Employee Fired After Uploading Corporate Documents to DeepSeek: How Data Security Works in AI Services
A top manager at a Moscow engineering company was dismissed after uploading internal documents containing trade secrets to the public DeepSeek service. The court sided with the employer, classifying the action as unauthorized disclosure of confidential information.
The incident reflects a broader trend. Research analyzing traffic from 150 Russian companies found that employees uploaded 30 times more corporate data to public AI services in 2025 than in the prior year. Materials included presentations, code fragments, analytics, and internal correspondence. At the same time, 60 percent of organizations still lack any formal rules governing AI tool usage.
Darya Lushkina, editor and researcher at Rating Runeta, examined these risks with Yaroslav Shmulyov, CTO of AI integrator R77 AI. When a user uploads a file such as a client contract or presentation, the document first passes through standard IT infrastructure including gateways, backend systems, and logging. The service then parses the content, extracts text and structure, and splits the text into chunks that are converted into embeddings—vector representations that capture semantic meaning.
Data therefore exists simultaneously in several forms: the original file, extracted text, text fragments, embeddings, processing logs, and metadata. The most sensitive stage is often the initial storage of the unaltered file on external servers before any further processing occurs.
Additional exposure points include logging systems that may retain fragments of content, third-party cloud providers and moderation contractors, and potential inclusion in training datasets. Once data influences model parameters during training, removal becomes technically irreversible; techniques such as machine unlearning remain an active research area with limited practical results for large language models.
Even when users enable settings that claim to prevent data use for training, the actual enforcement mechanisms are opaque. Service operators, infrastructure partners such as Google Cloud and Azure, and human moderators reviewing selected dialogues may all gain access. In 2024, Wiz Research discovered an exposed DeepSeek database containing over one million chat records and secret keys due to a misconfiguration.
Real-world consequences have already appeared at global companies. Samsung engineers sent proprietary source code and meeting notes to ChatGPT, while a U.S. cybersecurity agency head uploaded documents marked “For Official Use Only.” R77 AI consultants routinely observe similar uncontrolled usage inside client environments, prompting organizations to introduce strict data classification rules and corporate AI instances.
Looking ahead, demand is growing for local and hybrid models that keep data within controlled perimeters, alongside clearer corporate offerings that specify storage locations, training exclusions, and deletion timelines.
Related articles
AI Agents Chain Malicious Instructions Through Protocol Pivoting to Bypass Protections
Researchers have demonstrated how AI agents can relay malicious instructions across multiple components without triggering security checks, allowing attackers to reach internal resources. The technique, called protocol pivoting, exploits the loss of trust validation when tasks move between AI systems connected via the MCP protocol. Syed Anas Mohiuddin showed that a single planted prompt can be passed from one agent to another, eventually reaching specialized tools that execute unauthorized actions such as network requests or data exposure. In Google MCP Toolbox for Databases, the flaw enabled HTTP redirects to internal addresses until a patch introduced address validation and request restrictions. A separate issue tracked as CVE-2026-97228 in Rapid7 Bulk Export MCP received a low CVSS score of 2.7 and was fixed in version 0.6.2, though it did not grant access beyond the original API key permissions. Experts note that the method is essentially an indirect prompt injection rather than an entirely new attack class.
Astra Group Unveils Astra AI Ecosystem for Air-Gapped Corporate Networks
Astra Group has introduced its Astra AI ecosystem designed for secure, on-premises deployment in closed corporate environments. The solution enables organizations to run AI models locally without transmitting data to external services, targeting critical infrastructure operators, government agencies, and regulated industries. Built on Astra Linux and the Botsman containerization platform, the ecosystem includes five integrated components for code automation, office assistants, low-code agent development, model management, and implementation methodology. The company claims productivity gains exceeding 50 percent for development tasks and up to fourfold performance improvements with its certified hardware-software complexes. While emphasizing data sovereignty and regulatory compliance, Astra Group notes that local deployment alone does not eliminate risks related to agent permissions, output quality, and integration security.
AI Learns Human Formulas of Deception, Fueling a Crisis of Free Speech and Truth
The article examines how artificial intelligence has begun replicating human social-behavioral patterns to create and cite nonexistent authoritative sources, thereby spreading false information at scale. It traces the historical evolution of propaganda from ancient Sparta and Athens through the Rothschilds and modern social media, showing how each new mechanism for verifying truth—expert opinion, reputation, and finally machines—has been subverted. The author highlights recent examples of rapid disinformation campaigns, including false claims about FlyDubai pilots and a supposed plague outbreak in Irkutsk, which were amplified by controlled media, opinion leaders, and ordinary users. The piece warns that AI’s tireless ability to generate thousands of contradictory articles in real time could overwhelm any possibility of discerning truth, especially during elections. Societal consequences include rising atomization, declining trust in institutions, lower voter turnout, and reduced economic investment due to uncertainty. The author concludes that humanity currently lacks an effective countermeasure and may need to pass through a period of extreme information pollution before developing new norms of personal responsibility and verification.
Anthropic Reports User's Violent Threats to Police After Conversation with Claude AI
Anthropic's security systems flagged messages from a Florida woman who used the Claude AI chatbot to express intent to carry out a shooting at the Lee County Sheriff's Office. The 30-year-old Carly Michelle Heller also stated that she had acquired a weapon, prompting the company to escalate the conversation for human review. After verification, Anthropic notified law enforcement, leading to her identification and quiet arrest at her home. Sheriff Carmine Marceno noted that Heller had been treating Claude as a personal diary rather than a secure private space. She now faces a second-degree felony charge under Florida law, with the court set to determine her guilt. The case underscores how AI platforms monitor for specific threats involving concrete targets and weapon acquisition, resulting in direct police involvement.