TL;DR: 39.7% of data employees share with AI tools is sensitive, while endpoint-based AI agents grew 509% in 2025, according to Cyberhaven research, underscoring why legacy blocking and content-only DLP cannot govern machine-speed data flows effectively. The security issue is no longer whether employees will use AI, but whether organisations can apply policy without losing visibility or control.
NHIMG editorial — based on content published by Cyberhaven: How Modern DLP Enables AI Adoption Without Slowing Down the Business
By the numbers:
- 39.7% of the data employees share with AI tools is sensitive.
- 509% in 2025., d AI agents grew 509% in 2025.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: How should security teams govern employee AI use without blocking productivity?
A: Start with visibility into sanctioned and shadow AI use, then apply runtime policies that inspect intent and context rather than only keywords.
Q: Why do traditional DLP controls struggle in cloud and AI workflows?
A: They rely too heavily on static rules, shallow content inspection, and limited context.
Q: What do security teams get wrong about blocking AI tools outright?
A: They assume network blocking creates control, but users often shift to personal devices, browser workarounds, or OS-level agents that bypass those restrictions.
Practitioner guidance
- Map AI data flows by endpoint, not just by network path. Inventory where employees use chat assistants, copilots, and endpoint-based AI agents, then verify whether your current controls can see those flows outside browser traffic.
- Classify AI-use data by destination and context. Apply different policy outcomes for source code, customer PII, contract text, and unclassified content, and distinguish approved tools from shadow AI.
- Require lineage for high-risk AI interactions. Preserve origin, transformation, and destination metadata for sensitive content that enters AI systems so you can support audit, investigation, and policy proof later.
What's in the full article
Cyberhaven's full blog covers the operational detail this post intentionally leaves for the source:
- Endpoint visibility requirements for AI-native DLP deployments across SaaS and OS-level agents
- Data lineage implementation details for tracing origin, transformation, and destination across AI workflows
- Policy examples for allowing approved AI use cases while blocking or prompting on sensitive data
- Practical governance framing for CIO, CFO, and security ownership decisions
👉 Read Cyberhaven's analysis of modern DLP for AI adoption and data governance →
Modern DLP and AI adoption: what security teams need to govern?
Explore further
Modern DLP is becoming the enforcement layer for AI governance, not a perimeter add-on. The article describes a shift from broad blocking to policy-based control, and that shift reflects a broader market reality: employees are already using AI tools across sanctioned and unsanctioned channels. For practitioners, the lesson is that AI governance fails when the control model assumes one network path and one application boundary.
A question worth separating out:
Q: Which controls matter most when AI tools touch privileged data?
A: The most important controls are access classification, secrets governance, telemetry, and restrictions on where sensitive data can be processed. If an AI workflow can reach privileged data, then access review alone is not enough. The organisation also needs monitoring that shows what the tool actually did.
👉 Read our full editorial: Modern DLP is becoming the control layer for AI adoption