By Olivia Dubois
·
August 1, 2026
The issue can be summed up in one sentence: file-centric DLP is no longer enough for AI usage in SaaS. Today, a leak often happens through a prompt, a copy-and-paste action or an automation between tools, rather than through an attachment. And the visibility gap is clear: 68% of users do not declare their AI usage, while 92% of organisations have no complete view of their AI agents and assistants.
When reading this article, the main point I take away is this: to stay in control, I need to see AI usage, classify sensitive data, and then act at the exact moment of the exchange with blocking, alerting or masking rules. The goal is not to shut everything down. It is to let teams work without allowing HR, financial, customer or R&D data to leave the organisation.
In short:
| Point to check | What I look for |
|---|---|
| Visibility | Which AI tools are used, by whom and with what data |
| Detection | HR, finance, customer data, code, API keys, personal data |
| Control | Prompt, copy-and-paste, file, automation |
| Response | Blocking, alerting, masking |
| Traceability | Logs, applied rules, ongoing tracking |
The rest of the article explores these blind spots, detection methods and control layers needed to regain control without slowing adoption.
Leaks no longer happen only through files. They also happen through the browser, AI prompts and SaaS automations. The risk first appears in everyday actions — discreet, almost routine actions that nevertheless often sit outside the reach of traditional controls.
The scenario is simple. An employee copies an extract from a contract into ChatGPT “just to summarise it”, or pastes a customer list into an AI assistant “just to draft an email”. No file is sent. But the data has already left the company's perimeter.
What most often slips through the net are text exchanges outside the file flow: copy-and-paste actions, prompts, comments and automations. This fileless exfiltration travels through a text field in a browser, sometimes from a personal account and outside any tenant managed by the company. The same problem applies to SaaS-to-SaaS automations, which move data between CRM, ERP and AI tools without precise controls.
The most sensitive situations involve HR, finance, legal, sales and R&D: salaries, M&A data, CRM exports, source code and API keys.
On paper, these uses seem legitimate. The user is authenticated. The action is intentional. But as soon as these exchanges move outside the company's guardrails, sensitive data can leave with them. The breaking point is not always intent. It is often the action itself.
The most common exposures fall into the following categories:
| Data category | Concrete exfiltration scenario |
|---|---|
| Finance & M&A | Pasting financial spreadsheets or M&A documents into an AI tool |
| Customer data | Copying CRM lists into an external assistant to draft personalised messages |
| R&D / Technical | Pasting proprietary source code or API keys into a debugging assistant |
The common thread is obvious: these cases fall outside the detection scope for which traditional DLP was designed. Faced with HTTPS traffic, chat interfaces and SaaS-to-SaaS automations, traditional DLP cannot see what passes through a browser window or what an autonomous AI agent sends via API to an external service.
| Dimension | Traditional DLP | AI DLP |
|---|---|---|
| Main channel | Email, file sharing, managed SaaS | Browser prompts, chat interfaces, personal accounts |
| Detection method | Signatures, fingerprints, network patterns | Real-time text analysis, browser-side interception |
| Blind spots | Copy-and-paste, prompts, SaaS-to-SaaS | Usage outside the browser, unmanaged native applications |
Another blind spot carries even more weight: 92% of organisations have no complete visibility into their AI identities [2] — autonomous agents capable of accessing critical systems such as Salesforce or SAP — and 86% have no specific access policies for these AI identities [2]. Put simply, some flows are now controlled by ungoverned AI agents without direct supervision.
These blind spots cannot be fixed by adding another pile of rules. What changes the situation is reading the context. In practical terms, AI DLP relies on three levers: classify data, identify anomalies and apply controls according to the situation.
Modern AI DLP solutions combine more than 350 preconfigured data types with machine learning to identify sensitive data in documents, spreadsheets, prompts and chats [1]. For French companies, this includes native detection of the French national identification number (NIR), IBANs, payslips and even internal project codes such as PROJ-.*-CONF.
This is not limited to files stored somewhere in a folder. Detection also applies to text pasted into a browser, a prompt entered in an AI tool or a file such as employees.csv sent to Claude [4].
Detecting the data is only the first step. On its own, it is not enough. It must then be matched with actual usage to determine whether there is a risk.
The signal does not come only from the content. It comes from cross-checking what is being handled with how it is being handled.
A large CRM export followed by a series of prompts sent to an external AI service at unusual times is a real signal. The same applies to a query about salary data sent to a copilot.
