Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-based exfiltration and browser leakage: where DLP breaks down


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Data exfiltration now moves through AI tools, browser sessions, cloud sync, email, and removable media, and Cyberhaven says 39.7% of AI interactions involve sensitive data while about 44% happen through personal accounts. Legacy DLP cannot reliably track transformed data or prompt-level movement, so detection has to shift toward lineage and behavior-aware controls.

NHIMG editorial — based on content published by Cyberhaven: Most Common Forms of Data Exfiltration

By the numbers:

Questions worth separating out

Q: What breaks when legacy DLP is used to protect intellectual property?

A: Legacy DLP breaks when the sensitive asset has no predictable pattern to match.

Q: Why do personal accounts make AI data leakage harder to control?

A: Personal accounts remove enterprise visibility from the session, so security teams often cannot see which data was entered, who can access the account, or whether the information was reused elsewhere.

Q: What do security teams get wrong about insider-driven exfiltration?

A: They often focus on malicious intent alone.

Practitioner guidance

  • Implement session-aware controls for AI use Track prompt-level and upload-level interactions for sanctioned AI tools, and block sensitive data submission when the session lacks approved context or account ownership.
  • Extend DLP to browser and SaaS workflows Instrument browser sessions for copy-paste, screenshots, form submissions, and personal cloud uploads so exfiltration signals are visible outside email and file gateways.
  • Harden contractor and departing-employee access lifecycles Revoke temporary access immediately at task completion, and review access outside the user’s normal scope in the days around notice periods or offboarding.

What's in the full article

Cyberhaven's full blog post covers the operational detail this post intentionally leaves for the source:

  • Channel-by-channel examples of AI, browser, cloud sync, email, USB, and print exfiltration patterns.
  • Detection logic for distinguishing intentional exfiltration from ordinary productivity and employee departure behaviour.
  • How data lineage is used to trace copies, transformations, and downstream destinations across workflows.
  • Practical examples of endpoint and browser visibility that a security operations team would need for implementation.

👉 Read Cyberhaven's analysis of the most common forms of data exfiltration →

AI-based exfiltration and browser leakage: where DLP breaks down?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-based exfiltration is now an identity governance problem, not just a DLP problem. The most dangerous part of AI-assisted data movement is that it begins inside legitimate workflows, often with valid credentials and approved devices. That means the security boundary has moved from the perimeter to the interaction itself. For IAM and NHI programmes, this is a signal to treat AI tools and agents as governed identities with explicit data-use limits.

A question worth separating out:

Q: How should organisations reduce exfiltration risk without blocking normal work?

A: Use contextual controls that follow the user, device, and destination rather than just the file. That allows legitimate work in SaaS and AI tools while stopping high-risk transfers to personal accounts, unsupported browser sessions, or unauthorised endpoints before the data leaves organisational control.

👉 Read our full editorial: AI-based data exfiltration is outpacing legacy DLP controls



   
ReplyQuote
Share: