TL;DR: Basic exfiltration remains highly effective even as security teams focus on shadow AI and AI-assisted data loss, with recent cases showing insiders and bribed support agents moving sensitive data through familiar channels, according to Orion and cited reporting. The real gap is not new transfer methods but weak visibility into intent, context, and legitimate access paths that DLP has never fully governed.
At a glance
What this is: This is an Orion analysis arguing that DLP’s oldest failure mode, insider-driven data exfiltration, still persists even as AI expands the threat surface.
Why it matters: It matters because IAM, PAM, and data security teams still need to control who can move sensitive data, through which channels, and under what context, whether the actor is human, insider-assisted, or AI-enabled.
👉 Read Orion's analysis of why basic data exfiltration still defeats modern DLP
Context
Data loss prevention often fails at the boundary between allowed access and allowed movement. The article argues that the core problem is not a lack of new controls, but that organisations still struggle to see when a legitimate user, support agent, or AI-assisted workflow is moving sensitive data for the wrong reason.
That distinction matters for identity governance as much as for DLP tooling. If access is granted broadly, monitored weakly, or reviewed only at the application layer, exfiltration can happen through ordinary channels such as USB, email, or web transfer without triggering the level of scrutiny the data deserves.
Key questions
Q: How should security teams reduce data exfiltration when users already have legitimate access?
A: They should combine data classification, identity context, and behavioural policy instead of relying only on channel blocking. Legitimate access must not imply unrestricted export rights. The strongest programmes review who is acting, what data is involved, why the transfer is happening, and whether the action matches normal behaviour before the data leaves the boundary.
Q: Why do AI tools increase the visibility problem for DLP programmes?
A: AI tools can move, summarise, or forward data through prompts, outputs, and connectors that do not look like classic exfiltration. That makes the transfer harder to observe with legacy controls built for email, USB, and web uploads. Organisations need telemetry that follows the data through the workflow, not just the exit channel.
Q: What do security teams get wrong about insider-driven exfiltration?
A: They often focus on malicious intent alone. In practice, negligent users can create the same exposure through cloud sync, email, AI tools, or removable media. The more useful signal is behaviour change, such as unusual downloads, access outside normal scope, or activity that accelerates before departure.
Q: Who is accountable when AI-enabled attacks bypass legacy access controls?
A: Accountability sits across IAM, security operations, and application owners because the failure spans authentication, telemetry, and abuse response. Frameworks such as the NIST Cybersecurity Framework 2.0 and Zero Trust architecture expect shared ownership of identity assurance, detection, and containment.
Technical breakdown
Why channel-based DLP misses the real exfiltration problem
Traditional DLP controls are built around transfer paths, such as USB blocking, email inspection, web upload filtering, and application restrictions. Those controls can reduce exposure, but they do not answer the harder question of whether a person or system had a legitimate reason to move the data in the first place. Once access is approved, the security model often assumes the transfer is acceptable unless a rule says otherwise. That is why insiders and bribed employees can still extract data through simple means. The mechanism is less about technical sophistication and more about misplaced trust in authorised access.
Practical implication: pair channel controls with identity- and context-aware policy so authorised access does not automatically equal authorised export.
How AI changes visibility, not just exfiltration speed
AI does not invent the exfiltration problem, but it can make data movement harder to observe. AI-assisted workflows may copy, summarise, transform, or forward sensitive information in ways that blend into normal usage patterns, especially when the organisation lacks telemetry on prompts, outputs, connectors, and downstream transfers. The article’s point is not that AI replaces insider risk. It is that AI can widen the visibility gap by creating more places where sensitive data leaves without leaving a clear, human-readable trail. That makes context and intent more important than the transfer mechanism alone.
Practical implication: extend monitoring to AI interactions, connectors, and delegated access paths, not just classic egress channels.
Why intent-based controls matter more than ever
Intent-based DLP asks why data is moving, not just where it is going. That shifts governance from static channel rules toward risk-based decisions that factor user role, data sensitivity, behaviour, and session context. In identity terms, this brings DLP closer to PAM and access governance because the control question becomes whether the actor should be able to perform the action at that moment. For organisations dealing with NHIs, copilots, or human insiders, the underlying issue is the same: sensitive data should not move simply because a route exists. The route must also be justified.
Practical implication: define policy conditions that combine identity, data classification, and behavioural context before approving sensitive exports.
Threat narrative
Attacker objective: The attacker or insider seeks to remove sensitive data from the organisation while staying inside legitimate access boundaries long enough to avoid immediate detection.
- Entry occurs through legitimate access, whether held by an employee, a support agent, or an AI-assisted workflow with permission to reach sensitive systems.
- Credentialed access is then abused to copy data through simple channels such as USB media, internal transfer, or bribed third-party assistance, avoiding overt exploitation.
- Impact follows as regulated, personal, or operationally sensitive data leaves the organisation with limited visibility and delayed detection.
NHI Mgmt Group analysis
Basic exfiltration is still the primary DLP failure mode. The industry keeps framing data loss as a next-generation problem, but the article shows that ordinary insider misuse, bribery, and physical transfer remain effective. That means DLP programmes still depend on the oldest assumption in security: that approved access implies approved use. It does not. Practitioners should treat uncontrolled data movement as a governance failure, not just a tooling gap.
