Skip to content

AI DLP & governance

Stop staff pasting customer data into AI

AI data loss prevention is a structured engagement for Australian small businesses that stops confidential client records, source code and financial data leaking into ChatGPT, Copilot, Gemini and other AI tools, without banning AI outright. Cyberhaven research found 11% of data pasted into ChatGPT was confidential and 4.2% of workers had pasted company data into a public AI tool at least once. The risk extends beyond Microsoft Copilot to personal accounts, meeting bots, browser assistants and AI features embedded throughout SaaS.

Want to gauge your exposure first? Take the free self-check for an indicative risk score.

The leak surface

AI tools turn every staff member into a way data can walk out the door

A bookkeeper pastes a client's profit and loss statement into ChatGPT to summarise it. A salesperson asks Claude to redline a contract. A developer shares source code with a coding assistant. None is malicious; each person is trying to work faster.

Across a team, that adds up to exposure that is hard to see until something goes wrong. AI DLP brings the use of approved tools, personal accounts, meeting bots, browser assistants and embedded SaaS features under one set of rules covering every tool.

Scope

What an AI DLP engagement actually covers

AI tool inventory

Find sanctioned tools, personal login shadow tools, browser extensions, meeting bots and AI features embedded in existing SaaS.

Data classification

Define plain English categories for client records, source code, financial data, health information, contracts and other sensitive material.

Microsoft 365 controls

Stop Copilot surfacing files people should not see, with sensitivity labels, Purview rules and conditional access (login rules).

Public AI tool policy

Write usable rules for ChatGPT, Claude, Gemini and other public tools, with safer alternatives where the use case is justified.

Meeting bot and SaaS AI

Review which assistants are processing company data, disable unjustified features and document approved ones.

Incident response

Create a step by step playbook for assessment, documentation, vendor contact and possible Notifiable Data Breach obligations.

Engagement status

Three ways to engage, all scoped to your size

Pricing is on application, with scope and the figure agreed in writing before commencement. The assessment references our Privacy Act 2026 checklist.

Assessment · one off

Assessment

A fixed scope written assessment, usually the starting point for a small business and estimated at two to three weeks.
  • AI tool inventory
  • Data classification
  • Privacy Act gap analysis
  • Prioritised remediation list
Implementation · project

Implementation

We deliver the agreed remediation in an estimated four to eight weeks.
  • Everything in Assessment
  • Microsoft 365 controls configured
  • Policy and cheat sheet written
  • Staff training delivered
Managed · retainer

Managed

Ongoing monitoring and quarterly review on a rolling monthly retainer.
  • Everything in Implementation
  • Quarterly control review
  • New tool risk reviews
  • Incident response on call

Method

How the engagement runs

We work primarily with Australian small businesses of five to fifty staff, with the assessment as the usual starting point.
  1. Scope

    30 min scoping call

    We confirm the tier, contact, boundaries and what is in or out of scope.
  2. Inventory

    Find every AI tool

    We map browser plugins, personal logins, meeting bots, embedded SaaS AI and sanctioned tools.
  3. Classify

    Map the data risk

    We identify the data categories that should never reach a public AI tool.
  4. Remediate

    Lock the leak surface

    Controls are configured, the public tool policy is signed off and staff training is delivered.
  5. Maintain

    Keep it current

    The Managed tier reviews controls quarterly as tools and vendor terms change.

Boundaries

What this engagement is not

Not in scope

Network or device DLP

Endpoint and network DLP remains the MSP's territory; this engagement focuses on the AI tool surface above it.
Not the objective

A blanket AI ban

The objective is productive sanctioned use with risky paths made difficult, not a prohibition staff work around.
No reseller interest

A Microsoft licence sale

VibeZero does not resell Microsoft 365 SKUs or earn margin on Copilot licences.
Advisory boundary

Legal advice

We work alongside privacy counsel and do not replace legal opinions or final compliance sign off.
Separate service

A penetration test

AI DLP addresses authorised user data leakage; penetration testing addresses unauthorised access.

Triggers

When this engagement makes sense

Copilot rollout

M365 Copilot is live or imminent

Sensitivity labels and Purview rules need review before staff use Copilot with sensitive information.
Cyber insurance

Renewal form has AI questions

An insurer or procurement form asks for evidence of AI policy, data handling and incident response.
Near miss

Something nearly went wrong

A staff member shared information with a public tool and the business wants a repeat prevented.
Regulator pressure

Sector regulator asking about AI

A regulator wants to know how client or patient information is governed when AI is used.
Tender

Procurement questionnaire

A larger client or government tender requires credible answers on AI governance.
Shadow AI

Staff using personal AI logins

The business suspects company data is moving through personal ChatGPT, Claude or Gemini accounts.

Practical details

Questions about AI Data Loss Prevention

What is assessed, what you receive and where advisory responsibility stops.

Start here

Worried about what staff are pasting into AI? Start with a scoping call

Honest answers, no pitch deck, no commitment.