AI has reshaped nearly every corner of cybersecurity, and data security might just be one of the biggest functions impacted. It’s changed what kind of data is actually at risk, where that data can end up, and how much of it moves at once.
A few years ago, the data most organizations worried about losing had a predictable shape: Social Security numbers, credit card numbers, health records. Now the material that causes the most damage (source code, financial models, product roadmaps, strategy documents) has no fixed shape at all. It can leave the device in the time it takes to paste it into a chat window.
At Bold, we've had a front-row seat to the evolution of endpoint security, data security, and the point where the two converge, and AI has completely transformed how we need to approach that convergence point. What hasn't changed is the goal: protect the data that actually matters, at the layer where people, and now AI, do the work.
Key Takeaways
- The at-risk data has changed. The highest-risk data today is unstructured and proprietary, like source code and financial models, rather than the structured PII legacy DLP was built to catch.
- New AI risk patterns have no legacy equivalent. Shadow AI adoption and unattended agent activity are risk categories that barely existed a few years ago.
- Enforcement location determines visibility. Every layer except the endpoint misses AI activity like desktop apps and agent actions that never touch a browser.
- No single lever fixes AI data loss on its own. People, process, and technology all have to move together. That means coaching-first policy, shared ownership across teams, and real-time on-device classification.
- Block-or-monitor is a false choice. Enforcement without context forces teams to choose between blocking too aggressively or monitoring only, which is why most programs end up stuck in monitor-only mode.
New AI Data Loss Threats and Examples
AI has introduced a set of endpoint risks that didn't exist just a few years ago. A few specific patterns show up across nearly every organization adopting AI:
- Shadow AI adoption. Employees are picking up AI tools faster than IT can inventory them, let alone approve them. Example: A shadow AI tool is in daily use with no one aware of its data retention policy
- Public-tier data exposure. Sensitive data pasted into a free or consumer-tier AI tool may be retained or used to improve the model, with none of the guarantees an enterprise agreement provides.
Example: An employee pastes proprietary code or a customer list into a personal AI account to get help finishing a task, with no data processing agreement behind it - Autonomous agent activity. AI agents now read, move, and act on files and systems with no person directly at the keyboard, which means some of the riskiest activity on a device has no human to attribute it to. Example: An AI agent is given standing access to a sensitive system with no ongoing oversight boundary
- Encrypted desktop traffic. Desktop AI apps increasingly encrypt their own traffic end-to-end, so it never reaches a network or cloud inspection point at all. Example: A desktop AI app operates entirely outside what the proxy or CASB can see
How AI Has Changed Data Security
Four things moved at once, and each one on its own would have been enough to strain a legacy DLP program.
|
Pre-AI |
AI Era |
| Classification target |
Regulated, structured data (PII, PCI, PHI, GDPR) |
Unstructured, proprietary data (source code, financials, IP) |
| Speed required |
After-the-fact detection was often tolerable |
Real-time, at the moment of action |
| The actor question |
Assumed to be a person |
Person or autonomous agent, and telling them apart matters |
| Egress volume |
A known, relatively stable set of channels |
New channels added continuously as AI tools are adopted |
The Enforcement Layers Behind AI Data Loss Prevention
AI DLP vendors position themselves at different points in the stack, and where enforcement happens changes what a tool can see and (potentially) act on.
Network and CASB/SASE. Sits in the traffic path between users and cloud services. It can allow, block, or log access to an AI tool at the domain level. It can't read what's inside a prompt, so it can't tell a harmless question from one that contains a customer list.
Platform and SaaS-embedded AI. Covers AI features built into tools like Microsoft 365, Google Workspace, or Salesforce. Enforcement here depends on the platform vendor's own controls, so visibility stops at the edge of that platform. An AI feature in a different tool, or a personal AI account outside the sanctioned platform, falls outside its view.
