AI use outside corporate channels raises security risks in Colombia

34% of surveyed Colombian workers occasionally use artificial intelligence tools they obtain on their own, a share 12 percentage points above the global average.
The use of AI outside channels defined by organizations raises concerns about control over the tools employees use and the information they share through them.
34% of surveyed Colombian workers occasionally use artificial intelligence tools they obtain on their own, a share 12 percentage points above the global average. The figure comes from KnowBe4’s report, From Agentic Risk to Human Wins: How to Build a Security Culture in the Age of Agentic AI.
The use of these tools does not occur solely outside solutions provided by companies. In Colombia, 49% of surveyed workers use only tools provided by their organization, while 7% use only external tools. Globally, those proportions are 48% and 8%, respectively.
AI adoption is advancing at different speeds
The contrast becomes clearer when comparing individual adoption with organizations’ ability to define how AI is used. According to Strand Partners, more than 130,000 companies began using AI tools over the past year, but only 12% reached a milestone considered truly transformative.
When an official solution is slow to arrive or does not exist, workers may turn to alternatives on their own.
The main risk identified is related to data traceability. When a tool is used outside the corporate perimeter, an organization may no longer know what information was transferred, which provider received it or under what retention policy it was stored. It may also lose records and access controls, as well as the ability to revoke information that has already been shared.
External use exposes corporate information
Most workers are aware of this risk, although not all of them. Some 84% of respondents in Colombia recognize the risks associated with indiscriminate AI use, while 16% are not familiar with them. In addition, 17% say they have entered confidential information into external providers.
Workers themselves identify information sharing as one of the main exposures. Some 45% rank confidential data shared with AI tools through prompts, file uploads or images among the top three human-related cybersecurity risks in their organizations, four percentage points above the global average of 41%.
Among security professionals, 43% rank AI use outside corporate policy among the three behaviors that have most affected their security posture over the past year.
Awareness does not always translate into control
The issue is not limited to risk perception. Some 20% of respondents acknowledge that AI is used without official authorization in at least some areas, showing that the boundaries between permitted use and potential exposure are not always clearly defined.
The report points to the need for frameworks that can turn awareness of these risks into security rules, oversight and practices.
”Cybersecurity has entered a volatile phase in which organizations are trying to protect a hybrid workforce made up of people and AI agents. It is a dynamic environment that is changing faster than security leaders can keep pace,” said Rafael Peruch, CISO Technical Advisor at KnowBe4.
The situation is part of a transformation of Colombia’s workforce, which is incorporating AI agents capable of interacting with corporate systems and data in an environment marked by rapid change and limited visibility.
In this context, employees’ use of AI tools on their own presents organizations with the challenge of establishing clear rules, oversight and control mechanisms for a technology that workers are already adopting.

