A contract to summarise, an email to rewrite, code to debug, a customer file to analyse… In just a few seconds, generative AI tools can save employees valuable time.
But behind these increasingly common uses lies an essential question: what data is actually being shared with these tools?
The rapid adoption of artificial intelligence is creating new information flows that companies now need to integrate into their cybersecurity strategy. The objective is not necessarily to ban AI, but to enable its use without losing control over company data.
When a Simple Prompt Becomes a Risk to Your Data
Using generative AI may seem harmless. Yet, to obtain a relevant answer, users are often tempted to provide additional context.
That context may contain confidential information: customer data, financial information, contractual documents, HR data, source code, strategic information or technical credentials.
The risk therefore does not come solely from the tool itself, but also from what employees share with it.
Sending text, images or documents to a third-party generative AI service may involve transmitting this information to an infrastructure outside the company’s direct control.
This issue is becoming increasingly important as AI use cases continue to spread across business functions.
Why Is AI Changing the Way Companies Protect Their Data?
Companies already have numerous measures in place to protect their information: access rights management, encryption, endpoint security, email controls and file transfer monitoring.
But generative AI is creating new use cases.
An employee can copy a few lines from a contract directly into a web interface, upload an entire document to an AI assistant or connect a tool to various internal sources of information.
The risk becomes even more significant with the development of agentic AI. These systems go beyond answering questions: they can access different applications, process information from multiple sources and perform certain actions on behalf of the user.
The more AI becomes integrated into information systems, the more strategic control over data flows becomes.
DLP: What Is Data Loss Prevention?
DLP, or Data Loss Prevention, refers to the technologies and policies used to identify sensitive information and prevent its unauthorised disclosure or transfer.
Traditionally, a DLP strategy can be used to monitor or control:
- sensitive data sent by email;
- file transfers to cloud services;
- data copied to external devices;
- the sharing of confidential documents;
- certain actions performed from employee workstations.
With the rise of generative AI, these systems now need to consider a new potential channel through which information can leave the organisation: AI tools themselves.
The objective may, for example, be to detect when a user attempts to send certain categories of data to an unauthorised service and, depending on company policies, alert, block or control the action.
Is DLP Enough to Secure AI Use?
No. Technology alone cannot address every risk.
An effective strategy relies on several complementary layers of protection.
Identify the data that needs to be protected. Not all information has the same level of sensitivity. Companies need to know which data is confidential, personal, strategic or subject to specific requirements.
Define authorised tools. An AI solution integrated and managed by the company does not necessarily operate under the same conditions as a public service freely used by an employee.
Implement technical controls. DLP and other cybersecurity tools can translate part of the company’s security policy into practical controls.
Raise employee awareness. Users need to understand why certain information should not be copied into a prompt and which tools should be used depending on the context. Awareness is a key component of any cybersecurity strategy, as we also discuss in our article “Awareness: A Strategic Pillar of Cybersecurity.”
Monitor changing use cases. AI is evolving rapidly. Rules defined today will need to adapt as new assistants and agents become integrated into working environments.
Protecting data in the age of AI therefore requires a combination of governance, technology and awareness.
From AI Governance to Data Protection
Defining an AI charter or usage policy is an essential first step. It can specify which tools are authorised, which uses are accepted and what information may or may not be shared.
But those rules also need to be enforced.
This is precisely where cybersecurity and DLP complement governance: governance defines the framework, while security measures help enforce it.
This approach avoids treating innovation and security as opposing objectives. Instead, it gives employees access to the benefits of AI within an environment where risks have been identified and managed.
To explore this topic further, read our article “You’re Already Using AI. Have You Defined the Rules That Go With It?”
How Can Lùkla Support You?
Securing AI use first requires understanding how data flows through your organisation and how employees are actually using these new tools.
Through our Cloud & Cyber expertise, Lùkla helps companies assess and secure their environments through security audits, risk analysis, data protection and the definition and deployment of appropriate security measures.
This approach can help identify sensitive data, the flows that need to be monitored and AI uses that may present a risk, before defining appropriate technical measures, including DLP solutions where relevant.
It can be complemented by our Change & Adopt expertise to address governance, usage rules, employee awareness and the responsible adoption of AI tools.
Protecting your data does not mean giving up on AI.
It means creating the conditions to use AI without exposing the information that creates value for your business.
AI Is Accelerating Your Business. Keep Control of Your Data.
Artificial intelligence will continue to become embedded in business tools and processes. The associated data flows will therefore continue to grow.
Identifying use cases, classifying sensitive information, governing tools and implementing the right controls are becoming essential to benefit from AI without creating new areas of risk.
Contact us
Secure your AI use with our experts.



