Dive Brief:
- Data security firm Sentra launched a tracking tool to help organizations block unauthorized AI use and keep sensitive data safe from ChatGPT, Claude, Gemini, Copilot and other generative AI applications. The capability is embedded in the vendor’s data platform and aims to combat shadow AI, according to a Tuesday announcement.
- Shadow AI is a pressing security concern for companies seeking to protect their data and employees grappling with the rapid implementation of AI. According to Gartner research, 69% of organizations suspect or have evidence that employees are using prohibited public GenAI.
- “AI-related web traffic has grown quickly year-over-year, and roughly half of organizations expect a shadow-AI-driven incident within the next 12 months,” Yair Cohen, cofounder and CPO of Sentra, told Channel Dive. “Employees are turning to chatbots, coding assistants and image generators to improve productivity without involving IT or security. Organizations need visibility and enforcement tools that can block, coach or audit activity without disrupting workflows.”
Dive Insight:
As business leaders push for AI adoption, some employees are using external or personal applications for company tasks. Many of these tools are low-security, consumer-grade chatbots, according to Cohen.
The problem isn’t restricted to non-technical staff. IT and infrastructure professionals are one of the biggest sources of shadow AI, WitnessAI found in a recent survey. Regardless of the source, Cohen said that any unauthorized AI use creates vulnerabilities, and that every upload into an ungoverned tool is a potential data breach.
“Increasingly, boards, regulators, and customers don't want to know whether you have an AI policy,” he said. “They want evidence that you're enforcing it. Once sensitive data reaches a third-party AI tool, it can't be recalled, so prevention is the only real control. Organizations that can't govern AI end up banning it and losing the productivity their competitors are capturing.”
Sentra’s Shadow AI DLP tracking tool departs from traditional data loss prevention built to monitor email, file transfers and network traffic, though the company said it’s not a replacement for email, network or full endpoint DLP. The capability was designed to continuously discover and classify sensitive data across cloud, SaaS and on-premises environments.
Shadow AI DLP also has visibility into browsers, where employees commonly use AI tools, according to Cohen. The challenge is allowing employees to access third-party applications when necessary while preventing data leaks.
“The capability has two parts,” Cohen said. “Shadow AI Discovery identifies which AI tools employees are using, whether sanctioned or not, and helps organizations understand the risks those tools introduce. AI Browser DLP then inspects pastes and uploads before data leaves the browser, classifies the content locally using Sentra’s existing data classifications and enforces policy based on the AI application and the sensitivity of the data. Organizations can block the action, require justification, prompt the user to confirm, or allow and log it.”
Employee tracking and data privacy are issues every vendor should address, Cohen said. He added that Sentra’s classification of AI use happens locally in the employee’s browser, and that their content never leaves the device.
“The intent is coaching and offering a safety net, not surveillance,” he said. “Employees are told what triggered a policy and why, in the moment. Organizations should explain what is being monitored, why the policy exists and what happens when a user triggers it. If employees understand the goal is to help them use AI safely rather than catch them doing something wrong, the control is much easier to roll out.