AI Governance
What is AI DLP?
How organisations prevent sensitive data from reaching generative AI services.
Short answer
AI DLP (data loss prevention for AI) identifies and protects sensitive information when employees, applications or AI agents interact with generative AI systems. It inspects prompts, files, context and model outputs, and applies policy — allowing, redacting, routing, blocking or requiring approval — so confidential data does not leave the enterprise through an AI service.
Traditional data loss prevention was built for the channels enterprises already knew: email, endpoints, networks and cloud storage. Generative AI opened a new one — the prompt. When an employee pastes a contract, a customer record or a block of source code into a chatbot, the data leaves through a path traditional DLP never inspects. AI DLP closes that gap.
AI DLP operates on the content and intent of an AI interaction, at runtime, before a request reaches the model. It understands what is in a prompt, an attached file or the context retrieved for it, classifies any sensitive data, and applies policy — so an organisation can adopt AI broadly without confidential information leaving through it.
Crucially, AI DLP governs both directions: it inspects what goes to the model and what comes back, and it records each decision as evidence for security, risk and compliance teams.
How AI DLP inspects a request
- Employee, app or agent
- ThreatLens AI DLP
- Inspect prompt · files · context
- Classify sensitive data
- Evaluate policy
- Decision: allow · redact · route · block · approve
- Approved AI model + output check
- Immutable governance log
How AI DLP works
- 1A request is made — A user, application or agent submits a prompt, file or context to a generative AI service.
- 2The interaction is inspected — AI DLP analyses the prompt, attached files, retrieved context and, on return, the model’s output.
- 3Sensitive data is classified — PII, financial data, secrets, source code and regulated or contractual information are identified.
- 4Policy is evaluated — Rules consider the user, the data classification, the destination model and the context.
- 5A decision is enforced — The request is allowed, sensitive values are redacted, it is routed to an approved model, blocked, or held for approval.
- 6The decision is recorded — Every detection and decision is written to an immutable log for audit and investigation.
Key controls
- Prompt inspection
- Analyse the text of a prompt for sensitive content before it reaches a model.
- File & attachment scanning
- Inspect documents and files sent to a generative AI service.
- Context / RAG inspection
- Check retrieved context before it is added to a prompt and sent to a model.
- Output DLP
- Inspect the model’s response for sensitive or leaked content — not just the input.
- Redaction & tokenisation
- Mask or tokenise sensitive values so a request can proceed safely instead of being blocked.
- Policy by data class
- Apply different rules to PII, secrets, source code and regulated data.
- Model routing
- Send sensitive requests to approved, private or region-appropriate models.
- Immutable evidence
- Record every detection and decision for governance, audit and investigation.
AI DLP vs. traditional DLP
| AI DLP | Traditional DLP | |
|---|---|---|
| Channel | AI prompts, files, context and model outputs | Email, endpoints, network and cloud storage |
| Understands | The content and intent of an AI interaction | Files and data moving through known IT channels |
| Acts | Before a prompt reaches a model, and on the response | On data at rest, in use or in transit through IT channels |
| Controls | Allow, redact, route, block or approve — per request | Block, quarantine, encrypt or alert |
| Primary gap addressed | Sensitive data entering generative AI services | Data leaving via traditional IT channels |
A real scenario
How ThreatLens delivers AI DLP
ThreatLens AI DLP identifies and protects sensitive information when employees, applications or AI agents interact with generative AI systems. It applies controls to prompts, files, contextual data and model outputs based on enterprise policy. The AI Gateway is the enforcement layer; AI DLP is the sensitive-data protection capability operating through that layer — with immutable evidence for every decision.
See how ThreatLens detects, redacts, routes or blocks sensitive AI requestsFrequently asked questions
What is the difference between AI DLP and traditional DLP?
Traditional DLP protects data moving through email, endpoints, networks and cloud storage. AI DLP protects data moving into and out of generative AI services — inspecting prompts, files, context and model outputs, which traditional DLP does not see.
Is AI DLP the same as an AI gateway?
No. The AI gateway is the enforcement layer that evaluates requests; AI DLP is the sensitive-data protection capability that operates through it.
Can AI DLP stop sensitive data entering ChatGPT?
Yes. AI DLP inspects prompts and files before they reach a model and can redact, block or route the request, regardless of the destination service.
Does AI DLP inspect model outputs?
Yes. Output DLP checks a model’s response for sensitive or leaked content, not just the input.
How does AI DLP handle RAG and retrieved context?
It can inspect context before it is added to a prompt and sent to a model, so sensitive data pulled into a request is governed too.
Related
- What is an AI gateway?
- What is Shadow AI?
- Microsoft Copilot governance
- AI Governance Platform
- ThreatLens Core — AI-augmented threat investigation
- Use cases
- Take the free AI Governance Assessment
Sources
- NIST AI Risk Management Framework (AI RMF 1.0)
- ISO/IEC 42001:2023 — AI management systems
- OWASP Top 10 for LLM Applications
- EU AI Act
About the author
Manoharan Mudaliar
Founder & CEO, ThreatLens
Enterprise Cybersecurity Leader | AI Governance
Manoharan Mudaliar is the Founder & CEO of ThreatLens with more than 20 years of experience leading enterprise cybersecurity, security operations, cloud security, and AI governance initiatives. He writes about enterprise AI governance, AI security, secure AI adoption, and enterprise risk management.
Last reviewed: 12 July 2026