An employee pastes a contract into a free chatbot to summarize it before a meeting. A developer drops a function into an AI assistant to debug it. Neither uploaded a file. Neither triggered an alert. And both just moved corporate data outside the organization through a channel your security stack was never built to watch: the text box. Prompt data is the new shadow data layer and it is now the single largest way sensitive information leaves the enterprise.
Your DLP Is Watching the Wrong Layer
For fifteen years, data loss prevention – the tooling built to stop sensitive data from leaving the organization was designed around one assumption: that data moves as files and structured patterns. A DLP system inspects an email attachment, matches a 16-digit string to a credit-card rule, blocks an upload to an unsanctioned cloud drive. It watches discrete objects crossing a boundary. That model worked because, for fifteen years, that was how data left.
Prompt data breaks the model completely. When an employee types or pastes into a GenAI tool, there is no file to inspect, no attachment to quarantine, and often no pattern that matches a classic DLP rule. The data moves as free text inside an ordinary web session to a domain the organization has no reason to block. Everything the DLP stack was built to catch is absent, and everything it cannot see is present.
Chatbot risk travels through prompts, not files. The DLP controls most teams spent years configuring are watching the wrong channel entirely and the data knows it.
Propelex Security Intelligence
This is why the numbers moved so fast. The 2026 Verizon DBIR found that 45% of employees now regularly use AI on corporate devices, up from 15% the year before, making shadow AI the third most common non-malicious insider action in enterprise DLP datasets, a fourfold year-over-year increase. GenAI now accounts for 32% of all corporate-to-personal data movement, making it the single largest exfiltration vector in the enterprise.
Why Prompt Data Is Uniquely Invisible
Three properties make prompt data harder to govern than anything that came before it.
It is file-less. Traditional exfiltration produces an artifact, a file, an email, an upload that a control can intercept. Copy-paste into a prompt produces nothing to scan. LayerX telemetry found that 77% of employees paste data into GenAI prompts, and the average user makes multiple sensitive pastes per day through the browser, where most file-based controls have no visibility.
It travels through personal accounts. When organizations either ban AI or fail to provision enterprise accounts, employees use the personal credentials they already have on the same tools. Roughly 82% of copy-paste activity into GenAI happens through unmanaged, non-corporate accounts, and two-thirds of all AI access occurs outside corporate identity entirely. A corporate login that would at least generate an audit trail is not even in the picture.
Source code slips through cleanly. This is the most under-appreciated part. Across the 858,440 DLP events targeting AI tools that Verizon analyzed, source code was the number one data type submitted by a large margin. And unlike customer PII, source code rarely matches the keyword and pattern rules classic DLP depends on, so it moves with almost no friction. Engineers and R&D staff, who make up 39% of enterprise GenAI users, generate exactly this traffic every time they debug, review, or document code.
When proprietary source code enters a public LLM through a personal account, it leaves the organization’s control permanently. There is no retrieval mechanism, no deletion right that applies, and no audit trail to reconstruct what was shared. The 2023 Samsung incident where engineers pasted confidential code into ChatGPT across at least three separate occasions before the company noticed became the reference case precisely because it showed how quickly routine engineering behavior becomes irreversible IP loss.
The Three Tiers You Can’t Tell Apart
From the outside, all AI usage looks the same: traffic to a familiar domain. Underneath, there are three very different risk tiers, and most enterprises cannot distinguish them in real time.
The first tier is sanctioned enterprise AI, a provisioned account on a tier that contractually excludes training use. The second is unmanaged SaaS — a legitimate tool accessed without SSO or governance. The third is personal accounts an employee’s own ChatGPT or Claude login on a corporate device. All three hit the same domain. Only one is governed. And the ungoverned two account for the overwhelming majority of traffic.
There is a quieter fourth channel most programs are not measuring at all: AI browser extensions. The average company has more than 15% of users running unauthorized AI extensions, and many are designed to silently retain the context of every page visited. An extension with full page-content access does not need the employee to paste anything, it collects as they browse internal sites, and that passive vacuuming is invisible to every tool operating outside the browser session.
Bans Don’t Work. Approved Paths Do.
The instinct is to prohibit. The data says prohibition fails and predicts exactly how it fails.
The 2026 DBIR found that 60% of non-malicious insider incidents are now driven by convenience: employees prioritizing getting their work done over policy compliance. Shadow AI is that same dynamic without the malice, a form of insider risk driven by intent to finish work, not to do harm. The employee pasting a contract into a free LLM is not trying to exfiltrate data — they are trying to finish their preparation before a meeting. Ban the tool, and the behavior does not stop; it moves to a personal device or a personal account where the enterprise has even less visibility.
Prohibition will fail the same way blocking email-to-personal-account failed a decade ago. When 45% of your workforce has already integrated a tool into how they work, the question is not whether to allow it, it is whether you can see it.
Propelex Security Intelligence
The shadow IT era already taught this lesson. Consumer cloud services outpaced enterprise procurement; bans alone failed; visibility plus sanctioned alternatives worked. Shadow AI compressed that entire cycle into roughly 24 months and the surveys that provide approved alternatives show a sharp drop in unauthorized use, because the underlying driver was never rebellion. It was friction.
What to Build This Quarter
- Govern the content, not the tool. Blocking domains is a losing game when new AI features appear in your CRM, ERP, and email platforms weekly. Classify what data can never leave – source code, PHI, regulated records and enforce on the content, wherever it tries to go.
- Move visibility to the browser and the prompt layer. The action happens inside the browser session, before anything becomes a file. Prompt- and browser-native monitoring is the only vantage point that can see paste events, personal-account access, and extension activity that network DLP structurally cannot.
- Provision sanctioned AI before you restrict the rest. The single most effective control is a governed enterprise path that is easier to use than the personal one. Provide the alternative first; restriction without it just relocates the risk.
- Inventory AI browser extensions across the fleet. Treat any extension with full page-content access as a data egress channel. Most organizations have never audited these and cannot name which of their users are running them.
- Bring AI into your insider-risk and DLP strategy formally. 92% of organizations say GenAI has changed how employees share information, yet only 13% have integrated AI into their insider-threat strategy. Close that gap: the behavior already changed, the policy has to catch up.
- Generate the audit evidence now. Regulators under GDPR, HIPAA, and the emerging AI rules will ask what data went where. If your only record of AI usage is “we told people not to,” that is not an answer. Build the logging before the inquiry.
The Bigger Picture
The shift from files to prompts is not a new feature of the old problem, it is a new problem. Data loss prevention was built for a world where data moved as objects across a boundary. Prompt data moves as language inside a trusted session, and the entire control stack most enterprises spent a decade building was calibrated for the world that just ended.
This has already reached the boardroom. In the WEF’s 2026 outlook, CEOs named data leaks from generative AI their number one security concern at 30% up from 22% a year earlier, when adversarial AI capability topped the list. The concern moved from what attackers might do with AI to what an organization’s own employees are doing with it, one prompt at a time.
Prompt governance is the new DLP. The organizations that recognize the layer has moved and rebuild visibility around the prompt, the browser, and the content will govern their data. The ones still inspecting files are guarding a door the data stopped using.
Propelex Security Intelligence
The text box is not a productivity feature with a security footnote. It is now the primary channel through which sensitive data leaves the modern enterprise. The only open question is whether an organization can see what goes into it before a regulator, a competitor, or a public model already has.
Propelex’s AI Security & Privacy practice helps organizations govern the prompt layer inventorying shadow AI usage, mapping where sensitive data and source code flow into ungoverned tools, and building the content-level controls and sanctioned paths that stop leakage without stopping productivity. Fortune 50-experienced consultants across regulated industries.


