Classic DLP watches files and email gateways. LLM risk is different: free-text prompts, multi-turn memory and agent tool calls.
Gaps in classic DLP
- prompts are not files;
- users paste partial excerpts;
- agents can act (send, write, deploy);
- false confidence if only endpoints are locked.
What works better
Combine:
- prompt inspection / Vault masking;
- policy classes for actions;
- approved workspace UX so people stop bypassing controls;
- logs for investigations.
CTA: TrustAI Vault is built for LLM-era protection, not only legacy DLP labels.
FAQ
Is DLP enough for ChatGPT?
Endpoint DLP helps but rarely covers conversational prompts and agent actions. Add Vault masking and AI policy controls.