By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: StracPublished August 13, 2026

TL;DR: Data loss prevention now has to follow sensitive information across SaaS, cloud, browsers, GenAI, endpoints, APIs, and MCP-connected workflows, because detection-only controls no longer stop data from moving into the wrong place, according to Strac. The shift matters for IAM and NHI teams because AI tools and agents increasingly create new data egress paths that must be governed, not just observed.


At a glance

What this is: This is an analysis of how modern DLP has expanded from email and endpoint filtering into real-time control over sensitive data moving through SaaS, cloud, GenAI, browsers, APIs, and MCP-connected workflows.

Why it matters: It matters to IAM practitioners because the same data paths now intersect with human access, service credentials, and AI-driven workflows, so data governance and identity governance can no longer be treated as separate problems.

👉 Read Strac's analysis of modern data loss prevention across SaaS, cloud, GenAI, and MCP


Context

Data loss prevention is no longer just about stopping files from leaving the network. In 2026, sensitive information moves across SaaS applications, cloud services, browser sessions, endpoints, AI prompts, APIs, and MCP-connected tools, which means the control point has shifted from perimeter blocking to data-flow governance.

That shift matters because many organisations still rely on controls designed for email and endpoint leakage, while the real exposure now comes from everyday collaboration and AI workflows. Where identity and access intersect with DLP, the question is not only who can reach the data, but how that data can be copied, transformed, or handed off to another system.


Key questions

Q: How should organisations control sensitive data in GenAI tools?

A: Organisations should treat prompts, uploads, and model outputs as governed data flows, then apply classification, inspection, and logging at the point of use. The control objective is to stop sensitive information from entering AI workflows without visibility. That requires policy, access rules, and monitoring to work together, not as separate programmes.

Q: Why do DSPM and DLP need to work together?

A: DSPM finds sensitive data and shows where it lives. DLP enforces what happens when that data moves, is copied, or is exposed. Used together, they close the gap between knowing where risk exists and actually controlling it. Without both, teams either see too little of the estate or cannot act fast enough when sensitive content travels into the wrong system.

Q: What breaks when DLP is still built around endpoints and email gateways?

A: It misses the way data now moves through SaaS, cloud, and AI workflows that do not pass through a small set of inspection points. Modern DLP has to understand the data itself, its context, and the identities that can reach it. Without that, enforcement becomes reactive and incomplete.

Q: When should organisations treat MCP as a data governance issue?

A: As soon as MCP-connected tools can retrieve enterprise data or forward it to another service, the protocol becomes a governance concern. Organisations should classify connected tools, restrict tool permissions, inspect the content moving through those connections, and apply the same policy discipline they use for other sensitive data transfer points.


Technical breakdown

How modern DLP follows data across SaaS and AI workflows

Modern DLP works by identifying sensitive content wherever it appears and then enforcing policy at the point of movement. That requires discovery, classification, inspection, and inline action across structured and unstructured data, including files, messages, screenshots, prompts, and API traffic. The key change is that the control plane now sits around the data itself, not just around the network or device. Once data can move from SaaS to browser to GenAI and then into an MCP-connected tool, the security model has to track context, not just destination.

Practical implication: map every sanctioned data path and decide where inspection and enforcement must occur, especially across AI and SaaS handoffs.

Why DSPM and DLP are converging

DSPM answers where sensitive data exists, who can access it, and what posture it has. DLP answers what happens when that data is exposed, moved, or misused. The two are increasingly linked because discovery without enforcement leaves exposed data unmanaged, while enforcement without discovery misses the assets that matter most. In practice, convergence means the security team can identify sensitive stores in cloud and SaaS environments and then apply movement controls to the same content across collaboration, endpoint, and AI use cases.

Practical implication: use DSPM to locate high-risk data stores, then tie those findings to DLP policies that act on movement and misuse.

MCP and GenAI create new data egress paths

Model Context Protocol extends the problem by letting AI models and agents connect to tools and data sources. That makes it easier for an AI system to retrieve enterprise information and pass it to another application or service. The governance challenge is not just prompt leakage, but machine-mediated data transfer across connected systems. In this model, DLP has to inspect not only what a person types, but also what an agent can fetch and where that content can be forwarded. This is where AI governance and identity governance start to overlap in a practical way.

Practical implication: treat MCP servers and AI connectors as governed data conduits and apply policy to both retrieval and forwarding actions.


