Employees paste sensitive data into AI tools every day, and legacy DLP was not built to see it.
Customer records, source code, and internal docs move into public AI tools with a single copy-paste.
Pattern-matching engines miss prompts, agent tool calls, and multi-turn conversations where sensitive data actually leaks.
A single unsafe interaction can trigger regulatory reporting, contract violations, or competitive loss.
Each class is a separate control problem, not a severity tier.
Pasted into an assistant as a failing function or a config file, or read from the repository by an in-editor assistant.
Code has no pattern to fingerprint, so a pattern-matching engine has nothing to match against.
The live policy view approves source code into a sanctioned coding agent and blocks the same code everywhere else.
Records, health information and identifiers arrive inside a request rather than a file, pasted from a ticket or a claim.
Identifier matching is what legacy DLP does well, but a prompt box is not an attachment or a form post.
Detected in real time and judged against the destination, approved into an enterprise tenant and blocked into a personal one.
Roadmaps, contract drafts and board material go in for rewriting or summarising, which is the most rewarding use of these tools.
Nothing in the text declares itself confidential, there is no regulated identifier, and the material never carried a classification label.
Policy applies by data type and destination rather than pattern, and the attempt is recorded whether it is allowed or stopped.
An API key or connection string rides along inside the code, log line or error message being asked about.
Secrets scanning runs on repositories and pipelines, not on a browser chat request or an agent's tool call.
Secrets are a first class data type here, shown blocked to an unknown MCP server and written to the audit trail.
A dashboard screenshot, whiteboard photograph or scanned invoice is uploaded because describing it would take longer.
Text matching does not read pixels. Verizon's 2026 Data Breach Investigations Report, drawn from 858,440 data loss prevention events targeting generative AI tools, states, "the most common data submitted to external AI models was source code, by a large margin, followed by images and other types of structured data."
The same data type and destination policy applies, so the upload becomes an exposure record rather than an absence of one.
An agent reads from one system and writes into another in a tool call. Nobody types and no artefact crosses a boundary.
Legacy controls assume a person acting on an artefact. JFrog's 2026 Software Supply Chain Security State of the Union, surveying 1,508 IT professionals across 8 countries, found 18 percent of organisations have zero governance over their IDEs or MCP servers.
Agent tool calls sit at the same boundary, and an MCP server already appears as a destination in the live policy view.
AIBound sees exactly what data is going into every AI tool, applies policy in the moment, and gives you a complete audit trail of exposure attempts.
| Data Type | Destination | User | Action |
|---|---|---|---|
| PII (SSN) | ChatGPT personal | 184 events | Blocked |
| Source code | Cursor Agent | 67 events | Approved |
| Customer PHI | Perplexity | 12 events | Blocked |
| Financials | Claude Enterprise | 23 events | Approved |
| Secrets | Unknown MCP | 3 events | Blocked |
Legacy DLP inspects artefacts such as files, attachments and message bodies, and AI exposure happens somewhere else: inside prompts, across conversation turns, and in agent tool calls where no artefact crosses a monitored boundary. It also cannot separate the same data going to a sanctioned enterprise tenant from the same data going to a personal account, because the strings are identical and only the destination differs. Netskope found 50 percent of organisations lack enforceable data protection policies for generative AI applications at all.
Our legacy DLP had no idea what was going into ChatGPT. AIBound showed us in an afternoon, and stopped it the same day.
Get real-time, context-aware data protection at the AI boundary, with a full audit trail.