Some public and private organizations have made the radical decision to ban the use of AI such as ChatGPT in a professional environment.
With a few months of hindsight, this emergency measure seems more like a response to organizations’ lack of knowledge and the absence of user training on AI use cases. But is it wise to ban tools that deliver significant productivity gains when competitors may have fewer scruples?
Indeed, the advent of generative artificial intelligence (AI) opens up new opportunities, but also raises major security concerns for organizations. A recent study conducted by Salesforce highlights the urgent need to raise employee awareness of the risks associated with this emerging technology.
AI in the workplace
In the professional environment, generative AI can transform the way we work, providing valuable assistance with drafting documents, creating marketing content, and customer support. These tools offer undeniable time savings, drive innovation, and provide essential support for decision-making through their ability to process and generate information at scale.
Employees have clearly understood that these solutions can provide substantial productivity gains and are therefore increasingly using them in a professional context.
The well-known ChatGPT from OpenAI paved the way for many other solutions, such as Microsoft (which integrated it into Copilot) and Gemini (formerly Bard), developed by Google. In the field of image generation, Midjourney is the most widely used solution and continuously improves its algorithm to deliver increasingly realistic results. More recently, “text-to-video” solutions have emerged, making it possible to generate a video sequence from a prompt. The most promising solution in this area is Sora, developed by the creators of ChatGPT.
The uncontrolled use of generative AI exposes organizations to a range of risks, from data security to the integrity of intellectual property. Practices such as using unauthorized tools or misattributing AI-generated work can compromise organizations’ reputation and security.
Data security in AI
Generative AI is based on machine-learning algorithms (machine learning, neural networks / deep learning, etc.) and also feeds on the information provided to it.
Today, it is clear that many users of artificial intelligence tools do not grasp the consequences of sharing personal, sensitive, or professional data (such as trade secrets). The efficiency these tools provide can cause users to overlook basic security precautions.
Although ChatGPT commits to protecting data confidentiality, its retention terms and periods remain unclear. And there is no guarantee that the many alternatives to OpenAI, which have multiplied in recent months, provide a sufficient level of security and confidentiality.
Data confidentiality in ChatGPT
The ChatGPT FAQ provides a good illustration – https://help.openai.com/en/articles/6783457-what-is-chatgpt :
Who can view my conversations?
As part of our commitment to safe and responsible AI, we review conversations to improve our systems and ensure that content complies with our policies and safety requirements.
Will you use my conversations for training?
Yes. Your conversations may be reviewed by our AI trainers to improve our systems.
This information is confirmed in the service’s terms of use –
https://openai.com/policies/terms-of-use :
Our use of content: We may use content to provide, maintain, develop, and improve our services, comply with applicable law, enforce our terms and policies, and keep our services safe.
ChatGPT’s privacy policy is equally unambiguous
– https://openai.com/policies/privacy-policy (Chapter 3. Disclosure of personal information):
Users’ personal data may be shared with various third parties, such as partners or authorities.
AI reliability
The use of results provided by AI also raises questions. Since AI is not infallible, there is no guarantee that the information it generates is accurate and unbiased. The systematic use of artificial intelligence can therefore mislead an individual—or even a group of people—if the information is disseminated on a large scale.
This growing dependence can become problematic or even critical when a business process systematically relies on an AI tool (such as through an API call). Inaccuracies and even service unavailability can paralyze an organization.
Deepfake: phishing and fake news
Deepfake is a sophisticated AI technology. It presents significant dangers because of its ability to generate realistic and falsified video or audio content. Its rapid evolution, fueled by continuous advances in deep-learning algorithms, makes detecting forgeries increasingly difficult. This technology has become a preferred tool for scams and phishing, in which manipulated videos or audio recordings are used to mislead victims and encourage them to disclose sensitive information or carry out financial transactions. Sophisticated deepfakes can perfectly imitate the voices (voice cloning) and facial expressions of real people (face swap), increasing the risk of online manipulation and fraud.
Progress in machine translation is also concerning when it is misused. It now allows attackers to target a multitude of countries with flawlessly translated, and therefore credible, content. Gone are the days when phishing emails could be easily identified due to poor language skills and haphazard formatting.
This technology also presents major risks in terms of disinformation and public opinion manipulation. Deepfakes can be used to create fake videos or audio recordings of political figures, business leaders, or public personalities in order to spread false statements or fictional scenarios for propaganda purposes.
Example of a France 24 DeepFake involving Emmanuel Macron:
Banning AI: a good idea?
The AI tsunami is flooding the planet. Hardly a day goes by without new solutions or new developments to existing platforms being announced.
We must face reality by recalling William Shakespeare’s quote: “What cannot be avoided must be embraced.” In other words, in the face of the tidal wave of artificial intelligence-based solutions, it would be unrealistic to ban their use entirely. Every technological leap humanity has experienced has sparked fears and introduced new risks.
As a reminder, at the beginning of the 20th century, especially in rural areas, people were afraid of electricity. For most, the passage of electric current from the wire to the light bulb seemed like magic, which made electricity appear uncontrollable and therefore dangerous. This mistrust was reinforced by a reluctance to see electrical wires integrated into the structures of homes, fueling the belief that electricity could escape and cause harm.
In reality, this fear of electricity stemmed from a general lack of understanding of how it worked.
Like electricity, AI seems magical and will permeate our daily lives, making training and information essential. It will also help prevent a generational divide, which we still see today with computing. Some generations are still not comfortable using technology because they did not embrace the shift early on.
As with any technology, risks do exist and must be understood. Mastering AI will take time, as it does with any new technology, and it can be frightening at first. To avoid being left behind by this advance, it is necessary to understand everything about it.
The urgency of training
It is therefore imperative for organizations to raise their employees’ awareness of potential dangers and the best practices to counter them. Unfortunately, many people still do not receive specific training on sophisticated phishing techniques, exposing businesses to serious security, reputation, and trust threats. In addition, the use of generative AI raises further concerns, particularly regarding the sharing of personal or confidential data and the risk of inaccuracies in generated data.
AI risk awareness solutions
Some organizations have taken the initiative to integrate specialized training programs to raise their employees’ awareness of the security challenges posed by generative AI. These programs aim to increase employee vigilance in the face of potential risks and promote a security culture within organizations.
BlueSecure offers a comprehensive range of cybersecurity training courses, including responsible AI use and the dangers associated with deepfakes.
BlueSecure’s awareness program is based on several educational pillars, combining online training, interactive games, and advanced AI-based phishing simulations.
This approach, combining theory, practice, and hands-on experience, empowers users without making them feel guilty.



