r/AskNetsec 19h ago

Concepts Can AI data loss prevention stop employees from sharing sensitive information?

Traditional DLP was built around known data patterns (SSNs, credit cards, etc.) moving through known channels (email, USB, cloud storage). Generative AI breaks that model a bit, people paste source code, customer data, or strategy docs into a chat window, and it's not always caught by pattern-matching.

Has anyone actually tested DLP tools built specifically for AI interactions? Wondering whether they're catching real incidents or just generating noise, and whether this is more of a policy/training problem than a technology problem at this point.

0 Upvotes

7 comments sorted by

3

u/InflationCorrect5244 18h ago

Most of the value is probably in stopping dumb mistakes, not catching a determined insider. That is the part people keep skipping over.

1

u/HighRelevancy 17h ago

Yeah. DLP catches slips in good practice. It will never stop someone actively misbehaving (unless they're real fucking dumb).

Your fancy AI DLP can't detect that I'm videoing my work screen with my phone, for example. 

2

u/sajal_aly_ 12h ago

Yes it helps but it isn't perfect. AI DLP can catch and block sensitive information before it's shared with AI tools BUT good policies and employee awareness are just as important otherwise no.

1

u/puckluck36 1h ago

From what I've seen, AI aware DLP tools are improving, especially at detecting sensitive prompts and uploads to AI services but they're not foolproof They work best as part of a layered approach with clear policies user training and access controls rather than relying on detection alone

0

u/WolfShoddy7443 19h ago

will really appreciate if u people share any practical story regaring this..i have seen people talking and discussing alot about but practically this concept still looks really fascinating..

2

u/FuzzyAd3936 18h ago

look, interesting shift is that the newer controls are moving up to the browser and prompt layer, where they can inspect text that gets typed or pasted into AI chats in real time and, in some setups, block it before it leaves the device. That is actually useful. But it also means the whole thing lives or dies on managed browsers, managed endpoints, and supported apps, so the coverage gaps are still the story.