Table of contents
Step 1: Write a clear AI acceptable use policy first
Step 2: Classify your sensitive data before configuring controls
Step 3: Discover and control AI tool usage
Step 4: Apply endpoint controls for prompt-level inspection
Step 5: Train employees on what not to paste
Step 6: Monitor, review and tighten policy over time
HowAcronis GenAI Protection stops data leakage at the prompt
Key takeaways
Frequently asked questions
AI productivity tools are creating a prompt-level data leakage problem: 77% of employees paste data into generative AI tools, and 82% of that activity comes from unmanaged accounts, according to the LayerX Enterprise AI and SaaS Data Security Report 2025. Every paste into ChatGPT, Copilot or another GenAI tool is a potential exposure of sensitive data that traditional file-focused controls were never built to see.
To stop employees pasting company data into ChatGPT, Copilot and other GenAI tools, set a clear acceptable use policy, classify your sensitive data, then enforce it with endpoint controls that inspect prompts before content leaves the machine.
Step 1: Write a clear AI acceptable use policy first
Technical controls enforce a decision, so the decision has to exist first. A clear acceptable use policy is that decision, written down.
The policy must specify three things. First, the sanctioned tools employees may use and the account type required, such as a corporate plan with single sign-on. Second, the data types prohibited in prompts and uploads, named explicitly rather than left to interpretation. Third, the upload restrictions that apply, including file types and content that may never leave the organization.
Policy precedes technical controls because controls without a policy produce arbitrary blocks employees do not understand and route around. Without a written policy, there is no agreed standard to enforce, no basis for consequences and no way to tell an employee why an action was stopped. The policy turns a vague concern into an enforceable rule.
Step 2: Classify your sensitive data before configuring controls
You cannot stop the leakage of data you have not defined. Classification is the prerequisite that makes every later control precise instead of guesswork, and it gives you a basis for reporting on where sensitive data risk concentrates, not just for blocking it.
Focus on the four categories most at risk in AI prompts: personally identifiable information, protected health information, payment card data covered by PCI-DSS, and confidential business content such as contracts, financials and strategy. These are the categories that carry regulatory and competitive consequences when exposed.
Map each category to where it lives in your organization: which systems hold it, which teams handle it, and which workflows tempt an employee to paste it into an AI tool to save time. A usable scheme is simple enough that an employee can apply it without calling IT, with a small number of clear labels rather than a long taxonomy no one remembers.
Step 3: Discover and control AI tool usage
Before blocking everything, gain visibility into which AI tools employees are actually using, who is using them, and where risky patterns are emerging. That visibility turns policy enforcement from a reactive guess into an informed decision about which AI tools to sanction, restrict or block.
With that visibility, a policy and classification in place, control access at the network layer. Block unsanctioned AI domains at the DNS resolver or proxy so casual use of unapproved tools stops at the gateway.
A blocklist alone fails without a sanctioned alternative. Employees adopt AI tools because the tools make work faster, and a pure block sends them to a personal phone or home machine where you have no visibility at all. Pair every block with an approved tool that does the same job, so the easy path is also the safe path.
Communicate what is and is not allowed in plain language. Publish the sanctioned tool list, explain why specific tools are blocked, and tell employees how to request a new tool. Silent blocks breed workarounds; explained blocks build compliance.
Step 4: Apply endpoint controls for prompt-level inspection
DNS and domain-based controls see access patterns, not prompt content. Endpoint prompt inspection reads what an employee is about to submit and applies a rule based on the data inside the prompt, which is something network controls cannot do for an encrypted session.
Endpoint inspection runs in two modes. Detect-only mode logs and alerts on a risky prompt without stopping it, which suits a learning period when you are tuning rules and do not want to disrupt work. Block mode stops the submission outright, which suits high-risk data once your rules are trusted. Use detect-only first to calibrate, then move sensitive categories to block.
Tie the action to the data type. A prompt containing payment card data or protected health information can trigger a block, while a lower-risk match raises an alert for review. Endpoint inspection catches the clipboard paste that bypasses the network entirely on protected endpoints, because it inspects the content on the machine before it ever reaches the AI service.
Step 5: Train employees on what not to paste
Technical controls reduce risk, but training closes the gap controls cannot reach, including personal machines and judgment calls. Employees who understand why a rule exists follow it even where no control is watching.
Cover the three most common mistakes directly: pasting client records to summarize or reformat them, pasting prompt. Each is a routine productivity shortcut with an outsized consequence
Run a short, practical session rather than a slide deck. Show a real example of a risky paste, show the safe alternative, and let employees ask where the line is. Repeat briefly after any policy change so the rules stay current in people’s minds.
Step 6: Monitor, review and tighten policy over time
Controls degrade as tools and behavior change, so monitoring is ongoing work. Watch detect-only alerts, blocked-prompt logs and new AI domains appearing in network traffic to see where data is still at risk.
