All Organizations Now Have Employees Using China-Based AI Tools

Published on
July 21, 2026
Contributors

Every organization Harmonic Security monitored in the first half of 2026 had at least one employee sending data to a China-based AI tool. Across 79 organizations, employees sent 26,530 prompts and uploaded 1,510 files, nearly 2.9 GB, to apps including Tencent Hunyuan, DeepSeek, and Youdao. The files and prompts carried M&A plans, source code, financial projections, and legal material. Once that data reaches these platforms, the organization has no practical way to get it back.

How has this changed since Harmonic Security's last report?

Harmonic Security first surfaced this pattern in July 2025, when its Code Red report found that nearly 1 in 12 employees, 7.95% of the average enterprise, used at least one Chinese GenAI tool over a 30-day period. A year on, the picture has moved from a subset of employees to the entire dataset. All 79 organizations Harmonic Security monitored between January 1 and July 1, 2026, had at least one employee using a China-based AI tool.

The volume moved in the same direction. The 2025 study covered roughly 14,000 users and recorded 535 incidents of sensitive data exposure across five platforms. The 2026 dataset recorded 26,530 prompts and 1,510 file uploads carrying named categories like M&A activity and source code, evidence that the exposure Harmonic Security flagged a year ago has become routine rather than an edge case.

How much data is moving to China-based AI tools?

Harmonic Security's telemetry recorded 26,530 prompts sent to China-based generative AI applications between January 1 and July 1, 2026, across every organization in the monitored dataset. Employees at 100% of these organizations used at least one China-based AI tool during the period.

File uploads compound the exposure. Employees submitted 1,510 files totaling 2.88 GB, and a complete file carries far more data than a typed prompt ever could. Pasting a contract or a code snippet into a chat window is one kind of risk. Uploading a full spreadsheet of financial projections as an attachment is another, and it happened over a thousand times in six months.

Which China-based AI tools are employees using most?

Three apps account for 93% of all recorded activity: Tencent Hunyuan, DeepSeek, and Youdao. Tencent Hunyuan led with 9,892 prompts, followed by DeepSeek at 8,111 and Youdao at 6,606. Kimi Moonshot, Manus, and a long tail of smaller tools made up the remainder.

AI tool Prompts sent (H1 2026)
Tencent Hunyuan9,892
DeepSeek8,111
Youdao6,606
Kimi Moonshot1,099
Manus435
All others387

Source: Harmonic Security telemetry, January 1 to July 1, 2026.

DeepSeek stands out on a different metric. It was the single largest destination for file uploads, taking 1,032 files, close to 2 GB of data. Employees are not just asking DeepSeek questions. They are handing it complete documents.

What kind of data are employees sending to these tools?

Mergers and acquisitions material topped the list, with 4,555 instances detected in submitted content, followed closely by source code at 4,352 and financial projections at 2,904. Legal discourse accounted for 2,528 instances.

Data category Instances detected
M&A activity4,555
Source code4,352
Financial projections2,904
Legal discourse2,528
General PII979
Sales pipeline952
Proprietary code827

Source: Harmonic Security telemetry, January 1 to July 1, 2026. Figures reflect sensitive data detected within submitted prompts and files.

Smaller but still material categories also showed up, in lower volumes than the ones above: access keys, security incident reports, investment portfolio data, and employee records.

Why does it matter that these tools are China-based?

Employees reach for whichever tool answers their question fastest, and China-based apps are often free, capable, and a single search away. Most of this activity is not malicious, just people trying to get work done: pasting a contract, a code file, or a set of numbers into a chat window without stopping to think about where that data ends up.

The destination is what separates this from ordinary shadow IT. Data sent to these tools can be stored, processed, and used for training on infrastructure that sits outside the reach of most corporate policy, and in many cases outside the jurisdictions companies assume their data stays within. Once a financial model or a block of source code has been submitted, there is no getting it back.

Does this concentrate in a few employees, or spread across the company?

Employee counts vary widely across organizations, so the median is the fairer measure here. Half of the 79 organizations Harmonic Security monitored had four or fewer employees using a China-based AI tool. That number sounds manageable until it is set against the file upload data: it only takes one employee pasting a merger model into DeepSeek to create exposure a security team cannot walk back.

What this means for security teams tracking shadow AI

Traditional data loss prevention tools were not built to see a prompt typed into a browser tab or a file dragged into a chat window, which is a large part of why 100% of monitored organizations had this exposure without necessarily knowing about it. Visibility has to come before control. A security team cannot write policy for tools it does not know its employees are using.

Harmonic Security's shadow AI detection identifies which AI tools employees are actually using, while its data loss prevention for generative AI flags sensitive categories like M&A material and source code before they leave the organization. To see what this data looks like for your own organization, request a demo.

Frequently asked questions

Is DeepSeek safe to use for work?

Harmonic Security's telemetry shows DeepSeek received 8,111 prompts and 1,032 file uploads, close to 2 GB, from monitored organizations between January and July 2026. Because DeepSeek is based in China, data submitted to it can be stored and processed outside the jurisdictions many companies assume their data stays within, and organizations have no practical way to retrieve it once it has been submitted.

Where does data go when employees use China-based AI tools?

Data submitted to China-based AI applications can be stored, processed, and used for training on infrastructure outside the reach of most corporate policy. Employees typically have no visibility into retention or training use, and once a file or prompt has been submitted, the organization cannot get it back.

How many companies have employees using China-based AI apps like Tencent Hunyuan or DeepSeek?

Harmonic Security found that 100% of the 79 organizations it monitored between January 1 and July 1, 2026, had at least one employee using a China-based AI tool. The median was four employees per organization, though usage ranged far higher at some companies.

What sensitive data are employees sending to China-based AI tools?

The most common categories Harmonic Security detected were M&A activity (4,555 instances), source code (4,352), financial projections (2,904), and legal discourse (2,528). Smaller volumes of general PII, sales pipeline data, and proprietary code also appeared.

Build Your AI Guardrails Now

Gain the visibility and control you need to guide AI use with confidence.

Harmonic Security Company Logo
As every employee adopts AI in their work, organizations need control and visibility. Harmonic Security delivers AI Governance and Control (AIGC), the intelligent control layer that secures and enables the AI-First workforce. By understanding user intent and data context in real time, Harmonic gives security leaders all they need to help their companies innovate at pace.
© 2026 Harmonic Security