Browser and prompt-level. Inspects the text of a prompt before it reaches an AI provider, in real time. This catches sensitive data pasted into a chat window regardless of which AI service it's headed to. Its blind spot is anything happening outside the browser: a desktop AI app, a local file operation, or an agent acting without a person typing anything at all.
Endpoint and device. Sits on the device itself, below the browser and below any single application. It sees prompt activity, desktop AI apps, local file operations, and agent activity in one place, without depending on network visibility or a platform integration. It's the only layer that keeps working when an AI tool encrypts its own traffic or runs offline.
None of these layers are wrong to have. Network and platform controls still matter for the channels they're built for. But AI usage increasingly happens in places only the endpoint can see, which is why AI data loss prevention has to include the device to be complete.
How to Approach AI DLP: People, Process, Technology
None of this is solved by a tool alone. It takes a change across all three levers organizations already use to manage risk.
People
Build a coaching-first culture around AI use, not a punitive one. Employees pasting data into a chatbot are almost never acting maliciously; they're trying to get work done with the tools in front of them. Make it clear which tools and account types are approved, and why, so the default behavior shifts before enforcement ever has to step in.
Process
An AI usage policy has to be grounded in the organization's actual risk tolerance and regulatory obligations, not a generic "don't paste sensitive data into AI tools" memo that nobody enforces. It also can't live in a security team silo — legal, compliance, and the business units actually using these tools need shared visibility into what's happening. The direction the market is already moving supports this: by 2027, 70% of CISOs at larger enterprises are expected to adopt a consolidated approach that addresses both insider risk and data exfiltration together, rather than treating them as separate programs (Gartner, Market Guide for Data Loss Prevention, 2025).
Technology
The tooling has to catch up to the threat. That means classification that understands what the data actually means, not just what pattern it matches; enforcement that acts in the moment rather than logging it for later; and, increasingly, the ability to distinguish a person's action from an AI agent's on the same device.
[IMAGE: three-column diagram — People / Process / Technology — one line under each summarizing the shift described above]
Data Loss Prevention in the AI Era: The Way Forward
With the right approach, AI innovation and data protection don't have to be a tradeoff. They only become one when the guardrails aren't fast enough or precise enough to stay switched on. Which is exactly why so many organizations end up turning off blocking and settling for just monitoring instead. The way forward is classification and enforcement that can actually keep pace with AI adoption, on the device, in real time.
Bold runs AI locally on the endpoint to classify data by meaning, tell human activity from AI-agent activity, and prevent risk the moment it happens — without a cloud round-trip and without the block-or-monitor tradeoff that's kept most DLP programs stuck in "monitor only."
Learn more about Bold to see what real-time, on-device data protection looks like against your own environment.
FAQ
Is AI data loss prevention different from endpoint DLP?
They overlap but aren't identical. Endpoint DLP is the broader category of stopping data loss at the device level, covering channels like email and file transfers along with AI tools. AI data loss prevention narrows in on the risk introduced specifically by AI tools and agents. The strongest programs run AI DLP as part of a broader endpoint DLP strategy rather than a separate bolt-on tool.
Can a CASB or network DLP stop data loss to AI tools?
Not on its own. A CASB can block or allow access to an AI service at the domain level, and network DLP can catch files leaving over known channels, but neither can read what's inside a prompt or see activity inside a desktop AI app. Stopping a specific leak requires visibility at the point where the interaction happens, which for most AI usage today is the endpoint itself.
Does AI data loss prevention cover AI agents, not just tools like ChatGPT?
It needs to. Agents can access and move data with no person at the keyboard, which means the riskiest activity on a device may have no human behavior pattern to flag it. Effective AI DLP tells a person's action apart from an agent's activity, since a chat window is only one of the ways data now moves.
Do I still need AI data loss prevention if I already have DLP for email and file storage?
Yes. Traditional DLP was built to catch structured data crossing known channels like email and file transfers. It wasn't built to see a prompt typed into a browser tab or a desktop AI app that encrypts its own traffic. AI usage introduces channels and data types that most existing DLP deployments were never configured to catch.