Skip to content

Category 7 of 12 · Controls: What data reaches agents

AI data security and DLP

Data discovery, classification, and loss prevention tuned for AI: finding what agents and copilots can read, catching oversharing, and blocking sensitive data in prompts and output.

Mitigates: LLM02 Sensitive Information Disclosure, LLM08 Vector and Embedding Weaknesses · MITRE ATLAS AML.T0057

Vendors, by signal score

Ranked within this category only. How the score works.

Also covers this category

Questions to ask a vendor

  1. Can it show which sensitive data each agent or copilot can reach today?
  2. Does classification feed agent policy automatically?
  3. Does it inspect both prompts and output for sensitive data?

Go deeper

FAQ

What is AI oversharing?
A copilot or agent surfacing data to someone who technically had access through a broad permission but was never meant to see it. AI makes old permission mistakes easy to find.
How is this different from classic DLP?
Classic DLP watches files and email leaving the company. AI data security also has to watch what enters prompts and retrieval context, and what the model writes back.