{"id":83124,"topic":"ai","source":"Spiceworks","title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","url_hash":"00e683e1ec99e0ba4e26b0f6596afa2e60d61ca5","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMiowFBVV95cUxOVElzbVpZcG82ME9Od3Q1SzdIckU4dFp4VXZpZnUtSlFOWm45WDBnT0M5a3RxVk5NbTJJc2xGSjR6LTBiRnNRS0RFLXZ1WV9TRTc3dnRUZWFRQ0lBN1NCNVlBd0J5ZUZmQ0pSam1PWjkxQ0lfNVpEN191NGQ0dWpmd2xaOVFhak1HVEJacUFjY2xWV0xKR00zSEItckdZd3JOaEcw?oc=5\" target=\"_blank\">How AI inference is creating a privacy problem your DLP tools can’t see</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">Spiceworks</font>","content":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary. A third person is sharing internal documents to see what the AI makes of them.\nNone of them think they’re doing anything wrong. And until recently, your data loss prevention tools (DLP) would have agreed, because the data never crossed a network boundary in a way those tools were built to detect.\nThat’s the problem. The privacy risk isn’t just about what data leaves your environment. It’s about what AI can do with data that never really “left” at all — and what it can piece together from fragments that look harmless on their own.\nREAD MORE: Your flat OT network was already a liability. AI just made it urgent\nAt the beginning of this month, the NSA, FBI, and the U.S. cybersecurity agency CISA issued a warning that Chinese AI firms are conducting extensive distillation campaigns to obtain proprietary data and features from the U.S.-developed frontier AI models.\nAI inference is being increasingly weaponized. Corporate competitors are using it to create inexpensive replicas that can mimic the original model’s logic, reasoning, and results.\nAdditionally, malicious actors are using it to obtain sensitive information like medical records, financial data, personally identifiable information (PII), and intellectual property from data that’s meant to be anonymized.\nGartner’s estimate puts a date on when this becomes your problem: by 2029, most privacy incidents will not stem from direct exposure of PII but from AI-generated inferences.\nBart Willemsen, VP Analyst at Gartner, warned in a web post that AI can reconstruct personal information without ever breaching traditional data controls. Privacy risks will occur not from how organizations store data or what data is exposed, but from what AI algorithms can infer about individuals. He added that organizations that see privacy as a data protection challenge will continue to be vulnerable to AI inference risks.\nIn other words: your data can be compliant on paper and exposed in practice.\nREAD MORE: The FCC router ban has Netgear and TP-Link at each other’s throats\nSimple, everyday interactions with artificial intelligence can quietly undermine organizational privacy, exploring the hidden mechanics behind AI inference risks and offering practical steps to safeguard enterprise data before standard controls fall short.\nWhat inference attacks actually do\nUnlike prompt injection attacks, where attackers bypass guardrails to hijack a model’s behavior, in inference-based attacks they probe the model’s memory until it inadvertently spits out sensitive data absorbed during training or through user prompts.\nA case in point is the incident reported by Politico in January, in which CISA’s then interim chief Madhu Gottumukkala allegedly uploaded classified contracting documents in a public instance of ChatGPT, despite an explicit ban by Department of Homeland Security (DHS) on the use of unapproved public GenAI tools for official government work.\nThree employees. Three prompts. Three categories of corporate data now sitting in someone else’s training pipeline.\nAI inference poses a significant risk for enterprises, as it can leak sensitive data and IP that can be harvested to carry out more sophisticated attacks.\nThe numbers behind the risk\nAs enterprises scale their gen AI usage, the risk of data leaks grows.\nAccording to security firm LayerX’s 2026 State of AI report, 48% employees have used AI for work extensively, while one out of 12 ChatGPT conversations included sensitive information. The report also shows that almost 75% of AI browser extensions were granted high or critical permission by employees.\nFurthermore, Palo Alto Networks’ 2025 State of Generative AI report shows that gen AI-related data loss incidents have doubled globally and now account for 14% of all data loss prevention incidents. One in seven DLP incidents, in other words, now traces back to someone typing something into a chat window.\nNeural Trust attributes the data leaks to structural flaws in how they are trained and deployed. The AI security company explains that models trained on high-signal datasets have a tendency to memorize examples and can regenerate them with the right prompt. Gen AI tools that share too much detail in an attempt to be helpful can accidentally expose private context, internal logic, and user data.\nFor enterprise, the implications stack up quickly. Leakage of source code or trade secrets can result in IP theft, while a single incident in highly regulated industries such as healthcare and finance can result in million dollar fines for violation of data privacy laws such as HIPAA and PCI DSS.\nWhy your DLP tools are looking the wrong way\nWhat separates inference risk from traditional data leaks is that it isn’t limited to a single file leaving a secure environment.\nCybersecurity firm Cyberhaven explains that it stems from Gen AI’s ability to synthesize context across prompts, documents, and sessions to generate output that is more sensitive than any single source that contributed to it. The challenge is that most DLP tools are designed for an era where sensitive data resides in easily identifiable files, structured databases, and predictable network flows. They can scan systems and tag sensitive data, track how users share or access data, and prevent restricted data from crossing a network boundary.\nWhat they can’t track is how data gets recombined by AI over multiple interactions.\n“AI workflows break all those assumptions. The inputs are fragments, and therefore the risk lives in what the model does with them,” Cyberhaven noted.\nHere’s what that looks like in practice: If an employee shares a department name, project code or vendor detail in a single prompt, it may not seem risky. However, an AI model can stitch together separate pieces of information over three sessions to deduce confidential information such as budget, headcount, and business strategy.\nNone of those individual prompts would trip an alert. The sensitive part never existed as a document.\nGartner’s Willemsen also warned that inference attacks are bad because they often evade detection by conventional security tools. “Individuals can be exposed through AI-generated conclusions rather than leaked records, creating privacy risks that undermine data integrity and are difficult to detect, explain and mitigate,” he said.\nCyberhaven’s 2026 AI Adoption and Risk report breaks down sensitive data shared with AI into three categories– research materials (10.7%), source code (8.3%), and HR data (6.2%). The report found that 39.7% of all human interactions with AI tools involve sensitive data.\nNearly four in 10 interactions with AI tools now involve sensitive data. Let that sit for a second.\nThis risk is further amplified by the widespread use of shadow AI tools. According to IBM’s 2026 Cost of Data Breach report, security incidents due to shadow AI more than doubled to 43% in 2026 from 20% last year.\nHow attackers are using this\nA 2026 study by Cloud Security Alliance found that online anonymity as we know it is breaking down because of AI. They found that AI agents can identify the individuals behind anonymous or pseudonymous online profiles with a 67% recall rate at 90% accuracy.\nWhat this means is that attackers with modest resources now have access to a mass-scale deanonymization tool at a moderate LLM API cost of one to four dollars per target.\nThe price of a cup of coffee to unmask someone who thought they were anonymous.\nThis challenges the fundamental privacy architectures that rely on anonymization and pseudonymization to protect PII. It means that all anonymized datasets and pseudonymous accounts should be presumed to be re-identifiable if attackers have access to modern LLMs.\nPII or company data harvested from AI models can be further used by attackers to carry out more targeted phishing campaigns, also known as spear phishing. Phishing was the top initial attack vector and accounted for the costliest breaches, according to IBM’s 2026 Cost of Data Breach report, AI generated phishing accounted for 17% of all malicious AI attacks.\nWhat to do about it\nThe good news is that this is solvable; it just requires thinking beyond the traditional perimeter.\nOn the technical side, Neural Trust recommends differential privacy techniques during training such as noise injection or gradient clipping to prevent memorization or reproduction of any particular data point. They can also implement output filtering to remove PII, code fragments, and reference from model outputs.\nPrompt context isolation can also help by blocking past chat history so it won’t leak in other sessions. Simulating inference attacks to extract training data can also help in identifying leaks before someone else finds them.\nEnterprises should implement AI acceptable use policies that restrict use to approved AI tools and include specific data-handling rules for employees. The company also recommends labeling sensitive data, real-time monitoring, and blocking sensitive data from flowing into AI tools. Employee awareness of AI data risks is also critical and can significantly mitigate the problem.\nNone of these are silver bullets. But together they shift the assumption from “our data is safe because it hasn’t leaked” to “our data is safe even when someone tries to infer what’s in it.”\nThat’s the standard now. The tools exist. The frameworks exist. What most organizations are missing is urgency – and with Gartner’s 2029 deadline on the horizon, there’s still time to build it.","image_url":"https://zd-brightspot.s3.us-east-1.amazonaws.com/wp-content/uploads/2026/09/15110148/AI-inference.jpg","lang":"en","published_at":"2026-09-15T19:00:03+00:00","fetched_at":"2026-09-15T19:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 9740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":9740,"summary_length":247,"usable_text_length":9740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":9740,"summary_length":247}},"news_item":{"id":83124,"canonical_url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","source_url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","source_name":"Spiceworks","author":null,"published_at":"2026-09-15T19:00:03+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMiowFBVV95cUxOVElzbVpZcG82ME9Od3Q1SzdIckU4dFp4VXZpZnUtSlFOWm45WDBnT0M5a3RxVk5NbTJJc2xGSjR6LTBiRnNRS0RFLXZ1WV9TRTc3dnRUZWFRQ0lBN1NCNVlBd0J5ZUZmQ0pSam1PWjkxQ0lfNVpEN191NGQ0dWpmd2xaOVFhak1HVEJacUFjY2xWV0xKR00zSEItckdZd3JOaEcw?oc=5\" target=\"_blank\">How AI inference is creating a privacy problem your DLP tools can’t see</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">Spiceworks</font>","full_text":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary. A third person is sharing internal documents to see what the AI makes of them.\nNone of them think they’re doing anything wrong. And until recently, your data loss prevention tools (DLP) would have agreed, because the data never crossed a network boundary in a way those tools were built to detect.\nThat’s the problem. The privacy risk isn’t just about what data leaves your environment. It’s about what AI can do with data that never really “left” at all — and what it can piece together from fragments that look harmless on their own.\nREAD MORE: Your flat OT network was already a liability. AI just made it urgent\nAt the beginning of this month, the NSA, FBI, and the U.S. cybersecurity agency CISA issued a warning that Chinese AI firms are conducting extensive distillation campaigns to obtain proprietary data and features from the U.S.-developed frontier AI models.\nAI inference is being increasingly weaponized. Corporate competitors are using it to create inexpensive replicas that can mimic the original model’s logic, reasoning, and results.\nAdditionally, malicious actors are using it to obtain sensitive information like medical records, financial data, personally identifiable information (PII), and intellectual property from data that’s meant to be anonymized.\nGartner’s estimate puts a date on when this becomes your problem: by 2029, most privacy incidents will not stem from direct exposure of PII but from AI-generated inferences.\nBart Willemsen, VP Analyst at Gartner, warned in a web post that AI can reconstruct personal information without ever breaching traditional data controls. Privacy risks will occur not from how organizations store data or what data is exposed, but from what AI algorithms can infer about individuals. He added that organizations that see privacy as a data protection challenge will continue to be vulnerable to AI inference risks.\nIn other words: your data can be compliant on paper and exposed in practice.