IP Leak: Your HR Strategy Is Now GenAI's Training Data
- By DWFTrends editors
- October 08, 2025

The integration of GenAI into daily workflows directly challenges the responsibilities of Chief Human Resources Officers (CHROs) for policy and compliance. A new Josys report, "Australia’s Shadow AI Crisis 2025," reveals that over one-third of Australian professionals are regularly uploading sensitive company data into unauthorized AI platforms, often without any formal oversight.
This surge in "shadow AI", where employees or even departments use unsanctioned tools that bypass security protocols or procurement policies, is exposing organizations to serious data leakage and regulatory compliance risks.
Critical data exposure and visibility gaps
The data being uploaded is no small matter. According to the report, 44% of employees share strategic plans, 40% share technical data, and 34% share financials. Even more concerning from a compliance standpoint, 24% admit to sharing customer Personally Identifiable Information (PII), while 18% share intellectual property and legal documents.
The first part of the problem is a technical one: lack of organizational visibility. While 78% of professionals use AI tools, 70% of organizations have limited to no visibility into the applications being utilized. This opacity creates a breakdown in control. Josys International's chief operating officer and president, Jun Yokote, comments, “Shadow AI is no longer a fringe issue. It’s a looming full-scale governance failure unfolding in real time.”
Workforce readiness undermines control
The capability gap within the workforce forms the second part. The report found that 63% of professionals are not confident in their ability to use AI securely. This lack of digital literacy is directly driving compliance risk.
The highest rates of sensitive data upload are concentrated in key business functions, where regulatory scrutiny is often highest:
- Sales and marketing lead the risk at 37%.
- Finance and IT/Telecoms follow closely at 36%.
The lack of preparedness across these departments is striking. Only 52% of finance teams and 55% of IT/telecom teams report being fully prepared to assess AI risks. Yokote warns, “Productivity gains mean nothing if they come at the cost of trust, compliance, and control.”
The policy enforcement challenge
The current policy infrastructure is not helping and appears inadequate for the speed of AI adoption. The report found that 50% of organizations still rely on manual policy reviews, and 33% have no formal AI governance processes in place. Even where controls exist, only 25% believe their current enforcement tools are highly effective.
With recent reforms to the Australian Privacy Act and growing pressure for transparency in AI models, this reactive governance posture presents an immediate compliance challenge. The report suggests organizations must take immediate and coordinated action to achieve a unified approach to AI governance.
Such an action includes:
- Auditing AI usage across all teams to close visibility gaps.
- Automating risk assessments based on data sensitivity and job function.
- Enforcing real-time policies aligned to role-based access.
For CHROs, the integration of technology and talent management has reached a critical juncture. Without immediate investment in visibility tools and mandatory, role-based training to close the capability gap, organizational data integrity and compliance resilience will remain severely compromised.
Image credit: iStockphoto/Moor Studio