A UK Government cyber security breaches survey suggests roughly 612,000 UK businesses experienced a cybersecurity breach in the past year. That figure is large, and it is the firmest part of a recent Security Magazine piece on preventing AI data breaches and leaks. The same piece also states that OpenAI and Anthropic recently committed data breaches "from uninstructed cyberattacks." That second claim is thin, and the source offers no detail to back it up. Here is what can responsibly be said about AI platform data breaches, and where a VPN fits in.
What the UK Breach Survey and the AI Claims Actually Say
The survey figure is the clear takeaway: approximately 612,000 UK businesses reported a breach in the past year, according to the UK Government's Cyber security breaches survey. The source does not break that number down by cause, sector, or technique, so it should not be read as a count of AI-related incidents.
The claim about OpenAI and Anthropic is a different matter. The source article gives no dates, no description of what data was exposed, no number of affected users, and no explanation of what "uninstructed cyberattacks" means. Without those details, we cannot confirm that either company suffered a breach of customer data, and we are not repeating it as established fact. The phrase may refer to AI systems acting autonomously, but the source does not say so. Readers should treat it as an unverified claim until the companies or independent reporting provide specifics.
What is safe to say is that the survey shows breaches are common for businesses of all kinds, and that any service holding large volumes of user text, such as an AI assistant, is an attractive target.
How Data You Give AI Assistants Ends Up Exposed
Even without a confirmed breach at a specific provider, there are several ordinary routes by which information shared with AI tools can leak:
- Account compromise. If someone gets into your account through a reused or phished password, they can read your conversation history.
- Retention and training policies. Depending on the service and your settings, prompts may be stored for a period or used to improve models. Check each provider's current policy, since terms vary and change.
- Workplace use. Employees pasting customer records, source code, or contracts into a consumer chatbot can move sensitive data outside company controls.
- Third-party apps and plugins. Tools that connect to an AI service add more places where your data is handled.
- Shared links and screenshots. Conversations shared with others can travel further than intended.
Notice that most of these depend on what you choose to type and how you secure your account, not on a dramatic attack against the AI company itself. Stolen data also has a second life: once exposed, it can be sold or used for pressure. Our piece on 2026 data extortion trends explains how attackers increasingly monetize stolen information beyond traditional ransomware.
Where a VPN Helps and Where It Doesn't
A VPN encrypts the connection between your device and the VPN server and hides your IP address from the sites you visit. That has real value in specific situations:
- Public Wi-Fi. It adds a layer of protection against snooping on the local network while you use an AI tool in a cafe or airport.
- IP privacy. It stops the AI service and other observers from seeing your home IP address.
But a VPN does not change what happens once your prompt reaches the AI provider. Specifically, it cannot:
- Stop a provider from storing or processing what you type.
- Protect your data if the provider's systems are breached.
- Prevent account takeover from a stolen or reused password.
- Hide your identity if you are logged in to your account.
In short, a VPN protects data in transit. The risks described above mostly concern data at rest on someone else's servers, which is outside a VPN's reach. It is one layer, not a fix for AI platform data breaches.
Practical Data Minimization When Using AI Tools
The most reliable protection is sharing less. Consider these habits:
- Strip identifying details. Replace names, account numbers, addresses, and client information with placeholders before pasting text.
- Never paste secrets. Passwords, API keys, medical details, and confidential documents do not belong in a chatbot.
- Review privacy settings. Look for options to turn off chat history or opt out of training use, and confirm what they actually cover.
- Secure your account. Use a unique password and multi-factor authentication.
- Delete old conversations you no longer need.
- Follow workplace rules. If you use AI at work, use approved tools and ask your security team what is permitted.
What This Means For You
The 612,000 figure is a reminder that breaches are routine for UK businesses, and your data may sit in many of those systems. The specific claims about OpenAI and Anthropic remain unverified in the source, so there is no need to panic, but there is good reason to be deliberate. Assume anything you type into an AI assistant could someday be exposed, and decide what to share on that basis.
Takeaways
To reduce your exposure to AI platform data breaches, limit what you share, lock down your accounts, and understand each tool's retention settings. Use a VPN if you want added protection on untrusted networks, but treat it as one layer among several. To see how leaked information is later turned into profit, read our look at data extortion trends for 2026.




