# Enterprise AI security: the OpenAI data CISOs cannot ignore

**Enterprise AI security** has become the number one priority for decision-makers. The figures set the scene: 1.2 million weekly conversations on suicidal thoughts, more than 700 companies compromised in a single breach, 97% of organisations without adequate AI controls. As 46% of Italian companies adopted artificial intelligence in 2025, against 12% in 2024 according to the EY Italy AI Barometer, security has not kept pace. The OpenAI case dismantles the illusion of AI that is safe by default.

## Why AI security is the new emergency

OpenAI published data that should trigger every red flag in boardrooms: every week, 1.2 million users — 0.15% of 800 million active users — hold conversations with ChatGPT containing explicit indicators of potential planning or intent of suicide. Another 560,000 show signs of psychosis or mania. For CISOs and CTOs this is not a public health problem to delegate to OpenAI. It is a concrete enterprise risk with immediate legal, compliance and reputational implications.

53% of large Italian companies already have ChatGPT or Copilot licences, according to the Artificial Intelligence Observatory of the Politecnico di Milano. The figure that should alarm every IT manager is another: 77% of employees copy and paste data into chatbot queries, and 22% of those operations include personal data or payment information protected by the GDPR. 82% of those accesses happen through personal accounts not managed by corporate IT. The operational translation is brutal: employees are already using ChatGPT with sensitive business data, probably without the company knowing. When one of them shows psychological distress during work sessions with company data, who answers the legal implications — the employer or OpenAI?

## Anatomy of an AI breach

In August 2025 an attack on the AI chatbot Drift, a provider later acquired by Salesloft, compromised more than 700 organisations in what Trend Micro calls a supply-chain attack via AI agent. The victims include Palo Alto Networks, Cloudflare, Zscaler and Proofpoint: the elite of global cybersecurity, on the wrong side of the barricade.

The attackers did not exploit sophisticated vulnerabilities. They stole OAuth tokens from an enterprise AI integration and gained access to the Salesforce instances of more than 700 customers, chatbot conversations with sensitive customer data, AWS and VPN credentials, cloud services and OpenAI API keys. The average compromise window was ten days, between 8 and 18 August, without any detection system raising significant alerts. According to the IBM Cost of a Data Breach Report 2025, AI-related incidents cost on average 670,000 dollars more than traditional breaches.

## The numbers of the emergency

IBM's 2025 report, covering 600 organisations between March 2024 and February 2025, shows a dramatically unprepared enterprise ecosystem. 13% of organisations suffered breaches of AI models or applications, and of those 97% had no AI access controls in place. The direct consequence: 60% of AI incidents involved data compromise, while 63% of affected organisations had no AI governance policy or were still developing one. A particularly alarming figure concerns shadow AI: 20% of breaches are caused by unauthorised employee use of AI tools. In Italy, according to Accenture, 56% of large European companies have not yet scaled a significant AI investment, and of those that have, only 19% have a mature data and AI strategy.

## The productivity-security paradox

Italian companies invest considerable sums: one in four allocates more than 675,000 euros a year to AI projects. 52% of top management sees tangible benefits in cost reduction and profit growth. But only 25% of companies have adopted adequate Data Loss Prevention controls for generative AI. The main concern remains security and data protection at 53%, followed by user experience at 40% and implementation costs at 32.5%. AI security is perceived as a priority but rarely translates into adequate investment.

## The OWASP Top 10 for LLMs

The OWASP Top 10 for LLM Applications identifies the most exploited criticalities in real attacks. Indirect prompt injection emerges as the primary vector: hidden instructions in external content that the chatbot processes as legitimate commands. Then come sensitive information disclosure, where error messages or unfiltered answers expose sensitive data, and system prompt leakage, which reveals the system's internal instructions. Excessive agency is particularly insidious: AI agents with more access privileges than necessary amplify the reach of a compromise. Improper output handling is the entry point for command injection when output validation is insufficient. In the FinOptiCorp case analysed by Trend Micro, attackers chained all five vulnerabilities to access customer databases, run system-level commands and compromise the whole microservices infrastructure in less than 48 hours.

## An operational framework

The first week should map the company's real AI sprawl: a complete inventory of officially approved tools and, above all, the shadow tools employees use on their own. The analysis should identify which departments and employees use AI, for what purposes, what data is processed — personal data, intellectual property, financial data, source code — and what share of use happens through personal accounts rather than centrally managed enterprise licences.

