Without layered controls, organisations lose visibility into what is being pasted, uploaded, or synchronised into AI tools. That makes it hard to prevent leaks of PII, contracts, code, credentials, and regulated records. The failure is not only exfiltration. It is also the inability to prove policy enforcement, investigate incidents, or support compliance obligations after the fact.
Why This Matters for Security Teams
When employees use ChatGPT through unmanaged browsers, endpoints, and SaaS tenants, the organisation loses control over the path data takes from the user to the model and back again. That creates exposure across confidentiality, governance, and incident response. Sensitive content can move into prompts, uploads, connected apps, and conversation history without being captured by normal DLP or logging. Current guidance suggests treating this as a visibility problem first and an AI risk problem second.
This matters because the failure is often not obvious at the point of use. A user may appear to be doing ordinary productivity work while silently transferring PII, source code, customer records, or internal procedures into an external AI service. The NIST Cybersecurity Framework 2.0 is useful here because it frames the issue as governance, protection, detection, and response across the whole environment rather than a single app control. Security teams also need to consider how unmanaged AI use undermines evidence collection, legal hold, and policy enforcement. In practice, many security teams encounter this only after a sensitive prompt, upload, or connector sync has already occurred, rather than through intentional control design.
How It Works in Practice
Layered controls work by constraining the browser session, the endpoint, and the SaaS workspace so AI activity is observable and enforceable. Browser controls can limit access to approved AI services, restrict uploads, block copy-paste of regulated content, and preserve session telemetry. Endpoint controls add device posture checks, local file protection, and process-level monitoring so that data cannot simply bypass the browser layer. SaaS controls then govern the tenant itself, including retention, sharing, third-party connectors, and audit logs.
In a well-designed environment, each layer answers a different question: who accessed the service, from what device, with what data, and whether the organisation can later prove what happened. That is why AI usage cannot be managed effectively with awareness training alone. It needs policy enforcement at the point of interaction, not just post hoc review. The OWASP guidance on browser and application abuse patterns is especially relevant when prompts and uploads can carry sensitive content into uncontrolled workflows, and teams should also align with OWASP Top 10 for Large Language Model Applications when assessing prompt abuse and data leakage paths.
A practical control stack usually includes:
- CASB or SaaS security controls to discover sanctioned and unsanctioned AI usage.
- Managed browser controls to restrict uploads, extensions, copy-paste, and session sharing.
- Endpoint protection and device compliance checks to block unmanaged or high-risk devices.
- Content inspection and DLP rules tuned for secrets, source code, contracts, and personal data.
- Central logging for prompts, uploads, connector actions, and policy decisions.
Where AI tools are connected to enterprise identity, the account itself becomes part of the control plane. Session protection, conditional access, and strong authentication reduce the chance that an attacker can reuse a legitimate user session to move data into an AI service. These controls tend to break down when employees access AI tools from unmanaged personal devices because the organisation cannot reliably enforce browser policy, endpoint telemetry, or SaaS audit coverage.
Common Variations and Edge Cases
Tighter browser and endpoint control often increases friction, so organisations have to balance security value against productivity and support overhead. That tradeoff becomes more visible in bring-your-own-device programmes, contractor access, and rapidly adopted shadow AI tools.
Best practice is evolving for agentic workflows, where a chatbot is not just receiving prompts but also calling tools, accessing files, and acting on behalf of a user. In those cases, the risk is broader than data leakage. A poorly governed AI session can trigger unauthorised actions, sync data into third-party plugins, or create records that are difficult to classify later. There is no universal standard for this yet, but current guidance suggests treating AI connectors and browser extensions as privileged pathways that require explicit approval and monitoring.
Some environments need special handling. Regulated sectors may require stronger retention and legal discovery controls, while software teams may need separate rules for source code, API keys, and repository access. If the AI tool is embedded inside a SaaS suite, the security team must also understand whether logs are tenant-owned, vendor-owned, or unavailable. For a broader resilience lens, the NIST Cybersecurity Framework 2.0 remains the cleanest way to map these gaps back to governance, detection, and recovery expectations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 | AI use needs scope and ownership defined before controls can be enforced. |
| OWASP Agentic AI Top 10 | Prompt and tool misuse risks are central when ChatGPT is used without controls. | |
| NIST AI RMF | Governance is needed to manage AI-related data, process, and accountability risks. |
Treat prompts, tools, and connectors as attack surfaces and restrict them explicitly.
Related resources from NHI Mgmt Group
- What breaks when employees use AI tools inside browser sessions without data controls?
- Should organisations use remote browser isolation instead of traditional endpoint controls?
- What breaks when organisations rely on endpoint controls alone for AI use?
- What breaks when endpoint management systems are breached without PAM controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org