MED

Sensitive documents uploaded to an unsanctioned AI tool

Shadow-AI SaaS usage

CASB flags employees pasting internal docs into an unapproved AI writing SaaS.

Full brief ▾

CASB detected uploads from ~30 employees to an AI document-summarizer SaaS not on the approved list. Some uploads match internal document classifications, including a few tagged "Confidential". The vendor's terms allow training on submitted data.

index=casb app="ai-summarizer.example" action=upload | lookup dlp_class filename | where classification IN ("Internal","Confidential") | stats count by user, classification
index=casb app="ai-summarizer.example" action=upload | lookup dlp_class filename | where classification IN ("Internal","Confidential") | stats count by user, classification
Signal feed3 events
2026-07-17T13:00:00Zcasbuser=sales-14 · app=ai-summarizer.example
ts2026-07-17T13:00:00Z
sourcecasb
usersales-14
appai-summarizer.example
actionupload
classificationConfidential
filenameQ3-pipeline.xlsx
2026-07-17T13:20:00Zcasbuser=hr-3 · app=ai-summarizer.example
ts2026-07-17T13:20:00Z
sourcecasb
userhr-3
appai-summarizer.example
actionupload
classificationInternal
filenameorg-plan.docx
2026-07-16T00:00:00Zvendor-tosuser= · app=ai-summarizer.example
ts2026-07-16T00:00:00Z
sourcevendor-tos
user
appai-summarizer.example
action
classification
filename
▸ syncing case…
SOC — Sensitive documents uploaded to an unsanctioned AI tool · PlayCISO