Visibility gap is the real control deficit, and AI makes it worse. When organisations cannot see how data moves through prompts, outputs, connectors, and delegated workflows, they lose the ability to distinguish benign from harmful transfer. That creates a blind spot across human identity, privileged access, and AI-assisted workflows. The question is no longer whether AI creates new exfiltration routes, but whether current controls can observe them before data leaves the boundary.
Intent-based governance should sit beside channel enforcement. Blocking USB or email is necessary but insufficient when the actor already has access and the data path is only one of several options. The more useful control model combines classification, user context, role, and behavioural risk so the policy decision happens before export. That is where DLP intersects with IAM and PAM: the control must know who is acting, what they can reach, and whether the action makes sense in context.
Non-human identities need the same exfiltration scrutiny as people. AI agents, service accounts, and automation workflows increasingly sit inside the same data flows as human users, but they often inherit broad access with weaker oversight. If those identities can retrieve, transform, or forward sensitive records, they become exfiltration paths in their own right. Security teams should stop treating NHI data movement as a separate problem from human insider risk and govern both with the same sensitivity to context and intent.
DLP is entering a governance reset, not a feature race. The article’s deeper point is that every new channel has historically produced a new control, yet the underlying trust model has stayed the same. That is why modern programmes must move toward policy decisions based on data sensitivity, session context, and identity assurance. Practitioners who keep buying more channel filters without fixing access logic will keep seeing the same breach pattern in a newer wrapper.
What this signals
Visibility, not volume, is becoming the defining DLP constraint. As organisations add AI workflows, shadow AI, and more delegated access paths, the limiting factor is no longer how many controls exist. It is whether the programme can see enough of the data journey to separate normal usage from harmful movement. That is a governance problem first, and a tooling problem second.
Identity and data policy are converging. The more a user, support agent, or AI workflow can reach sensitive records, the less useful pure channel blocking becomes. DLP teams should align with IAM and PAM teams around access context, because the next control question is not simply where data leaves, but whether the identity should have been allowed to move it at all.
Exfiltration is increasingly a mixed human and machine identity issue. Service accounts, copilots, and external AI platforms can all participate in data movement, often with more privilege than teams realise. That makes the operational priority clear: establish identity-aware export policy now, before a larger share of sensitive data flows through paths your current telemetry cannot reliably explain.
For practitioners
- Map sensitive export paths to identity context Identify where users, support agents, contractors, and service accounts can move restricted data, then tie each export path to role, location, device posture, and session risk before allowing transfer.
- Extend DLP telemetry into AI workflows Instrument prompts, outputs, connectors, and downstream copy actions so AI-assisted movement of sensitive data is visible alongside email, web, and removable media egress.
- Tighten privileged data access review Review which privileged identities can read, export, or duplicate regulated data, and remove standing access where the business case is weak or no longer current.
- Add intent checks to high-risk transfers Require policy decisions to consider data classification, user purpose, and behavioural signals before approving large or unusual exports, especially for personally identifiable data.
Key takeaways
- DLP still fails most often at the basic trust boundary, where legitimate access becomes unauthorised export.
- AI raises the visibility burden by moving sensitive data through prompts, connectors, and automated workflows that legacy controls do not see well.
- The next DLP model must combine classification, identity context, and intent checks before approving high-risk data movement.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access control is central where legitimate identity use becomes data exfiltration. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege directly addresses overbroad access to sensitive data and export paths. |
| CIS Controls v8 | CIS-6 , Access Control Management | Access control management limits who can reach and move regulated data. |
| MITRE ATT&CK | TA0009 , Collection; TA0010 , Exfiltration | The article centres on collection and data removal through trusted access. |
| ISO/IEC 27001:2022 | A.8.12 | Data leakage prevention controls are directly relevant to the article's subject. |
Map sensitive data movement to collection and exfiltration tactics to improve detection and response.
Key terms
- Data Loss Prevention: Data loss prevention is the set of controls used to detect, block, and report sensitive data moving in ways the organisation does not allow. In practice, DLP must account for endpoints, email, cloud apps, APIs, and user behaviour, or it will miss the paths where real exposure happens.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Intent-based control: Intent-based control is a security approach that evaluates what a user or system is trying to do, not just what data appears on the wire. For AI, this matters because prompts and responses can expose risk through context and meaning even when no obvious keyword or file transfer exists.
- Email Data Exfiltration: Email data exfiltration is the unauthorized transfer of sensitive information through email, attachments, links, or forwarding rules. It may be accidental or deliberate, but the governance challenge is the same: prove whether the sender, recipient, and content matched policy and access intent.
What's in the full article
Orion's full article covers the operational detail this post intentionally leaves for the source:
- The specific DLP control examples the article uses for USB, email, web upload, and application restrictions.
- The article's fuller discussion of how AI-assisted data movement creates blind spots in traditional monitoring.
- The source's examples of insider abuse, bribery, and whistleblower-style exfiltration patterns.
- The article's framing of why intent and context matter more than transfer mechanism alone.
👉 Orion's full post expands on the insider cases, AI visibility gap, and intent-based control shift.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners build the control foundations needed for modern access and exfiltration governance.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org