Using AI safely at work

How do you stop company data leaking into AI tools?

Short answerStop company data leaking into AI tools with five layers working together: a written policy that names what never goes into a prompt, approved business accounts, browser or endpoint controls on the devices people use, redaction of sensitive identifiers before a prompt is sent, and logs someone reviews. Traditional data loss prevention (DLP) was built for email and file sharing, so it needs AI-specific rules for pasting, uploads, and desktop apps. Detect shadow AI with cloud app discovery, browser signals, and the admin logs of the tools you approve.

AI data leakage is ordinary work going to the wrong place. Someone pastes a client spreadsheet into a chat window to tidy it, uploads a contract to get a summary, or drops source code into a chatbot to find a bug. Each act takes seconds and each one sends company data to a service nobody at the company has reviewed. The fix is a set of layers, each covering a gap the others leave open.

What happened in the Samsung ChatGPT leak?

In April 2023, Samsung employees uploaded sensitive data to ChatGPT. Fortune, reporting on a memo first covered by Bloomberg, said one engineer uploaded confidential source code while asking ChatGPT to fix a faulty database, and another shared an entire meeting to have minutes written. On May 1, 2023, Samsung told staff in one of its largest divisions to stop using generative AI tools on company devices and warned that violations could lead to dismissal. A later memo described the ban as temporary while Samsung built its own tools.

Nobody in that story was attacking the company. The data left through a helpful tool used for a reasonable task, which is the pattern every firm should plan for.

What does traditional DLP catch, and what does it miss with AI tools?

Traditional DLP watches channels it knows: outbound email, file shares, USB drives, and cloud storage. AI chat adds new channels, and each one needs its own rule. Microsoft's own documentation shows the gaps clearly. Its DLP for Microsoft 365 Copilot checks the text typed into a prompt, and Microsoft states it cannot scan files uploaded directly into a prompt. Its browser control, called Paste to supported browsers, evaluates content at the moment it is pasted and can audit, warn, or block based on the destination website, but only in supported browsers on onboarded devices.

Microsoft Purview behavior as documented on Microsoft Learn, read October 8, 2026. Several Copilot DLP features are in preview; re-check the current documentation before configuring.
How data reaches the AI toolWhat classic DLP seesWhat closes the gap
Pasting text into a chat site in a browserEmail and file-share rules watch other channels. Endpoint DLP with paste-to-browser rules can audit, warn, or block on supported browsers.Paste rules scoped to named AI sites, approved business accounts, redaction before send
Uploading a file to a chatMicrosoft states Purview DLP for Copilot checks typed prompt text only and cannot scan files uploaded into a prompt.Sensitivity labels on files, endpoint upload rules, a written rule on what can be uploaded
Desktop AI apps and command-line toolsBrowser controls apply to browsers. A desktop app or coding tool sends its traffic from the app itself.A control on the device that checks prompts before they leave, plus an approved apps list
Copilot reading company files and emailCopilot runs with each user's permissions, so it sees whatever that user can open.DLP rules that exclude labeled files and emails from Copilot, plus tighter sharing permissions
Personal accounts on personal phonesOutside managed devices and outside company logs.Policy, training, and an approved tool good enough that people prefer it

What are the layers of AI data leakage prevention?

  • Policy. A short written rule that names approved tools and lists the data that never goes into a prompt. People follow rules they can remember.
  • Approved accounts. Business plans change what happens to the data. OpenAI states that by default it does not train on inputs or outputs from ChatGPT Business, Enterprise, Edu, or its API, and ChatGPT Business includes single sign-on and domain verification so the company controls who signs in.
  • Browser or endpoint controls. Rules on managed devices that audit, warn, or block when sensitive content heads to an AI site. Start in audit mode for a week, read the results, then tighten.
  • Redaction before send. Replace card numbers, Social Security numbers, account numbers, and similar identifiers with placeholders before the prompt leaves the PC. The model still answers the question and the identifier never reaches the provider.
  • Logging and review. Keep a record of what was checked, redacted, and blocked, and have a named person read it on a schedule. OpenAI's Compliance Platform for Enterprise and Edu exports workspace logs to eDiscovery, DLP, and SIEM tools for this purpose.

Each layer covers a gap in the others. Policy without controls depends on memory under deadline pressure. Controls without an approved tool push people to personal phones, where nothing applies. See what happens to data once it reaches an AI provider for how retention and training differ by plan.

What should a data leakage prevention policy contain?

A small firm can adopt a one-page data leakage prevention policy for AI. This outline covers what matters; the full AI acceptable use policy template has wording you can copy.

