Sanctioned controls fail when they only cover one access path. Users can switch to a personal login, a personal device, or an unmanaged browser session, which bypasses corporate boundaries. Effective prevention needs coverage across web app use, desktop use, extensions, and shadow accounts, not just a corporate firewall rule or workspace setting.
Why This Matters for Security Teams
Sanctioned controls are often designed around an approved platform, but data leakage usually happens through the gaps between policy, device trust, and user behaviour. A corporate DLP rule or workspace restriction can reduce risk, yet it does not automatically stop a user from pasting sensitive material into a personal account, a browser profile outside management, or an unsanctioned extension. That is why control scope matters as much as control strength.
Security teams also need to account for the fact that ChatGPT usage is not one uniform channel. The same prompt can enter through a managed web app, a consumer login, a desktop client, or an integrated browser extension, each with different visibility and enforcement. Current guidance suggests aligning controls to the full data path rather than assuming a single sanctioned interface will contain the problem. NIST SP 800-53 Rev. 5 remains a useful baseline for access control, auditability, and system monitoring expectations, especially where organisations need to map policy to implementable safeguards through NIST SP 800-53 Rev 5 Security and Privacy Controls.
In practice, many security teams encounter the leak after the prompt has already left the managed boundary, rather than through intentional AI governance.
How It Works in Practice
Preventing ChatGPT data leaks requires treating AI use as a multi-channel access problem, not just a content filtering problem. The core issue is that sanctioned controls usually inspect one layer, while the real workflow spans identity, endpoint posture, browser state, network routing, and user choice. If controls do not follow the user across those layers, sensitive text can still reach a model through an unmanaged path.
A practical control stack usually combines:
- Identity enforcement, so only approved accounts can access the sanctioned service.
- Device posture checks, so unmanaged or high-risk endpoints are blocked or limited.
- Browser and extension governance, so shadow plugins cannot exfiltrate content.
- Data classification and copy-paste controls, so protected content is handled differently from ordinary text.
- Logging and detection, so unusual prompt patterns, account switching, and bulk submission are visible to the SOC.
This is also where AI-specific threat models matter. Prompt injection, indirect prompt injection, and malicious extension behaviour can all cause the model or the surrounding workflow to process data in unsafe ways. The recent Anthropic report on the Anthropic — first AI-orchestrated cyber espionage campaign report is a useful reminder that AI systems can be operationalised inside broader attack chains, not just used as standalone tools.
Best practice is to pair preventive controls with detection and response. That means alerting on unsanctioned AI domains, monitoring browser and endpoint telemetry, and correlating identity events with exfiltration patterns in SIEM and XDR workflows. These controls tend to break down when users can move sensitive work to personal devices or unmanaged browsers because the organisation loses both policy enforcement and reliable telemetry.
Common Variations and Edge Cases
Tighter AI access control often increases user friction and support overhead, requiring organisations to balance data protection against productivity and exception handling. That tradeoff becomes sharper in hybrid work, BYOD, and developer-heavy environments where AI tools are embedded into daily workflows and blanket blocking is rarely sustainable.
There is no universal standard for this yet, so the right response depends on the risk profile of the data being handled. For highly sensitive environments, the best pattern is to disallow pasting confidential content into consumer AI services unless the session is explicitly governed and logged. For lower-risk use cases, organisations may accept limited access with redaction, DLP, and approved-account requirements.
One important edge case is shadow identity. A user may have a sanctioned corporate login and a separate personal login to the same AI service, which defeats policy if controls only inspect SSO traffic. Another common gap is the browser extension layer, where sanctioned web access still leaks data through add-ons, clipboard handlers, or local automation. Organisations should also consider that desktop clients may bypass web proxy inspection entirely. The most resilient approach is to define controls by data sensitivity and trust boundary, not by the brand name of the AI application.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC | Access control must cover identities, devices, and sessions across AI use paths. |
| NIST AI RMF | GOVERN | AI risk governance is needed because leaks often stem from unmanaged AI usage patterns. |
| MITRE ATLAS | AML.T0021 | Prompt injection and model misuse are common paths that undermine content controls. |
| OWASP Agentic AI Top 10 | A02 | Agent and tool misuse can turn a benign prompt into an exfiltration path. |
| NIST AI 600-1 | GenAI profile guidance fits sanctioned-use controls and user behaviour monitoring. |
Restrict agent tool access and validate every action that can move data outside trust boundaries.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org