\nREAD MORE: The FCC router ban has Netgear and TP-Link at each other’s throats\nSimple, everyday interactions with artificial intelligence can quietly undermine organizational privacy, exploring the hidden mechanics behind AI inference risks and offering practical steps to safeguard enterprise data before standard controls fall short.\nWhat inference attacks actually do\nUnlike prompt injection attacks, where attackers bypass guardrails to hijack a model’s behavior, in inference-based attacks they probe the model’s memory until it inadvertently spits out sensitive data absorbed during training or through user prompts.\nA case in point is the incident reported by Politico in January, in which CISA’s then interim chief Madhu Gottumukkala allegedly uploaded classified contracting documents in a public instance of ChatGPT, despite an explicit ban by Department of Homeland Security (DHS) on the use of unapproved public GenAI tools for official government work.\nThree employees. Three prompts. Three categories of corporate data now sitting in someone else’s training pipeline.\nAI inference poses a significant risk for enterprises, as it can leak sensitive data and IP that can be harvested to carry out more sophisticated attacks.\nThe numbers behind the risk\nAs enterprises scale their gen AI usage, the risk of data leaks grows.\nAccording to security firm LayerX’s 2026 State of AI report, 48% employees have used AI for work extensively, while one out of 12 ChatGPT conversations included sensitive information. The report also shows that almost 75% of AI browser extensions were granted high or critical permission by employees.\nFurthermore, Palo Alto Networks’ 2025 State of Generative AI report shows that gen AI-related data loss incidents have doubled globally and now account for 14% of all data loss prevention incidents. One in seven DLP incidents, in other words, now traces back to someone typing something into a chat window.\nNeural Trust attributes the data leaks to structural flaws in how they are trained and deployed. The AI security company explains that models trained on high-signal datasets have a tendency to memorize examples and can regenerate them with the right prompt. Gen AI tools that share too much detail in an attempt to be helpful can accidentally expose private context, internal logic, and user data.\nFor enterprise, the implications stack up quickly. Leakage of source code or trade secrets can result in IP theft, while a single incident in highly regulated industries such as healthcare and finance can result in million dollar fines for violation of data privacy laws such as HIPAA and PCI DSS.\nWhy your DLP tools are looking the wrong way\nWhat separates inference risk from traditional data leaks is that it isn’t limited to a single file leaving a secure environment.\nCybersecurity firm Cyberhaven explains that it stems from Gen AI’s ability to synthesize context across prompts, documents, and sessions to generate output that is more sensitive than any single source that contributed to it. The challenge is that most DLP tools are designed for an era where sensitive data resides in easily identifiable files, structured databases, and predictable network flows. They can scan systems and tag sensitive data, track how users share or access data, and prevent restricted data from crossing a network boundary.\nWhat they can’t track is how data gets recombined by AI over multiple interactions.\n“AI workflows break all those assumptions. The inputs are fragments, and therefore the risk lives in what the model does with them,” Cyberhaven noted.\nHere’s what that looks like in practice: If an employee shares a department name, project code or vendor detail in a single prompt, it may not seem risky. However, an AI model can stitch together separate pieces of information over three sessions to deduce confidential information such as budget, headcount, and business strategy.\nNone of those individual prompts would trip an alert. The sensitive part never existed as a document.\nGartner’s Willemsen also warned that inference attacks are bad because they often evade detection by conventional security tools. “Individuals can be exposed through AI-generated conclusions rather than leaked records, creating privacy risks that undermine data integrity and are difficult to detect, explain and mitigate,” he said.\nCyberhaven’s 2026 AI Adoption and Risk report breaks down sensitive data shared with AI into three categories– research materials (10.7%), source code (8.3%), and HR data (6.2%). The report found that 39.7% of all human interactions with AI tools involve sensitive data.\nNearly four in 10 interactions with AI tools now involve sensitive data. Let that sit for a second.\nThis risk is further amplified by the widespread use of shadow AI tools. According to IBM’s 2026 Cost of Data Breach report, security incidents due to shadow AI more than doubled to 43% in 2026 from 20% last year.\nHow attackers are using this\nA 2026 study by Cloud Security Alliance found that online anonymity as we know it is breaking down because of AI. They found that AI agents can identify the individuals behind anonymous or pseudonymous online profiles with a 67% recall rate at 90% accuracy.\nWhat this means is that attackers with modest resources now have access to a mass-scale deanonymization tool at a moderate LLM API cost of one to four dollars per target.\nThe price of a cup of coffee to unmask someone who thought they were anonymous.\nThis challenges the fundamental privacy architectures that rely on anonymization and pseudonymization to protect PII. It means that all anonymized datasets and pseudonymous accounts should be presumed to be re-identifiable if attackers have access to modern LLMs.\nPII or company data harvested from AI models can be further used by attackers to carry out more targeted phishing campaigns, also known as spear phishing. Phishing was the top initial attack vector and accounted for the costliest breaches, according to IBM’s 2026 Cost of Data Breach report, AI generated phishing accounted for 17% of all malicious AI attacks.\nWhat to do about it\nThe good news is that this is solvable; it just requires thinking beyond the traditional perimeter.\nOn the technical side, Neural Trust recommends differential privacy techniques during training such as noise injection or gradient clipping to prevent memorization or reproduction of any particular data point. They can also implement output filtering to remove PII, code fragments, and reference from model outputs.\nPrompt context isolation can also help by blocking past chat history so it won’t leak in other sessions. Simulating inference attacks to extract training data can also help in identifying leaks before someone else finds them.