The minimum technical controls for the first weeks include IP allow-listing for critical AI endpoints, automatic rotation of OAuth tokens with a maximum cycle of seven days, monitoring of AI data consumption with behavioural baselines and automatic alerts on anomalous spikes, selective blocking of copy-paste into chatbots for specific categories of sensitive data through browser-based DLP, and multi-factor authentication covering all enterprise AI accounts without exception.

On governance, the AI usage policy must be written in clear language, approved jointly by Legal and the Data Protection Officer and distributed with mandatory acknowledgement. Data classification must state explicitly what can and cannot be entered into external LLMs. The AI-specific incident response plan should cover prompt injection, data leakage via chatbot and compromise of AI integrations.

In the medium term, a zero-trust architecture for AI requires clean segregation between personal accounts and enterprise licences, eliminating the BYOAI phenomenon that accounts for 82% of current vulnerabilities. Retrieval-Augmented Generation for enterprise chatbots anchors answers to verified knowledge bases. Dedicated data sandboxes with anonymised copies of production data allow experimentation without exposing critical assets. Continuous validation of deployed model integrity detects behavioural drift or malicious manipulation. The EU AI Act classifies business chatbots as limited-risk systems with transparency obligations, but when AI is used for HR decisions, credit scoring or algorithmic management of workers, the classification rises to high risk with strict documentation, testing and human oversight requirements. Sanctions reach 35 million euros or 7% of global annual turnover.

## Culture and continuous training

The EY data show that 74% of Italian managers know AI ethics frameworks, against only 47% of employees. The training programme must work on several levels: universal AI security awareness for all employees, advanced AI governance courses for IT and security teams, legal and compliance workshops on the AI Act, and quarterly red team exercises on enterprise chatbots. According to ISO/IEC 42001 standards, training accounts for 30% of the effectiveness of an AI security programme.

## The OpenAI case and the integration multiplier

OpenAI's 28 October 2025 announcement revealed that GPT-5 reaches 91% compliance on suicide-conversation safety protocols, with 170+ mental health experts consulted. What does the remaining 9% failure rate mean for enterprise security? That almost one time in ten, even the most advanced model does not respond appropriately in critical situations. Based on IBM data, fewer than 3% of Italian companies have done equivalent work on their own customer-facing or internal chatbots.

The Salesloft-Drift breach exposed an uncomfortable truth: enterprise AI chatbots are hyper-connected nodes that need access to CRMs, internal knowledge bases, customer databases, third-party APIs and other AI services, rather than standalone applications. Compromising a single chatbot means compromising the entire interconnected ecosystem. Attackers from the UNC6395 group accessed Salesforce data and harvested tokens for downstream services, multiplying the initial impact. Every integration is a new compromise vector, while OAuth and API tokens are worth more than traditional passwords because they grant direct access without further authentication challenges. Traditional SIEM monitoring struggles to distinguish legitimate AI consumption from exfiltration, creating dangerous blind spots.

## Cases worth remembering

In 2025 McDonald's exposed 64 million candidates through a recruiting chatbot with the password 123456, a basic security oversight that required GDPR notifications to 19 EU states and remediation costs estimated at 12 million euros. In 2023 Samsung suffered the leak of confidential code via ChatGPT by employees, responding with a total ban on generative AI and an opportunity cost estimated at 45 million euros a year. Also in 2023, Chevrolet's dealership chatbot was manipulated to sell a 76,000-dollar Tahoe for one dollar, an exemplary lesson on output control. These are paradigmatic examples, not edge cases, of what happens when security is treated as an afterthought.

## The point of no return in data exfiltration

The LayerX Enterprise AI Report 2025 confirms that AI has overtaken shadow SaaS and unmanaged file sharing as the main vector of corporate data loss. 45% of employees use generative AI, 77% copy and paste data, 22% include personally identifiable or payment information, and 82% use personal accounts. The security team has no visibility over this traffic. Traditional DLP tools are blind because they were built for sanctioned, file-based environments, not for the browser-native, conversational flows typical of AI.

## Reference frameworks

The NIST AI Risk Management Framework identifies autonomous misfire as a primary risk, where AI systems perform formally correct actions that are inappropriate for the real operating context. Applying CISA's Zero Trust Architecture to AI requires continuous identity verification throughout the session, micro-segmentation of AI access with least privilege, an assume-breach mentality and continuous monitoring for behavioural drift. ISO/IEC 42001 for AI management systems is becoming the de facto standard for enterprise procurement: companies that cannot demonstrate conformity risk exclusion from public tenders and critical B2B contracts.

