TL;DR: More than 60% of blocked activity and policy violations occurred in everyday channels like web apps, email, and instant messaging, while ChatGPT-related blocks surged 86% from Q3 to Q4 and free-form text and screenshots rose in blocked content, according to Safetica’s Data Protection Trends report. The real control problem is moving from file-centric policy to context-aware governance of data-in-use.
At a glance
What this is: This is Safetica’s analysis of H2 2025 data-protection trends, showing that insider-risk activity is concentrating in ordinary collaboration channels and in free-form, AI-era data handling rather than classic document exfiltration.
Why it matters: It matters because IAM, PAM, and broader security teams now have to govern how people move sensitive data across web, email, chat, cloud, and AI tools, not just whether files are leaving the network.
By the numbers:
- More than 60% of blocked activity and policy violations occurred in ordinary channels like web apps, email, and instant messaging.
- ChatGPT-related blocks surged 86% from Q3 to Q4, showing how quickly AI usage is becoming part of the insider-risk surface.
- ChatGPT accounted for about 20.1% of blocked AI interactions in Q4, concentrating risk around a few dominant tools.
- External USB represented 36.1% of unusual-activity triggers in Q4, confirming that removable media still matters in insider-risk monitoring.
👉 Read Safetica's Data Protection Trends analysis of insider-risk shifts in H2 2025
Context
Insider risk is increasingly a data-governance problem rather than a simple malicious-actor problem. The challenge is not only who has access, but how sensitive information moves through everyday collaboration channels, AI tools, and endpoint workflows that traditional policies do not always classify as high risk. In practice, that creates a gap between stated policy and actual data handling across the enterprise.
This article is especially relevant to teams managing human identity, access governance, and data controls together. When work shifts into web apps, messaging, and generative AI, IAM and security policy need to understand context, role, and content rather than assuming the file boundary is still the primary control point.
Key questions
Q: What should teams do when sensitive data is copied into collaboration tools?
A: Treat the copy event as a new governance checkpoint, not a harmless duplication. Re-evaluate sensitivity, preserve provenance if the platform allows it, and restrict onward sharing based on the original source and current access need. Collaboration tools are common loss points because labels often stop at the file boundary.
Q: Why do generative AI tools increase data security risk?
A: Generative AI tools increase risk because they expand the number of places where sensitive content can be ingested, copied, surfaced, or misused. They also consume unstructured data that legacy classification tools often misread, which weakens policy enforcement. The result is a larger blast radius when access is over-permissioned or data visibility is incomplete.
Q: What do organisations get wrong about blocking risky data movement?
A: They often assume a blocked channel means the risk has been reduced. In practice, users may simply move to another channel such as encrypted messaging, cloud sharing, or removable media. Effective governance measures displacement as well as prevention, because the same behaviour can reappear in a different workflow.
Q: How do organisations know whether insider threat controls are actually working?
A: They should look for reduced standing privilege, faster revocation after role change, better session traceability, and fewer unexplained data movement events. If alerts keep firing but entitlements remain broad and offboarding is slow, the control environment is not improving. The signal is not noise volume, but narrower blast radius and quicker containment.
Technical breakdown
Why data-in-use breaks file-centric control models
Data-in-use is information being handled inside active workflows, such as pasted text, screenshots, chat prompts, and copied snippets. Unlike a document at rest, it may never become a managed file, which means file DLP and storage controls can miss the risk entirely. That is why collaboration platforms, browser sessions, and AI inputs now matter as much as endpoints and repositories. The technical shift is from detecting exfiltration after the fact to governing how content is transformed while people work.
Practical implication: extend monitoring and policy enforcement to content in motion, not only files on disk.
Why context-aware policy matters across collaboration channels
Context-aware control uses signals such as role, destination, data type, device state, and channel behavior to decide whether movement is legitimate. Without that layer, organisations either overblock and create workarounds or underblock and miss risky transfers that look normal on the surface. The article’s evidence points to ordinary channels becoming the dominant path for policy violations, which means static rules are too blunt for modern work. Effective governance needs channel-aware classification plus identity-aware policy decisions.
Practical implication: align policy decisions with role and context so legitimate collaboration is separated from risky movement.
How AI tools change the boundary of insider-risk monitoring
Generative AI changes insider risk because the control surface is no longer just storage or messaging. Users can paste company data into prompts, summarize sensitive material in free-form text, or move information through screenshots and outputs that bypass classic office-document controls. That creates a governance problem for both identity teams and security teams: the user may be authenticated, but the data path is still uncontrolled. Monitoring AI interactions as data-handling workflows is now part of basic exposure management.
Practical implication: treat AI usage as a governed data pathway and classify prompts and outputs accordingly.
