What is AI data loss prevention (AI DLP)?

By Identra · Updated

AI data loss prevention (AI DLP) is the set of policies and controls that help prevent sensitive information from being disclosed through AI prompts, uploads, retrieved content and outputs. It evaluates data and its intended destination so unauthorized sharing can be stopped or sensitive details removed before disclosure.

What data does AI DLP protect?

Customer records, source code, credentials, HR data, contracts. The usual list. What's different is how it gets out. Someone pastes a customer export into ChatGPT. A coding agent pulls an .env file into its context. A file goes up as an attachment. An assistant retrieves a document on its own and quotes it back.

Destination matters as much as content. The same board deck might be fine in the company's ChatGPT Enterprise workspace and a policy breach in a personal account on the same site. An internal assistant can leak too, by showing a document to an employee who shouldn't see it. Stopping AI data leakage means deciding on content, account and recipient together.

How does AI data loss prevention work?

The control looks at content at a point where it can still stop it. Detection might use Microsoft Purview sensitivity labels, identifier patterns like card numbers, known API key formats, document fingerprints or a classifier. Then policy decides. Allow it, warn the user, mask the sensitive parts or block.

The check has to finish before the data crosses the line. If a file upload completes and the control only reads the next chat message, the file is already gone. An alert after the fact helps the investigation. It doesn't undo anything.

Check what actually gets sent. In coding agent workflows the typed prompt might be three harmless words while the agent attaches half a repo as context. Scanning model output can stop a bad answer reaching a user. It can't recall data already sent to the provider.

How is AI DLP different from traditional DLP?

Same principles. Different blind spots. Your endpoint, network and cloud DLP may already cover some AI traffic, but only if it can read the content and act before the transfer finishes.

Ask three things. Can it read uploaded files? Can it tell a company login from a personal one on the same domain? Does it see context an agent adds on its own? Blocking a domain answers none of these. Account-aware AI access handles the second.

  • Endpoint DLP

    What it's good for
    Data leaving a managed device
    What to check
    Whether it sees AI desktop apps, coding agents and uploads
  • Network or inline DLP

    What it's good for
    Traffic inspected before delivery
    What to check
    Whether it can read the content and knows the app
  • Cloud API scanning

    What it's good for
    Content already stored in a SaaS app
    What to check
    Whether detection happens before or after exposure
  • In-app AI controls

    What it's good for
    Prompts, retrieval and output inside one app
    What to check
    Where enforcement stops and what routes around it

What does an AI DLP event look like?

Say a support manager wants a quick summary of an escalation report. They upload it to a personal AI account. The report has customer names, contract terms and an API key someone pasted in during troubleshooting. The AI service itself is approved for research. This account and this data are not.

A preventive control blocks the upload and points them to the company workspace. They try again there with a trimmed version. Masking the names alone wouldn't have been enough, because the key and contract terms are still sensitive.

If the upload had already gone through, the job changes. Work out what was sent and to which account, rotate the key and follow the incident process. Deleting the chat may help. It doesn't prove the provider has no copy.

How do connectors and agents change AI DLP?

A connector pulls mail, files or CRM records straight from the source. Nothing passes through the prompt box. Prompt inspection can't see it. Look at the connector's scopes and the source's sharing settings instead.

Give each connection an owner, review OAuth app risk and drop grants nobody needs. Least privilege on the source limits what an assistant can retrieve in the first place.

For agents, also restrict where tools can send data and which actions need approval. Test whether instructions planted in a retrieved document can get data sent somewhere it shouldn't go.

How should you roll out AI DLP?

Write the sharing rules first and tie them to your AI acceptable use policy. People need to know what they can share, where and with which account, and what to do when they're blocked.

  • Map the paths: browser chats, desktop apps, coding agents, uploads, connectors.
  • Block what's prohibited. Mask only when what's left is genuinely safe to send. Use alerts to tune.
  • Test with synthetic secrets and realistic harmless work, including attachments and agent-added context.
  • Keep exceptions narrow, owned and time limited. Repeated blocks on the same task usually mean a missing approved tool.
  • Log the decision without copying the sensitive prompt into the log.

How Identra thinks about it

Identra checks browser prompts on the device before they are sent, then allows, alerts, masks or blocks them by policy. Prompt content stays on the device by default. File uploads to AI apps can be inspected, including sensitivity labels, and blocked by policy, and pastes are checked for secrets. On endpoints, prompts to Codex and Claude Code and desktop AI composers get the same on-device checks before they are sent.

Go deeper: Identra in the browser

Frequently asked questions

Is AI DLP the same as using AI to improve DLP?

No. Here it means protecting data that flows into and out of AI systems. Using AI classifiers inside a general DLP product is a different thing.

Does turning off model training prevent data leakage?

No. A no-training setting limits one use of the data. The data still left, and the recipient may not be authorized to have it.

Can masking make any prompt safe?

No. What's left can still identify a person or reveal a deal. Check the remaining text against the policy.

Can AI DLP stop prompt injection?

It may block the data transfer an injection tries to cause. It doesn't stop the injection itself or other actions the agent could take.

How do you know AI DLP is working?

Test whether prohibited content reaches its destination and whether normal work still gets through. Review misses, false blocks and unsupported paths.

Related terms

Keep exploring · AI security programs and controls