> For the complete documentation index, see [llms.txt](https://handbook.harmonic.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://handbook.harmonic.security/handbook/4.-data-protection-and-residency/4.1-dlp-for-genai.md).

# 4.1 DLP for GenAI

How to detect and control sensitive data moving into prompts, files, tools, connectors, and outputs where classic DLP often lacks visibility.

*Last reviewed: August 18, 2026*

{% hint style="info" %}
DLP for AI starts where data enters prompts and tools. Classic email and web DLP will miss part of the path unless it sees AI-specific context.
{% endhint %}

## DLP for GenAI: what security teams need to know

AI changes the DLP problem because the exit point is often a prompt, a file upload, a connector call, a browser action, or an API request. The same sensitive record can move through several of those surfaces in one session.

Effective GenAI DLP combines content detection with context. The policy should know which user, app, destination, connector, action, and data class are involved.

## Common DLP for GenAI security failures

* The control sees the browser but not the desktop app or CLI.
* A paste is blocked, but the same data moves through a file upload.
* Tool parameters and outputs are not inspected.
* The DLP rule sees a secret but cannot tell whether the destination is approved.
* Users move to personal accounts when enterprise tools are blocked.

## DLP for GenAI security controls checklist

* Map all AI data entry points: prompt, paste, upload, connector, browser, desktop, and API.
* Classify data before deciding which AI surfaces may receive it.
* Inspect tool parameters and outputs where telemetry allows it.
* Use block, warn, justify, and allow modes based on data class and destination.
* Review incidents for bypass paths across blocked and allowed events.

## Anthropic

### Overview

Anthropic's enforcement points sit in roles, connector policy, and managed settings rather than in a single DLP console. Enterprise custom roles gate capabilities per surface — chat, web search, skills, Claude Code, Cowork, and Claude for Chrome — and connector permissions can require approval, block access, or always allow it. The organization-wide per-tool policy acts as a ceiling: role grants can narrow access within it but cannot widen it, and enforcement fails closed toward denial.

On the desktop, Team and Enterprise owners can enable or disable public desktop extensions, and enterprise policy controls override in-app allowlist and blocklist settings. Cowork and the Claude Office add-ins need separate telemetry paths: both are outside the Compliance API today, while Anthropic offers OpenTelemetry exports that can include full prompts, tool parameters, file paths, document URLs, and user identity. Configure filtering, access, and retention before that stream reaches a broad SIEM index.

Claude Tag moves the DLP boundary into Slack channels. Channel members share the agent's Access bundles, memory, repositories, and service-account authority, while direct messages use personal connectors. Restrict who can invoke it, keep sensitive credentials and repositories out of organization-wide bundles, and include Slack retention, Agent Proxy destinations, and target-system logs in the data-flow review.

### Anthropic documentation

* [Manage custom roles on Enterprise plans](https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans)
* [Use connectors to extend Claude's capabilities](https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilities)
* [Getting Started with Local MCP Servers on Claude Desktop](https://support.claude.com/en/articles/10949351-getting-started-with-local-mcp-servers-on-claude-desktop)
* [Claude Code settings](https://code.claude.com/docs/en/settings)
* [Monitoring](https://code.claude.com/docs/en/monitoring-usage)
* [Monitor Claude Cowork activity with OpenTelemetry](https://support.claude.com/en/articles/14477985-monitor-claude-cowork-activity-with-opentelemetry)
* [Work across Microsoft 365 apps](https://support.claude.com/en/articles/13892150-work-across-microsoft-365-apps)
* [Configure a custom OpenTelemetry collector for Office agents](https://support.claude.com/en/articles/14447276-configure-a-custom-opentelemetry-collector-for-office-agents)
* [Claude Tag security and data handling](https://claude.com/docs/claude-tag/concepts/security-and-data)
* [Restrict where Claude Tag operates](https://claude.com/docs/claude-tag/admins/restrict-access)

### Applicable Harmonic guides for Anthropic

* [Securing Claude Cowork: A Security Practitioner's Guide](https://www.harmonic.security/resources/securing-claude-cowork-a-security-practitioners-guide)

## OpenAI

### Overview

OpenAI's closest DLP primitives are Lockdown Mode, RBAC, and app action controls. Lockdown Mode limits outbound web and external-service access to reduce prompt-injection data exfiltration, and admins assign it through RBAC roles; note that it does not affect Codex network access, so Codex needs its own egress controls. RBAC custom roles also gate apps, GPTs, canvas networking, and skills per group.

