-
Average GenAI prompts per user rose to 106 in August from 78 in June
-
86% of regular users still recorded high-risk activity
The growing use of generative artificial intelligence (GenAI) across businesses is raising fresh concerns over the protection of sensitive patient information, after healthcare and medical organisations recorded the highest rate of high-risk AI prompt activity in August.
According to Check Point Research’s Global Threat Intelligence Insights for August 2026, 4 percent of GenAI prompts from healthcare and medical organisations were classified as posing a data exposure risk, equivalent to one in every 25 prompts.
The rate was the highest among the industries tracked by the cybersecurity firm, placing healthcare ahead of software, where one in every 28 prompts, or 3.6 percent, was classified as high risk. Business services followed at 3.5 percent, also equivalent to one in every 28 prompts.
The finding comes as enterprise use of GenAI continues to expand rapidly, with the average user generating 106 prompts in August, up from around 78 prompts in June and 95 in July.
Although the proportion of high-risk prompts declined in August to one in every 43 prompts globally, Check Point said the underlying data exposure risk remained widespread. Some 86 percent of organisations that regularly use GenAI were still affected by high-risk prompt activity.
The figures point to a growing challenge for organisations as AI moves from experimental use into routine business activities, increasing the volume of information employees enter into AI systems.
“…the risk is not only whether employees are using approved or unapproved AI tools, but what information they enter into them. As teams rely on multiple GenAI applications and generate higher volumes of prompts, sensitive data can move into environments that lack sufficient visibility, governance, or control. This also increases exposure to prompt manipulation and indirect prompt injections, where hidden instructions embedded in external content can influence AI behavior and potentially expose information,” the report noted.
For healthcare organisations, the implications are particularly sensitive because employees may use AI tools to assist with tasks involving medical information, including summarising documents, drafting communications, interpreting information or processing other work-related content.
Check Point noted that sensitive data exposure in healthcare is especially concerning because the information involved can include highly private patient details.
The cybersecurity firm cited an example of a prompt entered into a web-based ChatGPT service that contained a patient’s full name, symptoms, examination results and diagnosis, illustrating how information that would ordinarily require strict protection could potentially be entered into a generative AI system.
The example, however, does not by itself establish that such information was exposed through a breach or that the healthcare sector’s 4 percent rate represents confirmed patient-data breaches. Rather, the research highlights the potential for sensitive information to be submitted through AI prompts.
The broader data shows that the problem extends beyond healthcare.
Among organisations where GenAI prompts contained sensitive information, network and IT infrastructure data appeared in 67 percent, followed by financial data at 65 percent, legal and regulatory information at 64 percent, employee and human resources data at 59 percent and personally identifiable information at 57 percent.
Check Point said the growing use of multiple AI applications was also creating a governance challenge, with organisations using an average of seven different GenAI tools.
As employees move between different AI platforms, organisations may have less visibility into what information is being submitted, where it is processed and what controls apply to the data.
The cybersecurity firm also warned that the risk extends beyond deliberate submission of sensitive information, pointing to prompt manipulation and indirect prompt injection attacks in which hidden instructions contained in external content can influence an AI system’s behaviour.
The increase in AI use is occurring alongside a broader rise in cyber threats.
Organisations globally experienced an average of 2,422 weekly cyber attacks in August, representing a 4 percent increase from July and 22 percent growth from August 2025.
Africa recorded an average of 3,335 weekly attacks per organisation, making it the second most targeted region by volume behind Latin America, which recorded 3,577. Africa’s figure was 3 percent higher than the same period last year.
Email phishing also increased during the month, with one in every 112 emails classified as phishing, compared with one in every 128 emails in July.
Ransomware activity rose further, with 1,042 reported attacks in August, up 8 percent from July and nearly double the number recorded a year earlier.
The combination of rising cyber threats and expanding AI use places greater pressure on organisations to treat AI governance as part of their broader cybersecurity and data protection frameworks.






