Last-mile AI data protection.
Why SASE, CASB and endpoint DLP miss the prompt, and what an interaction-layer control has to do instead.
Generative AI moved data exposure to the one place the security stack does not look.
Sensitive data now leaves organisations through a paste into a text box, inside an encrypted session, on a site that is already permitted. Network, cloud-access and endpoint controls are each right about what they see and blind to that moment.
This paper sets out why, and derives the requirements for an interaction-layer control: detection on the device, enforcement before submit, no decryption, and a record that holds decisions rather than content. It closes with the honest limits of the approach.
- The shift to file-less, last-mile data movement
- What each control layer sees, and what it misses
- Requirements for interaction-layer protection
- Detection on the device: checksums, context and a model
- Enforcement without interception
- Evidence without a second copy of the data
- Honest limits
Get the white paper
5 pages · PDF · Architecture · 2026
