Category 7 of 12 · Controls: What data reaches agents
AI data security and DLP
Data discovery, classification, and loss prevention tuned for AI: finding what agents and copilots can read, catching oversharing, and blocking sensitive data in prompts and output.
Mitigates: LLM02 Sensitive Information Disclosure, LLM08 Vector and Embedding Weaknesses · MITRE ATLAS AML.T0057
Vendors, by signal score
- #1Cyera55
Data security platform whose AI Guardian discovers AI models and agents, maps them to the identities and data they can reach, evaluates tool invocations and data access against policy at runtime, and can quarantine an agent.
- #2Nightfall AI34
AI-native DLP that inspects data moving through AI agents, MCP servers, endpoints, and SaaS, with an MCP gateway that applies per-tool policy, logs every tool call with the SSO user, and lets admins revoke access.
- #3Cyberhaven31
Data security platform built on data lineage: inventories AI apps, coding assistants, agent frameworks, and MCP servers, and blocks, warns, or redacts when sensitive data moves into or out of AI tools and agents.
- #4Securiti AIAcquired by Veeam30
Data security posture management, privacy, and AI governance platform; its Gencore AI builds permission-aware retrieval pipelines with prompt, retrieval, and response firewalls. Acquired by Veeam in 2025.
- #5Harmonic Security19
Data protection for employee AI use, using specialized language models to spot sensitive data in prompts, plus an MCP gateway that sets what actions agents may take and what data they may share with each tool.
- #6Knostic15
Need-to-know access control for enterprise AI: finds where assistants such as Microsoft 365 Copilot overshare data, and its Kirin product enforces least-privilege profiles and runtime guardrails for agents, coding assistants, and MCP servers.
Ranked within this category only. How the score works.
Also covers this category
- LayerXAcquired by Akamai20
Browser-based AI usage control and enterprise browser security: discovers shadow AI, prevents sensitive data leaking into AI tools, restricts access to unsanctioned AI apps and accounts, and covers AI browsers, IDEs, and plugins. Acquired by Akamai in 2026.
Questions to ask a vendor
- Can it show which sensitive data each agent or copilot can reach today?
- Does classification feed agent policy automatically?
- Does it inspect both prompts and output for sensitive data?
Go deeper
FAQ
- What is AI oversharing?
- A copilot or agent surfacing data to someone who technically had access through a broad permission but was never meant to see it. AI makes old permission mistakes easy to find.
- How is this different from classic DLP?
- Classic DLP watches files and email leaving the company. AI data security also has to watch what enters prompts and retrieval context, and what the model writes back.