Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

DLP intent detection: can current controls handle human error, insiders, and AI?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15520
Topic starter  

TL;DR: Most DLP tools fail because they monitor single signals rather than intent, leaving gaps across human error, insider risk, and external attackers, according to Orion, while citing cases such as TalentHook, Toronto-Dominion Bank, and Change Healthcare. The underlying governance problem is that one control model cannot safely handle very different data-loss behaviours at enterprise scale.

NHIMG editorial — based on content published by Orion: intent-aware DLP and the three hazards of data loss

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging (37%) and over-privileged accounts (37%).

Questions worth separating out

Q: How should security teams implement DLP for human error, insider risk, and AI-driven data movement?

A: Use different control responses for different loss modes.

Q: Why do AI agents make data loss prevention harder to govern?

A: AI agents can move data at machine speed, repeat mistakes across many records, and operate through multiple tools in one session.

Q: What breaks when DLP only looks at content or destination?

A: It misses the difference between normal work and harmful behaviour.

Practitioner guidance

  • Implement intent-based DLP policies Classify alerts by likely intent, then route accidental sharing to user nudges, insider anomalies to investigation, and attacker-like behaviour to blocking and containment.
  • Correlate DLP with identity and privilege data Join DLP telemetry with IAM, PAM, and HR signals so you can spot unusual access growth, odd-hour use, and role mismatch before data leaves the environment.
  • Treat AI agents as governed identities Give each agent scoped data access, explicit tool permissions, and logging that shows which records it touched, which action it took, and whether it exceeded its task boundary.

What's in the full article

Orion's full article covers the operational detail this post intentionally leaves for the source:

  • The decision logic for distinguishing accidental sharing from malicious exfiltration in real time
  • Examples of contextual intent signals, including who is acting, what the data is, where it is going, and how behaviour deviates from normal
  • The frequency-versus-impact framing used to separate human error, insider risk, and external attackers
  • Practical guidance for reducing false positives without weakening protection

👉 Read Orion's analysis of intent-aware DLP and AI-era data loss →

DLP intent detection: can current controls handle human error, insiders, and AI?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15105
 

Intent is the control gap most DLP programmes still miss: organisations tend to over-invest in content matching and under-invest in behavioural interpretation. That leaves them blind to the difference between accidental sharing, malicious insider activity, and AI-driven bulk movement. The real issue is not whether the data is sensitive, but whether the action matches the actor’s normal purpose. Practitioners should treat intent as a governance requirement, not a nice-to-have signal.

A question worth separating out:

Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?

A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.

👉 Read our full editorial: Intent-aware DLP is becoming essential for AI-era data loss



   
ReplyQuote
Share: