— Blog

Field notes

Dispatches on synthetic media, manipulation, and AI governance.

Prompt theft: the insider risk your DLP cannot see

Every data-loss tool your company owns was built for a world where data moved through predictable channels: email, uploads, USB. That world is gone. Employees do not paste the contract into an email anymore. They paste it into a chat box, ask for a summary, and move on. Your compliance team cannot see inside that prompt. You cannot govern what you cannot see.

Why this is hard

Prompts are unstructured, they cross into third-party models, and they look like ordinary web traffic. Classic DLP keys off file types and destinations; an LLM prompt has neither in any way the old rules understand. The result is a growing blind spot precisely where the most sensitive material now flows: source code, customer PII, unreleased financials, legal text.

Observability before enforcement

Defog Shield sits as a layer between your people and the models they already use — browser extension, OS agent, or optional network proxy — and inspects prompts client-side before they leave. PII, PHI, secrets, source, and contract language are detected against 58 default patterns plus your own regex, then blocked or redacted according to policy you commit to Git. Every decision is logged immutably for your auditor. You do not replace your SIEM or your IDP; you add the missing visibility and forward events to the stack you already pay for.

One CISO put it plainly after a week: the behavior did not change — people still paste into ChatGPT — but the risk did, because hundreds of PII events were caught before they left the building. That is the realistic goal. Not banning a tool everyone will use anyway, but making its use observable and governable.

← All posts