How Do I Stop Staff Pasting Client or Company Data Into AI Tools?
Three layers stop client data reaching AI tools: an approved tool, controls at the point of egress and a reporting route staff will actually use. Bans do not.
You stop staff pasting client data into AI tools with three layers working together: an approved tool that is safe to use, technical controls that inspect content leaving the browser and a reporting culture where people declare mistakes instead of hiding them. Blanket bans fail because they move the same behaviour onto personal devices.
This Q&A is for IT leads and data protection officers who accept staff will use AI and want controls that hold.
Reviewed by Jason Holloway, QL Security.
Why doesn’t blocking AI websites at the firewall solve the problem?
Two reasons. First, the block only covers devices and networks you control. Someone facing a deadline uses a phone, a home laptop or a personal account and the paste happens outside your telemetry entirely. Second, AI features now arrive inside tools you have already approved: browser extensions, meeting note-takers, code assistants and the assistant in your document suite. Blocking is a holding position while you stand up an approved alternative. Our view is that a ban with no sanctioned alternative in place displaces Shadow AI onto channels you cannot see rather than reducing it.
What does a layered control set actually look like?
Three layers, in this order.
- A sanctioned tool on terms that exclude your inputs from model training, with logs you can query.
- Technical controls at the point of egress, meaning browser or endpoint inspection of paste and upload events plus warnings on patterns such as client reference formats and card data.
- A safe reporting route, so staff can declare a mistake within 24 hours with no disciplinary consequence for a first instance.
We sequence these deliberately, because we take the view that technical controls imposed without an approved alternative invite workarounds. Tooling is the second step of AI governance, never the first.
Can our existing DLP tooling detect data pasted into an AI tool?
Partly, and the gaps matter. Traditional data loss prevention was built around email, file transfer and removable media. Detecting a paste into a browser text field needs an endpoint or browser agent that recognises the destination, so check whether your licence tier includes browser event inspection. The harder limit is linguistic: pattern matching catches structured identifiers such as account numbers and postcodes, but misses a paragraph of prose summarising a client’s refinancing position, which carries no identifier and is still a confidentiality breach. DLP reduces volume and evidences intent; it does not replace the other two layers.
How do we find out which AI tools our staff already use?
Cross-reference four sources rather than trusting one. Outbound DNS and proxy logs show direct traffic to AI services. Your identity provider’s OAuth grant list shows tools staff have connected to corporate data, often the higher risk. Expense records reveal personal subscriptions bought with company money. A short anonymous survey surfaces the personal-device usage no log will show. Our Shadow AI Discovery work runs all four and ranks the inventory by data sensitivity rather than request volume, because the tool used twice a month by the legal team matters more than the one used daily by marketing.
What should our AI acceptable use policy say about client data?
Be specific enough to act on. Name the approved tools and the data classes permitted in each. State plainly what must never be entered into an unapproved tool: client-identifiable information, credentials, unpublished financials, legal advice and special category personal data. Give one worked example per business function, because abstract prohibitions are read as applying to somebody else. Then publish a route for requesting approval of a new tool, with a committed response time of five working days. A policy that only forbids creates pressure with no release valve, and ISO 42001 frames auditable evidence of control ownership.
What do we do about data staff have already pasted into AI tools?
Run a declared amnesty before you tighten controls, otherwise your first day of monitoring produces a backlog you cannot triage. Ask staff to record what they shared, with which tool and roughly when. Then work the list: submit deletion requests to each provider, revoke OAuth grants you cannot justify, rotate any credential that appeared in a prompt and assess each disclosure against the relevant client contract. The declaration window needs visible senior sponsorship and a stated no-blame position, or you receive nothing useful. We set out the mechanics and triage order in our answer on banning ChatGPT and running an amnesty instead.
Do we have to tell clients or the regulator when this happens?
Assess both duties separately, because they trigger differently. Contractual obligations to clients are frequently stricter than statute: many professional services and financial agreements require notification of any unauthorised disclosure of confidential information, with no risk threshold attached. Read the confidentiality and subprocessor clauses first. Under UK GDPR the question is whether personal data was involved and whether the disclosure poses a risk to the individuals concerned. Document the assessment either way, including the reasoning where you conclude notification is not required, because an undocumented decision looks identical to no decision eighteen months later. Treat this as general guidance rather than legal advice, and see what to do when an employee puts confidential data into an AI tool for the incident sequence.
Can we do this in-house, or do we need external help?
Most organisations with a functioning security team can complete the first pass without help. Log review, OAuth audit, policy drafting and an amnesty are all internal work. If that describes you, do it yourself and spend the budget on tooling instead. External help earns its place in three situations: when internal usage involves the executive team and you need an independent view, when you must evidence control effectiveness to a client or certification body or when discovery reveals AI embedded in a customer-facing process and the question shifts from data handling to system behaviour. That is what our AI Security Gap Analysis and AI Behaviour Verification work addresses.
Find out what is already leaving
We run discovery across network, identity, endpoint and finance evidence, then rank the inventory by data sensitivity.