For connected apps, action control determines whether an app can read only, take actions, or use a custom set of actions. ChatGPT Work, ChatGPT for Excel or Google Sheets, and ChatGPT for PowerPoint can carry approved apps and skills into document workflows, so DLP must follow the source file, connected app, generated artifact, and final share. OpenAI's Work guidance says the Compliance API covers user messages and responses across Chat, Work, and Codex, but not files, actions, or tool calls.

### OpenAI documentation

* [Lockdown Mode](https://help.openai.com/en/articles/20001061)
* [RBAC](https://help.openai.com/en/articles/11750701-rbac)
* [Admin Controls, Security, and Compliance in apps](https://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-in-apps-enterprise-edu-and-business)
* [Codex Governance](https://developers.openai.com/codex/enterprise/governance)
* [ChatGPT Work Admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq)
* [ChatGPT for Excel and Google Sheets](https://help.openai.com/en/articles/20001063)
* [ChatGPT for PowerPoint](https://help.openai.com/en/articles/20001242)

### Applicable Harmonic guides for OpenAI

* [Securing ChatGPT Enterprise Guide](https://www.harmonic.security/resources/securing-chatgpt-enterprise-guide)

## Frequently asked questions about DLP for GenAI

### What is GenAI DLP?

GenAI data loss prevention is the set of controls that detect and govern sensitive data moving into and out of AI tools such as ChatGPT, Claude, Copilot, and Gemini. It inspects prompts, pasted text, file uploads, connector and tool calls, and generated outputs rather than just email and web traffic. The decision logic pairs content detection with context: which user, account type, surface, and destination are involved.

### Why does classic DLP miss AI risk?

Classic DLP focuses on email, web uploads, and storage, so it tends to see the browser but not desktop apps, CLIs, connectors, or API traffic. AI workflows move the same record through several of those surfaces in one session, and tool parameters or model outputs are rarely inspected at all. Coverage needs to follow the surface list, not the network perimeter.

### Should DLP block all sensitive data in AI tools?

No. Blanket blocking pushes users toward personal accounts, which is usually a worse outcome than monitored enterprise use. Match the response — block, warn, justify, or allow — to the data class, the destination, the user's role, and whether the surface is an approved enterprise tenant.

### What should be monitored first?

Start with secrets and credentials, regulated records, customer data, source code, and financial data, plus any use of personal accounts for corporate work. These classes produce the highest-impact incidents and the clearest policy decisions. Expand into lower-sensitivity classes once triage keeps up with the alert volume.

### How should DLP alerts be triaged?

Triage on data class, destination, and account type first: a secret sent to a personal account outranks internal data in an approved workspace. Then check whether the event created a durable external copy, such as a shared artifact or a connector write. Close the loop by reviewing blocked and allowed events together to spot bypass paths.

## Applicable regulations and frameworks

| Governance page                                     | Relationship to this article                                                                                                                       |
| --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| G.1 Map your controls to NIST AI RMF and CSF 2.0    | This article supplies implementation evidence for the NIST AI RMF and matching NIST CSF 2.0 outcomes.                                              |
| G.3 DORA and AI resilience in financial services    | Conditional: for a DORA-regulated workflow, this supports data protection, integrity, and third-party service review.                              |
| G.5 SANS Critical AI Security Guidelines mapping    | This article implements relevant SANS Data Protection guidance.                                                                                    |
| G.6 Write an AI Acceptable Use Policy that holds up | This article supplies a technical or process control used to enforce the acceptable-use policy.                                                    |
| G.7 Ownership and RACI for AI security              | This control depends on the ownership and evidence responsibilities defined in the RACI.                                                           |
| G.9 HIPAA controls for AI systems handling PHI      | Conditional: for a workflow handling ePHI, this supports HIPAA PHI identification, minimum-necessary handling, retention, and disclosure controls. |

*G.2, G.3, G.4, and G.9 are conditional mappings. They apply only when the deployment is within the legal or regulatory scope described on the linked governance page.*

## Related handbook guidance

* [4. Data Protection & Residency](/handbook/4.-data-protection-and-residency.md)
* [4.2 Data classification for AI prompts and outputs](/handbook/4.-data-protection-and-residency/4.2-data-classification-for-ai-prompts-and-outputs.md)
* [2.6 AI hooks: inference controls and lifecycle automation](/handbook/2.-supply-chain-and-extensibility/2.6-ai-hooks-inference-controls-and-lifecycle-automation.md)
* [5.2 Data exfiltration via tools and connectors](/handbook/5.-threats-and-adversarial/5.2-data-exfiltration-via-tools-and-connectors.md)
* [6.3 Compliance APIs by platform](/handbook/6.-observability-audit-and-evidence/6.3-compliance-apis-by-platform.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://handbook.harmonic.security/handbook/4.-data-protection-and-residency/4.1-dlp-for-genai.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
