Skip to main content

Aug 14, 2026

The Data That Left in a Prompt

The fastest way sensitive data leaves your company now is an employee pasting it into a chatbot to get their job done

Every day, employees paste source code, customer lists, and unreleased financials into public AI tools to work faster. The moment they hit enter, that data has left the company, often into a model that may train on it. No policy debate required for it to be gone.

There is no breach, no attacker, no exfiltration in the usual sense. A well-meaning employee moves sensitive data into a system you do not control, and the loss does not look like an incident. It looks like productivity. DLP tuned for email attachments and USB drives rarely sees the paste into a browser tab.

Exfiltration That Feels Like Help

The person is not trying to leak anything. They are trying to finish a report. That is what makes it hard to catch: there is no malice to detect, and the action blends into an ordinary workday.

Baseline What Leaves and Where

PeopleBase profiles where each identity normally sends data, so sensitive content moving toward a destination the person's role never touches surfaces even when the intent is harmless. The employee wanted an answer; the company data did not need to be the price of it.

The next serious data loss may not be stolen. It may be pasted.

See the latest from Abnormal's product and engineering teams.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.