\nEnterprises should implement AI acceptable use policies that restrict use to approved AI tools and include specific data-handling rules for employees. The company also recommends labeling sensitive data, real-time monitoring, and blocking sensitive data from flowing into AI tools. Employee awareness of AI data risks is also critical and can significantly mitigate the problem.\nNone of these are silver bullets. But together they shift the assumption from “our data is safe because it hasn’t leaked” to “our data is safe even when someone tries to infer what’s in it.”\nThat’s the standard now. The tools exist. The frameworks exist. What most organizations are missing is urgency – and with Gartner’s 2029 deadline on the horizon, there’s still time to build it.","excerpt":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 9740 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 9740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":9740,"summary_length":247,"usable_text_length":9740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":9740,"summary_length":247}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","summary":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary.","source":"Spiceworks","date":"2026-09-15T19:00:03+00:00","content":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary. A third person is sharing internal documents to see what the AI makes of them.\nNone of them think they’re doing anything wrong. And until recently, your data loss prevention tools (DLP) would have agreed, because the data never crossed a network boundary in a way those tools were built to detect.\nThat’s the problem. The privacy risk isn’t just about what data leaves your environment. It’s about what AI can do with data that never really “left” at all — and what it can piece together from fragments that look harmless on their own.\nREAD MORE: Your flat OT network was already a liability. AI just made it urgent\nAt the beginning of this month, the NSA, FBI, and the U.S. cybersecurity agency CISA issued a warning that Chinese AI firms are conducting extensive distillation campaigns to obtain proprietary data and features from the U.S.-developed frontier AI models.\nAI inference is being increasingly weaponized. Corporate competitors are using it to create inexpensive replicas that can mimic the original model’s logic, reasoning, and results.\nAdditionally, malicious actors are using it to obtain sensitive information like medical records, financial data, personally identifiable information (PII), and intellectual property from data that’s meant to be anonymized.\nGartner’s estimate puts a date on when this becomes your problem: by 2029, most privacy incidents will not stem from direct exposure of PII but from AI-generated inferences.\nBart Willemsen, VP Analyst at Gartner, warned in a web post that AI can reconstruct personal information without ever breaching traditional data controls. Privacy risks will occur not from how organizations store data or what data is exposed, but from what AI algorithms can infer about individuals. He added that organizations that see privacy as a data protection challenge will continue to be vulnerable to AI inference risks.\nIn other words: your data can be compliant on paper and exposed in practice.\nREAD MORE: The FCC router ban has Netgear and TP-Link at each other’s throats\nSimple, everyday interactions with artificial intelligence can quietly undermine organizational privacy, exploring the hidden mechanics behind AI inference risks and offering practical steps to safeguard enterprise data before standard controls fall short.\nWhat inference attacks actually do\nUnlike prompt injection attacks, where attackers bypass guardrails to hijack a model’s behavior, in inference-based attacks they probe the model’s memory until it inadvertently spits out sensitive data absorbed during training or through user prompts.\nA case in point is the incident reported by Politico in January, in which CISA’s then interim chief Madhu Gottumukkala allegedly uploaded classified contracting documents in a public instance of ChatGPT, despite an explicit ban by Department of Homeland Security (DHS) on the use of unapproved public GenAI tools for official government work.\nThree employees. Three prompts. Three categories of corporate data now sitting in someone else’s training pipeline.\nAI inference poses a significant risk for enterprises, as it can leak sensitive data and IP that can be harvested to carry out more sophisticated attacks.\nThe numbers behind the risk\nAs enterprises scale their gen AI usage, the risk of data leaks grows.\nAccording to security firm LayerX’s 2026 State of AI report, 48% employees have used AI for work extensively, while one out of 12 ChatGPT conversations included sensitive information. The report also shows that almost 75% of AI browser extensions were granted high or critical permission by employees.\nFurthermore, Palo Alto Networks’ 2025 State of Generative AI report shows that gen AI-related data loss incidents have doubled globally and now account for 14% of all data loss prevention incidents. One in seven DLP incidents, in other words, now traces back to someone typing something into a chat window.\nNeural Trust attributes the data leaks to structural flaws in how they are trained and deployed. The AI security company explains that models trained on high-signal datasets have a tendency to memorize examples and can regenerate them with the right prompt. Gen AI tools that share too much detail in an attempt to be helpful can accidentally expose private context, internal logic, and user data.\nFor enterprise, the implications stack up quickly. Leakage of source code or trade secrets can result in IP theft, while a single incident in highly regulated industries such as healthcare and finance can result in million dollar fines for violation of data privacy laws such as HIPAA and PCI DSS.\nWhy your DLP tools are looking the wrong way\nWhat separates inference risk from traditional data leaks is that it isn’t limited to a single file leaving a secure environment.\nCybersecurity firm Cyberhaven explains that it stems from Gen AI’s ability to synthesize context across prompts, documents, and sessions to generate output that is more sensitive than any single source that contributed to it. The challenge is that most DLP tools are designed for an era where sensitive data resides in easily identifiable files, structured databases, and predictable network flows. They can scan systems and tag sensitive data, track how users share or access data, and prevent restricted data from crossing a network boundary.