From Ritu Raj | Product & Market Analysis
DLP for AI Prompts: 223 Incidents a Month, and What Purview Now Blocks
On this page
The average organisation now records 223 attempts a month by its own staff to put sensitive data into generative AI apps. That is the headline from Netskope's Cloud and Threat Report 2026, and the count more than doubled in a year. Data loss prevention for AI prompts is now a real product category, with Microsoft, Netskope and Zscaler all shipping controls. They catch different leaks, and none of them catches all of them.
Key takeaways
- The average firm logs 223 genAI data policy violations a month. Netskope's 2026 telemetry puts the top quartile at 2,100 a month, and says both the incident count and the number of offending users doubled in a year.
- Regulated data, not source code, is the biggest category. Netskope reports uploads of personal, financial and healthcare data at 54% of genAI policy violations, ahead of intellectual property, source code and credentials.
- Purview's Copilot control reads typed text, not uploaded files. Microsoft's own documentation says DLP cannot scan files uploaded directly into a Copilot prompt, so the block applies only to what a user types.
- The personal account is where native controls run out. 47% of genAI users still use personal accounts, and catching those prompts needs a managed browser, a SASE integration or an inline proxy such as Netskope or Zscaler.
Short answer
DLP for AI prompts inspects the text and files an employee sends to an AI tool, then blocks or warns before sensitive data leaves. Microsoft Purview does this natively inside Microsoft 365 Copilot, and through Edge or a SASE partner for other AI apps. Netskope and Zscaler do it as inline proxies that decrypt the traffic.
What the 223 figure in the Netskope report measures
A data policy violation, in Netskope's usage, is an event where a user tries to send data that matches a DLP rule to a genAI app. It counts attempts that a policy detected. It does not count leaks that no policy was written to see.
That distinction matters more than the number. The report says the average organisation records 223 genAI-related data policy violations per month, rising to 2,100 in the top 25% of organisations. Those are detections by firms that already run Netskope, which means they are firms that bothered to look.
The volume underneath is growing faster than the violations. Netskope says prompts sent to genAI apps rose from an average of 3,000 to 18,000 per organisation per month, with the top quartile above 70,000. On my arithmetic, 223 violations against 18,000 prompts is roughly one detection per 80 prompts. Treat that as directional, because violations also include file uploads, not just prompts.
Doubled, from a base the release does not give
Netskope says both the number of users committing data policy violations and the number of incidents doubled over the year. The press coverage I could open does not state the prior-year count. "More than doubled" is therefore a ratio you can quote, but not a starting point you can check.
My reading is that most of the growth tracks usage, not carelessness. When prompts grow sixfold and violations grow twofold, the violation rate per prompt has fallen.
Regulated data leads the list
The categories Netskope names are regulated data, intellectual property, source code, and passwords and keys. According to ITPro's report on the findings, uploads of regulated data, meaning personal, financial or healthcare records, are the biggest category at 54%.
That matters for tool choice. Regulated data has stable formats, such as card numbers, national ID numbers and health identifiers, which pattern-based DLP detects well. Source code and intellectual property have no fixed format, so they are where every product in this comparison is weakest.
DLP for AI prompts has four distinct leak paths
Most vendor comparisons treat "AI DLP" as one feature. It is four separate interception problems, and each product sits at a different point in the path between a user's keyboard and a model.
The first path is the sanctioned assistant, such as Microsoft 365 Copilot, where the employer controls the tenant. The second is the file a user drags into a prompt, which is a different object from typed text. The third is the personal account, where a user signs into consumer ChatGPT or Gemini on a work laptop. The fourth is the assistant embedded inside another SaaS app, such as Copilot inside Word or an AI feature inside a CRM.
Netskope's own figure explains why the third path matters most. It reports that 47% of genAI users still use personal accounts, either exclusively or alongside company tools. The policy and contract side of that problem is covered in the analysis of personal AI accounts as the new perimeter. This post is about the controls.
What Microsoft Purview DLP now blocks inside Copilot
Purview's Copilot policy location is the only control in this comparison that runs inside the AI service itself. That gives it one large advantage. It does not care which device, network or browser the user is on, because it evaluates the request where Copilot processes it.
Microsoft's documentation, updated on 5 October 2026, describes three behaviours that matter for prompt leakage. It covers Microsoft 365 Copilot, Copilot Chat, Cowork, and Copilot in Word, Excel and PowerPoint.
Prompts that carry sensitive information types
A sensitive information type, or SIT, is Purview's name for a defined pattern such as a card number or a passport number. When a prompt contains one, the policy can stop Copilot returning a response and stop it using that data for internal or web searches. Microsoft's page marks this as a preview that is rolling out to tenants, and says only out-of-the-box and custom SITs are supported.
