Your ChatGPT Policy Doesn't See Claude, Copilot or Bedrock
0 min read

Lionel Menchaca
Your security team knows ChatGPT is in your environment. You don't know which employees are using it, what data they're submitting, what responses they're getting back, or whether sensitive information is leaving your organization through an AI prompt. Neither does your DLP tool. Neither does your proxy. And that's not just a ChatGPT problem anymore.
Employees are using Claude, Microsoft 365 Copilot, AWS Bedrock and a dozen other AI tools. They're uploading files. Pasting credentials into prompts under deadline pressure. Asking ChatGPT to analyze contracts. Connecting personal AI accounts from corporate devices. The AI adoption that's accelerating productivity is also accelerating data risk, and your security controls were never built to see any of it.
This is the prompt inspection gap. It's bigger than ChatGPT security. It's about whether your organization has any visibility into what's moving through AI.
What Actually Moves Through an AI Interaction
Most enterprise security conversations about AI focus on what employees type into a prompt. That's where the conversation ends. But that's where the risk begins.
A prompt isn't just text. It's:
- Source code an engineer pastes from a repository to debug a problem
- A customer spreadsheet an analyst uploads to ask ChatGPT to forecast revenue
- PII that an HR manager copies from a personnel record to ask for guidance on a policy question
- Credentials an operations team member types in to ask for help with a troubleshooting workflow
- A contract fragment a legal team member pastes to get a second opinion on language
What comes back is equally risky. A ChatGPT response might include sensitive information from your data that the model was trained on. An AI-generated summary might inadvertently recreate PII by pattern matching. An extracted data field from a file upload returns more than the requester asked for.
What moves in a file upload is what your endpoint DLP can't see. Your web proxy can't inspect file contents moving through a SaaS API. Your CASB logs the app access but not the data inside the attachment. For the first time, employees are uploading entire files—earnings models, customer lists, configuration details—and your visibility just stops there.
The result: data is leaving your organization in plain sight, and you have no audit trail proving you saw it or tried to stop it.
The Multi-Tool Problem Is Bigger Than ChatGPT Governance
When your security team drafted ChatGPT policy in 2023, ChatGPT was the problem. In 2026, it's one problem among many. Your environment now includes:
- Sanctioned AI tools (ChatGPT Enterprise, Microsoft 365 Copilot, Claude for Enterprise)
- Shadow AI tools (ChatGPT Free, personal Claude accounts, unauthorized tools employees found)
- API-based AI (AWS Bedrock, company-built agents, AI integrations into business applications)
- Embedded AI (AI features built into Slack, Salesforce, Microsoft 365 without separate adoption friction)
- Agent-based AI (autonomous workflows accessing your most sensitive business systems)
ChatGPT security policy doesn't govern any of that. A sanctioned ChatGPT Enterprise contract doesn't prevent an employee from using personal Claude on the same laptop. A SWG block on ChatGPT.com doesn't block the Copilot feature built into Microsoft 365 that already has corporate credentials. An endpoint DLP rule built for text prompts doesn't inspect API calls from autonomous agents to your Salesforce instance.
The binding problem isn't ChatGPT security. It's visibility into what data moves through every AI interaction, regardless of which tool, which account tier or which user is involved. That requires controls at every AI layer.
Real-Time Inspection Across Every AI Channel
Inspection means seeing what's in the prompt before the user submits it. It means knowing what came back in the response before the user acts on it. It means understanding what data left your organization in a file upload.
Real-time means at the moment the action happens, not in logs you query hours later. It means the ability to block, redact, warn or quarantine before data leaves your control.
Across every AI channel means ChatGPT prompts and Claude conversations, Copilot interactions and custom agents calling your business systems, personal AI accounts and sanctioned deployments, file uploads and text input, responses that come back and data that flows between systems.
This requires three capabilities traditional tools weren't built for:
- Prompt-level inspection that understands what's being typed or uploaded into an AI tool before submission, not after
- Response inspection that catches sensitive data in what the AI returns to the user
- Identity attribution that traces every action to the human user or agent that triggered it, even when that agent is autonomous and acting without approval
When those three capabilities work together, your security team moves from a reactive position—discovering breaches after sensitive data went through a channel you couldn't see—to a preventive one—stopping the submission before it happens.
Enforcement That Matches the Risk
Not every policy violation deserves the same response. An employee who accidentally pastes a contract into a ChatGPT prompt needs guidance, not termination. An employee who systematically routes customer records through personal AI accounts needs escalation.
Inline enforcement makes this possible at the moment of action. When your DLP detects a policy violation in a prompt:
- Audit mode logs the event for review later
- Warn mode alerts the user and asks them to confirm they want to continue
- Restrict mode prevents submission unless the user confirms and is logged for audit
- Block mode stops the submission entirely
- Redact mode removes the sensitive data before submission
The same policy logic that governs email and endpoint now governs AI. You don't rebuild your taxonomy. You don't create separate policies for AI. The classification system already protecting data in your email archive now protects data in ChatGPT prompts. The DLP rules already enforced on your web proxy now apply to Claude conversations.
This is possible only when inspection happens at the point where AI touches your data, not at the proxy layer where you're blind to what's inside encrypted API calls or cloud-resident agent-to-SaaS traffic that never touches the corporate network.
Beyond Prompts: Agents and Autonomous AI
The conversation around ChatGPT security assumes a human at the keyboard. Autonomous agents challenge that model.
Your organization is now deploying AI agents on platforms like AWS Bedrock. These agents query Salesforce for customer records. They pull financial data from Microsoft 365. They read tickets from your ticketing system. They aggregate data across systems, process it and sometimes transmit it to new locations. They do this without a human prompt. They operate outside the network perimeter and the endpoint. They authenticate directly to business applications using service account credentials that no DLP rule was built to inspect.
When an agent acting on behalf of an employee queries Salesforce and pulls a customer record, is that data access human-initiated or agent-initiated? When the agent transmits that data to another system, is it exfiltration or approved workflow? When an autonomous agent running on AWS Bedrock accesses your most sensitive systems, does your audit trail show what it did?
Traditional DLP was built for human-speed data access and email attachment patterns. It was not built for agent-scale data aggregation happening in real time across cloud-resident systems with no human in the loop.
Covering agent risk means extending inspection to agent-to-SaaS traffic, attributing each agent action to the user who deployed it and the system it accessed, and maintaining an audit trail sufficient for incident investigation and regulatory proof. It means knowing not just that data left, but which agent took it, when, and whether a human ever approved that access.
How Forcepoint Closes the Prompt Inspection Gap
Forcepoint AI Data Security closes the prompt inspection gap with a single platform that combines discovery, classification and real-time enforcement across every AI channel.
The foundation is data visibility. Forcepoint discovers and classifies sensitive information across cloud, SaaS and on-premises environments before AI reaches it, answering the foundational question: which of your most sensitive data can AI actually access, and through which paths? This upstream classification work is what makes downstream enforcement accurate.
Real-time enforcement happens where it matters: at the moment an employee or agent tries to move data through an AI interaction. Forcepoint sees prompts and uploads before submission, catches sensitive data in responses, and maintains an audit trail for compliance and investigation. It does this across ChatGPT, Claude, Copilot, AWS Bedrock and other tools—without requiring you to rebuild your existing DLP rules. Your policy taxonomy stays the same. The same classifications governing email and endpoint now govern every AI channel.
The result is adaptive control. As risk signals accumulate, enforcement tightens automatically. As activity normalizes, friction decreases. That adaptive posture is how organizations keep pace with AI adoption accelerating faster than static policy can track.
See how Forcepoint secures data in ChatGPT and how prompt security works in practice.
The Visibility-Control Gap Is Your Biggest AI Risk
What started as a ChatGPT security conversation is now broader. The real question: can your security program see what's actually moving through your organization's fastest-growing data channel? And can it act on that visibility before data leaves your control?
Understanding AI security fundamentals means recognizing this visibility-control gap is where breaches happen. Close it.
Your path forward: get visibility into what data enters and leaves your AI tools. Then enforce policy at the point where AI touches your data. That's how you close the gap.

Lionel Menchaca
Read more articles by Lionel MenchacaLionel Menchaca has covered data security at Forcepoint since 2020, writing about DLP, DSPM, insider risk and AI security for security and IT leaders. He works with Forcepoint X-Labs threat researchers to turn their findings on emerging threats, from AI-targeted supply chain attacks to prompt injection, into practical guidance, and he leads the company's editorial strategy across the blog and the X-Labs newsletter. Before Forcepoint, Lionel founded and ran Dell's corporate blog for seven years and spent two decades helping enterprise tech companies explain security, cloud and AI.
- The Enterprise Guide to AI Data Security
In the Article
The Enterprise Guide to AI Data SecurityRead the eBook
X-Labs
Get insight, analysis & news straight to your inbox

To the Point
Cybersecurity
A Podcast covering latest trends and topics in the world of cybersecurity
Listen Now