NHI Mgmt Group analysis

Modern DLP is becoming a governance layer for data movement, not just a detection tool. The article reflects a broader market shift away from alert-only controls toward inline remediation across collaboration, cloud, and AI workflows. That matters because policy now has to follow the data into systems where identity, context, and destination all change at runtime. Practitioners should treat DLP as a control architecture, not a point product.

AI governance and identity governance are converging through the data path. Once users and AI systems can move the same sensitive content through MCP-connected tools, the old separation between access control and data control becomes artificial. Identity proves who or what is acting, but DLP determines whether the action should be allowed to move sensitive information onward. Teams should align IAM, PAM, and DLP policies around the same risk decisions.

Data lineage is the missing control concept in most modern leakage programmes. The article’s emphasis on tracing data from source to destination exposes a real governance gap: organisations often know what data exists, but not how it travels through SaaS, browser, and AI workflows. That gap weakens investigations and makes policy exceptions difficult to justify. Practitioners should build lineage-aware controls that can explain both origin and movement.

Browser and SaaS controls are now frontline controls for sensitive data governance. The enterprise boundary has shifted into the browser because that is where collaboration, AI use, and file movement increasingly happen. Traditional perimeter assumptions do not hold when the same session can touch sanctioned SaaS, shadow AI, and unmanaged tools. Security teams should prioritise browser-mediated enforcement as part of their broader identity and data governance stack.

What this signals

Modern DLP programmes will be judged less by how many alerts they generate and more by whether they can stop sensitive content from crossing into untrusted workflows. The operational pressure point is shifting toward browser controls, AI egress governance, and data lineage that can explain what happened after the fact.

Data-flow governance: the next maturity step is not broader scanning, but tighter control over how content moves between people, applications, and AI systems. Teams that already run DSPM should use those findings to prioritise where inline enforcement has the greatest risk reduction value.


For practitioners

  • Define policy around sensitive-data movement paths Inventory the main routes sensitive content takes across SaaS, cloud storage, browsers, endpoints, and AI tools, then decide which paths require blocking, redaction, masking, or quarantine.
  • Pair DSPM findings with DLP enforcement Use discovery to locate the highest-risk data stores, then attach movement controls to the specific repositories, applications, and collaboration channels where those records can be exposed.
  • Treat AI prompts and MCP connectors as egress points Review how employees and agents move information into GenAI tools and through MCP-connected workflows, and apply policy to both content entering the model and content leaving connected tools.
  • Build lineage-aware incident review steps Ensure responders can trace where a file or message originated, how it moved, and which control allowed the transfer, so investigations focus on path, context, and policy outcome.

Key takeaways

  • Data loss prevention now has to govern movement across SaaS, cloud, browser, and AI workflows, not just monitor email and endpoints.
  • Discovery without enforcement leaves sensitive data visible but still exposed, which is why DSPM and DLP are converging operationally.
  • Once AI agents and MCP connectors can move data, identity and data governance must be designed together instead of managed in separate silos.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The article covers GenAI, MCP, and tool-based data movement risk.
NIST CSF 2.0PR.DS-1DLP is fundamentally about protecting data in motion and use.
NIST SP 800-53 Rev 5AC-4Data flow enforcement aligns with information flow control.
NIST AI RMFMANAGEAI prompt and connector governance requires ongoing risk treatment.
MITRE ATT&CKTA0010 , ExfiltrationThe threat model includes data movement into unauthorized tools and services.

Map AI tool exposure paths to agentic application risks and restrict tool permissions accordingly.


Key terms

  • Data Loss Prevention: Data loss prevention is the set of controls used to detect, block, and report sensitive data moving in ways the organisation does not allow. In practice, DLP must account for endpoints, email, cloud apps, APIs, and user behaviour, or it will miss the paths where real exposure happens.
  • Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
  • Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
  • Inline remediation: Inline remediation is the practice of presenting security guidance directly in the developer environment where code is written. It reduces context-switching and can speed up fixes, but it only improves governance when the guidance is accurate, explainable, and consistently adopted by engineering teams.

What's in the full article

Strac's full article covers the operational detail this post intentionally leaves for the source:

  • Specific DLP capability examples for SaaS platforms such as Slack, Zendesk, Google Workspace, and Microsoft 365
  • The article's breakdown of detection methods including OCR, machine learning, and contextual classification
  • Examples of inline remediation actions such as redaction, masking, blocking, quarantine, deletion, and encryption
  • The source's discussion of how browser DLP and MCP DLP fit into modern data security workflows

👉 Strac's full article covers the detection, remediation, and workflow details behind modern DLP.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and workload identity. It helps identity and security practitioners connect access control, lifecycle management, and machine identity risk.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org