## Awareness gap and the Italian market

The EY Italy AI Barometer shows a dangerous split: 59% of managers increased AI use against 39% of employees, 55% of executives see productivity gains against 33% of operational workers, and 74% of managers know AI ethics principles against 47% of employees. This top-down adoption without shared culture generates shadow AI, resistance, compliance gaps and ineffective incident management.

The Italian AI market reached 1.2 billion euros, up 58%, with 43% represented by generative AI. But only 7% of small companies have started projects, just 15% of medium companies are active, and more than 80% of the market is driven by large companies. According to Netskope, less than 5% of this investment goes to AI security. The SME fabric — 99% of Italian companies, 77% of employment — is largely unprotected while adopting consumer-grade AI without governance. The Italian enterprise supply chain includes thousands of subcontracting SMEs using free ChatGPT with sensitive client data.

## The attack landscape

The Adversa AI report on 2025 security incidents confirms that 70% of incidents involve generative AI, 35% are caused by simple prompts with no coding skills, while agentic AI causes the most dangerous failures among crypto theft, API abuse and legal disaster. Prompt injection becomes the SQL injection of the AI era. The difference is that no technical skill is required: anyone can manipulate a chatbot with natural language.

## Operating conclusions

The question is no longer whether to adopt AI, but how to implement enterprise AI security without becoming the next Salesloft case. The minimum checklist for CTOs and CISOs covers a complete assessment of AI sprawl, a written AI policy approved by Legal and the DPO, browser-based DLP controls, automated rotation of OAuth and API tokens, consumption baseline monitoring with spike detection, a tested AI-specific incident response plan, a gap analysis on AI Act compliance, AI security awareness training for 100% of employees, an active vendor AI due diligence framework and a board briefing on AI risk appetite.

The recommended budget: 15-20% of total AI investment should go to security and compliance. On the average Italian investment of 675,000 euros, that means 100,000-135,000 euros. Today most companies spend less than 5%, creating a protection gap that attackers are systematically exploiting. OpenAI, with infinite resources and the best AI researchers, reaches 91% compliance in critical scenarios after 170+ experts and months of work. A company that put an internal chatbot into production in three weeks with a team of two should ask whether it can implement adequate enterprise security without proportionate investment. 97% of breached organisations had no adequate security controls.

When data crosses a model, the obligations follow: [the EU AI Act compliance checklist](/en/ecorner/2025/eu-ai-act-compliance-checklist.html) turns the perimeter question into documented controls.

Protecting the model is not enough if the tunnel is the weak link, as [VPNs that became an entry point](/en/ecorner/2025/vpn-security-vulnerabilities.html) show.

## Frequently asked questions

**What is enterprise AI security?**
It is the set of technical, organisational and governance controls that protect company data and systems when artificial intelligence tools are used, including access management, data loss prevention, incident response and compliance with the GDPR and the AI Act.

**What was the Salesloft-Drift breach?**
An August 2025 attack on the Drift AI chatbot that compromised more than 700 organisations by stealing OAuth tokens. Attackers accessed Salesforce data, chatbot conversations, cloud credentials and API keys for ten days without detection.

**What is shadow AI and why is it dangerous?**
Shadow AI is unauthorised employee use of AI tools outside IT supervision. It causes 20% of breaches according to IBM and adds around 670,000 dollars to the average cost of a data breach, because the company has no visibility or control over the data involved.

**How much should a company invest in AI security?**
The recommended share is 15-20% of total AI investment. Most companies currently spend less than 5%, which leaves a protection gap attackers exploit.

## Sources

OpenAI mental health and safety report 2025 — https://techcrunch.com/2025/10/27/openai-says-over-a-million-people-talk-to-chatgpt-about-suicide-weekly/
IBM Cost of a Data Breach Report 2025 — https://www.ibm.com/reports/data-breach
The Hacker News — Salesloft Drift OAuth breach affecting 700+ organisations — https://thehackernews.com/2025/08/salesloft-oauth-breach-via-drift-ai.html
Cloudflare — response to the Salesloft Drift incident and UNC6395 — https://blog.cloudflare.com/response-to-salesloft-drift-incident/
OWASP Top 10 for Large Language Model Applications — https://owasp.org/www-project-top-10-for-large-language-model-applications/
NIST AI Risk Management Framework — https://www.nist.gov/itl/ai-risk-management-framework
ISO/IEC 42001, AI management systems — https://www.iso.org/standard/42001
LayerX, Enterprise AI Report 2025 — https://layerxsecurity.com