Review incidents on a set cadence. Each blocked or flagged prompt tells you whether a rule is too loose, too strict or missing, and whether a data category needs to move from alert to block. Feed those findings back into the policy so it reflects reality rather than last quarter’s assumptions.
A practical cadence is a monthly review of incidents and alerts, a quarterly review of the sanctioned tool list, and an annual review of the full policy. Out-of-cycle reviews should follow any major new AI tool, regulatory change or security incident.
HowAcronis GenAI Protection stops data leakage at the prompt
Sensitive data leakage is one part of the broader GenAI risk problem, alongside Shadow AI usage that IT teams cannot see and harmful prompts that can manipulate AI behavior. Prompt-level leakage specifically can be missed by network-only controls and legacy file-focused DLP workflows, because the data may move through browser prompts, clipboard paste or text input rather than as a traditional file transfer. Acronis GenAI Protection closes that gap at the point of the prompt, as part of a broader approach to GenAI risk.
Visibility into GenAI usage. Acronis GenAI Protection gives IT teams visibility into which GenAI tools are being used across the organization, by whom and how often, so policy decisions are based on actual usage patterns rather than guesswork.
Sensitive data protection for AI interactions. It inspects prompts for personally identifiable information, protected health information, PCI-DSS data and content marked confidential, and it covers text, documents, presentations, spreadsheets and archives. It runs in detect-only or block mode, so you can log and learn before you enforce, then block high-risk data once your rules are tuned. Because inspection happens on the endpoint, it catches the clipboard paste that bypasses the network on protected endpoints.
Harmful prompt detection and blocking. Sensitive data leakage is not the only risk in GenAI interactions. Harmful prompts, including prompt injection attempts, can manipulate AI behavior or introduce unsafe instructions into workflows. Acronis GenAI Protection also helps detect and block harmful prompts based on policy.
Acronis GenAI Protection runs on Windows 10, Windows 11 and macOS, delivered through the Acronis platform alongside existing endpoint protection.
Key takeaways
- The paste problem is large: 77% of employees paste data into generative AI tools, and 82% of that comes from unmanaged accounts, according to the LayerX Enterprise AI and SaaS Data Security Report 2025.
- The four data types most at risk in prompts are personally identifiable information, protected health information, PCI-DSS payment data and confidential business content.
- Policy comes first: technical controls enforce a written decision, and without a policy there is nothing to enforce.
- Detect-only mode logs risky prompts without stopping them, while block mode prevents submission; calibrate with the former, then enforce with the latter.
- Network-only approaches see access patterns but not prompt content, so they miss the clipboard paste that endpoint inspection catches on protected endpoints.
- The human element is the through-line, present in 68% of breaches, according to the Verizon 2024 Data Breach Investigations Report.
Frequently asked questions
What data types are most commonly pasted into ChatGPT?
The highest-risk categories are personally identifiable information, protected health information, payment card data covered by PCI-DSS, and confidential business content such as contracts, financials andr debug them, treating a routine shortcut as harmless while exposing data with real regulatory and competitive consequences
Can network controls alone stop data leakage to AI tools?
No. Network controls block or allow domains but cannot read the content of an encrypted prompt, so they cannot tell a harmless question from a paste of client records. They also miss personal accounts on unmanaged machines. Effective prevention pairs network blocking with endpoint inspection that reads the prompt before it leaves the endpoint.
What is the difference between detect-only and block mode?
Detect-only mode logs and alerts on a risky prompt but lets it through, which suits a calibration period when you are tuning rules and avoiding disruption. Block mode stops the submission outright, which suits high-risk data once rules are trusted. Most organizations start in detect-only mode, then move sensitive categories to block.
Does Microsoft Purview protect against ChatGPT data leakage?
Microsoft Purview can apply endpoint DLP policies that warn or block users from pasting sensitive information into third-party AI sites, including ChatGPT Coverage depends on supported browsers, onboarded endpoints, a browser extension and qualifying licensing, so confirm your configuration meets those prerequisites before relying on it as your sole control
How do I stop employees using personal ChatGPT accounts on work devices?
Combine three controls. Block unsanctioned access at the network and require a sanctioned tool with corporate single sign-on. Inspect prompts at the endpoint so sensitive content is caught regardless of the account used. Then train employees on why personal accounts are prohibited, because a personal session on a work endpoint is the leak hardest to see.
A Swiss company founded in Singapore in 2003, Acronis has 15 offices worldwide and employees in 60+ countries. Acronis Cyber Platform is available in 26 languages in 150 countries and is used by over 21,000 service providers to protect over 750,000 businesses.
Ransomware protectionCyber protectionMSP cybersecurityCorporate cybersecuritySecurity software for businessCloud cyber protectionCloud securityacronis cyber agent