\nWhat they can’t track is how data gets recombined by AI over multiple interactions.\n“AI workflows break all those assumptions. The inputs are fragments, and therefore the risk lives in what the model does with them,” Cyberhaven noted.\nHere’s what that looks like in practice: If an employee shares a department name, project code or vendor detail in a single prompt, it may not seem risky. However, an AI model can stitch together separate pieces of information over three sessions to deduce confidential information such as budget, headcount, and business strategy.\nNone of those individual prompts would trip an alert. The sensitive part never existed as a document.\nGartner’s Willemsen also warned that inference attacks are bad because they often evade detection by conventional security tools. “Individuals can be exposed through AI-generated conclusions rather than leaked records, creating privacy risks that undermine data integrity and are difficult to detect, explain and mitigate,” he said.\nCyberhaven’s 2026 AI Adoption and Risk report breaks down sensitive data shared with AI into three categories– research materials (10.7%), source code (8.3%), and HR data (6.2%). The report found that 39.7% of all human interactions with AI tools involve sensitive data.\nNearly four in 10 interactions with AI tools now involve sensitive data. Let that sit for a second.\nThis risk is further amplified by the widespread use of shadow AI tools. According to IBM’s 2026 Cost of Data Breach report, security incidents due to shadow AI more than doubled to 43% in 2026 from 20% last year.\nHow attackers are using this\nA 2026 study by Cloud Security Alliance found that online anonymity as we know it is breaking down because of AI. They found that AI agents can identify the individuals behind anonymous or pseudonymous online profiles with a 67% recall rate at 90% accuracy.\nWhat this means is that attackers with modest resources now have access to a mass-scale deanonymization tool at a moderate LLM API cost of one to four dollars per target.\nThe price of a cup of coffee to unmask someone who thought they were anonymous.\nThis challenges the fundamental privacy architectures that rely on anonymization and pseudonymization to protect PII. It means that all anonymized datasets and pseudonymous accounts should be presumed to be re-identifiable if attackers have access to modern LLMs.\nPII or company data harvested from AI models can be further used by attackers to carry out more targeted phishing campaigns, also known as spear phishing. Phishing was the top initial attack vector and accounted for the costliest breaches, according to IBM’s 2026 Cost of Data Breach report, AI generated phishing accounted for 17% of all malicious AI attacks.\nWhat to do about it\nThe good news is that this is solvable; it just requires thinking beyond the traditional perimeter.\nOn the technical side, Neural Trust recommends differential privacy techniques during training such as noise injection or gradient clipping to prevent memorization or reproduction of any particular data point. They can also implement output filtering to remove PII, code fragments, and reference from model outputs.\nPrompt context isolation can also help by blocking past chat history so it won’t leak in other sessions. Simulating inference attacks to extract training data can also help in identifying leaks before someone else finds them.\nEnterprises should implement AI acceptable use policies that restrict use to approved AI tools and include specific data-handling rules for employees. The company also recommends labeling sensitive data, real-time monitoring, and blocking sensitive data from flowing into AI tools. Employee awareness of AI data risks is also critical and can significantly mitigate the problem.\nNone of these are silver bullets. But together they shift the assumption from “our data is safe because it hasn’t leaked” to “our data is safe even when someone tries to infer what’s in it.”\nThat’s the standard now. The tools exist. The frameworks exist. What most organizations are missing is urgency – and with Gartner’s 2029 deadline on the horizon, there’s still time to build it.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 9740 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 9740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":9740,"summary_length":247,"usable_text_length":9740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":9740,"summary_length":247}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/83124","export_markdown":"/api/items/83124/export?format=markdown","export_json":"/api/items/83124/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/"},"formats":{"full":{"id":83124,"title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","source":"Spiceworks","author":null,"published_at":"2026-09-15T19:00:03+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary.","full_text":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary. A third person is sharing internal documents to see what the AI makes of them.\nNone of them think they’re doing anything wrong. And until recently, your data loss prevention tools (DLP) would have agreed, because the data never crossed a network boundary in a way those tools were built to detect.\nThat’s the problem. The privacy risk isn’t just about what data leaves your environment. It’s about what AI can do with data that never really “left” at all — and what it can piece together from fragments that look harmless on their own.\nREAD MORE: Your flat OT network was already a liability. AI just made it urgent\nAt the beginning of this month, the NSA, FBI, and the U.S. cybersecurity agency CISA issued a warning that Chinese AI firms are conducting extensive distillation campaigns to obtain proprietary data and features from the U.S.-developed frontier AI models.\nAI inference is being increasingly weaponized. Corporate competitors are using it to create inexpensive replicas that can mimic the original model’s logic, reasoning, and results.\nAdditionally, malicious actors are using it to obtain sensitive information like medical records, financial data, personally identifiable information (PII), and intellectual property from data that’s meant to be anonymized.\nGartner’s estimate puts a date on when this becomes your problem: by 2029, most privacy incidents will not stem from direct exposure of PII but from AI-generated inferences.\nBart Willemsen, VP Analyst at Gartner, warned in a web post that AI can reconstruct personal information without ever breaching traditional data controls. Privacy risks will occur not from how organizations store data or what data is exposed, but from what AI algorithms can infer about individuals. He added that organizations that see privacy as a data protection challenge will continue to be vulnerable to AI inference risks.