NHI Mgmt Group analysis
Data-in-use is becoming the new center of insider-risk governance. The report shows that risk is no longer concentrated in obvious file transfer events. It is increasingly embedded in routine collaboration, which makes the control problem less visible and more persistent. That means identity and data teams need to govern the work surface itself, not just repositories and endpoints.
Role-aware and context-aware policy is now a baseline requirement, not a mature-state enhancement. If the majority of risky movement happens through normal work channels, blanket blocking will simply shift behavior to another app or device. The practical challenge is policy precision, because security controls that cannot distinguish legitimate collaboration from risky movement will fail operationally.
AI governance now overlaps directly with insider-risk management. Free-form prompts, screenshots, and copied text create a data path that sits outside traditional file-centric protection. This is the same governance gap that many identity programmes face when a human identity is authenticated but the data flow itself is not governed. Practitioners should treat AI input and output paths as controlled handling zones.
Channel switching is a measurable control-evasion pattern, not just user inconvenience. When one path is blocked, risky movement often migrates to encrypted messaging, cloud tools, or removable media. That means detection has to be cross-channel and behaviourally correlated. Teams should measure whether a policy action reduces risk or merely displaces it elsewhere.
Data-in-use policy sprawl is a named governance gap that many programmes have not explicitly solved. The issue is not the absence of security tools, but the absence of a coherent model for content moving through browsers, chat, AI prompts, and screenshots. That gap belongs in the same conversation as identity governance because users, entitlements, and data handling now intersect continuously.
What this signals
Data-in-use governance will become a more visible part of identity-adjacent security programmes. As work shifts into browser-based collaboration and AI tools, teams will need policies that understand content movement, not just access entitlements. The practical direction is toward identity-aware data control, where authentication, context, and handling rules work together.
The pressure will also move measurement upstream. Security leaders should expect more scrutiny on whether their controls reduce risky handling or merely move it into another application, channel, or device. That shift will matter for governance reporting, incident triage, and the design of future DLP and insider-risk programmes.
For practitioners
- Map sensitive-data movement across collaboration channels Inventory where sensitive content actually moves across web apps, email, instant messaging, cloud tools, and USB. Use those paths to prioritise policy controls, logging, and exception handling where the highest-risk handling occurs.
- Apply context-aware controls to routine work surfaces Use role, destination, device posture, and content type to decide whether a transfer is allowed. Avoid blanket blocks that force users into shadow channels and make the control problem harder to see.
- Treat AI prompts and outputs as governed data flows Classify copied text, pasted prompts, screenshots, and generated outputs as part of the protected data lifecycle. Add logging and policy checks for AI interactions that handle sensitive information, even when no file is created.
- Measure channel switching after every blocking change After tightening one control, check whether activity moves to encrypted messaging, cloud sharing, browser uploads, or removable media. A good policy reduces risk without simply relocating it.
Key takeaways
- Insider risk is increasingly about how data moves through normal work, not only about who intends harm.
- AI prompts, screenshots, and pasted text have become part of the protected data lifecycle, which weakens file-only control models.
- Teams need context-aware, cross-channel governance if they want to reduce exposure without pushing people into shadow collaboration paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity-based access control is central when data movement follows user context. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is relevant where users move sensitive data across everyday collaboration tools. |
| CIS Controls v8 | CIS-3 , Data Protection | The report is fundamentally about protecting sensitive data in motion and use. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policies must cover modern collaboration and data-handling channels. |
Tie data-handling policy to verified identity and context so access decisions reflect actual work patterns.
Key terms
- Data In Use: Data in use is information being actively accessed, processed, or modified by a user, application, or workload. It is the hardest state to govern because policy must follow live identity behaviour, not just storage location or network transit.
- Context-Aware Policy: Context-aware policy is a control model that decides access based on current conditions, not just preassigned entitlement. For AI agents and other non-human identities, this means privileges, tool use, and monitoring expectations can change as the task, environment, or risk signal changes.
- Channel switching: Channel switching is the pattern where users move activity from one blocked or watched path to another, such as shifting from email to chat or from a file upload to a browser-based transfer. It is a useful signal that a control is displacing behaviour rather than reducing risk.
- Insider Risk Management: Insider Risk Management is the practice of detecting, investigating, and reducing harm caused by legitimate identities misusing access. It covers human error, malicious insiders, compromised accounts, and increasingly AI-driven actors that can move sensitive data without breaking perimeter controls.
What's in the full report
Safetica's full report covers the operational detail this post intentionally leaves for the source:
- Quarter-over-quarter trend tables showing how blocked activity shifted across email, web, chat, cloud, and USB channels
- Breakdowns of which content types were blocked most often, including free-form text, screenshots, and AI-related interactions
- The underlying aggregate methodology behind the anonymized H2 2025 signal set
- Visual comparisons that show how user behaviour changed when one channel was restricted
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, secrets management, and workload identity. It helps practitioners connect identity controls to the broader security programmes that rely on them.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org