TL;DR: Insider risk is moving into everyday workflows, with blocked activity rising in Microsoft and Google sites, AI tools concentrating around ChatGPT and Read.ai, and text, screenshots, and USB emerging as common movement channels, according to Safetica’s Data Protection Trends report. The governance gap is no longer perimeter blocking, but consistent control over data-in-use across approved collaboration tools.
NHIMG editorial — based on content published by Safetica: Insider
By the numbers:
- In Q4 2025, ChatGPT represented 20.1% of blocked AI tool activity, while Read.ai reached 15.4%.
- The top policy violation channels in Q4 were web apps at 20.6%, email at 20.5%, and instant messaging at 19.8%.
- External USB accounted for 36.1% of unusual activity triggers in Q4.
Questions worth separating out
Q: How should security teams govern AI-powered insider threats?
A: Treat AI-powered insider threat as an identity governance problem first.
Q: Why do screenshots and plain text files matter in insider risk programmes?
A: Because they often indicate that users are repackaging sensitive information to bypass controls or to move it through a channel the policy does not understand.
Q: How can security teams tell whether DLP is actually reducing risk?
A: Look for better prioritisation of high-value data, fewer noisy alerts, and clearer visibility into which identities can reach sensitive content.
Practitioner guidance
- Map sensitive-data movement across approved channels Inventory where confidential data actually moves across browser, web apps, cloud storage, email, chat, AI tools, screenshots, and USB, then apply the same policy logic where the work occurs.
- Treat AI prompts and pasted text as governed inputs Classify AI tools as data-handling workflows, then define what content can be pasted, summarised, or generated in each population.
- Correlate screenshots, text files, and USB use Use one detection view for .txt creation, screenshot activity, and external USB events so the same user behaviour can be tracked across repackaging paths.
What's in the full report
Safetica's full report covers the operational detail this post intentionally leaves for the source:
- Quarter-over-quarter channel breakdowns showing where blocked activity is actually rising across the environment
- Policy violation tables for web, email, instant messaging, and USB that help teams compare channel pressure
- App-category and file-extension trend data that show how users repurpose content in practice
- Behavioural observations that help security teams distinguish friction from intent
👉 Read Safetica's Data Protection Trends report on insider risk and data movement →
Trusted workflows, AI tools, and the insider risk gap teams miss?
Explore further
Insider risk is becoming a workflow governance issue, not a perimeter problem. When web apps, email, chat, and AI tools become the main movement paths, the question is no longer whether an app is trusted. The question is whether the organisation can apply differentiated rules to trusted tools based on identity, role, and data type. That is a control design issue, not an endpoint-only problem. Practitioners should read this as a push toward contextual policy enforcement.
A question worth separating out:
Q: What is the difference between blocking a channel and governing data movement?
A: Blocking a channel is a blunt control that stops one route. Governing data movement means understanding which users, content types, and workflows are acceptable across all the places work happens, so the organisation can reduce risky handling without forcing people into another workaround.
👉 Read our full editorial: Insider risk is shifting into trusted workflows and AI tools