| SASE and SSE | Network access, connectivity and application-level policy | The prompt, the paste and the upload inside an encrypted session to a permitted site | Inspects the interaction in the page itself, before the request is sent |
|---|
| Proxy and SWG with TLS inspection | Routed web traffic, URL and category filtering | Requires a root certificate on every device and decrypts everything; still sees a request, not who typed what | No root certificate, no decryption, no rerouting. Enforcement runs inside the browser sandbox |
|---|
| CASB | Sanctioned SaaS through APIs: configuration, sharing and posture | Real-time text input into AI tools, and personal accounts that never touch the API | Acts on the prompt at submit, whichever account is signed in to the AI site |
|---|
| Endpoint DLP and EDR | Files, processes, devices and removable media | File-less actions: typed prompts and text pasted into a web form | Treats typed and pasted text as a first-class data flow, and scans files on the device before upload |
|---|