AI DLP & governance
Stop staff pasting customer data into AI
AI data loss prevention is a structured engagement for Australian small businesses that stops confidential client records, source code and financial data leaking into ChatGPT, Copilot, Gemini and other AI tools, without banning AI outright. Cyberhaven research found 11% of data pasted into ChatGPT was confidential and 4.2% of workers had pasted company data into a public AI tool at least once. The risk extends beyond Microsoft Copilot to personal accounts, meeting bots, browser assistants and AI features embedded throughout SaaS.
Want to gauge your exposure first? Take the free self-check for an indicative risk score.
The leak surface
AI tools turn every staff member into a way data can walk out the door
A bookkeeper pastes a client's profit and loss statement into ChatGPT to summarise it. A salesperson asks Claude to redline a contract. A developer shares source code with a coding assistant. None is malicious; each person is trying to work faster.
Across a team, that adds up to exposure that is hard to see until something goes wrong. AI DLP brings the use of approved tools, personal accounts, meeting bots, browser assistants and embedded SaaS features under one set of rules covering every tool.
Scope
What an AI DLP engagement actually covers
Data classification
Microsoft 365 controls
Public AI tool policy
Meeting bot and SaaS AI
Incident response
Engagement status
Three ways to engage, all scoped to your size
Pricing is on application, with scope and the figure agreed in writing before commencement. The assessment references our Privacy Act 2026 checklist.
Assessment
- AI tool inventory
- Data classification
- Privacy Act gap analysis
- Prioritised remediation list
Implementation
- Everything in Assessment
- Microsoft 365 controls configured
- Policy and cheat sheet written
- Staff training delivered
Managed
- Everything in Implementation
- Quarterly control review
- New tool risk reviews
- Incident response on call
Method
How the engagement runs
Scope
30 min scoping call
We confirm the tier, contact, boundaries and what is in or out of scope.Inventory
Find every AI tool
We map browser plugins, personal logins, meeting bots, embedded SaaS AI and sanctioned tools.Classify
Map the data risk
We identify the data categories that should never reach a public AI tool.Remediate
Lock the leak surface
Controls are configured, the public tool policy is signed off and staff training is delivered.Maintain
Keep it current
The Managed tier reviews controls quarterly as tools and vendor terms change.
Boundaries
What this engagement is not
Network or device DLP
A blanket AI ban
A Microsoft licence sale
Legal advice
A penetration test
Triggers
When this engagement makes sense
M365 Copilot is live or imminent
Renewal form has AI questions
Something nearly went wrong
Sector regulator asking about AI
Procurement questionnaire
Staff using personal AI logins
Related work
What tends to sit beside AI Data Loss Prevention
Practical details
Questions about AI Data Loss Prevention
Start here