By NHI Mgmt Group Editorial TeamBased on Entro Security: “Entro WebGuard: stop sensitive data from leaking into AI tools” (June 26, 2026)

TL;DR: AI assistants are now a common path for accidental secret exposure, and Entro Security says WebGuard scans prompts in the browser to block secrets and PII before they reach major LLMs. The governance gap is that current IAM and DLP assumptions do not see what users paste into AI tools in real time.


At a glance

What this is: This is a browser-side control that scans AI prompts in real time to block or log secrets and PII before they reach external LLMs.

Why it matters: It matters because the weakest link is often the user paste event, where existing IAM and DLP controls do not see sensitive data before it leaves the browser.


Context

The security gap is not that AI tools exist, but that sensitive data can leave the organisation at the point of human input before any downstream control sees it. When employees paste API keys, tokens, customer data, or code into browser-based AI assistants, traditional IAM and DLP models often have no real-time view of the transfer.

For identity and access teams, this is a governance problem around human behaviour interacting with external AI services, not just a content filtering problem. The control question is whether the organisation can inspect, classify, and enforce action at prompt time, rather than after the data is already outside the boundary.


Key questions

Q: How should security teams govern employee use of public AI tools in the browser?

A: They should treat browser AI use as an identity and data-control problem, not just an acceptable-use issue. The team needs visibility into what was pasted, which account was active, whether the content was sensitive, and whether policy enforcement occurred before the data left the organisation. Controls that only inspect network events will miss the real decision point.

Q: What breaks when prompts are not scanned before they reach external AI tools?

A: Without prompt scanning, sensitive data can leave through a sanctioned workflow before any enterprise control sees it. IAM still shows a valid user and DLP may never see the content in time, so the organisation loses both visibility and meaningful intervention at the moment disclosure occurs.

Q: How do teams know whether AI prompt controls are actually working?

A: Look for whether the control is operating at the moment of prompt entry and whether it can distinguish data classes, account type, and destination. If users can still paste regulated content into personal AI sessions without warning or enforcement, the control is cosmetic rather than operational. Effective controls reduce silent leakage, not just alert volume.

Q: What is the difference between blocking and auditing sensitive AI prompts?

A: Blocking stops the prompt and removes the sensitive content from the request, while auditing allows the prompt to continue and records what was detected and who approved it. Blocking is for high-risk secrets; auditing is for observation, policy tuning, and lower-risk data where visibility comes first.


How it works in practice

How browser-side prompt scanning works

Browser-side prompt scanning inspects text before it is sent to an external LLM. In this pattern, the control checks both what the user types and the full outbound prompt at send time, including text from attached files. The point is to catch secrets in context, not only obvious token strings. Entro Security describes a flow where detected content is validated and classified, so the system can distinguish a GitHub token from an AWS access key or a Stripe key. That matters because classification drives the response, whether the organisation wants to block, warn, or audit. Practical implication: treat the browser as the enforcement point when AI prompting is the data-loss path.

Practical implication: enforce inspection at prompt time, not after data has already left the browser.

Why prompt-time controls differ from DLP and IAM

Traditional DLP and IAM controls are usually built around storage, network, or policy enforcement points that sit after the user has already decided to share data. Prompt-time leakage breaks that assumption because the sensitive content is created in the browser and can be transmitted instantly to a third-party model. In practice, the problem is not only access to the AI service, but uncontrolled disclosure through the interaction itself. That is why a control can be effective even when the destination model is legitimate and sanctioned. It is governing the moment of disclosure, not the destination. Practical implication: align AI usage controls to the disclosure event, not just the account or app boundary.

Practical implication: align controls to the disclosure event, not just the identity or application boundary.

What block, prevent, and audit mean in practice

A browser control needs response modes because not every sensitive disclosure deserves the same treatment. Block stops the request and redacts sensitive content, which is suited to private keys and production credentials. Prevent warns the user and allows cancellation or continuation, which gives teams room to tune policy for lower-risk data. Audit allows the prompt but records what was found and who proceeded, which is useful for phased governance and monitoring. The important design point is that detection without action creates visibility but not control. Practical implication: define response tiers by data class and make the user decision itself part of the audit trail.

Practical implication: map response tiers to data classes and preserve the user decision in the audit trail.


NHI Mgmt Group analysis

Browser-side prompt inspection is a control point, not a convenience feature: the core issue is that users now disclose secrets inside a browser session before enterprise logging or DLP can intervene. That shifts the enforcement boundary from network and endpoint monitors to the prompt itself. Organisations that do not control the prompt moment are effectively relying on user restraint as a security control, which is not governance. The implication is that AI usage policy must be enforced where data is authored, not only where it is stored or transmitted.

Prompt-time leakage creates identity governance blind spots: IAM programmes assume access is visible through accounts, entitlements, and sanctioned applications, but browser-based AI use creates a disclosure path that does not look like a classic access event. The user is authenticated, the model may be approved, and the secret still leaves the organisation. That means the control failure is not merely weak DLP, but a missing governance layer for sanctioned external AI interaction. The implication is that AI usage now belongs in identity governance, not only in acceptable-use policy.

