Because they mostly rely on predefined rules, labels, and known data patterns. That works for structured secrets and classified files, but not for free-text disclosures, board drafts, or contextual sharing decisions. The missing layer is intent-aware enforcement that understands who is sending data, from which account, and to which AI destination.
Why Workspace-Native Controls Miss the Real Leakage Path
Workspace-native safeguards are useful for known records, labelled files, and policy-triggered sharing events, but Gemini leakage often happens in the gray area of free text, summaries, drafts, and conversational context. That matters because AI assistants can transform harmless-looking content into a broader disclosure when the model infers meaning from adjacent prompts, account context, or connected tools. NIST’s control guidance for access enforcement is necessary, but it does not by itself solve semantic leakage across AI interactions. NHIMG’s Gemini AI Breach — Google Calendar Prompt Injection shows how the risk is not only what data exists, but how an AI destination interprets it. The problem is magnified when organisations assume the workspace boundary is the enforcement boundary.
For teams trying to reduce exposure, the practical lesson is that labels and DLP rules are necessary but incomplete. They can stop obvious secrets, yet they rarely capture intent, business context, or whether the sender should be allowed to route sensitive text into an AI system at that moment. In practice, many security teams encounter leakage only after a user has already asked an assistant to summarise or transform protected content, rather than through intentional policy design.
How It Works in Practice
Effective control needs to move beyond static content inspection and toward context-aware decisioning. That means evaluating who is sending the data, from which account, to which model or workspace, and under what business context. The relevant policy question is not just “does this text contain a secret?” but “should this identity be allowed to share this content with this AI destination right now?”
Current guidance suggests combining several layers:
- Classification and labelling for structured secrets, regulated content, and known sensitive repositories.
- Identity-aware enforcement that ties the action to the authenticated user, device state, and destination scope.
- Intent-based policy for AI interactions, especially when content is being summarised, translated, or cross-posted into a model context.
- Logging and post-action review so teams can trace which prompts and attachments triggered disclosure.
This aligns with the broader NHI lesson in NHIMG’s Ultimate Guide to NHIs — Why NHI Security Matters Now: identities and permissions must be governed as active attack surfaces, not as static account records. For AI-assisted workflows, that often means treating the Gemini interaction as a privileged destination and applying policy at request time, not after the content has already moved.
Security teams also need an operational standard for exceptions. For example, board materials, incident notes, customer data, and source code may each require different handling even when the same user is involved. NIST SP 800-53 Rev. 5 supports access control, audit, and information flow enforcement, but organisations still have to map those controls into AI-specific workflows. These controls tend to break down in highly collaborative environments where people routinely paste, summarise, or forward mixed-sensitivity content across chat, docs, and model prompts because the policy engine cannot reliably infer user intent from content alone.
Common Variations and Edge Cases
Tighter AI content control often increases friction, requiring organisations to balance leakage reduction against user productivity and false positives. That tradeoff is especially visible in environments that depend on rapid drafting, knowledge work, or cross-functional review. Best practice is evolving because there is no universal standard for this yet, and vendors implement workspace-native protections differently.
One common edge case is free-text disclosure that never matches a known secret pattern. Another is context leakage, where a harmless fragment becomes sensitive only when combined with meeting history, email threads, or previous prompts. A third is delegated access, where assistants act on behalf of a user and inherit more context than the user intended to expose. NHIMG’s Guide to the Secret Sprawl Challenge is relevant here because AI leakage often surfaces in the same places secrets sprawl does: scattered systems, inconsistent governance, and weak visibility into what is actually in use.
For higher-risk environments, current guidance suggests pairing workspace controls with explicit AI-use policy, destination restrictions, and human review for sensitive classes of content. Where this guidance is weakest is in fast-moving, multi-system workflows that mix chat, document editing, and embedded AI features, because the policy boundary becomes too fragmented to enforce consistently.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A01 | AI leakage risk grows when agentic tools can expose context unexpectedly. |
| CSA MAESTRO | GOV-1 | Governance must cover model use, data flow, and destination controls. |
| NIST AI RMF | AI RMF addresses contextual risk, accountability, and ongoing monitoring. | |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access helps limit who can send data into AI systems. |
| OWASP Non-Human Identity Top 10 | NHI-03 | AI integrations rely on secrets and tokens that can widen leakage exposure. |
Rotate AI-connected secrets quickly and remove unused credentials from workspace integrations.