
Ecuadorian Companies Grapple with 'Shadow AI' Risks Amidst Significant Data Protection Gaps
The use of Artificial Intelligence (AI) has become widespread among consumers, companies, and organizations in Ecuador. However, many AI usage practices are not governed by controlled environments, highlighting gaps in data protection culture.
According to a GMS report published in September 2026, 66% of employees in Ecuadorian organizations state they use AI tools every day. The same report indicates that around 70% of these employees affirm their workplace has basic or significantly flawed preparation for AI use. A concerning finding from the document is that 33% of workers used personal accounts for work activities involving AI.
This activity, known in the industry as 'shadow AI,' involves the use of unauthorized AI tools that do not meet minimum standards for business use. This practice increases the risk of sensitive information being disclosed to unknown persons. Paul Nacimba, a cybersecurity expert and GMS Pre-sales Manager, explains that individuals often have a false perception that well-known applications share data securely, which is not always the case. He adds that when personal accounts are used, they are completely open, lacking the controls and blocking capabilities available with corporate AI.
Further compounding the issue, ESET reports that 70% of organizations do not have internal regulations for AI. The theft of credentials or personal accounts is also considerably easier compared to corporate accounts, which typically feature more security layers. While corporate AI services like ChatGPT or Gemini offer higher restriction levels, allowing configuration to prevent uploaded information from being used for training, experts note that internal data visibility issues can still arise, with employees from one department potentially accessing sensitive information from unrelated areas.
Iván Ortiz, director of the Cybersecurity program at the Universidad de las Américas, emphasizes that companies using AI must first educate employees on the personal and organizational risks associated with AI misuse. He also points out that some Ecuadorian companies, particularly smaller ones, often do not allocate sufficient resources for cybersecurity, limiting themselves to legal compliance rather than technological safeguards. Daniel Tenorio, a cybersecurity expert from bSmart and specialist for ESET Ecuador, highlights severe cases globally where organizations have lost databases following AI agent implementation.
Experts agree that despite rapid AI adoption, a widespread data protection culture is still developing in Ecuador. A gap exists between large entities that apply robust data protection and smaller ones that often prioritize legal compliance over technological security. The increased use of AI tools in programming environments also raises the risk of defective or malicious code reaching public platforms. Tenorio cautions that current AI tools are not yet ready for automated use in critical tasks.
What to watch
Organizations in Ecuador should review their internal policies regarding AI tool usage and invest in cybersecurity infrastructure. The prevalence of 'shadow AI' suggests an immediate need for clear guidelines, employee training, and the implementation of corporate AI solutions with appropriate data governance. The gap in data protection culture, particularly among smaller enterprises, indicates a broader challenge for national data security standards.
Sources: primicias.ec.
Support daily Ecuador business intelligence.
Research support funds source monitoring, data checks, editing, publishing, and sector coverage for professionals tracking Ecuador.