\nIn other words: your data can be compliant on paper and exposed in practice.\nREAD MORE: The FCC router ban has Netgear and TP-Link at each other’s throats\nSimple, everyday interactions with artificial intelligence can quietly undermine organizational privacy, exploring the hidden mechanics behind AI inference risks and offering practical steps to safeguard enterprise data before standard controls fall short.\nWhat inference attacks actually do\nUnlike prompt injection attacks, where attackers bypass guardrails to hijack a model’s behavior, in inference-based attacks they probe the model’s memory until it inadvertently spits out sensitive data absorbed during training or through user prompts.\nA case in point is the incident reported by Politico in January, in which CISA’s then interim chief Madhu Gottumukkala allegedly uploaded classified contracting documents in a public instance of ChatGPT, despite an explicit ban by Department of Homeland Security (DHS) on the use of unapproved public GenAI tools for official government work.\nThree employees. Three prompts. Three categories of corporate data now sitting in someone else’s training pipeline.\nAI inference poses a significant risk for enterprises, as it can leak sensitive data and IP that can be harvested to carry out more sophisticated attacks.\nThe numbers behind the risk\nAs enterprises scale their gen AI usage, the risk of data leaks grows.\nAccording to security firm LayerX’s 2026 State of AI report, 48% employees have used AI for work extensively, while one out of 12 ChatGPT conversations included sensitive information. The report also shows that almost 75% of AI browser extensions were granted high or critical permission by employees.\nFurthermore, Palo Alto Networks’ 2025 State of Generative AI report shows that gen AI-related data loss incidents have doubled globally and now account for 14% of all data loss prevention incidents. One in seven DLP incidents, in other words, now traces back to someone typing something into a chat window.\nNeural Trust attributes the data leaks to structural flaws in how they are trained and deployed. The AI security company explains that models trained on high-signal datasets have a tendency to memorize examples and can regenerate them with the right prompt. Gen AI tools that share too much detail in an attempt to be helpful can accidentally expose private context, internal logic, and user data.\nFor enterprise, the implications stack up quickly. Leakage of source code or trade secrets can result in IP theft, while a single incident in highly regulated industries such as healthcare and finance can result in million dollar fines for violation of data privacy laws such as HIPAA and PCI DSS.\nWhy your DLP tools are looking the wrong way\nWhat separates inference risk from traditional data leaks is that it isn’t limited to a single file leaving a secure environment.\nCybersecurity firm Cyberhaven explains that it stems from Gen AI’s ability to synthesize context across prompts, documents, and sessions to generate output that is more sensitive than any single source that contributed to it. The challenge is that most DLP tools are designed for an era where sensitive data resides in easily identifiable files, structured databases, and predictable network flows. They can scan systems and tag sensitive data, track how users share or access data, and prevent restricted data from crossing a network boundary.\nWhat they can’t track is how data gets recombined by AI over multiple interactions.\n“AI workflows break all those assumptions. The inputs are fragments, and therefore the risk lives in what the model does with them,” Cyberhaven noted.\nHere’s what that looks like in practice: If an employee shares a department name, project code or vendor detail in a single prompt, it may not seem risky. However, an AI model can stitch together separate pieces of information over three sessions to deduce confidential information such as budget, headcount, and business strategy.\nNone of those individual prompts would trip an alert. The sensitive part never existed as a document.\nGartner’s Willemsen also warned that inference attacks are bad because they often evade detection by conventional security tools. “Individuals can be exposed through AI-generated conclusions rather than leaked records, creating privacy risks that undermine data integrity and are difficult to detect, explain and mitigate,” he said.\nCyberhaven’s 2026 AI Adoption and Risk report breaks down sensitive data shared with AI into three categories– research materials (10.7%), source code (8.3%), and HR data (6.2%). The report found that 39.7% of all human interactions with AI tools involve sensitive data.\nNearly four in 10 interactions with AI tools now involve sensitive data. Let that sit for a second.\nThis risk is further amplified by the widespread use of shadow AI tools. According to IBM’s 2026 Cost of Data Breach report, security incidents due to shadow AI more than doubled to 43% in 2026 from 20% last year.\nHow attackers are using this\nA 2026 study by Cloud Security Alliance found that online anonymity as we know it is breaking down because of AI. They found that AI agents can identify the individuals behind anonymous or pseudonymous online profiles with a 67% recall rate at 90% accuracy.\nWhat this means is that attackers with modest resources now have access to a mass-scale deanonymization tool at a moderate LLM API cost of one to four dollars per target.\nThe price of a cup of coffee to unmask someone who thought they were anonymous.\nThis challenges the fundamental privacy architectures that rely on anonymization and pseudonymization to protect PII. It means that all anonymized datasets and pseudonymous accounts should be presumed to be re-identifiable if attackers have access to modern LLMs.\nPII or company data harvested from AI models can be further used by attackers to carry out more targeted phishing campaigns, also known as spear phishing. Phishing was the top initial attack vector and accounted for the costliest breaches, according to IBM’s 2026 Cost of Data Breach report, AI generated phishing accounted for 17% of all malicious AI attacks.\nWhat to do about it\nThe good news is that this is solvable; it just requires thinking beyond the traditional perimeter.