AI DLP & governance
AI data loss prevention for Australian teams
AI data loss prevention (AI DLP) is the work of stopping client records, source code and financial data from entering the wrong AI tool. VibeZero delivers it as a fixed scope engagement for Australian small businesses. The work combines an inventory, usable rules, staff guidance and technical controls suited to the systems in scope.
Describe the problem in a sentence or two. Please do not send credentials or sensitive records.
Want to gauge your exposure first? Take the free self check for an indicative risk score.
- Best fit
- Teams using Copilot and public AI with sensitive information
- Main deliverable
- Tool inventory, data rules and a prioritised control plan
- Client access
- A sponsor, a sample of staff and the relevant Microsoft administrator
- Commercial model
- Fixed scope assessment, project delivery or managed review
- Scope
- Review
- Findings
- Walkthrough
The accountable team stays involved from scoping through the final walkthrough. Specialist capability is added where the evidence needs it, with responsibilities agreed before work starts.
The leak surface
AI use creates a data path most businesses cannot see
A bookkeeper pastes a client's profit and loss statement into ChatGPT to summarise it. A salesperson asks Claude to redline a contract. A developer shares source code with a coding assistant. None is malicious; each person is trying to work faster.
Cyberhaven's 2026 AI Adoption and Risk Report says 39.7% of the AI interactions it analysed involved sensitive data. That is vendor research, not a measure of your environment. No control removes every path.
Across a team, that adds up to exposure that is hard to see until something goes wrong. AI DLP brings approved tools and the personal accounts, meeting bots, browser assistants and embedded SaaS features found during the agreed review under one set of usable rules.
Scope
What an AI DLP engagement covers
Data classification
Microsoft 365 controls
Public AI tool policy
Meeting bot and SaaS AI
Incident response
Client perspective
A client view of our security review work
Every issue came with a practical fix, sequenced so we could ship safely, and they handed over their testing tools so the value outlasted the engagement.
Engagement status
Assessment, implementation or managed review
Pricing is on application, with scope and the figure agreed in writing before commencement. See the Pricing page for how projects and retainers are handled. The assessment can also reference our Privacy Act 2026 checklist, but it is not legal advice or compliance certification.
Assessment
- AI tool inventory
- Data classification
- Privacy control gap review
- Prioritised remediation list
Implementation
- Everything in Assessment
- Microsoft 365 controls configured
- Policy and cheat sheet written
- Staff training delivered
Managed
- Everything in Implementation
- Quarterly control review
- New tool risk reviews
- Incident guidance within agreed support hours
Method
How the engagement runs
Scope
30 min scoping call
We confirm the tier, contact, boundaries and what is in or out of scope.Inventory
Map the AI tool surface
We review sanctioned tools, reported personal use, meeting bots, browser plugins and embedded SaaS AI within the agreed scope.Classify
Map the data risk
We identify the data categories that should never reach a public AI tool.Remediate
Reduce the leak surface
We configure the agreed controls, the client signs off the public tool policy and we deliver staff guidance.Maintain
Keep it current
The Managed tier reviews controls quarterly as tools and vendor terms change.
Choose the right starting point
Readiness, usage, DLP or privacy advisory
AI Readiness Audit
AI Usage Review
AI Data Loss Prevention
Data and Privacy Advisory
Boundaries
What this engagement is not
Network or device DLP
A blanket AI ban
A Microsoft licence sale
Legal advice
A penetration test
Triggers
When this engagement makes sense
Microsoft 365 Copilot is live or imminent
Renewal form has AI questions
Something nearly went wrong
Sector regulator asking about AI
Procurement questionnaire
Staff using personal AI logins
Practical details
Questions about AI Data Loss Prevention
AI data loss prevention is the work of reducing the chance that confidential data leaves the business through AI tools. It can cover Microsoft 365 permissions, staff pasting information into public AI tools, meeting bots, browser assistants and AI features inside existing software. The engagement combines proportionate technical controls, a written usage policy, staff guidance and an incident response playbook.
Start here