Organisations should allow AI use where possible, but apply guardrails that prevent sensitive data from leaving approved boundaries. A practical model is warn first, then redact or block only high-risk content, while preserving productivity. This keeps AI available for everyday work and creates audit evidence for compliance, incident review, and policy refinement.
Why This Matters for Security Teams
GenAI adoption creates a simple but high-stakes problem: employees want speed, while data protection teams need to prevent sensitive information from flowing into tools that may store, reuse, or expose it outside approved boundaries. The risk is not limited to deliberate misuse. Routine prompts often contain source code, customer data, internal plans, credentials, or regulated data that should never leave controlled systems.
Current guidance suggests treating GenAI as a data-handling path, not just a productivity tool. That means policy, detection, and user experience have to work together. Security teams that only block AI outright often drive shadow use, while teams that allow everything without classification create audit and compliance gaps. The practical goal is selective control: let low-risk work continue, then warn, redact, or block only when the content is sensitive enough to matter. This aligns with the broader direction in the NIST AI 600-1 GenAI Profile and with NHIMG research showing how quickly compromised credentials and exposed secrets can be abused in AI-adjacent attacks, as seen in the LLMjacking research.
In practice, many security teams encounter data leakage only after employees have already normalized unsafe AI use across daily workflows.
How It Works in Practice
The most effective pattern is layered: classify the data, inspect the prompt, and apply the least disruptive control that still protects the organisation. At a minimum, this means defining what counts as sensitive data, deciding which GenAI tools are approved, and setting different outcomes for different risk levels. Public or low-risk content may pass with logging. Internal but non-sensitive content may trigger a warning. Confidential, regulated, or credential-bearing text should be redacted or blocked.
That approach works best when controls are embedded where employees actually work. Browser gateways, desktop clients, collaboration plugins, and secure enterprise AI portals can all enforce policy before data reaches an external model. For higher-risk use cases, organisations should pair content controls with identity and access controls so only approved users, devices, and tenants can use GenAI services. The NIST Cybersecurity Framework 2.0 is useful here because it ties governance, access control, and monitoring into a single operating model.
NHIMG research also shows why guardrails matter. In the Ultimate Guide to NHIs, identity and secret sprawl are recurring drivers of exposure, and the same pattern appears when employees paste secrets into AI tools. Good controls therefore do three things:
- Warn users before risky submission so they can self-correct.
- Redact obvious sensitive fields such as API keys, tokens, and personal data.
- Block only the highest-risk content where policy or law requires it.
These controls tend to break down when employees use unsanctioned AI tools from unmanaged devices because policy enforcement and audit logging are no longer reliably in the data path.
Common Variations and Edge Cases
Tighter data controls often increase friction, so organisations have to balance protection against workflow disruption and user resistance. The best practice is evolving, and there is no universal standard for exactly where to place the line between warning, redaction, and blocking.
One common variation is the treatment of regulated data. For personal data under GDPR, the threshold for acceptable AI use is usually lower because purpose limitation, minimisation, and transfer controls apply. Another edge case is code development, where prompts may contain secrets, proprietary logic, or vulnerable snippets. In those workflows, redaction engines must be careful not to over-block harmless code context, or developers will route around the control.
Another issue is vendor retention. Some GenAI services may retain prompts for abuse monitoring, training, or troubleshooting unless enterprise settings override that behaviour. That is why policy should distinguish between approved enterprise deployments and consumer tools, even when the interface looks similar. NHIMG has documented the operational consequences of weak control boundaries in incidents such as the DeepSeek breach, where exposed data became immediately actionable for attackers.
Security teams should expect exceptions for legal, HR, research, and incident response functions, but those exceptions need explicit logging and review. The practical rule is simple: if a prompt would be unsafe to email externally, it should be treated as unsafe for GenAI unless a specific approved workflow says otherwise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | GenAI tools often expose or misuse secrets and tokens through prompt workflows. |
| OWASP Agentic AI Top 10 | A01 | Employees using GenAI create prompt-injection and data-exfiltration paths. |
| CSA MAESTRO | M1 | MAESTRO addresses governance for AI systems handling enterprise data. |
| NIST AI RMF | AI RMF guidance supports govern-map-measure-manage treatment of GenAI risk. | |
| NIST CSF 2.0 | PR.DS-1 | Data security controls directly apply to preventing sensitive prompt leakage. |
Apply prompt and output controls that prevent sensitive data from leaving approved boundaries.
Related resources from NHI Mgmt Group
- How should organisations govern AI usage when employees use unapproved tools?
- What breaks when employees use AI tools inside browser sessions without data controls?
- What breaks when employees use unapproved AI tools with company data?
- How should organisations protect intellectual property when employees use AI tools?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org