The rapid adoption of artificial intelligence is giving Ghanaian businesses new productivity tools, but it is also creating a growing risk: employees could be feeding sensitive company information into AI platforms without fully understanding how that data may be handled.
A 2025 study of 1,107 professionals found that 67% of enterprises in Ghana had adopted AI, data analytics or both, highlighting how quickly the technology is entering everyday business operations.
But an employee uploading a customer database, financial statement, contract, business plan or confidential company information into a public AI chatbot may effectively be transferring commercially valuable data outside the company’s direct control.
Mr. Jake France, Head of the Cyber Security Authority, warned businesses against exposing their identity and sensitive information when using AI tools.
“If you are fond of using AI to do your work, please leave out the company name in your searches because when you put it there, the tool is smart enough to gather all that stuff, aggregate it and start figuring out how things work,” he said.
France said the authority had tested the issue with some companies and was able to identify private company information that appeared to have been entered into AI tools by employees.
The risk is particularly high when employees use AI tools without approval from their employers, a practice commonly known as “shadow AI”.
IBM’s 2025 Cost of a Data Breach research found that 63% of organisations lacked AI governance policies, while companies with extensive shadow AI reported average breach costs $670,000 higher than those with low or no shadow AI use.
For Ghanaian companies, the exposure is not limited to cyberattacks. Confidential pricing, customer information, supplier agreements, product designs or financial data could lose commercial value if disclosed to competitors or otherwise accessed without authorisation.
Ghana’s Data Protection Commission already requires organisations to implement safeguards against unauthorised access and processing of personal data. It also identifies the introduction of technologies such as AI as a circumstance that may require a Data Protection Impact Assessment.
The government is also preparing a new Data Protection Bill expected to address AI, automated decision-making and cross-border data transfers.
Businesses therefore face a balancing act: use AI to reduce costs and improve productivity while ensuring that sensitive information does not become an unintended input into systems they do not fully control.
Businesses need clear rules on which AI tools employees can use and what information they are allowed to put into them. As AI becomes more embedded in Ghana’s economy, protecting company data will become a business-risk issue, not simply an IT concern.
