TL;DR: Shadow AI is creating visibility and policy gaps that policy-based DLP struggles to close, while more than 90% false positives keep many teams stuck in tuning mode, according to Orion and Lawrence Pingree's webinar analysis. The governance problem is no longer just detection quality; it is whether DLP can operate on live context fast enough to prevent data movement in unmanaged AI workflows.
NHIMG editorial — based on content published by Orion: the Great DLP Reset and the impact of AI on DLP
By the numbers:
- The industry average is over 90%.
Questions worth separating out
Q: How should security teams govern shadow AI without relying on discovery alone?
A: Security teams should use discovery as the starting point, then combine it with runtime identity telemetry.
Q: Why do policy-based DLP controls fail in AI-enabled workflows?
A: They fail because they assume data moves through predictable channels and can be matched against fixed patterns.
Q: How do teams know whether DLP is actually preventing data loss?
A: Look for evidence that the control is making accurate decisions in real time, not just generating alerts.
Practitioner guidance
- Map shadow AI exposure paths Inventory where employees use unapproved AI tools across browsers, SaaS, endpoints, email, and unmanaged sessions so you can identify which data paths are currently outside policy coverage.
- Tie identity signals to enforcement Feed user, role, and session context into DLP decisions so the control can judge whether a transfer is normal for that identity rather than relying only on file or destination rules.
- Measure false positive drag Track how much analyst time is consumed by tuning and exception handling, then separate that workload from true prevention outcomes to understand whether the programme is stuck in detection mode.
What's in the full article
Orion's full article covers the operational detail this post intentionally leaves for the source:
- How the webinar speakers describe the shift from tuning-heavy DLP to agentic prevention in practice
- Examples of how Orion evaluates identity, behaviour, content, lineage, and environmental context together
- The reasoning behind autonomous block, redact, and quarantine decisions in live deployments
- The vendor's own framing of how unmanaged sessions and AI tools change the DLP operating model
👉 Read Orion's analysis of the DLP reset and shadow AI risk →
Shadow AI and DLP: what the governance gap means for teams?
Explore further
Shadow AI creates a verification gap, not just a monitoring gap. When security teams cannot see which AI tools are being used, they cannot reliably define the identity of the session, the approval boundary, or the policy scope. That makes the problem one of governance drift as much as data loss prevention. For IAM and NHI programmes, this is a reminder that unmanaged AI sessions behave like unowned access paths, and unowned access paths cannot be governed with static rules alone.
A question worth separating out:
Q: What is the difference between detection-driven DLP and autonomous prevention?
A: Detection-driven DLP identifies risky activity and sends it for human review. Autonomous prevention uses confidence and context to block, redact, or quarantine immediately, with humans stepping in only when the decision is ambiguous. The difference is operational: one asks teams to react, the other resolves the action at runtime.
👉 Read our full editorial: Shadow AI is exposing the limits of policy-based DLP