By · Last updated 2026-02-17

Späť na blogBezpečnosť AI

AI: Hlavny kanal unikov dat

77 % zamestnancov vlozi citlive udaje do nastrojov AI. GenAI zodpoveda za 32 % vsetkych firemnych unikov dat. Zistite, ako ochranit svoju organizaciu.

February 17, 20268 min čítania
AI securityChatGPTdata leakageenterprise security

AI je dnes najvacsi kanal unikov dat

V oktobri 2025 zverejnila spolocnost LayerX Security sprav, ktora znepokojila CISO na celom svete. Klucove zistenie: 77 % zamestnancov vlozi citlive subory do nastrojov GenAI. Z toho 82 % pochadi z osobnych, nespravovanych uctov.

Hlavne cislo: GenAI dnes sposobuje 32 % vsetkych firemnych unikov dat. Je to najvacsi jednotlivy kanal nepovolenych presunov dat v podnikatelskom prostredi.

Toto nie je riziko buducnosti. Deje sa to vo vasej organizacii prave teraz.

Cisla za problemom

ZistenieHodnotaZdroj
Zamestnanci vladiaci udaje do AI77 %LayerX 2025
Uniky dat cez nastroje AI32 %LayerX 2025
Pouzivanie ChatGPT cez osobne ucty67 %LayerX 2025
Vkladania za den na zamestnanca14LayerX 2025
Vkladania s citlivym obsahom za den3+LayerX 2025

Zamestnanci vykonaju 14 vkladani denne z osobnych uctov. Najmenej tri obsahuju citlive zaznamy. Stare nastroje DLP su navrhnuty pre subory. Aktivity zalozene na vkladani uplne prehliadaju.

Preco zakazy AI nefunguju

Samsung zakázal ChatGPT potom, co zamestnanci prezradili zdrojovy kod. Zakaz nevydrzal.

Nastroje AI robia ludi rychlejsimi. Vyskum ukazuje, ze vyvojari pouzivajuci AI dokoncuju ulohy o 55 % rychlejsie. Ked zablokujete AI, zamestnanci roobia jednu zo troch veci:

  1. Pouzivaju ju aj tak cez osobne ucty — 67 % to uz robi
  2. Stracia produktivitu a vzdoruju obmedzeniu
  3. Odidu k zamestnavatelom, ktori AI povoluju

Zakaz presunie riziko. Neeliminuje ho.

Narusenie bezpecnosti 900 000 pouzivatelov rozsirenia

V decembri 2025 nasla spolocnost OX Security dve skodlive rozsirenia Chrome. Dokopy mali 900 000+ pouzivatelov. Obe kradli konverzacie z ChatGPT a DeepSeek.

Jedno rozsirenie neslo odznak Google "Featured" — znak, ktore pouzivatelia doveryuju.

Obe fungovali rovnako:

  • Zachytavali obsah konverzacii v realnom case
  • Ukladali ho na zariadeni obete
  • Odosielali davky na vzdialene servery kazde 30 minut

Osobitnove setrovanie odhalilo bezplatne rozsirenia VPN s viac ako 8 milionmi stahnutiami. Zachytavali konverzacie AI od jula 2025.

Viac o ohrozeniach na urovni prehliadaca najdete v nasej prirucke o bezpecnosti Chrome Extension.

Zastavte uniky skor, ako sa odosle dopyt

Jedina spolahliva obrana: maskovat osobne identifikatory skor, ako sa dostanu k AI. Konanie po fakticite je prilis neskoro.

Presne to robia Chrome Extension a MCP Server od anonym.legal.

Chrome Extension

  • Blokuje text skor, ako ho odoslete do ChatGPT, Claude alebo Gemini
  • Nachadza a nahradzuje OÚ: "Jan Novak" → `[PERSON_1]`
  • Obnovuje mena v odpovedi AI

MCP Server (pre vyvojarov)

  • Funguje s Claude Desktop, Cursor a VS Code
  • Pôsobi ako transparentny proxy — vás pracovny tok zostava rovnaky
  • OÚ su maskovane skor, ako dopyt opusti vas pocitac

Co je chranene

Obe nastroje rozpoznaju 285+ typov entit v 48 jazykoch:

  • Osobne — mena, e-maily, telefonne cisla, datumy narodenia
  • Financne — cisla kreditnych kariet, bankove ucty, IBAN
  • Vladne — rodne cisla, cisla pasov, vodicske preukazy
  • Zdravotnicke — cisla zdravotnych zaznamov, ID pacientov
  • Firemne — ID zamestnancov, interné cisla uctov

Ak pride k naruseniu — ako u tych 900 000 pouzivatelov — nie je co obnovovat. V zazname konverzacie zostanu len maskovane tokeny.

Cena neinnosti

Pomyslite na to, co zamestnanci denne vkladaju do nastrojov AI:

  • Financne spravy odoslane na kontrolu
  • Zaznamy zakaznikov pouzivane v podpornych konverzaciach
  • Zdrojovy kod zdielany pri ladeni chyb
  • Pravne subory odoslane na zhrnutie
  • Zdravotne zaznamy spracovavane pre insighty

Sprava IBM o nakladoch na narusenie dat z roku 2024 stanovuje priemerny naklad narusenia na 4,88 miliona dolarov. Aktualizacia IBM z roku 2025 uvadza narusenia v zdravotnictve na 7,42 miliona dolarov — stale najvyssie v akomkolvek odvetvi.

Chrome Extension je bezplatne. MCP Server je sucastou planov Pro od 15 €/mesiac.

Zacnte dnes

AI tu zostane. Vasi zamestnanci ju uz pouzivaju. Sprava LayerX ukazuje, ze standardne nastroje su slepé voci unikom cez AI. Potrebujete kontroly navrhnuté priamo pre tento kanal.


anonym.legal maskuje osobné identifikatory skor, ako dosiahnu akykolvek model AI. Prace v prehliadaci zostávaju lokalne. Ziaden obsah konverzacii sa pocas procesu nedotkne serverov anonym.legal.

Zdroje

Pripravení chrániť vaše údaje?

Začnite anonymizovať PII s 285+ typmi entít v 48 jazykoch.

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

Related reading

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our servers live in Falkenstein, Germany.

We use Hetzner. They hold ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.