TL;DR: Data exfiltration now moves through AI tools, browser sessions, cloud sync, email, and removable media, and Cyberhaven says 39.7% of AI interactions involve sensitive data while about 44% happen through personal accounts. Legacy DLP cannot reliably track transformed data or prompt-level movement, so detection has to shift toward lineage and behavior-aware controls.
NHIMG editorial — based on content published by Cyberhaven: Most Common Forms of Data Exfiltration
By the numbers:
- According to Cyberhaven research, 39.7% of all AI interactions involve sensitive data.
- Approximately 44% of AI use occurs through personal accounts where enterprise visibility is absent.
Questions worth separating out
Q: What breaks when legacy DLP is used to protect intellectual property?
A: Legacy DLP breaks when the sensitive asset has no predictable pattern to match.
Q: Why do personal accounts make AI data leakage harder to control?
A: Personal accounts remove enterprise visibility from the session, so security teams often cannot see which data was entered, who can access the account, or whether the information was reused elsewhere.
Q: What do security teams get wrong about insider-driven exfiltration?
A: They often focus on malicious intent alone.
Practitioner guidance
- Implement session-aware controls for AI use Track prompt-level and upload-level interactions for sanctioned AI tools, and block sensitive data submission when the session lacks approved context or account ownership.
- Extend DLP to browser and SaaS workflows Instrument browser sessions for copy-paste, screenshots, form submissions, and personal cloud uploads so exfiltration signals are visible outside email and file gateways.
- Harden contractor and departing-employee access lifecycles Revoke temporary access immediately at task completion, and review access outside the user’s normal scope in the days around notice periods or offboarding.
What's in the full article
Cyberhaven's full blog post covers the operational detail this post intentionally leaves for the source:
- Channel-by-channel examples of AI, browser, cloud sync, email, USB, and print exfiltration patterns.
- Detection logic for distinguishing intentional exfiltration from ordinary productivity and employee departure behaviour.
- How data lineage is used to trace copies, transformations, and downstream destinations across workflows.
- Practical examples of endpoint and browser visibility that a security operations team would need for implementation.
👉 Read Cyberhaven's analysis of the most common forms of data exfiltration →
AI-based exfiltration and browser leakage: where DLP breaks down?
Explore further
AI-based exfiltration is now an identity governance problem, not just a DLP problem. The most dangerous part of AI-assisted data movement is that it begins inside legitimate workflows, often with valid credentials and approved devices. That means the security boundary has moved from the perimeter to the interaction itself. For IAM and NHI programmes, this is a signal to treat AI tools and agents as governed identities with explicit data-use limits.
A question worth separating out:
Q: How should organisations reduce exfiltration risk without blocking normal work?
A: Use contextual controls that follow the user, device, and destination rather than just the file. That allows legitimate work in SaaS and AI tools while stopping high-risk transfers to personal accounts, unsupported browser sessions, or unauthorised endpoints before the data leaves organisational control.
👉 Read our full editorial: AI-based data exfiltration is outpacing legacy DLP controls