The AI Data Risk Dashboard allows you to move beyond monitoring alerts to actively governing how your organization interacts with AI technology.
You can use the dashboard to identify specific risks and take the following technical actions:
Block Copy and Paste: Configure Clipboard rules to prevent users from copying sensitive text into AI prompts.
Prevent File Uploads: Use Application File Access or Web Protection rules to stop the upload of classified files to public AI platforms such as ChatGPT or Gemini.
Apply Granular Tool Controls: Use the Top AI Usage Destinations widget to identify specific AI platforms. You can then apply targeted Block or Monitor actions to those specific URLs using the AI URLs [built-in] list.
Multi-Vector Protection: Apply rules across several protection vectors, including printer, removable storage, and screen capture.
Key benefits
Behavioral Control: Prevent specific high-risk actions, such as copying sensitive text into prompts or uploading classified files to AI platforms.
Optimize Policies: Use No Action Taken insights to identify misconfigured rules or deployment gaps.
Mitigate Shadow AI: Identify frequently accessed public AI platforms that are not approved by the security department.
Coach Users: Identify users who violate guidelines to initiate data privacy training.
Classify Data: Identify the types of classified sensitive information users share with AI platforms.
(Optional) Assign permissions to users
By default, the DLP Administrator has permission to view the AI Data Risk Dashboard. Follow these steps only if you want to allow other specific users to view incidents in the dashboard.
In ePO - On-prem, select Menu → User Management → Permission Sets.
Select Data Loss Prevention and click Edit.
Under Incident Management, navigate to Incident Access by Type and select Data Protection or Device Control.
Navigate to AI Data Risk Dashboard and enable the permission User can view the incident AI Data Risk Dashboard.
Configure rules to generate AI usage incidents
You must configure DLP rules using the built-in AI URLs definitions to generate the AI usage incidents data on the dashboard. To apply this definition, create or edit a rule for Application File Access Protection, Clipboard Protection, Printer Protection, Removable Storage Protection, Screen Capture Protection, or Web Protection and add the AI URLs [built-in] list to the rule conditions.
In ePO - On-prem, select Menu → DLP Policy Manager.
Navigate to your Rule Set and either create a new rule or edit an existing one from the following supported rule types.
In the Conditions tab, select the Web address (URL) property.
Set the operator to is one of (or) and select the AI URLs from the AI URLs [built-in] list.
Save and apply the policy.
When a rule is triggered, the built-in URL list is matched with the generated incident's destination property. Only matched destination URLs' incidents are aggregated and displayed on the dashboard. For more information, see Create a rule and Create a URL list definition.
Filter and drill through dashboard data
The dashboard features six pre-defined, dynamically interactive widgets that provide a synchronized view of your data risk insights. You can initiate filtering by clicking a bar or pie segment or by using the filters. When a filter is applied, all widgets automatically reset to provide unified results.
.png)
Option | Definition | |
|---|---|---|
Filters | Use the drop-down lists to select a single Destination, Classification, Actions Taken, Protection Vector, User group, or User. When a filter returns a result, all other widgets on the dashboard immediately reset to provide synchronized results. | |
Actions | Show filters in Incident List | Displays the filtered data in the Incident List tab to view endpoint details and additional information. |
Widget Name | Description |
|---|---|
Top AI Usage Destinations | Displays the top 10 AI platforms most frequently associated with sensitive data alerts. The lists are ordered by alert volume. |
Top Classifications | Displays the types of sensitive information the users are sharing with AI platforms based on your organization's defined classifications. Examples include PII or source code. |
Top Actions Taken | Displays the action taken when sensitive data is shared on any of the AI platforms. For example, Monitor, Blocked, or No Action Taken. |
Top Exfiltration Vectors | Displays which rules were triggered to help you to identify the channel used to share information. For example, a clipboard or a cloud storage rule. |
Top User Groups with Violations | Displays top 10 Active Directory groups with the highest volume of AI-related violations. |
Top Users with Violations | Displays the top 10 individual users with the highest volume of AI-related violations. |
Using the dashboard to refine security controls and mitigate exfiltration risks
DLP Administrators can use the AI Data Risk Dashboard to analyze real-time exfiltration trends and refine security controls without disrupting business workflows.
Use dashboard widgets to audit and test your security policies in real time. These widgets help you transition from reactive alerting to proactive risk mitigation. By identifying and closing protection gaps, you can quarantine threats and maintain regulatory compliance.
As a DLP Administrator, we recommend that you use the following widgets to identify gaps in protection and optimize rule sets:
Top Exfiltration Vector: This is the primary widget for technical audit. It allows you to see which channels like Clipboard, Web, or Removable Storage are being utilized to move data to AI platforms, ensuring that all exfiltration paths are covered by active policies.
Top User Groups: By identifying which Active Directory groups are most active on AI sites, you can create more granular, department-specific policies. For example, allowing the Marketing group access to specific AI tools while blocking Engineering from sharing source code via unsanctioned AI engines.
Top Actions Taken: You can check that Block rules are triggering correctly for sensitive content classifications and the Monitor rules are not creating excessive workload for the Security Analyst.
Top AI Usage Destinations: This widget is essential for integration and tool orchestration. It reveals new, potentially unsanctioned AI tools being used by employees, allowing you to proactively update the AI URLs built-in list in the DLP Policy Manager.
After reviewing the insights from the AI Data Risk Dashboard, you can take the following proactive steps for effective policy enforcement.
Establish a Performance Baseline: Review the Top Exfiltration Vectors and Top Actions Taken widgets. This creates a high-level baseline of current policy enforcement across AI traffic, identifying which channels are most active. For example, clipboard protection rule or cloud protection rule.
Identify Protection Gaps: Monitor the Top Actions Taken widget, the administrator identifies potential vulnerabilities, such as a high volume of "No Action Taken" events originating from the Clipboard Protection vector. This data points to a specific gap where sensitive information is being moved to AI platforms without rules enforcement.
Execute Technical Policy Translation: To close identified gaps, navigate to the DLP Policy Manager to refine existing rules. They leverage insights from the Top User Groups with Violations widget to apply targeted, stricter controls to high-risk departments ensuring robust protection while maintaining user efficiency for the rest of the organization.
Maintain Operational Intelligence: Regularly monitor the Top AI Usage Destinations widget to ensure the built-in URL list remains comprehensive. If the dashboard reveals a popular, unsanctioned AI tool, you can update the AI URLs [built-in] definition to align with the organization’s operational expectations and security posture.