A separate action blocks external web search for any prompt that contains a SIT, while Copilot still answers from internal Microsoft 365 data. That is a sensible middle setting. It keeps the user productive while stopping the prompt from reaching a search engine.
Purview can also exclude files and emails carrying chosen sensitivity labels from Copilot's responses. Microsoft notes that those items still appear in citations, but Copilot does not use their content. This addresses grounding, which is the data Copilot retrieves, rather than prompts. The oversharing side of grounding is examined in the comparison of Glean and Copilot permission models.
The file upload gap in Copilot DLP
This is the sentence buyers should read twice. Microsoft's documentation states that DLP cannot scan the contents of files uploaded directly into prompts and only checks the text typed into the prompt itself.
A user who pastes a customer list as text is caught. A user who attaches the same list as a spreadsheet is not, at least by this control. Given that Netskope's largest violation category is uploads of regulated data, the gap is not a footnote. It is the most common case.
The other limits are operational. A single rule cannot combine SIT and sensitivity label conditions. The location is available only in the custom policy template, other locations in that policy are disabled, and updates can take up to 4 hours to apply.
Purview beyond Copilot: Edge and network data security
Microsoft's answer for the personal account path is to inspect traffic before it leaves the device or the network. It offers two routes, and they have different prerequisites.
Edge for Business on managed Windows
Purview inline protection in Edge for Business can inspect text and files sent to a listed set of consumer AI apps, then allow or block, with both actions audited. Microsoft's list includes consumer ChatGPT, Google Gemini, DeepSeek, Perplexity, Grok, Meta AI and Microsoft Copilot, among 19 entries. Claude does not appear on that browser list.
The conditions are strict. Unmanaged-app policies work only on Windows 10 and 11 devices managed by Intune, in the two latest stable Edge versions from 144 onward. Protecting data sent to unmanaged apps is billed pay-as-you-go. When the policy is set to block, Microsoft says users are also blocked from opening Firefox, and from Chrome unless the Purview extension is installed.
That last detail is the real design. The browser control works by making Edge the only browser that can reach the AI app. It is effective on a locked-down Windows fleet. It does nothing for a Mac, a phone or a contractor's laptop.
Network data security through a SASE partner
Purview network data security sends traffic from a secure access service edge, or SASE, product to Purview for classification. Microsoft names its own Entra Global Secure Access, plus non-Microsoft SASE and secure browser partners listed in its Security Store.
It inspects text sent to AI apps, files uploaded, text received and files downloaded, with audit and block as the supported actions. Microsoft names ChatGPT, Gemini and Claude as examples, and draws on a catalogue of over 35,000 cloud apps. Evaluation stops at 4 MB of text and 3 MB per file.
Microsoft is unusually candid about the failure modes. It says some apps, including ChatGPT, Runway and Meta AI, may send content in encoded form or through dynamically generated endpoints, which can affect enforcement. B2B guest users are not covered at all.
Netskope and Zscaler: the inline proxy route to prompt DLP
Netskope and Zscaler come at the problem from the network side. Both run cloud proxies that decrypt web traffic, read the prompt, and apply a DLP policy before the request reaches the AI provider. Their strength is breadth. Their weakness is that they see only the traffic routed through them.
Netskope: policy per activity, with user coaching
Netskope's documentation defines four genAI activities a real-time policy can target. Post is a prompt to a standalone app such as ChatGPT. Response is the answer. AI Post and AI Response cover embedded assistants, with Copilot inside Microsoft Word as the documented example.
The available actions are Alert, Allow, Block and User Alert. With Block or User Alert, an admin can attach a notification template that coaches the user at the moment of the violation. The documentation notes that some activities are not available for certain apps.
The embedded assistant coverage is the notable part. It is the one place in this comparison where a non-Microsoft tool documents a control aimed at Copilot inside an Office app. Netskope's general DLP documentation also lists fingerprinting and exact match, which are the methods that can recognise a known document or dataset rather than a pattern.
Zscaler: dictionaries, isolation and a tenant split
Zscaler's product pages describe inline DLP for prompts across 100+ DLP dictionaries, naming Source Code, PII, PCI and PHI. Policies can warn, block, or open the AI app in browser isolation, a remote browser where the user can type prompts but cut, paste and download are disabled.
Two features stand out for this problem. Zscaler says it can apply separate policy to a corporate tenant and a personal account of the same AI app, approving one and cautioning or containing the other. It also describes prompt-level visibility, meaning admins can see the prompts users send. A February 2025 Zscaler post extends inline DLP and prompt visibility to Microsoft Copilot.
