National Theatre, London, the event will convene senior government officials, cyber security founders, investors, and top CISOs to chart how the UK can seize market leadership in emerging cyber security areas including secure AI adoption and cyber resilience. Amongst those taking to the stage inclu...

22% of All Files and 4.37% of Prompts Submitted to GenAI tools by Employees Contain Sensitive Data

LONDON & SAN FRANCISCO--(BUSINESS WIRE)--Organizations are leaking data at a staggering rate according to new analysis from Harmonic Security conducted on a sample of 1 million prompts and 20,000 files submitted to 300 GenAI tools and AI-enabled SaaS applications between April and June. Of these numbers, 22% of files (total 4,400) and 4.37% of prompts (total 43,700) contain sensitive information - this includes source code, access credentials, proprietary algorithms, M&A documents, customer...

Harmonic Is Recognized as a Representative Vendor for Data Loss Prevention by Gartner®

LONDON & SAN FRANCISCO--(BUSINESS WIRE)--Harmonic Security has been recognized by analyst firm Gartner and listed among 20 ‘Representative Vendors in Data Loss Prevention’. The report states that ‘today, the DLP market is evolving to address the well-known limitations of traditional approaches to DLP, which relied heavily on resource-intensive, data-centric content inspection and often led to performance issues with high numbers of false positives.’ Instead, the firm notes that ‘the DLP market...
Back to Newsroom