Evidence over alarm
← The full AI security framework
AI SECURITY / 01 / EMPLOYEES

Employees.

Which AI tools are people using—and what are they sharing?

The AI people use
PICTURE IT THIS WAY

Give people an approved front door and a clear way to check who is on the other side.

AREA 01 / The AI people use

Make safe use easier.

Sensitive information can leave through an unapproved tool. A convincing message can trick someone into handing over access.

01

Know what is in use

Identify AI services, connected apps, the people using them, and the data they can access. Offer an approved route for common tasks.

02

Protect the moment of sharing

Warn or block sensitive transfers where policy requires it. Check app permissions and detect suspicious messages and account activity.

03

Verify consequential requests

Confirm payment, account-change, or sensitive-data requests through a separate trusted channel. Do not share passwords or sign-in codes. Give people a simple way to report concerns.

ASK TO SEE THE EVIDENCE

Show one sensitive-data test from warning to resolution, and list the apps and devices that are outside coverage.

WHO SHOULD OWN THIS?

Workplace IT + security + privacy

WHAT TO KEEP IN MIND

Discovery can miss personal accounts or unmanaged devices. Polished text alone does not prove AI involvement; blocking prompts cannot eliminate deception.

What are these technologies called?

Names you may encounter in a buying conversation. Products often span several areas.

AI usage discovery
Find which AI services and connected apps people use.
Data loss prevention
Detect or restrict sharing of specified sensitive information.
Email and messaging security
Identify suspicious messages and attempts to impersonate trusted people.
Identity protection
Detect suspicious account access and reduce account takeover risk.

Every area depends on clear ownership, policy, and evidence.

See the governance foundation