  • Purpose and scope. Applies to every employee, contractor, and device used for company work, and to every AI feature, including those built into email, documents, and browsers.
  • Approved tools. Name each approved tool and plan, signed in with a company account. Everything else needs approval first.
  • Never in a prompt. Client names paired with account details, Social Security numbers, card and bank numbers, health records, passwords, API keys, source code, and anything under a confidentiality agreement.
  • Allowed with care. Internal drafts and anonymized examples, in approved tools only, with identifiers removed first.
  • Uploads. Files go only into approved tools, and only files you would be comfortable emailing to the vendor.
  • Output review. A person checks AI output before it goes to a client, a regulator, or production code.
  • Requesting a new tool. One named owner, one short form, an answer within a stated number of days.
  • Reporting a mistake. Report a paste or upload of restricted data the same day, with no penalty for reporting. Early reports make cleanup possible.
  • Monitoring. State plainly that AI use on company devices is logged and reviewed.
  • Review date. Re-read the policy every six months, because AI vendors change plans and settings often.

How do you detect shadow AI use?

Shadow AI is AI used for company work outside the approved path. Four signals find most of it.

  • Cloud app discovery. Microsoft Defender for Cloud Apps has a Generative AI category with more than a thousand AI apps in its catalog. Admins can see which ones staff use, review each app's risk assessment, and sanction or block specific apps.
  • Browser and device signals. Microsoft Purview DSPM for AI reports AI activity and sensitive interactions per AI app. Monitoring third-party AI sites requires devices onboarded to Purview.
  • Admin logs of approved tools. Sign-in records and compliance logs show who uses the approved tool. A department with zero use is often using something else.
  • Asking. A short anonymous survey about which AI tools people find useful surfaces needs the approved list has missed.

Treat each finding as a request. If a team keeps reaching for a tool, review it and either approve it with controls or offer something that does the same job.

Which standards cover AI data protection?

The NIST Cybersecurity Framework 2.0 (February 2024) sets the outcomes this work serves: inventories of data are maintained (ID.AM-07), data in transit and in use are protected (PR.DS-02 and PR.DS-10), cybersecurity policy is established, communicated, and enforced (GV.PO-01), and software and their data are monitored for adverse events (DE.CM-09). In May 2025, CISA, NSA, FBI, and partner agencies published joint guidance, AI Data Security, covering risks across the AI lifecycle and calling for stronger data protection, proactive risk management, and better monitoring. Map each layer above to one of these outcomes and the program is easy to explain to an auditor or a board.

Frequently asked questions

What is AI data leakage?
AI data leakage is company or client data reaching an AI service through a prompt, a file upload, or an AI feature reading company files, outside the rules the company set. Most cases are employees doing ordinary work with a helpful tool.
Can traditional DLP tools stop data leaks into ChatGPT?
Partly. Endpoint DLP with paste-to-browser rules can audit, warn, or block sensitive pastes into named AI sites in supported browsers. Desktop apps, file uploads, and personal devices need additional controls.
Does Microsoft Purview DLP work with Copilot?
Yes. Purview DLP can stop Copilot from responding to prompts containing chosen sensitive information types and can exclude labeled files and emails from Copilot responses. Microsoft states it cannot scan files uploaded directly into a Copilot prompt.
What should a data leakage prevention policy include?
Scope, approved tools and accounts, a list of data that never goes into a prompt, rules for uploads and output review, how to request a new tool, how to report a mistake, monitoring, and a review date.
How do you detect shadow AI?
Combine cloud app discovery that categorizes generative AI apps, browser or device monitoring on managed endpoints, the admin logs of approved tools, and a short survey of staff.
Is banning AI tools an effective way to stop data leaks?
A ban covers company devices only and pushes use to personal phones, where no control or log applies. Samsung described its 2023 ban as temporary while it built internal tools. An approved tool with controls keeps the work where you can see it.
What data should never be pasted into an AI tool?
Social Security numbers, card and bank numbers, health records, passwords, API keys, source code, client account details, and anything covered by a confidentiality agreement, unless the tool and plan are approved for that data.

Sources

  1. Microsoft Learn, Microsoft Purview DLP for Microsoft 365 Copilot and Cowork. Read October 8, 2026.
  2. Microsoft Learn, Help prevent leakage of sensitive content by restricting paste actions into browsers. Read October 8, 2026.
  3. Microsoft Learn, How do I discover AI apps and the sensitive data these use in my organization? Read October 8, 2026.
  4. OpenAI, Business data privacy, security, and compliance. Read October 8, 2026.
  5. OpenAI Help Center, Setting up single sign-on (SSO) for ChatGPT Business. Read October 8, 2026.
  6. OpenAI Help Center, Compliance Platform for Enterprise and Edu customers. Read October 8, 2026.
  7. CISA, NSA, FBI, and partners, AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems (May 22, 2025). Read October 8, 2026.
  8. NIST, The NIST Cybersecurity Framework (CSF) 2.0, CSWP 29 (February 26, 2024). Read October 8, 2026.
  9. Fortune, Samsung bans employee use of ChatGPT after data leak (May 2, 2023). Read October 8, 2026.
  10. Bloomberg, Samsung Bans Staff's AI Use After Spotting ChatGPT Data Leak (May 2, 2023). Read October 8, 2026.

Reviewed

Free practical kit

Get the full kit: policy, quick-reference, and rollout checklist

Download the ten-section policy, one-page employee quick-reference, and rollout checklist.