Context classification matters more than raw detection: Entro Security's model distinguishes secrets from PII and then maps each finding to block, prevent, or audit. That reflects a broader principle: disclosure controls fail when every sensitive string is treated the same. In practice, a production API key and an email address do not carry the same blast radius, so the governance model should not impose one response for all cases. The implication is that policy needs differentiated treatment by data class, not a single blanket rule.

Prompt scanning is a governance layer for shadow AI behaviour: employees will keep using browser-based assistants because the workflow is faster, which means the control problem is not adoption but unmanaged disclosure. The named concept here is prompt-time disclosure control: the ability to inspect and classify AI prompts before they exit the user’s environment. That concept is becoming central to AI governance because it addresses the exact moment risk is created. The implication is that teams need controls that work with real user behaviour, not ideal user behaviour.

Real-time scanning only matters when it is operationally silent on clean traffic: controls that interrupt every prompt will be bypassed, while controls that only react to sensitive content can become part of normal workflow. The article’s emphasis on no-friction clean prompts reflects a broader governance truth: adoption depends on selective enforcement. That is especially relevant for AI usage controls, where excessive friction pushes users toward unmonitored paths. The implication is that effective governance must be precise enough to catch the leak without becoming the workaround trigger.

From our research library:

  • 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to the State of Secrets in AppSec.
  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

What this signals

The governance shift is that AI prompts are becoming an unmanaged disclosure channel, which means security teams need controls that act before data exits the browser. According to the Ultimate Guide to NHIs, 92% of organisations expose NHIs to third parties, a reminder that external interaction surfaces are already a major control concern.

Prompt-time disclosure control: browser-based inspection turns AI usage into a governed event instead of a blind paste-and-send action. That matters because the control objective is no longer just to secure the destination system, but to stop sensitive content from being disclosed in the first place.


For practitioners

  • Define prompt-time enforcement as a control boundary Treat the browser prompt as the point where sensitive data can leave the organisation, and write policy to enforce there rather than only in storage or network controls.
  • Classify data by response severity Separate production secrets, credentials, and PII into different response paths so the control can block high-risk disclosures and warn or audit lower-risk ones.
  • Log user decisions on prompt warnings Record what was detected, which action fired, and whether the user proceeded anyway so security and audit teams can trace disclosure decisions after the fact.
  • Inspect attached files as part of prompt review Scan content pulled from uploaded files and pasted text together, because secrets buried in supporting material can create the same exposure as secrets typed directly into the box.

Key takeaways

  • Browser-based AI use creates a disclosure path that existing IAM and DLP models often do not see in real time.
  • Prompt-time inspection changes the control point from the destination model to the moment a user authors or sends sensitive content.
  • Differentiated responses such as block, prevent, and audit are more practical than a single blanket rule for every secret or data type.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and OWASP API Security Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article is about secrets leaving the browser in AI prompts before they can be controlled.
Recommendation — Scan prompt content for exposed secrets and stop high-risk disclosure before it reaches external AI tools.
OWASP Agentic AI Top 10ASI09 — Human-Agent Trust ExploitationUsers trust browser AI assistants with sensitive content, creating a disclosure channel based on that trust.
Recommendation — Reduce trust-based prompt disclosure by enforcing inspection before users can send sensitive content.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governing how people use AI tools and who is accountable for disclosure.
Recommendation — Define accountable governance for AI prompt handling, data classification, and override logging.
NIST CSF 2.0PR.DS-01 — Data-at-rest is protectedThe article concerns sensitive data protection, but the main issue is disclosure before data leaves the browser.
Recommendation — Extend data protection controls to the prompt boundary so sensitive content is handled before external transmission.
OWASP API Security Top 10API8 — Security MisconfigurationThe post discusses configuration of prompt-scanning controls and how enforcement is applied in the browser.
Recommendation — Review browser prompt enforcement settings so risky AI disclosures are blocked or logged consistently.

Key terms

  • Prompt-time disclosure control: A control that inspects user-entered content before it leaves an interface and is sent to an external AI service. It is designed to stop secrets, credentials, or personal data at the point of authoring, where traditional network or storage controls often have no visibility.
  • Browser Enforcement: Browser enforcement is policy execution inside the browser or closely adjacent endpoint layer where the user interaction occurs. It is relevant when employees use AI tools through web interfaces, because sensitive text can be copied, pasted, or generated without ever passing through traditional network controls.
  • Prompt Leakage: The unintended exposure of user prompts, system prompts, or tool output from an AI runtime. In NHI terms, prompt leakage matters because those strings often carry sensitive instructions, credentials, or business context, and they may be stored in memory, logs, or exported artifacts.
  • Data-classed response: A policy model that applies different actions based on the type of data detected. High-risk secrets can be blocked, lower-risk items can be warned on, and observational cases can be audited, allowing controls to match the sensitivity and operational context of the disclosure.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org