Stopping data leakage into AI tools on a small budget

Concrete controls a company without a security team can put in place this month, using licences you probably already hold.

Order of work

Do these in order. The first three deliver most of the risk reduction.

1. Give people a sanctioned tool. One enterprise licence with contractual no training terms, single sign on and administrative controls. Microsoft 365 Copilot, Google Gemini for Workspace, ChatGPT Enterprise or Team, and Claude for Work all offer this. Cost per seat is small compared with a breach notification.

2. Close the easy leaks. Require single sign on for the approved tool so accounts are visible and revocable. Block consumer tiers of the same tools at the DNS or gateway layer if you can, because staff will default to whichever is easiest. Cloudflare Gateway, Cisco Umbrella and the filtering bundled with Microsoft Defender all do this.

3. Write one memorable rule. For example: client identifiable material only goes into the approved tool, never into anything else. A rule people can recall beats a policy people cannot find.

4. Turn on the data loss prevention you already pay for. Microsoft Purview data loss prevention in Business Premium and above, and Google Workspace data loss prevention on Enterprise plans, can warn or block on patterns such as client references, national insurance numbers and card numbers in uploads and pastes.

5. Control the browser. Managed browser profiles in Chrome or Edge let you allow list extensions. Unvetted extensions with page read access are a genuine exfiltration route and are usually overlooked.

6. Review the OAuth grants. Quarterly, list third party applications with access to mail and files, and revoke anything unrecognised.

Contract points worth checking

  • Is your input used to train or improve the model? Get this in writing for the tier you actually buy.
  • What is the retention period for prompts, and can you set it to zero or near zero?
  • Where is processing carried out, and what transfer mechanism applies?
  • Are sub processors listed, and are you notified of changes?
  • What are the security incident notification timescales?

What good looks like at this size

A single page listing approved tools, the rule, the blocked alternatives and the named person to ask, plus the technical controls above actually switched on. That is a proportionate control set for a company of thirty people, and it will pass review.