Prompt visibility is a governance decision before it is a security feature. A log of every employee prompt is itself a store of sensitive data, and it needs its own retention policy and access controls. I would not switch it on without deciding who may read it.
Control map: Netskope incident categories against each tool
The table below maps each Netskope violation category to the detection method each product documents. It describes capability on paper, from vendor documentation. No independent test of detection accuracy across these three tools has been published that I could find.
| Netskope category | Microsoft Purview | Netskope | Zscaler |
|---|---|---|---|
| Regulated data (54% of violations) | Out-of-the-box SITs in typed Copilot prompts; Edge and network for other apps | DLP profiles with data identifiers on Post activity | PII, PCI and PHI dictionaries applied inline |
| Source code | Custom SITs only; Copilot location does not list other classifiers | DLP profile on Post; fingerprinting for known code | Named Source Code dictionary |
| Intellectual property | Sensitivity labels keep labelled files out of Copilot answers | Fingerprinting and exact match | Blocking on Purview sensitivity labels, per a 2025 blog |
| Passwords and keys | Depends on SIT coverage of your key formats; test it | Data identifiers; check coverage of your key formats | Not among the named dictionaries; check the list |
| Where it does not reach | Files uploaded to Copilot prompts; unmanaged devices for Edge route | Traffic not routed through the proxy | Traffic not routed through the proxy |
The prerequisites differ as much as the coverage. This is the table to bring to procurement, because licensing usually decides the shortlist before capability does.
| Route | Device or network prerequisite | Licensing named in documentation |
|---|---|---|
| Purview, Copilot location | None beyond Copilot itself; custom policy template | Microsoft 365 Copilot and enterprise plans; no single SKU named |
| Purview, Edge for Business | Intune-managed Windows 10 or 11, Edge 144 or later | Pay-as-you-go for unmanaged AI apps |
| Purview, network data security | Entra-joined device and TLS inspection, or a partner SASE | Microsoft 365 E7, or Purview E5 with Entra Internet Access or pay-as-you-go |
| Netskope | Traffic steered through Netskope with TLS inspection | CASB Inline or SWG licence, per a Netskope community guide |
| Zscaler | Traffic steered through Zscaler with TLS inspection | Not stated on the product pages read |
Where this comparison is weakest
The incident figures come from one vendor's telemetry about its own customers. Netskope sells the DLP that produces the detections, so its customer base skews toward firms that already monitor genAI. A firm with no prompt policy records no violations. The 223 average describes Netskope's customers, not the economy.
I could not open the report body itself. Netskope's report page renders through scripts that my tools could not read, so every Netskope figure here comes from press coverage of the release, cross-checked across Business in the News, Cyber Security Asia and ITPro. Those three agree on 223, 2,100, 47% and 54%. Some secondary summaries circulate a different category split, with source code first, which I could not trace to Netskope and have not used.
The control comparison is built from vendor documentation, which describes what a product is designed to do. It says nothing about false positive rates, missed detections or how often a prompt slips through encoding tricks. Microsoft is the only vendor of the three whose documentation lists its own failure modes in detail. That makes Purview look weaker on paper, when it may simply be more honest.
Finally, Purview's prompt blocking for SITs is still in preview, and Zscaler's Copilot claims come from a 2025 blog rather than a configuration guide. Both could change within a quarter. Re-check any row of the tables above before you sign anything.
Which data loss prevention for AI prompts fits your estate
The decision turns on one question: where does most of your genAI traffic actually go? Netskope's data says the answer for many firms is half sanctioned, half personal, which is why one product rarely covers it.
If you are standardised on Microsoft 365 Copilot and run a managed Windows fleet, start with Purview. The Copilot location costs nothing extra to turn on in simulation mode, and Edge for Business closes much of the personal account path on those devices. My view is that this is the cheapest meaningful control available to a Microsoft shop today.
If your fleet is mixed, with Macs, contractors or several AI tools, a SASE proxy is the stronger base. Netskope and Zscaler see every app routed through them, whatever the browser. The question between those two is mostly which one you already own, because migrating your proxy to gain AI DLP is rarely worth it on its own.
In both cases, write the policy before you buy the tool. Netskope reports that only about half of organisations have deployed DLP for genAI at all, while 90% block at least one genAI app. Blocking is easier than inspecting, and it pushes users toward the personal accounts that are hardest to see. The governance options across the main assistants are compared in the review of enterprise controls in ChatGPT, Claude and Gemini.
