Red Access || Edge Security Radar

GenAI DLP must follow identity through retrieval and tools

GenAI DLP must follow identity through retrieval and tools

Key Questions

What is the gap between GenAI adoption and security policies?

Shadow AI shows 77% adoption versus 28% policy coverage, creating class-action risks under EU AI Act and NIST. 80-90% of shadow AI occurs on BYOD devices with significant DLP gaps.

How does OpenAI's Lockdown Mode address data exfiltration?

OpenAI rolled out Lockdown Mode to all accounts as optional exfiltration blocking. This validates inherent ChatGPT DLP limitations and the need for complementary session-layer controls.

What new exfiltration vectors target GenAI tools?

Multiple Copilot SearchLeak exploits enable one-click email and 2FA theft via prompt injection and SSRF. Markdown image rendering and URL encoding in Claude also bypass filters.

Why is traditional DLP insufficient for AI agents?

MCP tool poisoning, RAG retrieval attacks, and multimodal hidden instructions create distinct attack classes. Enterprise AI has outgrown prompt security, requiring runtime session-layer DLP.

What regulatory frameworks impact GenAI DLP strategies?

Global AI governance frameworks including EU AI Act, NIST, and ISO 42001 provide compliance roadmaps. Microsoft Purview AI compliance for M365 adds regulatory signals for enterprises.

How do browser extensions increase GenAI data risks?

Six risky extensions exposed 346M users, with 900K Chrome users having AI conversations stolen. This validates the need for GenAI DLP on unmanaged devices.

What solutions help secure credentials for AI agents?

1Password-Anthropic integration injects secrets directly without model visibility. This validates zero-trust-for-agents approaches while reducing credential exposure.

How does context engineering relate to data protection?

The shift from prompt engineering to context engineering emphasizes runtime data governance. This reinforces the need for session-layer DLP beyond traditional prompt filters.

GenAI governance is moving beyond prompt inspection into native desktop applications, interaction telemetry, policy explainability, and investigation across browser, endpoint, identity, cloud, LLM, and DLP signals. Microsoft's Purview Change Insights preview highlights the operational need to explain policy deltas and audit-to-blocking changes; Red Access should pair explainability with real-time, fail-closed enforcement and lower tuning burden.

Sources (7)
Updated Sep 16, 2026
What is the gap between GenAI adoption and security policies? - Red Access || Edge Security Radar | NBot | nbot.ai