August 2026 · 6 min read
The Second Wave: AI's Sensitive-Data Exposure

Key Definitions
Second Wave of AI The phase where AI moves from experimentation to operational dependency, with agents and coding assistants genuinely connected to enterprise data and workflows at billions-scale data movement.
AI Adoption Gap The wide divergence in AI tool count and employee adoption between frontier and average companies — frontier firms adopt at nearly 6x the rate, leaving data governance behind.
Cyberhaven Labs' 2026 AI Adoption & Risk Report, built on billions of real data movements from 222 companies, paints a picture that has been underestimated: AI's "Second Wave" has arrived and is operational. 39.7% of all AI interactions involve sensitive data — the average employee inputs proprietary information into AI once every three days. Data is flowing to AI at an unprecedented scale.
The Second Wave: From Experimentation to Operational Dependency
The report exposes a sharp "AI Adoption Gap." Frontier organizations now use over 300 GenAI tools at nearly 6x the average adoption rate; 71.4% of employees use GenAI in leading organizations versus just 2.5% in cautious ones. The most aggressive adopters are technology (40.5%), pharmaceuticals (33%), and financial services (28.7%) — precisely the industries with the highest sensitive-data density.
When the adoption gap is this wide, data governance and security controls almost cannot keep pace. That is what distinguishes the "Second Wave" from early experimentation: it is no longer a few teams testing the waters, but an entire organization's data flows beginning to move through AI tools.
Sensitive Data: A Leak Risk Every Three Days
39.7% of all AI interactions involve sensitive data, meaning the average employee inputs proprietary information into AI once every three days. This is not an edge case — it is part of everyday workflow. With coding assistants covering nearly 50% of developers (90% in frontier companies) and 23% of enterprises having adopted agent-building platforms, both the channels and the frequency of sensitive data flowing into AI are climbing.
The risk is not only about input; it is about output and redistribution. Once proprietary data enters an AI tool, enterprises often lose control of it — who accessed it, what it was used for, and whether a third-party model trains on it may all fall outside the enterprise's control.
Shadow Accounts: One in Three Use Personal Accounts
One of the report's most troubling findings is that roughly one in three employees access AI tools via personal accounts, including 58% of Claude users and 60% of Perplexity users. This means a large volume of sensitive data flows to third-party systems outside enterprise control — data the enterprise cannot audit and cannot respond to quickly in the event of a breach.
Equally concerning: 82%of the top-100 most-used GenAI SaaS applications are classified as "medium" to "critical" risk. High adoption does not mean low risk — on the contrary, the most popular tools are often the ones that most need controls.
Chinese Open-Weight Models: Half of Endpoint Usage
Chinese open-weight models like DeepSeek and Qwen now account for 50% of all endpoint-based AI usage. For enterprises, this is a phenomenon that demands dedicated handling: substantial data is flowing to open-weight models whose security commitments, data residency, and auditability need separate evaluation — open source must not be assumed safe by default.
Combined with the shadow-account problem, enterprises face a double loss of control: personal accounts bypass enterprise governance, while open-weight models add data-governance uncertainty. Stacked together, the enterprise's sensitive-data exposure surface is significantly amplified.
An Action Checklist: Embed Data Governance into AI Workflows
Facing the "Second Wave," enterprises need to act on three fronts. First, build visibility — identify which of all AI interactions touch sensitive data; you cannot govern what you cannot see. Second, shut down shadow accounts — force AI use from personal accounts into enterprise-controlled workspaces with model toggles to prevent surprise activations. Third, govern high-adoption tools — apply dedicated DLP and least-privilege policies to coding assistants and agent platforms, ensuring model providers do not retain or train on enterprise data.
The key principle: data governance must be embedded into AI workflows, not retrofitted afterward. When nearly 40% of AI interactions already touch sensitive data, the cost of waiting for problems to surface is far higher than building controls at the point of adoption.
References:
Frequently Asked Questions
What is the 'Second Wave' of AI?+
Cyberhaven defines 2026 as AI's Second Wave — the shift from experimentation to operational dependency. Based on billions of real data movements from 222 companies, the report shows frontier organizations now use over 300 GenAI tools at nearly 6x the average adoption rate; 71.4% of employees use GenAI in leading organizations versus just 2.5% in cautious ones.
How big is the sensitive-data risk?+
39.7% of all AI interactions involve sensitive data, meaning the average employee inputs proprietary information into AI once every three days. The most aggressive adopters — technology (40.5%), pharmaceuticals (33%), and financial services (28.7%) — are also raising the stakes for sensitive-data oversight the highest.
How serious is the shadow-account problem?+
One-third of employees access AI tools via personal accounts, including 58% of Claude users and 60% of Perplexity users. This removes visibility entirely — sensitive data flows into third-party systems the enterprise neither audits nor can quickly respond to when breached.
Why do Chinese open-weight models account for half of endpoint usage?+
Chinese open-weight models like DeepSeek and Qwen now account for 50% of all endpoint-based AI usage. For enterprises, this means substantial data flowing to open-weight models whose security and data-residency commitments require separate evaluation — open source must not be assumed safe by default.
How should enterprises respond to data-exposure risk?+
First, build visibility — identify which AI interactions touch sensitive data. Second, shut down shadow accounts — move AI use from personal accounts to enterprise-controlled workspaces with model toggles. Third, apply dedicated governance to high-adoption tools like coding assistants and agent platforms with DLP and least-privilege policies, embedding data governance into AI workflows rather than retrofitting it.
Related Articles
Okta Survey: Shadow AI Outpaces Governance
58% of orgs had an AI security incident while 95% of execs trust employees; 52% use unapproved AI tools.
The Shadow AI Agent Crisis: Running Agents You Can't See
Over 53% of enterprise agents exceed their intended permissions; 47% had an agent security incident last year.
AI Agent Security 2026: Adoption Outpaces Control
81% past planning yet only 14.4% of agents launch with full security approval; 88% saw agent incidents.
Agent Identity's Ownership Vacuum: Who Governs?
Only 23% of enterprises have a formal agent-identity strategy; fragmented ownership blocks production.