AI Data Security Risks: What Government AI Bans Reveal
AI tools create a genuine data security risk for any company whose engineers paste source code, credentials, or customer records into a chatbot outside the company's own control. That risk is serious enough that governments have started restricting their own access to advanced AI models.
Governments Are Already Restricting AI Tools Over Data Security
In June 2026, the US Department of Commerce ordered Anthropic to cut off access to its two newest models, Claude Fable 5 and Claude Mythos 5, for every foreign national anywhere in the world, including Anthropic's own foreign employees.
Anthropic's account of the shutdown explains that researchers had found a way around the models' safety guardrails and prompted Fable 5 to identify, and in one case exploit, a software vulnerability. That was enough to trigger an export control directive on national security grounds.
Now, because the order took effect immediately and Anthropic lacked a reliable way to verify a user's nationality in real time, the company suspended both models worldwide rather than risk noncompliance. This suspension lasted 19 days.
The Department of Commerce lifted the export controls on June 30, and access began rolling back out globally on July 1. However, 19 days is a short window in absolute terms, but it is a long stretch for any team that had already built a workflow around a model it assumed would simply be available.
Other governments reached similar decisions for a completely different reason, focused less on the model's capability and more on what happens to the data sent into it. India's finance ministry told staff to avoid ChatGPT and DeepSeek entirely on official devices, citing risk to the confidentiality of government documents. Australia's Department of Home Affairs banned DeepSeek from federal government devices outright, and Taiwan and South Korea issued similar restrictions for their own government agencies.
TechRadar's reporting on the Australian and Indian bans, and Al Jazeera's roundup of the wider pattern, both point to the same worry that a chat window is now a viable path for confidential information to leave an organization's control.
The underlying instinct is the same one that shows up in enterprise security reviews everywhere being that sensitive information should stay inside the systems an organization actually controls, regardless of how good the AI on the other side of the connection happens to be that month.
What an AI Data Security Risk Actually Costs
Government caution is one signal. The financial numbers are another, and they are less abstract.
IBM's 2025 Cost of a Data Breach Report put the average cost of a data breach at $4.44 million globally, a 9 percent decline from 2024's record high but still among the highest figures the report has ever recorded. In the United States specifically, the average reached $10.22 million, the highest figure of any country IBM has studied.
| Finding | Figure |
|---|---|
| Breached organizations where shadow AI (unsanctioned AI tools) played a role | 1 in 5, adding $670,000 to the average breach cost |
| Organizations reporting a breach of an AI model or application itself | 13 percent |
| Of those, the share that lacked proper AI access controls beforehand | 97 percent |
| Global average cost of a data breach | $4.44 million |
| Average cost of a data breach in the United States | $10.22 million |
Source: IBM Cost of a Data Breach Report 2025
The 97% figure is the one worth sitting with. Almost every company that suffered a breach of an AI model or application was found to have skipped basic access controls beforehand. This rarely reflects negligence so much as a visibility gap. Employees adopt AI tools faster than security and procurement teams can review them, and a tool that skipped approval is also a tool nobody is watching. IBM's researchers describe this as shadow AI, and the pattern echoes the shadow IT wave of the previous decade, except the stakes are higher because the tools in question ingest source code, contracts, and customer records directly, then send that data to a third party model provider entirely outside the organization's control.
Reducing AI Data Security Risk Without Losing AI's Benefits
Blocking AI outright tends to push the behavior underground anyway, and it gives up real productivity gains in the process. The more durable fix addresses the actual mechanism of the risk: sensitive data leaving a machine before anyone has reviewed where it is going.
This is the problem Pretense is built to solve, and it is worth disclosing plainly that I work on Pretense before going further.
Pretense runs locally as a proxy between a developer and whatever AI coding tool the team already uses, including GitHub Copilot, Cursor, Claude Code, and ChatGPT.
Before a prompt leaves the machine, Pretense finds the sensitive parts (API keys, credentials, source code, customer records) and swaps them for realistic stand-ins. The AI model does its work on the safe version, seeing only the stand-ins it was given. When the response comes back, Pretense restores the original data on the developer's own machine. Every sensitive value stays on the laptop for the entire exchange.
This mutation approach is deliberately different from redaction or blanket blocking, the two most common responses security teams reach for first. Redacting or stripping sensitive fields removes the context an AI model needs, and accuracy degrades with every prompt as the model works from an incomplete picture. Mutation keeps the model working with realistic, complete looking data, so answer quality holds steady while the real values stay entirely within the developer's control.
Pretense is open source, and it is designed to fit inside the workflows that compliance-driven teams already have to think about, including SOC 2, ISO 27001, and HIPAA. Both SOC 2 and ISO 27001 certification are in progress at Pretense rather than complete, and any team evaluating tools in this category should ask every vendor, including this one, exactly where they stand.
Pricing starts at $0 a month on a free tier for smaller teams, and $29 a seat a month on the Pro plan for teams that need unlimited code protection and SOC 2 exports.
Set against a $670,000 AI breach premium, or a $4.44 million breach overall, that is a comparison most security budgets can make quickly. Pretense will be one tool among several on any shortlist for this problem, and that is exactly where it belongs.
Related reading: how the Samsung ChatGPT leak happened, the full IBM 2025 breach cost breakdown, what IBM's shadow AI finding means for engineering teams, and the CISO guide to AI coding tools for 2026.
Try Pretense free or book a walkthrough to see how mutation works on a real codebase.



