Yolande Gething | Principal Cyber Security Specialist | Cyberforensics | mail me |
As businesses accelerate the use of generative AI tools, cybersecurity teams face a growing reality. Traditional Data Loss Prevention (DLP) controls were never designed for the way employees now use Artificial Intelligence (AI).
For years, DLP strategies focused on monitoring structured data. They tracked information moving through predictable channels such as email, USB devices, printing, and file transfers. However, browser-based AI platforms, autonomous agents, and AI-connected enterprise applications are fundamentally changing how sensitive data moves through systems.
How AI adoption is changing data loss risks
Traditional DLP tools were built around known loss vectors and structured data. But employees are now pasting sensitive information directly into AI tools. They are also uploading files into browser-based platforms and connecting AI systems to internal data sources. Many businesses are not properly monitoring these activities.
Unlike conventional data transfers, AI-related exposure often occurs through ordinary employee workflows. Staff upload reports into AI assistants to summarise documents, analyse spreadsheets, draft presentations, or generate communications. Developers increasingly rely on AI coding assistants to accelerate software delivery. AI tools are also being connected directly to cloud platforms such as SharePoint and Google Drive.
The problem, cybersecurity specialists warn, is that many users do not fully understand where data goes once it leaves the organisation’s environment. Depending on provider policies and configurations, public AI tools may temporarily store information entered by users. They may retain that information for monitoring or even use it to improve future AI models.
Furthermore, traditional DLP solutions rely heavily on pattern matching, exact fingerprinting, and predefined rules. AI interactions are far less predictable. Sensitive information can now appear in prompts, screenshots, conversational queries, generated outputs, or automated workflows. Older DLP tools were never designed to inspect these channels effectively.
Autonomous agents add new risks
At the same time, autonomous AI agents introduce additional concerns. Compromised agents could potentially exfiltrate sensitive information rapidly or exploit excessive permissions that organisations grant to AI systems. Poorly configured integrations may also unintentionally expose large volumes of enterprise data.
Software development environments present another growing risk area. AI-generated code may contain vulnerabilities or insecure logic. Developers can create these risks if they fail to apply sufficient human oversight before deploying outputs into production systems.
In response, organisations are beginning to rethink how DLP functions in practice. Security teams are increasingly exploring AI-aware monitoring tools. These tools can analyse browser interactions, prompt activity, and contextual data usage patterns.
Technologies such as browser isolation, API-level inspection, and real-time redaction are also gaining traction. Businesses are adopting these technologies as they attempt to regain visibility into how employees share sensitive information with AI platforms.
Governance must keep pace with AI adoption
Governance is also becoming a priority. Many businesses are introducing formal AI acceptable-use policies, employee awareness programmes, and vendor risk assessments. These measures aim to clarify how AI providers store, process, and protect enterprise data.
NLP-enabled DLP tools are also emerging as a key focus. They can analyse the meaning and context of information rather than relying solely on static keywords or file fingerprints. The reality is that companies need to evolve their current approach to DLP by incorporating technologies that are proving successful in monitoring AI interactions.
The growing concern among cybersecurity professionals is that AI adoption is happening faster than governance and security controls can mature. Many employees already use AI tools informally, often outside approved enterprise frameworks. This trend is creating a rise in so-called “shadow AI” usage.
Balancing innovation and security
At the same time, organisations face pressure not to slow innovation. Businesses want employees to benefit from the productivity gains AI can deliver. However, they must do so without exposing sensitive customer data, intellectual property, financial information, or regulated records in the process.
As AI adoption continues to accelerate, organisations must find ways to manage these risks without blocking legitimate use. Security teams therefore need controls that reflect how employees actually interact with AI.
For many, the question is no longer whether AI introduces new data loss risks. Instead, the question is whether existing security models can evolve quickly enough to keep pace with AI adoption.

























