Companies urged to rein in workplace artificial intelligence
Monday 24th August 2026 on 13:45 in
Iceland
Companies are increasingly using artificial intelligence as virtual employees, but cybercriminals can deceive these systems using methods similar to those used against staff, mbl.is reported. Arnar S. Gunnarsson, head of security solutions at OK, said many companies still lack clear rules for using the technology.
Artificial intelligence may take the form of a chatbot or a system that produces daily or weekly reports. In effect, Arnar said, it can function as an artificial intelligence employee and be targeted by phishing in much the same way as a human employee.
He said the image of cybercriminals breaking through firewalls using complex technical methods no longer describes a large proportion of attacks. Instead, employees are often the target.
“It is no longer about breaking in through firewalls. It is simpler to send an email to five million people and then see who clicks the link and provides their password,” Arnar said.
Email addresses can be obtained from data breaches and company websites, while people also use their work email addresses widely online.
Arnar said companies should establish clear policies on where, when and how employees may use artificial intelligence, and should train staff in safe use of the technology.
He compared these restrictions to a bridle on a horse, setting limits on what artificial intelligence may do, which information it can access and how it operates. With appropriate safeguards, he said, artificial intelligence can be used safely for a wide range of tasks.
Particular care is needed over what information is entered into online artificial intelligence services. Arnar said personal data, sensitive information and customer data should not be entered into services such as Claude, ChatGPT and Grok.
He said examples had emerged abroad of employees accidentally entering sensitive company information, including internal price lists, into artificial intelligence services. Competitors could then obtain the information and adjust their prices accordingly.
Rapid changes by artificial intelligence companies also make it difficult for users to keep track of how their data is handled. Settings governing whether user data is used to improve and train artificial intelligence models may vary between services and may change over time.
Companies and individuals should therefore familiarise themselves with privacy settings and monitor changes to them, Arnar said.