Reliable Technology Services co-founder and CEO Jason Denton said that geopolitics is causing asymmetric warfare, and North Texas businesses are at risk.

"Some of the nations at war want to hurt the U.S., but they don’t necessarily have the kinetic, tactical weapons to make that happen," Denton said. "So, it’s very cheap and easy … to deploy a team of hackers overseas. According to the FBI’s 2025 Internet Crime Report, Texas ranks second in the country in both cybercrime complaints and reported losses, behind only California. The concentration of corporate headquarters in Dallas-Fort Worth puts a heavy share of that in our backyard."

Line chart 2022-2026 showing cyberattack trends: credential abuse falling, exploitation of vulnerabilities rising, phishing and pretexting steady.
Known initial access vectors in non-Error, non-Misuse breaches over time (n for 2026 dataset=19,905) Source: Verizon 2026 Data Breach Investigations Report

Many small- or medium-sized businesses believe they are not at risk, but that is actually not the case.

"We small business owners are the low-hanging fruit,” Denton said. “Verizon's 2026 Data Breach Investigations Report found ransomware in 48 percent of all breaches last year, up from 44 percent. The encouraging part is that 69 percent of victims refused to pay."

Because of this increase, Denton advises all North Texas businesses and employees to prioritize cybersecurity. One way to do this is by enhancing the security of artificial intelligence systems and policies.

Bar chart of attack types: Ransomware 83%, stolen creds 39%, exploit vuln 30%, phishing 10%, other 2.1%, pretexting 1.4%.
Top Action varieties in SMB breaches (n=6,182) Source: Verizon 2026 Data Breach Investigations Report

What is shadow AI, and why is it a growing concern for businesses?

Shadow AI occurs when employees use their personal ChatGPT, Gemini, Claude or other AI tools to process confidential company information.

"Verizon's 2026 Data Breach Investigations Report found that 67 percent of users are using non-corporate accounts on their corporate devices to access AI services, and that 45 percent of employees are now regular users of AI on corporate devices, up from 15 percent the previous year,” Denton said. “Shadow AI is now the third most common non-malicious insider action in their data loss prevention dataset, a fourfold increase."

Bar chart: File sharing 32%, personal webmail 20%, shadow AI 12%, pirated media 9%, blocked website 9%.
Top non-malicious insider untrusted DLP event targets (n=4,280,149) Source: Verizon 2026 Data Breach Investigations Report

Using a personal account is dangerous because it puts company data outside the company’s reach. The terms are between the employee and the vendor, not the business, and consumer accounts use conversations for training by default.

"There’s no malintent, but inadvertently, someone could be dropping the customer list into AI to reorganize it," Denton said. "Maybe they’re preparing a presentation for the management team, and not realizing that once it goes into a personal account, the company has lost control of it. There’s no contract, no retention setting, no administrator who can see what left the building, and no way to pull it back."

The common assumption is that the danger is the data surfacing in a stranger’s chat. Denton said that researchers at Google DeepMind and several universities have shown that AI models do memorize portions of their training data, and that it can be extracted, but doing so requires a deliberate attack, and it is not how most business exposure happens.

The realistic risks are simpler. A personal account carries no data processing agreement, so for a business operating under a client confidentiality obligation, entering client data can be the breach on its own. The account belongs to the employee, not the company, so the data walks out the door when they do.

Retention is set by the vendor rather than by you. And Denton noted that in 2025, thousands of shared ChatGPT links were indexed by Google, exposing resumes and confidential work material, which had nothing to do with model training and everything to do with a checkbox most users did not understand.

Bar chart of attack types: Phishing 44%, Exploit 32%, Credential abuse 21%, Third-party 3.0%.
Generative AI-assisted techniques categorized as initial access methods (n=837) Source: Verizon 2026 Data Breach Investigations Report

"Every one of those risks is still present even if the employee turns the training setting off," Denton said. "Businesses operating under SOC 2 attestation, the NIST AI Risk Management Framework, or CMMC for defense contracting have committed to controls over where company data goes. Personal AI accounts break those controls. The line is not free versus paid. ChatGPT Plus and Pro are paid consumer accounts, and they still default to using conversations for training. Business and Enterprise workspaces exclude company data from training by default, and more importantly, they give you a contract, administrator visibility, retention control and an audit trail. That’s what you’re actually buying. A setting an employee can switch off isn’t a control.”

Additionally, companies are now vibe coding, generating software from plain language prompts without closely reviewing the code that comes out. Some are building their own CRM systems this way.

"I think there’s an extreme risk in doing that," Denton said. "There’s nothing wrong with doing it, but I think businesses need to have a developer overseeing their work, who can certify that it’s at the level of quality that they can trust, … so that it doesn’t create a productivity loss or some kind of outage in the future."

Bar chart: source code 28%, image 16%, structured data 14%, document 13%, PDF 10%, research documents 3.2%.
Select data types in untrusted DLP events targeting generative AI tools (n=858,440) Source: Verizon 2026 Data Breach Investigations Report

What data should never be entered into AI tools?

