TL;DR: Email has become a high-volume data transport layer for credentials, PHI, PII, screenshots, and shared links, and legacy DLP still misses much of that context, according to Polymer. The control gap is no longer attachment scanning but runtime visibility into who is sending what to which human or LLM and why.
NHIMG editorial — based on content published by Polymer: LLMs, inbox data, and why legacy DLP keeps missing the real leak paths
Questions worth separating out
Q: What breaks when email security only scans attachments?
A: Attachment-only DLP misses the most common modern leak paths: data pasted into message bodies, screenshots, and text copied into AI tools.
Q: Why does email now need identity-aware data controls?
A: Because the risk is no longer just what content exists, but which identity can move it, share it, or paste it into an LLM.
Q: What should organisations measure to know if email controls are actually working?
A: Organisations should measure detection fidelity, containment speed, and whether suspicious messages lead to fewer successful impersonation or credential theft events.
Practitioner guidance
- Implement content-aware inspection for email bodies Classify sensitive data in message text, not just attachments, and add OCR so screenshots and embedded text are inspected before delivery or forwarding.
- Correlate downloads with subsequent uploads Join mailbox, browser, SaaS, and endpoint telemetry so a file downloaded from corporate email and reuploaded to a personal or AI tool is visible as one chain.
- Govern shared links as revocable access objects Apply expiry, owner review, and revocation workflows to Drive and SharePoint links so persistent access does not survive beyond the intended business need.
What's in the full article
Polymer's full post covers the operational detail this analysis intentionally leaves for the source:
- Policy logic for classifying sensitive text in message bodies, screenshots, and complex document types
- Runtime controls for ChatGPT, Claude, and other LLM tools using the Polymer browser extension
- Automation options for redaction, deletion, ticket creation, quarantine, and labelling
- Examples of building policies with NLP rules, regular expressions, dictionary values, and business logic
👉 Read Polymer's analysis of how email becomes an LLM data channel →
Email data exposure and LLMs: what security teams are missing?
Explore further