\nOn the technical side, Neural Trust recommends differential privacy techniques during training such as noise injection or gradient clipping to prevent memorization or reproduction of any particular data point. They can also implement output filtering to remove PII, code fragments, and reference from model outputs.\nPrompt context isolation can also help by blocking past chat history so it won’t leak in other sessions. Simulating inference attacks to extract training data can also help in identifying leaks before someone else finds them.\nEnterprises should implement AI acceptable use policies that restrict use to approved AI tools and include specific data-handling rules for employees. The company also recommends labeling sensitive data, real-time monitoring, and blocking sensitive data from flowing into AI tools. Employee awareness of AI data risks is also critical and can significantly mitigate the problem.\nNone of these are silver bullets. But together they shift the assumption from “our data is safe because it hasn’t leaked” to “our data is safe even when someone tries to infer what’s in it.”\nThat’s the standard now. The tools exist. The frameworks exist. What most organizations are missing is urgency – and with Gartner’s 2029 deadline on the horizon, there’s still time to build it.","reading_time_min":8,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 9740 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 9740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":9740,"summary_length":247,"usable_text_length":9740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":9740,"summary_length":247}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 9740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":9740,"summary_length":247,"usable_text_length":9740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":9740,"summary_length":247}},"actions":{"read":"/item/83124","export_markdown":"/api/items/83124/export?format=markdown","export_json":"/api/items/83124/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/"}},"digest":{"id":83124,"title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","source":"Spiceworks","topic":"ai","published_at":"2026-09-15T19:00:03+00:00","excerpt":"How AI inference is creating a privacy problem your DLP tools can’t see Somewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary.","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 9740 characters.","reading_time_min":8,"cluster_id":null},"card":{"display_title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","subtitle":"Spiceworks · 2026-09-15","summary":"How AI inference is creating a privacy problem your DLP tools can’t see Somewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting…","badges":["quality:high"],"links":{"read":"/item/83124","original":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","diagnose":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/"},"quality_warning":null},"export":{"title":"How AI inference is creating a privacy problem your DLP tools can’t see - Spiceworks","url":"https://www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","summary":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary.","source":"Spiceworks","date":"2026-09-15T19:00:03+00:00","content":"How AI inference is creating a privacy problem your DLP tools can’t see\nSomewhere on your team right now, someone is pasting a chunk of source code into ChatGPT to debug an error. Someone else is dropping in meeting notes and asking for a summary. A third person is sharing internal documents to see what the AI makes of them.\nNone of them think they’re doing anything wrong. And until recently, your data loss prevention tools (DLP) would have agreed, because the data never crossed a network boundary in a way those tools were built to detect.\nThat’s the problem. The privacy risk isn’t just about what data leaves your environment. It’s about what AI can do with data that never really “left” at all — and what it can piece together from fragments that look harmless on their own.\nREAD MORE: Your flat OT network was already a liability. AI just made it urgent\nAt the beginning of this month, the NSA, FBI, and the U.S. cybersecurity agency CISA issued a warning that Chinese AI firms are conducting extensive distillation campaigns to obtain proprietary data and features from the U.S.-developed frontier AI models.\nAI inference is being increasingly weaponized. Corporate competitors are using it to create inexpensive replicas that can mimic the original model’s logic, reasoning, and results.\nAdditionally, malicious actors are using it to obtain sensitive information like medical records, financial data, personally identifiable information (PII), and intellectual property from data that’s meant to be anonymized.\nGartner’s estimate puts a date on when this becomes your problem: by 2029, most privacy incidents will not stem from direct exposure of PII but from AI-generated inferences.\nBart Willemsen, VP Analyst at Gartner, warned in a web post that AI can reconstruct personal information without ever breaching traditional data controls. Privacy risks will occur not from how organizations store data or what data is exposed, but from what AI algorithms can infer about individuals. He added that organizations that see privacy as a data protection challenge will continue to be vulnerable to AI inference risks.\nIn other words: your data can be compliant on paper and exposed in practice.\nREAD MORE: The FCC router ban has Netgear and TP-Link at each other’s throats\nSimple, everyday interactions with artificial intelligence can quietly undermine organizational privacy, exploring the hidden mechanics behind AI inference risks and offering practical steps to safeguard enterprise data before standard controls fall short.\nWhat inference attacks actually do\nUnlike prompt injection attacks, where attackers bypass guardrails to hijack a model’s behavior, in inference-based attacks they probe the model’s memory until it inadvertently spits out sensitive data absorbed during training or through user prompts.\nA case in point is the incident reported by Politico in January, in which CISA’s then interim chief Madhu Gottumukkala allegedly uploaded classified contracting documents in a public instance of ChatGPT, despite an explicit ban by Department of Homeland Security (DHS) on the use of unapproved public GenAI tools for official government work.\nThree employees. Three prompts. Three categories of corporate data now sitting in someone else’s training pipeline.\nAI inference poses a significant risk for enterprises, as it can leak sensitive data and IP that can be harvested to carry out more sophisticated attacks.\nThe numbers behind the risk\nAs enterprises scale their gen AI usage, the risk of data leaks grows.