Regardless of whether someone is using a personal or business account, there is a lot of information that should never be entered into an AI tool, including:

  • Personal information: home addresses, driver’s license numbers, social security numbers and phone numbers

  • Credential information: passwords and IT information

How can business leaders establish safe AI policies?

To enhance security, business leaders should establish clear AI use policies with their employees, explaining which tools can be used, what platforms employees can access with the tools and what data can be entered into them.

Leaders should also provide an AI governance document to their employees with these specifications outlined, and there are data loss prevention (DLP) tools available to ensure these guidelines are being followed and that there is no data leakage.

Additionally, when using large language models, AI systems learn from what humans enter.

"Large language models were trained with literature and other forms of content initially, but as we’re using AI every day, we’re actually training it," Denton said. "When you have millions of people using, for example, ChatGPT or Claude, it’s actually learning how we as human beings talk. I think that does advance the tool, but for a business, the question isn’t whether the model remembers. It’s whether you can answer a client who asks where their data went. In a personal account, you can’t."

It is important to note that AI is evolving quickly, so a business’ policy today might need to be reevaluated in three to six months.

How can safely using AI give companies a competitive edge?

Keeping safety in mind, Denton mentioned several ways AI can make a positive impact on companies. The first is using tools like Fireflies.ai to capture meeting notes and summaries.

Additionally, Reliable Technology Services uses a tool that records calls, with their clients’ permission. The tool will give feedback to the speaker, such as mentioning the number of times they said the word, "Um," as well as a list of five things the speaker did well.

AI can also help filter job applications, but this is a regulated area. Automated screening falls under EEOC adverse impact rules and a growing list of state and local bias audit requirements. Denton said that companies should involve employment counsel before they deploy anything here.

Next, he said AI excels in pulling information from large data sets.

"If you have a large data set of records that you’re prospecting for a certain type of client, I think it’s easier to use an AI tool to help glean out exactly what you’re looking for. It helps you get there faster," Denton said.

Lastly, search visibility is helpful for businesses. Denton addressed a common misconception about AI-generated content and search rankings.

"I think human beings appreciate reading content written by other human beings. Google does not downgrade content for being AI-assisted. What it targets is thin content produced at scale. Publishing volume with no original insight is what costs you. Real expertise is still what separates your content from everyone else’s," Denton said.

How can North Texas businesses get started with cybersecurity?

When used securely, AI can be very beneficial to small- and medium-sized businesses. For those interested in learning more about Reliable Technology Services, resources can be found here:

  • Website: https://reliabletsi.com/ 

  • Phone number: 972-829-5300

  • Address: 1518 Legacy Dr., Ste. 240, Frisco, TX 75034

  • Hours: Mon.-Fri. 8 a.m.-5 p.m.

Man in a gray suit and white shirt with a lapel pin, posing against a light gray background.

A quick recap FAQ

What is shadow AI, and why is it a risk for businesses?

Shadow AI occurs when employees use personal AI accounts, such as ChatGPT, Gemini or Claude, to process confidential company data. Personal accounts carry no data processing agreement, no company-controlled retention and no administrator visibility, so the business loses control of anything entered, has no way to retrieve it and cannot prove where it went if a client or regulator asks.

What data should never be entered into an AI tool?

Regardless of account type, employees should never enter personal information (home addresses, driver’s license numbers, social security numbers, phone numbers) or credential information (passwords and IT details) into any AI tool.

What is "vibe coding," and what security risks does it introduce for companies?

Vibe coding refers to generating software directly from plain-language prompts using AI, often without thorough review of the output. The security risks include unreviewed code shipping with flaws, dependencies nobody vetted and credentials hardcoded where they do not belong. Have a developer review anything that touches company or customer data.

What precautions should companies take when using AI tools for content creation?

Companies should avoid generating thin content at scale without original human insight, as real expertise separates their content from others’.

How can business leaders establish safe AI policies for their employees?

Leaders should establish clear AI governance documents outlining approved tools, allowed platforms and the specific types of data employees may enter. To ensure these guidelines are followed and prevent data leakage, companies can deploy Data Loss Prevention (DLP) tools. Additionally, because AI technology evolves rapidly, business leaders should re-evaluate their policies every three to six months.

How can Reliable Technology Services help my business with cybersecurity?

Reliable Technology Services, based in Frisco, provides IT support for small- and medium-sized businesses, including cybersecurity strengthening, technology management, disaster recovery and Cloud solutions. Call 972-829-5300 or visit reliabletsi.com to learn more.

This story was published on Aug. 14, 2026. The following sources were provided by Denton:

  • Verizon 2026 Data Breach Investigations Report

  • FBI Internet Crime Complaint Center, 2025 Internet Crime Report

  • Nasr et al., "Scalable Extraction of Training Data from (Production) Language Models," 2023; Fast Company’s reporting on indexed ChatGPT share links, July 2025

  • OpenAI’s enterprise privacy documentation

  • Google Search Central spam policies

The above story was produced by Senior Multi-Platform Journalist Sydney Heller with Community Impact’s Storytelling team with information solely provided by the local business as part of their "sponsored content" purchase through our advertising team.