Skip to content

CyberGrant protects every aspect of your digital security

Discover the modular solutions designed to protect your company from external and internal threats, as well as new challenges like AI.

key-minimalistic-square-3-svgrepo-com

Digital asset protection

Automatic classification

Cloud encryption

Email protection

Anti-phishing

password-minimalistic-input-svgrepo-com

Remote access

Access rules

Credentials

Stolen Device

Web access

email grant

Post-send control

Protected Attachments

Human error

Advanced encryption

laptop-svgrepo-com (1)

Beyond Antivirus

External Threats

Data Exfiltration

Remote Work

Zero trust

pulse-svgrepo-com

Device control

Shared files

Audit Trail

Credential Access

Email Channel

Anomaly detection

password

Company vault

Controlled sharing

Zero-trust encryption

Logging and generation

share

Third-party users

RBAC

Anti-AI scraping

VDR

medal-ribbons-star-svgrepo-com

GDPR and encryption

NIS2

DORA

AI act

Audit

bot-svgrepo-com

AI control

Automated classification

AI blocking

Private AI

magnifer-bug-svgrepo-com

Attack Surface Mapping

Penetration testing

Ransomware

Human Factor

After the Test

Tailored cybersecurity for every business.
Scalable solutions compatible with legacy systems, designed for both SMEs and large enterprises requiring full control over data, access, and sharing.


IT
Consulting
Travel
Advertising

Construction
Real Estate

Oil & Gas
Electricity
Telco

E-commerce
Transportation
Shipping
Retail chains

Design
Automotive
Industrial

Central agencies
Local agencies
Supranational orgs

Discover security features to protect your data, files, and endpoints

FileGrant
FileGrant

Securely store, share, and manage your files with an advanced, easy-to-use, and highly customizable platform

 

SG_pittogramma_blu
SecretGrant

Control every credential like a file. Share, track, and revoke access instantly.

 

RemoteGrant
RemoteGrant

RemoteGrant protects your business from attacks and data loss by enabling employees to securely access workstations and files from anywhere.

 

EmailGrant
EmailGrant

Encrypt every email and keep control of attachments, even after sending.

 

AG_pittogramma_blu
AIGrant

AIGrant is your personal assistant - it understands your data, keeps it secure, and delivers exactly what you need.

 

Connector CyberGrant
Connector

Encrypts every file on SharePoint and OneDrive, in any format, leaving your libraries, permissions, and daily workflows untouched.

 

BlogHero_GretaNasi-1
CyberGrant TeamSep 21, 2026, 4:46:31 PM6 min read

Shadow AI and confidential data: why governance isn't enough

Shadow AI and confidential data: why governance isn't enough
5:57

An employee uploads a confidential document to ChatGPT. Not out of malice: to finish faster. Can any organization, public or private, withstand that scenario with the governance it has today?

Greta Nasi, Associate Professor at Università Bocconi and co-director of the MSc in Cyber Risk Strategy and Governance, answered that question at CyberGrant's Beyond the Perimeter event for CISOs and CIOs. Her take carries weight precisely because it comes from an independent perspective, one not tied to any single vendor.

 

Key takeaways

  • Employees uploading confidential data to consumer AI tools aren't behaving badly. They're responding rationally to a governance gap.
  • Organizations without clear AI use policies face data exposure that traditional DLP tools never catch, because the action looks legitimate from the outside.
  • "It's not a technology problem. It's an awareness problem," says Nasi. Technology handles the technical side. Without defined, simple, and enforceable rules, the organizational problem stays open.
  • Training and governance have to be designed together. You can't train people on rules that don't exist, and rules nobody understands don't get followed.
  • File-centric protection is the infrastructure that makes governance rules enforceable: data is protected at creation, regardless of which tool an employee uses to handle it.

 

Why it happens: urgency and the absence of rules

The question put to Greta Nasi at the event was specifically about public sector employees, but her answer immediately opened the frame.

"This applies to public employees, but also to anyone working in any organization," she said. "Usually, if someone does this, they do it for two reasons. One is urgency: the need to manage data and information faster, to move faster in general. But above all, they do it because there's no governance, there are no adequate policies and no adequate rules."

That diagnosis breaks a convenient but wrong narrative: the one that blames employee carelessness or weak security awareness. Someone who uploads a contract to ChatGPT usually knows it's risky. They do it anyway because the immediate benefit is concrete and the perceived cost is abstract. It's not incompetence. It's a misaligned incentive structure.

The Verizon Data Breach Investigations Report 2026 confirms the pattern: the human element is present in 68% of breaches, not as a sophisticated attack but as an error, a habit, or an operational shortcut. The Samsung incident in 2023, where three engineers uploaded proprietary source code to ChatGPT across separate weeks, is the documented proof of how this plays out at scale.