\nAccording to security firm LayerX’s 2026 State of AI report, 48% employees have used AI for work extensively, while one out of 12 ChatGPT conversations included sensitive information. The report also shows that almost 75% of AI browser extensions were granted high or critical permission by employees.\nFurthermore, Palo Alto Networks’ 2025 State of Generative AI report shows that gen AI-related data loss incidents have doubled globally and now account for 14% of all data loss prevention incidents. One in seven DLP incidents, in other words, now traces back to someone typing something into a chat window.\nNeural Trust attributes the data leaks to structural flaws in how they are trained and deployed. The AI security company explains that models trained on high-signal datasets have a tendency to memorize examples and can regenerate them with the right prompt. Gen AI tools that share too much detail in an attempt to be helpful can accidentally expose private context, internal logic, and user data.\nFor enterprise, the implications stack up quickly. Leakage of source code or trade secrets can result in IP theft, while a single incident in highly regulated industries such as healthcare and finance can result in million dollar fines for violation of data privacy laws such as HIPAA and PCI DSS.\nWhy your DLP tools are looking the wrong way\nWhat separates inference risk from traditional data leaks is that it isn’t limited to a single file leaving a secure environment.\nCybersecurity firm Cyberhaven explains that it stems from Gen AI’s ability to synthesize context across prompts, documents, and sessions to generate output that is more sensitive than any single source that contributed to it. The challenge is that most DLP tools are designed for an era where sensitive data resides in easily identifiable files, structured databases, and predictable network flows. They can scan systems and tag sensitive data, track how users share or access data, and prevent restricted data from crossing a network boundary.\nWhat they can’t track is how data gets recombined by AI over multiple interactions.\n“AI workflows break all those assumptions. The inputs are fragments, and therefore the risk lives in what the model does with them,” Cyberhaven noted.\nHere’s what that looks like in practice: If an employee shares a department name, project code or vendor detail in a single prompt, it may not seem risky. However, an AI model can stitch together separate pieces of information over three sessions to deduce confidential information such as budget, headcount, and business strategy.\nNone of those individual prompts would trip an alert. The sensitive part never existed as a document.\nGartner’s Willemsen also warned that inference attacks are bad because they often evade detection by conventional security tools. “Individuals can be exposed through AI-generated conclusions rather than leaked records, creating privacy risks that undermine data integrity and are difficult to detect, explain and mitigate,” he said.\nCyberhaven’s 2026 AI Adoption and Risk report breaks down sensitive data shared with AI into three categories– research materials (10.7%), source code (8.3%), and HR data (6.2%). The report found that 39.7% of all human interactions with AI tools involve sensitive data.\nNearly four in 10 interactions with AI tools now involve sensitive data. Let that sit for a second.\nThis risk is further amplified by the widespread use of shadow AI tools. According to IBM’s 2026 Cost of Data Breach report, security incidents due to shadow AI more than doubled to 43% in 2026 from 20% last year.\nHow attackers are using this\nA 2026 study by Cloud Security Alliance found that online anonymity as we know it is breaking down because of AI. They found that AI agents can identify the individuals behind anonymous or pseudonymous online profiles with a 67% recall rate at 90% accuracy.\nWhat this means is that attackers with modest resources now have access to a mass-scale deanonymization tool at a moderate LLM API cost of one to four dollars per target.\nThe price of a cup of coffee to unmask someone who thought they were anonymous.\nThis challenges the fundamental privacy architectures that rely on anonymization and pseudonymization to protect PII. It means that all anonymized datasets and pseudonymous accounts should be presumed to be re-identifiable if attackers have access to modern LLMs.\nPII or company data harvested from AI models can be further used by attackers to carry out more targeted phishing campaigns, also known as spear phishing. Phishing was the top initial attack vector and accounted for the costliest breaches, according to IBM’s 2026 Cost of Data Breach report, AI generated phishing accounted for 17% of all malicious AI attacks.\nWhat to do about it\nThe good news is that this is solvable; it just requires thinking beyond the traditional perimeter.\nOn the technical side, Neural Trust recommends differential privacy techniques during training such as noise injection or gradient clipping to prevent memorization or reproduction of any particular data point. They can also implement output filtering to remove PII, code fragments, and reference from model outputs.\nPrompt context isolation can also help by blocking past chat history so it won’t leak in other sessions. Simulating inference attacks to extract training data can also help in identifying leaks before someone else finds them.\nEnterprises should implement AI acceptable use policies that restrict use to approved AI tools and include specific data-handling rules for employees. The company also recommends labeling sensitive data, real-time monitoring, and blocking sensitive data from flowing into AI tools. Employee awareness of AI data risks is also critical and can significantly mitigate the problem.\nNone of these are silver bullets. But together they shift the assumption from “our data is safe because it hasn’t leaked” to “our data is safe even when someone tries to infer what’s in it.”\nThat’s the standard now. The tools exist. The frameworks exist. What most organizations are missing is urgency – and with Gartner’s 2029 deadline on the horizon, there’s still time to build it.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.spiceworks.com/ai/how-ai-inference-is-creating-a-privacy-problem-your-dlp-tools-cant-see/","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 9740 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 9740 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":9740,"summary_length":247,"usable_text_length":9740,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":9740,"summary_length":247}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}