Subscribe to the Non-Human & AI Identity Journal

Why do cloud-only DLP and DSPM controls miss the highest-risk data movements?

Because they observe data after it has been stored, queried, or reported by an application, not when a user or AI tool actually handled it. The most consequential leak often happens on the endpoint during active use, where data can be copied, reshaped, and redistributed before cloud visibility catches up.

Why This Matters for Security Teams

Cloud-only DLP and DSPM tools are useful for discovering sensitive data at rest and mapping exposure in storage systems, but they do not reliably capture the moment data is used, transformed, or exfiltrated in the workflow. That gap matters because the highest-risk movement often occurs during active interaction on the endpoint, in browser sessions, in desktop applications, or through an AI assistant that can copy, summarize, paste, or export content outside the original control boundary. The NIST Cybersecurity Framework 2.0 emphasises risk-based governance and continuous protection across the full lifecycle, which is exactly where cloud-only visibility tends to fall short.

Practitioners often assume that if a file is classified in the cloud, the main risk is already contained. In reality, once a user downloads data, opens it in a local tool, or feeds it into an agentic workflow, the control problem shifts from storage governance to active usage governance. That is where context, intent, and short-lived handling matter most, especially when sensitive material is moved into chat tools, temporary caches, clipboard buffers, screenshots, or unmanaged SaaS workflows. In practice, many security teams encounter the exposure only after downstream sharing or AI-assisted redistribution has already occurred, rather than through intentional prevention at the point of use.

How It Works in Practice

Effective coverage requires pairing cloud discovery with controls that observe data in motion and data in use. Cloud DLP and DSPM remain valuable for classification, posture management, and identifying overexposed repositories, but they should be treated as upstream intelligence rather than the final enforcement point. The practical control stack usually extends into the endpoint, identity, browser, and collaboration layers, where the real movement happens. This is also where organisations need to account for human behaviour and AI-mediated behaviour, because an employee and an AI agent can both move sensitive content quickly once they have execution authority.

A stronger approach usually includes:

  • Endpoint DLP for copy, paste, print, upload, and local file transfer actions.
  • Browser and SaaS session controls for webmail, collaboration tools, and file sharing.
  • DSPM for locating sensitive stores, then feeding prioritised findings into response workflows.
  • Identity-aware policies that tighten access when risk, device posture, or location changes.
  • Telemetry that can connect endpoint events to cloud audit logs and SIEM correlation.

Security teams should also consider how AI changes the path of movement. If a user pastes sensitive content into a chat-based assistant, the exposure may not be a traditional file exfiltration event, but it is still a data handling event that deserves policy and logging. Guidance from CISA cloud logging and monitoring guidance and threat models such as MITRE ATT&CK support this more operational view of detection and response. These controls tend to break down in bring-your-own-device environments because the organisation cannot consistently observe the endpoint layer where the data is copied, reshaped, or forwarded.

Common Variations and Edge Cases

Tighter endpoint and session controls often increase friction for users and administrators, requiring organisations to balance stronger prevention against workflow disruption. That tradeoff is especially visible in engineering, finance, legal, and customer support teams, where rapid movement of data is part of daily work and blanket blocking can push users toward shadow IT. Best practice is evolving toward risk-adaptive policy, where controls become stricter only when the data type, destination, or user context indicates elevated exposure.

There is also no universal standard for handling AI-assisted data movement yet. Some organisations classify prompts, outputs, and conversation histories as protected data flows; others treat them as ordinary collaboration traffic unless regulated content is involved. The most defensible model is to extend DLP and DSPM into a broader data control strategy that includes device posture, identity assurance, and application context. For cross-domain governance, CISA Zero Trust guidance is useful for separating implicit trust from verified access, while NIST Cybersecurity Framework 2.0 helps anchor the program in continuous risk management.

Where cloud-only controls break down most decisively is in high-trust internal environments with unmanaged endpoints, offline file handling, or agentic workflows that can transform sensitive data faster than cloud telemetry can detect.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.DS Data security outcomes depend on protecting data throughout its lifecycle, not just in cloud storage.
MITRE ATT&CK T1020 Exfiltration over alternative channels maps to the data movement risk DLP often misses.
NIST AI RMF AI-assisted data movement needs governance across use, output validation, and risk monitoring.
OWASP Agentic AI Top 10 Agentic workflows can move sensitive data outside cloud-only visibility and policy boundaries.
NIST AI 600-1 GenAI systems need controls for prompt/output handling and downstream data leakage risk.

Extend protection to endpoints and active use paths, then verify controls with continuous monitoring.