AI Governance

What is AI DLP?

How organisations prevent sensitive data from reaching generative AI services.

Short answer

AI DLP (data loss prevention for AI) identifies and protects sensitive information when employees, applications or AI agents interact with generative AI systems. It inspects prompts, files, context and model outputs, and applies policy — allowing, redacting, routing, blocking or requiring approval — so confidential data does not leave the enterprise through an AI service.

By Manoharan Mudaliar
Founder & CEO, ThreatLens
Enterprise Cybersecurity Leader | AI Governance
Last reviewed: 12 July 2026

Traditional data loss prevention was built for the channels enterprises already knew: email, endpoints, networks and cloud storage. Generative AI opened a new one — the prompt. When an employee pastes a contract, a customer record or a block of source code into a chatbot, the data leaves through a path traditional DLP never inspects. AI DLP closes that gap.

AI DLP operates on the content and intent of an AI interaction, at runtime, before a request reaches the model. It understands what is in a prompt, an attached file or the context retrieved for it, classifies any sensitive data, and applies policy — so an organisation can adopt AI broadly without confidential information leaving through it.

Crucially, AI DLP governs both directions: it inspects what goes to the model and what comes back, and it records each decision as evidence for security, risk and compliance teams.

How AI DLP inspects a request

How AI DLP works

  1. 1
    A request is madeA user, application or agent submits a prompt, file or context to a generative AI service.
  2. 2
    The interaction is inspectedAI DLP analyses the prompt, attached files, retrieved context and, on return, the model’s output.
  3. 3
    Sensitive data is classifiedPII, financial data, secrets, source code and regulated or contractual information are identified.
  4. 4
    Policy is evaluatedRules consider the user, the data classification, the destination model and the context.
  5. 5
    A decision is enforcedThe request is allowed, sensitive values are redacted, it is routed to an approved model, blocked, or held for approval.
  6. 6
    The decision is recordedEvery detection and decision is written to an immutable log for audit and investigation.

Key controls

Prompt inspection
Analyse the text of a prompt for sensitive content before it reaches a model.
File & attachment scanning
Inspect documents and files sent to a generative AI service.
Context / RAG inspection
Check retrieved context before it is added to a prompt and sent to a model.
Output DLP
Inspect the model’s response for sensitive or leaked content — not just the input.
Redaction & tokenisation
Mask or tokenise sensitive values so a request can proceed safely instead of being blocked.
Policy by data class
Apply different rules to PII, secrets, source code and regulated data.
Model routing
Send sensitive requests to approved, private or region-appropriate models.
Immutable evidence
Record every detection and decision for governance, audit and investigation.

AI DLP vs. traditional DLP

AI DLPTraditional DLP
ChannelAI prompts, files, context and model outputsEmail, endpoints, network and cloud storage
UnderstandsThe content and intent of an AI interactionFiles and data moving through known IT channels
ActsBefore a prompt reaches a model, and on the responseOn data at rest, in use or in transit through IT channels
ControlsAllow, redact, route, block or approve — per requestBlock, quarantine, encrypt or alert
Primary gap addressedSensitive data entering generative AI servicesData leaving via traditional IT channels

A real scenario

A developer pastes a block of proprietary source code into a public chatbot to debug it. Traditional DLP — watching email and endpoints — never sees it, because the code leaves through the prompt. With AI DLP, the content is classified as sensitive intellectual property; the secrets within it are redacted (or the request is blocked) before it reaches the model, and the event is recorded for the security team.

How ThreatLens delivers AI DLP

ThreatLens AI DLP identifies and protects sensitive information when employees, applications or AI agents interact with generative AI systems. It applies controls to prompts, files, contextual data and model outputs based on enterprise policy. The AI Gateway is the enforcement layer; AI DLP is the sensitive-data protection capability operating through that layer — with immutable evidence for every decision.

See how ThreatLens detects, redacts, routes or blocks sensitive AI requests

Frequently asked questions

What is the difference between AI DLP and traditional DLP?

Traditional DLP protects data moving through email, endpoints, networks and cloud storage. AI DLP protects data moving into and out of generative AI services — inspecting prompts, files, context and model outputs, which traditional DLP does not see.

Is AI DLP the same as an AI gateway?

No. The AI gateway is the enforcement layer that evaluates requests; AI DLP is the sensitive-data protection capability that operates through it.

Can AI DLP stop sensitive data entering ChatGPT?

Yes. AI DLP inspects prompts and files before they reach a model and can redact, block or route the request, regardless of the destination service.

Does AI DLP inspect model outputs?

Yes. Output DLP checks a model’s response for sensitive or leaked content, not just the input.

How does AI DLP handle RAG and retrieved context?

It can inspect context before it is added to a prompt and sent to a model, so sensitive data pulled into a request is governed too.

Related

Sources

About the author

Manoharan Mudaliar

Founder & CEO, ThreatLens

Enterprise Cybersecurity Leader | AI Governance

Manoharan Mudaliar is the Founder & CEO of ThreatLens with more than 20 years of experience leading enterprise cybersecurity, security operations, cloud security, and AI governance initiatives. He writes about enterprise AI governance, AI security, secure AI adoption, and enterprise risk management.

Last reviewed: 12 July 2026