All Organizations Now Have Employees Using China-Based AI Tools


Every organization Harmonic Security monitored in the first half of 2026 had at least one employee sending data to a China-based AI tool. Across 79 organizations, employees sent 26,530 prompts and uploaded 1,510 files, nearly 2.9 GB, to apps including Tencent Hunyuan, DeepSeek, and Youdao. The files and prompts carried M&A plans, source code, financial projections, and legal material. Once that data reaches these platforms, the organization has no practical way to get it back.
How has this changed since Harmonic Security's last report?
Harmonic Security first surfaced this pattern in July 2025, when its Code Red report found that nearly 1 in 12 employees, 7.95% of the average enterprise, used at least one Chinese GenAI tool over a 30-day period. A year on, the picture has moved from a subset of employees to the entire dataset. All 79 organizations Harmonic Security monitored between January 1 and July 1, 2026, had at least one employee using a China-based AI tool.
The volume moved in the same direction. The 2025 study covered roughly 14,000 users and recorded 535 incidents of sensitive data exposure across five platforms. The 2026 dataset recorded 26,530 prompts and 1,510 file uploads carrying named categories like M&A activity and source code, evidence that the exposure Harmonic Security flagged a year ago has become routine rather than an edge case.
How much data is moving to China-based AI tools?
Harmonic Security's telemetry recorded 26,530 prompts sent to China-based generative AI applications between January 1 and July 1, 2026, across every organization in the monitored dataset. Employees at 100% of these organizations used at least one China-based AI tool during the period.
File uploads compound the exposure. Employees submitted 1,510 files totaling 2.88 GB, and a complete file carries far more data than a typed prompt ever could. Pasting a contract or a code snippet into a chat window is one kind of risk. Uploading a full spreadsheet of financial projections as an attachment is another, and it happened over a thousand times in six months.
Which China-based AI tools are employees using most?
Three apps account for 93% of all recorded activity: Tencent Hunyuan, DeepSeek, and Youdao. Tencent Hunyuan led with 9,892 prompts, followed by DeepSeek at 8,111 and Youdao at 6,606. Kimi Moonshot, Manus, and a long tail of smaller tools made up the remainder.
| AI tool | Prompts sent (H1 2026) |
|---|---|
| Tencent Hunyuan | 9,892 |
| DeepSeek | 8,111 |
| Youdao | 6,606 |
| Kimi Moonshot | 1,099 |
| Manus | 435 |
| All others | 387 |
Source: Harmonic Security telemetry, January 1 to July 1, 2026.
DeepSeek stands out on a different metric. It was the single largest destination for file uploads, taking 1,032 files, close to 2 GB of data. Employees are not just asking DeepSeek questions. They are handing it complete documents.
What kind of data are employees sending to these tools?
Mergers and acquisitions material topped the list, with 4,555 instances detected in submitted content, followed closely by source code at 4,352 and financial projections at 2,904. Legal discourse accounted for 2,528 instances.
| Data category | Instances detected |
|---|---|
| M&A activity | 4,555 |
| Source code | 4,352 |
| Financial projections | 2,904 |
| Legal discourse | 2,528 |
| General PII | 979 |
| Sales pipeline | 952 |
| Proprietary code | 827 |
Source: Harmonic Security telemetry, January 1 to July 1, 2026. Figures reflect sensitive data detected within submitted prompts and files.
Smaller but still material categories also showed up, in lower volumes than the ones above: access keys, security incident reports, investment portfolio data, and employee records.
Why does it matter that these tools are China-based?
Employees reach for whichever tool answers their question fastest, and China-based apps are often free, capable, and a single search away. Most of this activity is not malicious, just people trying to get work done: pasting a contract, a code file, or a set of numbers into a chat window without stopping to think about where that data ends up.
The destination is what separates this from ordinary shadow IT. Data sent to these tools can be stored, processed, and used for training on infrastructure that sits outside the reach of most corporate policy, and in many cases outside the jurisdictions companies assume their data stays within. Once a financial model or a block of source code has been submitted, there is no getting it back.
Does this concentrate in a few employees, or spread across the company?
Employee counts vary widely across organizations, so the median is the fairer measure here. Half of the 79 organizations Harmonic Security monitored had four or fewer employees using a China-based AI tool. That number sounds manageable until it is set against the file upload data: it only takes one employee pasting a merger model into DeepSeek to create exposure a security team cannot walk back.
What this means for security teams tracking shadow AI
Traditional data loss prevention tools were not built to see a prompt typed into a browser tab or a file dragged into a chat window, which is a large part of why 100% of monitored organizations had this exposure without necessarily knowing about it. Visibility has to come before control. A security team cannot write policy for tools it does not know its employees are using.
Harmonic Security's shadow AI detection identifies which AI tools employees are actually using, while its data loss prevention for generative AI flags sensitive categories like M&A material and source code before they leave the organization. To see what this data looks like for your own organization, request a demo.
Frequently asked questions
Is DeepSeek safe to use for work?
Harmonic Security's telemetry shows DeepSeek received 8,111 prompts and 1,032 file uploads, close to 2 GB, from monitored organizations between January and July 2026. Because DeepSeek is based in China, data submitted to it can be stored and processed outside the jurisdictions many companies assume their data stays within, and organizations have no practical way to retrieve it once it has been submitted.
Where does data go when employees use China-based AI tools?
Data submitted to China-based AI applications can be stored, processed, and used for training on infrastructure outside the reach of most corporate policy. Employees typically have no visibility into retention or training use, and once a file or prompt has been submitted, the organization cannot get it back.
How many companies have employees using China-based AI apps like Tencent Hunyuan or DeepSeek?
Harmonic Security found that 100% of the 79 organizations it monitored between January 1 and July 1, 2026, had at least one employee using a China-based AI tool. The median was four employees per organization, though usage ranged far higher at some companies.
What sensitive data are employees sending to China-based AI tools?
The most common categories Harmonic Security detected were M&A activity (4,555 instances), source code (4,352), financial projections (2,904), and legal discourse (2,528). Smaller volumes of general PII, sales pipeline data, and proprietary code also appeared.
.png)
