AI introduces new risks around data leakage, particularly when sensitive information is unknowingly shared with external AI tools or APIs. Regulations such as the EU AI Act and GDPR increase accountability, requiring organisations to monitor AI usage, manage incidents, and control data flows. The priority is clear: implement data discovery, classification, and governance controls before scaling AI, supported by a holistic view of people, processes, and technology.