Your spec sheet is in somebody's chat
For manufacturing, the bigger exposure is not personal data — it is trade secret. And that one does not come back.
August 17, 2026 · F7 KORE · Applied AI · Manufacturing · Governance
When AI risk comes up, the conversation goes straight to personal data. GDPR, consent, data subject, DPO. It is a necessary conversation and a mature one.
For manufacturing, it is not the main one.
What actually gets uploaded to an AI account in a plant’s working day is something else: spec sheets, formulations, cost breakdowns, supplier contracts, commercial terms, project memoranda, drawings. It is what the company spent years developing and publishes nowhere. It is trade secret — and it does not come back.
How this happens without anyone doing wrong
The moralizing reading is useless here: nobody is being careless.
The engineer pastes the customer specification into a chat because they need to understand a sixty-page memorandum quickly. The buyer uploads the comparison spreadsheet because they want a summary before the two o’clock meeting. Quality pastes the lab report to check it against the standard. Sales uploads last year’s proposal to adapt it. Every one of them is a competent professional solving in two minutes something that would take two hours.
The problem is in none of those acts. It is in the fact that they happen in an account that does not belong to the company.
Three consequences that surface later
1. The learning belongs to the person, not the company.
All the context the AI accumulated about your operation — how you quote, the exceptions in your process, the vocabulary of your line — lives in one individual’s chat history. When that person leaves, it leaves with them.
It is the same pain as when someone with twenty years of service retires, with one uncomfortable aggravation: in that case the company at least had the knowledge at some point. Here, it never came to own it.
2. Two tools, two policies, no shared memory.
Each vendor has its own contract and its own data handling, and the choice was made by personal preference rather than risk assessment. There is nobody in the middle deciding what may be uploaded and what may not.
Which means the answer to “what terms govern our company information sitting inside an AI?” is: depends which person, in which tool, on which plan. That is not an answer you give an enterprise customer auditing a supplier.
3. There is no record that it was uploaded at all.
This is the quietest one. Nowhere in the company is it noted that the product spec sheet was pasted into a chat in March. No trail, no inventory, no way to answer — not even to say everything is fine, or to know the size of the exposure.
How much of this has already happened
So far this may read as hypothetical risk. It is not — and the difference matters, because the numbers below do not come from self-reported surveys but from measurement of real browser and network traffic.
77% of employees paste data into AI tools, and 82% of that activity comes from accounts the company does not manage. That is an average of 14 pastes per person per day through personal accounts, of which at least three carry sensitive data. And 40% of the files uploaded to AI tools contain personal or payment data (LayerX · Enterprise AI and SaaS Data Security Report 2025).
On the network side the reading matches: the average company logs 223 incidents per month of sensitive data sent to an AI app — double the previous year (Netskope · Cloud and Threat Report 2026).
Note that these numbers measure neither intent nor opinion. They measure what actually left. And they doubled in twelve months.
The data being uploaded is exactly what the ERP left out
There is a structural irony here, and it explains why the problem is sharper in manufacturing than elsewhere.
Among manufacturers that already invested in an execution system, 93% have an MES — and only 23% integrated it end to end (Rockwell Automation). One rung down, 54% of small and mid-sized plants still run on paper and spreadsheets as their execution system (IoT Analytics, MES Market Report 2025–2031). Different populations — and that is the point: the ones who bought the system never connected it; the ones who did not buy it have nothing. Either way, the operational data stayed outside.
Translated: an enormous share of what the operation actually produces — spec sheets, inspections, formulations, shift reports, work orders — never entered any system at all. It lives in spreadsheets and loose documents.
And that is precisely the material that ends up in the chat. Not by accident: it is the material nobody can query any other way. People upload the spreadsheet because it is not anywhere that answers questions.
The data that exposes the company most is the same data it never managed to organize. That is not a coincidence — it is the cause.
What does not work
Blocking. The tool is on the phone. It works. It solved a real problem last week. Banning it pushes usage into the dark, and invisible usage is worse: you lose even the chance to know what went up.
A usage policy with no alternative. Publishing a rule that says “do not upload confidential information” hands an employee a judgement call they cannot make well, in the middle of a task they have to finish today. They will upload it. Now with guilt, which only lowers the odds they tell you.
Waiting for the corporate tool to fix it. An enterprise AI plan solves the contract and the data handling — which is already a lot. But it does not solve per-person permission, it does not solve the current version of the document, and it leaves no record of what was done. The data stops leaving the company; it remains ungoverned inside it.
What works: the data has somewhere to go
The way out is not to suppress the demand. It is to meet it somewhere that has the foundation underneath.
- Permission. The AI sees exactly what the person who invoked it sees — not one document more. The buyer does not see engineering’s cost sheet because they would not see it anyway.
- Evidence. Every query and every action with author, timestamp and version, in a record that cannot be altered. “What of ours was used, by whom, when” becomes a question with an answer.
- Current version. The spec consulted is the one valid today, approved by whoever signs off — not the copy someone downloaded in March.
- A path to write back. The result does not end on a screen: it raises the task, assigns the owner, chases the deadline, inside the process.
And one decision that in manufacturing usually outweighs the four: where the data lives. Cloud or inside the plant — the product is the same, and the choice is yours. In the on-premises model the archive stays in your own environment; what travels is the slice sent to the model at the moment of the task, encrypted and logged.
The one-question test
If you want to measure your company’s exposure today without commissioning an assessment, ask one question at the next board meeting:
“If a customer audits how we handle confidential information, what do we say about AI?”
If the answer involves “I do not think anyone uploads anything important”, you already have the size of the problem. And it is not a discipline problem — it is that until now there has been no right place for that material to go.
This is the fourth of four pieces on the same thesis. The other three: how AI came in through the boardroom, the new silo that talks back and why 95% of pilots return nothing.
The company behind F7 KORE has automated industrial processes for over a decade, in real operations and regulated environments. Where the data runs and what leaves your network is detailed on the security page.
If the information that underpins your product is scattered across personal accounts, the first thing to do costs no contract: run the board-meeting question above and bring back the answer. Talk to us.