In late January, DeepSeek AI, developed by the Chinese startup “DeepSeek,” caused a sensation upon its release on the App Store. The DeepSeek-R1 model demonstrated outstanding performance in various areas, including mathematics and programming, rivalling OpenAI. However, its training cost was only 4% of OpenAI’s. Another DeepSeek-V3 model achieved scores close to Claude and Alibaba in tests such as software engineering and Chinese language proficiency and even received the highest score in mathematics. What was even more shocking was that the training cost of the V3 model was only one-twentieth of OpenAI’s GPT-1. DeepSeek not only surpassed 16 million downloads in the first 18 days after the app’s launch, and topped the free app charts in many countries, but also saw its user base explode, causing service delays.
Employee misuse of AI tools can lead to corporate data breaches
However, DeepSeek has been plagued by controversies since its launch. Beyond suspicions of using OpenAI’s training data and censorship during user interaction, it has also been banned from public sector use by several governments, including Taiwan, the United States, South Korea, Australia, and Italy, due to cybersecurity concerns. These concerns primarily stem from its personal data collection practices. Like other AI models, it collects personal information such as user emails, phone numbers, IP addresses, birthdays, and text and voice conversation records during registration and use. However, DeepSeek is suspected of having vulnerabilities in its underlying code that could leak this user data to the Chinese government.
In fact, with workers increasingly relying on AI assistance, any AI tool can pose a risk of data breaches. In 2023, there were reports of Samsung employees uploading and processing confidential internal company data in ChatGPT, leading to a leak. Numerous experts have also, through repeated testing, induced various large AI models to reveal internal confidential information.
Could Your Employees’ AI Tools Be a Security Nightmare?
Beyond the aforementioned issues of personal data protection and data breaches, businesses may face the following challenges when employees begin to heavily use AI tools to assist their daily work:
- Malware: Some hackers may use AI to develop sophisticated, hard-to-detect malware, which can then spread through the AI’s internal network. When employees use AI tools, they may accidentally trigger it, causing losses to the company.
- Access Rights: If employees use AI tools not recognized by the company to assist their work, they may create corporate security vulnerabilities due to the AI tool’s own defects. For example, when employees hand over the company’s internal data to AI for analysis, the access rights of specific data will no longer be fully controlled.
- Compliance: The operation of many enterprises needs to comply with international norms such as GDPR and ISO, but when employees use unreviewed AI tools without authorization, it may cause risks of regulatory compliance for the company.
- Security Awareness: Many employees are prone to lose their security awareness of AI tools due to convenience, and over-believing the information provided by AI may create a corporate security breach.
How Can Businesses Combat AI Security Risks?
In the age of AI, businesses should exercise caution not only with DeepSeek, but with any AI tool. Master Concept offers the following recommendations:
AI Policy Governance: Companies should establish internal AI policies, informing employees which tools are permissible for use in work and the usage guidelines. AI policies should have clear, specific content and be effectively communicated to all departments.
Providing Employees with Regular Cybersecurity Training: As mentioned earlier, employees often rely on AI tools for convenience and may inadvertently overlook many warning signs. Regular cybersecurity training for employees is not only to meet regulatory requirements but also an important security defense measure for businesses.
>>> Learn more about KnowBe4 Employee security awareness training platform
- Access Control: Faced with potential data breach crises, businesses should implement stricter access control. In addition to measures such as SSO and MFA, companies should also consider implementing privileged access management (PAM). Furthermore, SASE/CASB is a way to ensure that the web pages accessed and applications used on employees’ devices comply with corporate policy specifications.
>>> How SASE can help businesses?
>>> 了解思想科技的資安解決方案
AI tools are constantly evolving, and employees who want to increase work efficiency and simplify tasks will inevitably want to try them. Strict restrictions on use are only a temporary control measure. Strengthening all aspects of enterprise cybersecurity defense can truly reduce risks and address future trends. If businesses have any cybersecurity needs related to AI, they are welcome to contact Master Concept’s professional consultants!
參考資料
最強開源AI 模型之一!DeepSeek-V3 GPU 時間比Llama 3 少 11 倍
DeepSeek 容易受到邪惡越獄攻擊!KPMG:三大資安舊包袱仍是隱憂
何, 佩珊. “深度解讀DeepSeek效應.” 商業週刊, 06 02 2025, pp. 62-68.
Which countries have banned DeepSeek and why? | Business and Economy News | Al Jazeera