I would also price the breach side honestly. A prompt leak is rarely a single catastrophic event. It is a slow accumulation of regulated records in a vendor's retention store, which is why the ranking of AI vendor data retention terms belongs in the same decision as the DLP tool. The cost data on unsanctioned AI incidents is in the analysis of what shadow AI adds to a breach.
Frequently asked questions
What is DLP for AI prompts?
DLP for AI prompts is data loss prevention applied to the text and files employees send to generative AI tools. A policy inspects each prompt for sensitive data, such as card numbers, health records or source code, and then allows it, warns the user, or blocks it. It runs inside the AI service, in the browser, or in a network proxy that decrypts traffic.
Does Microsoft Purview DLP block sensitive data in Copilot prompts?
Yes, in preview. Purview's Copilot policy location can stop Microsoft 365 Copilot and Copilot Chat responding when a typed prompt contains a sensitive information type, and can block web searches for that prompt. It can also exclude labelled files from answers. Microsoft states it does not scan files uploaded directly into a prompt, so attachments are not covered by this control.
How many AI data policy violations does a typical company have?
Netskope's Cloud and Threat Report 2026 puts the average at 223 genAI data policy violations per organisation per month, rising to 2,100 in the top quartile. Both figures more than doubled in a year. They come from Netskope customer telemetry, so they count only what a deployed policy detected, and firms without prompt DLP will see fewer recorded incidents rather than fewer leaks.
Can Purview stop employees pasting data into personal ChatGPT accounts?
Partly. Purview inline protection in Edge for Business can inspect and block text and files sent to consumer ChatGPT and 18 other listed AI apps. It requires Intune-managed Windows 10 or 11 devices and is billed pay-as-you-go. Purview network data security extends this through Entra Global Secure Access or a partner SASE product, which reaches beyond the browser.
What is the difference between Netskope and Zscaler for genAI data protection?
Both decrypt web traffic inline and apply DLP to prompts. Netskope documents policy by activity, including prompts to embedded assistants such as Copilot in Word, with coaching notifications. Zscaler emphasises 100+ DLP dictionaries, browser isolation that disables paste and download, and separate rules for corporate and personal accounts. Neither publishes independent detection accuracy figures, so test both on your own data.
What types of data leak most often into AI tools?
Netskope reports that regulated data, meaning personal, financial and healthcare records, accounts for 54% of genAI data policy violations. Intellectual property, source code, and passwords and keys make up the other named categories. Regulated data is also the easiest to detect, because it follows fixed formats that pattern-based DLP recognises reliably, unlike code or internal strategy documents.
Where to start this week
Run your existing DLP rules in audit mode against one AI path before you write a single block rule. In Purview that means a Copilot location policy in simulation; with a proxy it means an Alert action on Post activity. A week of real detections will tell you which category dominates in your firm, and it may not be the 54% Netskope sees.
Then test the file path deliberately. Attach a dummy spreadsheet of fake card numbers to a prompt in each AI tool your staff use, and record which control catches it. If none does, you have found the gap this post is about, and you found it before a customer record did.
Related in this series
Prompt leakage is one half of the AI data problem. The other half is what an agent can be tricked into doing, covered in the breakdown of prompt injection in agent systems.
References
- Business in the News, GenAI data policy violations more than doubled in 2025, 6 January 2026. Used for 223, 2,100, 47%, 54%, prompt volumes and blocking figures from the Netskope Cloud and Threat Report 2026.
- Cyber Security Asia, Netskope Threat Labs: GenAI data policy violations surge in 2025, 8 January 2026. Used for the DLP deployment share, the 70,000-prompt top quartile and data categories.
- ITPro, Generative AI data violations more than doubled last year, 12 January 2026. Used to corroborate 223, 2,100 and 54%.
- Microsoft Learn, Microsoft Purview DLP for Microsoft 365 Copilot and Cowork, updated 5 October 2026. Used for Copilot prompt blocking, label exclusion and the file upload limitation.
- Microsoft Learn, Inline data protection in Edge for Business, updated 6 October 2026. Used for supported apps, device requirements and licensing.
- Microsoft Learn, Learn about network data security, updated 6 October 2026. Used for SASE integration, size limits, encoding caveats and licensing.
- Netskope documentation, Creating an AI Guardrails policy for real-time protection, undated, screenshots from late 2025. Used for activities, actions and coaching.
- Zscaler, Securing GenAI and Microsoft Copilot with Zscaler data security, 5 February 2025, with the Zscaler Secure Access to AI product page. Used for dictionaries, isolation, tenant policy and Copilot coverage.
Weakest point in the source base: every incident figure is Netskope's own customer telemetry, read through press coverage because the report body could not be opened, and every control claim is vendor documentation rather than independent testing.
Related reading