Artificial intelligence makes work easier, but it can also put a company in the firing line: according to Irena Hysková, head of the Czech cybersecurity firm Alintrust, employees often secretly use free public chatbots, such as ChatGPT, for routine tasks and feed them confidential company information — data that can later end up in the hands of hackers and make an attack on the company easier.
"If the AI tools a company uses are free, then all the information entered into them can be accessible to anyone else," Hysková explains. According to her, employees often use public chatbots in secret, without the knowledge of the IT department and without any security rules, simply to make their own work easier.
The expert notes that artificial intelligence can just as easily be exploited by a would-be attacker. "In the past, if someone was preparing a cyberattack, they needed to gather information about the company and its culture: who works there, what forms of address are used, and then draft a phishing email. Today AI helps do this very quickly, and even the employee themselves may not realize whether it's a cyberattack or not," Hysková adds.
According to the National Cyber and Information Security Agency, the Czech Republic recorded 203 such incidents last year — about sixty fewer than in 2024 — though the agency warned that attacks are becoming more sophisticated. From the start of this year through the end of August, 159 incidents had already been recorded. Victims have included large companies as well, such as the Partners group. Hackers often attack not the company itself but its weaker link — its suppliers.
According to IBM, Microsoft and other companies, employees and unsanctioned AI will be the fastest-growing security threat of 2026. Surveys show that 80% of employees use unauthorized AI tools at work. Microsoft reports that 78% of employees bring their own AI tools to work, while KPMG, following a survey across 47 countries, warns that 57% of employees actively hide their use of AI from their employer.
According to Hysková, management needs to clearly define which tools are allowed and will be used within the company, and employees need to be trained on what counts as sensitive data. "I strongly advise employees against entering anything at all into AI tools. Very often people thoughtlessly enter names, surnames, personal ID numbers, business contracts and a host of other things. These tools are helpful and boost productivity, but entering this kind of data into them is simply not worth the risk — the company could end up in the crosshairs of an attack," she says.
Hysková stresses that she does not think banning AI tools is the right approach — they bring real benefits and simplify routine tasks. But their use needs to be kept under control, and companies need to know exactly which tools their employees are using.
Alintrust has operated under its current name since February 2026, when it split off from the former firm Thein Security — the financially healthy part of entrepreneur Tomáš Budník's troubled Thein group. Alintrust now operates as an independent cybersecurity company, with the J&T group remaining one of its major shareholders.
Alintrust's clients include major retailers, banks and pharmaceutical companies. Last year the firm's revenue topped CZK 386 million, while EBITDA grew 60% to CZK 30 million. The company plans to grow further through acquisitions — according to Hysková, Alintrust has its eye on two or three companies that could round out its cybersecurity services portfolio.
Source: seznamzpravy.cz