This detection relies on analysing behavioural anomalies such as:
When AI usage is not declared, this analysis layer is often the only way to see what would otherwise remain invisible.
This signal then feeds blocking, alerting or masking policies.
Instead of a blunt block, contextual policies enable a graduated response based on the actual level of risk.
| Action mode | Typical trigger | Impact on productivity |
|---|---|---|
| Block | Source code, API keys or financial files sent to an unmanaged tool | High — action stopped |
| Warn | PII in a prompt, partial CRM export | Moderate — justification requested |
| Mask / pseudonymise | Names, email addresses, NIRs or IBANs in a drafting prompt | Low — transparent processing |
The Mask / pseudonymise mode is particularly useful. It automatically anonymises personal data before it reaches the AI provider. As a result, the employee can continue using the tool to summarise or draft content without exposing the real data [4].
In other words, you retain control without disrupting usage.

Identifying a risk is one thing. Blocking it, tracing it and governing it is another. Here, the response consists of three functional layers: native control, network control and browser control.

Microsoft Purview and Google Workspace manage classification, labelling and sharing rules for files, emails and collaborative workspaces. For AI, they also cover interactions with native tools such as Microsoft 365 Copilot and Google Gemini for Workspace.
For example, Purview can define DLP rules that also apply to prompts sent to Copilot [3]. In practical terms, it can block the sending of unlabelled files or trigger an alert when a user pastes sensitive data into a conversation.
The strength is clear: these controls work well within the internal ecosystem. But as soon as usage leaves the Microsoft or Google environment, coverage drops sharply. That is where the limitation appears.
Netskope and Zscaler inspect web and SaaS traffic to identify unsanctioned AI applications. With its AI Security Suite, Zscaler inventories the GenAI services, models and agents in use, classifies them by risk level and applies fine-grained access rules, such as read-only access or blocking uploads [3].
In other words, these tools primarily answer one simple question: can the user access this AI tool or not?
Network visibility, however, quickly reaches its limit. It shows which service is being used, but not exactly what the user is pasting into the prompt.
The most sensitive point remains the exchange itself: the prompt, the copy-and-paste action and the file upload. This is precisely where Avanoo operates. The solution acts at browser level, at the exact point where the action takes place.
It intercepts prompts, copy-and-paste actions and file uploads in real time, before data reaches the AI provider [4]. With Alert or Replace modes, it can discreetly mask sensitive data without blocking the user's work [4].
Avanoo also maps SaaS and undeclared AI usage, identifies which tools access sensitive data and centralises access management with automated controls aligned with the GDPR, NIS2 and DORA. In June 2026, Efficy deployed Avanoo to regain control of its digital usage and secure its AI interactions [1][2].
The role of each layer can be summarised as follows:
| Layer | Tools | What it covers | Limitation |
|---|---|---|---|
| Native control | Purview, Workspace | Files, emails, internal AI (Copilot, Gemini) | Data leaving the Microsoft or Google environment |
| Network control | Zscaler, Netskope | Web traffic, undeclared AI discovery, SaaS access | Prompt content, copy-and-paste |
| Browser control | Avanoo | Browser interactions, undeclared AI, GDPR/NIS2/DORA compliance | Applications outside the browser, unmanaged devices |
The real question now is coverage in the field, detection accuracy and deployment speed.
After identifying the blind spots, the next step is simple on paper but more difficult in practice: check whether the programme can cover them without disrupting usage.
The starting point is balance. An AI DLP solution must limit data leaks while allowing teams to work with the AI tools they need.
Coverage must go beyond traditional documents. It must also include prompts, copy-and-paste actions and files sent to AI tools. Otherwise, you are monitoring the front door while leaving the windows open.
Precision is another key point. Detection of HR, financial and customer data must be sufficiently accurate to avoid a flood of false positives. If the tool blocks everything, teams will quickly look for ways around it.
These are the criteria to check during an assessment:
Once the criteria are defined, it is time to move from diagnosis to execution.
Organisations that treat AI DLP as a governance programme — supported by data classification, behavioural analysis and SaaS visibility — can regain control without slowing adoption.
Shadow AI Expert & Chief AI Officer
Olivia Dubois is Shadow AI Expert and Chief AI Officer at Avanoo. An HEC Paris graduate and former BCG consultant, she helps enterprises detect and govern Shadow AI and Shadow IT.
See how Avanoo can map your SaaS and AI landscape, reduce risk, and optimize costs. A reliable platform with dedicated human support.