 

Not a technology problem

The sharpest part of Greta Nasi's answer addresses the category of problem organizations are actually dealing with.

"It's not a technology question. It's a question of awareness: not just of the benefits of technology, but also of the points of attention, because we don't use technology in an abstract context. We use it in the context of our personal lives and our organizations."

For a CISO, that translates directly: buying a DLP tool doesn't close the problem if employees don't know which behaviors are allowed and which aren't. Blocking ChatGPT doesn't close it if there's no governed alternative. Technology solves the technical problem. Governance solves the organizational one. Organizations that only have the first haven't solved anything yet.

This gap is especially visible in the public sector, where operational pressure is high, headcounts are often undersized relative to workloads, and consumer AI tools became daily productivity aids before any usage policies were written.

 

The fix: rules that are simple and actually enforceable

Greta Nasi closes with a prescription that applies equally to government agencies and large enterprises: "This requires, on one hand, training, and on the other, rules that are defined, clear, simple, and easily applicable."

The sequence matters. Training without rules is training on a void. Rules without training produce documents nobody reads. And rules that aren't simple and easily applicable get worked around, not out of bad faith, but because people take the path of least resistance.

This is where governance and technology have to meet. Rules work when the underlying infrastructure makes them easy to follow. A system that forces users through ten steps to share a file securely doesn't produce secure behavior. It produces people using WhatsApp to send confidential documents.

 

When technology backs governance up

Greta Nasi defines the requirement. File-centric technology provides the answer at the infrastructure level.

A file-centric approach protects data at creation. The document is encrypted the moment it's generated and stays encrypted wherever it goes: on a personal device, on an unsanctioned cloud platform, in a vendor's hands. If an employee uploads that file to ChatGPT, the content is unreadable. The rule "don't upload confidential data to consumer AI" is still necessary, but the cost of a violation drops from "data breach" to "non-compliant behavior."

CyberGrant's AIGrant takes it further: an on-premise RAG system that gives employees the same speed and simplicity as consumer AI, without the data ever leaving the organization. Per-department data segregation and zero-knowledge encryption mean the content isn't accessible even to the service provider. The rule becomes "use the company tool" instead of "don't use AI": a positive, simple, and enforceable instruction, exactly as Greta Nasi described.

File-centric protection doesn't replace governance. It makes governance more resilient: it builds the technical infrastructure that organizational policies can actually stand on.

 

Watch the full interview with Greta Nasi from CyberGrant's Beyond the Perimeter event.

Want to see how file-centric protection and private AI can work in your organization? Talk to the CyberGrant team.

 

Frequently asked questions

 

What is Shadow AI and why is it a risk for organizations?

Shadow AI is the use of AI tools that haven't been approved or governed by the organization: consumer ChatGPT, Gemini, Copilot, transcription and summarization apps. Employees use them because they're fast, accessible, and free. The risk is that data uploaded to these platforms leaves the organization, potentially feeds public models, and is no longer under organizational control. The Samsung 2023 incident, where proprietary source code was uploaded by three engineers across separate weeks, is the most documented example of how this mechanism works at scale.

Do public sector and enterprise organizations face specific AI compliance requirements in Europe?

Yes. AgID's guidelines on AI in the Italian public sector set constraints on using AI tools with personal or restricted data. The EU AI Act (Reg. 2024/1689) introduces tiered obligations by risk level, with the first deadlines already in effect for high-risk systems. On top of that, NIS2, transposed in Italy by Legislative Decree 138/2024, requires verifiable security measures for essential and important entities across both public and private sectors.

What does "enforceable AI governance" actually look like?

It means the rules on AI usage are written so an average employee can understand and follow them without legal advice. That includes: which tools are authorized, which data categories can't go into consumer AI systems, and what to do when someone needs to process sensitive data with AI support. Enforceable governance always comes paired with an alternative tool. Banning ChatGPT doesn't work if there's no company system offering equivalent functionality in a controlled environment.

How does an on-premise RAG system work?

A RAG (Retrieval-Augmented Generation) system on-premise is an AI that works on the organization's documents without sending data to external servers. All data stays inside the organization's own infrastructure. CyberGrant's AIGrant adds per-department data segregation (each team accesses only its own documents), zero-knowledge encryption (the content stays inaccessible even to the service provider), and full on-premise deployment. For government agencies and enterprises handling sensitive data, the difference between using AI and using AI securely comes down to exactly this.

Why does file-centric protection support organizational governance?

Because it protects data even when governance fails. If an employee violates policy and uploads a confidential file to an unsanctioned tool, the encrypted content is unreadable. The rule is still needed, but the consequence of a violation drops from a security incident to a compliance issue. Organizations with file-centric protection build governance on top of a technical foundation that holds even when human error enters the picture.

ARTICOLI CORRELATI