
The crux of the problem: an external LLM is a new channel for data leaks
The scale of the phenomenon is well documented by the security vendors themselves. In its reports, Netskope indicates that a significant portion of corporate use of generative AI occurs through employees’ personal accounts (so-called “shadow IT”), and the number of genAI applications in use runs into the thousands. Zscaler, in its analysis of customer traffic, reports a very high number of DLP policy violations generated annually by traffic to popular chatbots. One case that caused quite a stir involved an employee who uploaded internal source code to a public chatbot—it demonstrated that a single, seemingly innocent action can lead to intellectual property leaving the organization without the possibility of recovery.
The market responds to this phenomenon in four different ways. Below, we describe each of them separately, add a fifth, integrative perspective—the ISCG approach—and finally summarize everything in a single table.
Zscaler – an inline secure web gateway tailored for the AI era
Best for: organizations that want a single, robust point of inline inspection for all internet traffic (including AI) and strict DLP at the prompt level.
Zscaler approaches the problem from the perspective of network traffic. All user traffic—including queries to external LLMs—passes through the Zero Trust Exchange cloud, where, thanks to inline SSL decryption, the platform reads the content of prompts and retrieved responses. Based on this, three layers of control are in place:
- Monitoring of AI applications (sanctioned vs. unsanctioned). The platform identifies and categorizes AI applications within an organization—from chatbots and coding assistants to browser extensions and AI features built into SaaS. This makes it possible to detect shadow AI and decide what is allowed and what is blocked.
- DLP at the prompt level. Inline DLP policies block or redact prompts containing sensitive data (PII, financial data, source code, regulated data) before they leave the organization. A „allow but restrict” approach is also possible—allowing the prompts themselves while blocking bulk data uploads.
- Browser Isolation. What Sets Zscaler Apart: The AI application runs in an isolated session where users can enter prompts, but clipboard access, uploads, and downloads are restricted—which prevents large-scale data exfiltration.
Strengths: The largest inline inspection cloud, browser isolation as a hard barrier against data exfiltration, and full visibility through SSL decryption. Additionally, Zscaler offers query capture (Incident Receiver—forwarding every POST request to the chatbot to an incident management system or an auditor’s inbox) and user coaching via the Workflow Automation module.
What to look for: Effectiveness depends on decrypting all traffic using SSL, yet some organizations still block a significant percentage of AI transactions by default, thereby missing out on the real benefits of using them.
Netskope – CASB/SSE with semantic DLP and user coaching
Best for: organizations that want to clearly distinguish between business and personal accounts, understand the intent behind the text in a prompt, and teach users safe habits, rather than simply blocking them.
Netskope builds on the CASB tradition and emphasizes context. The Netskope One platform combines AI-powered visibility with granular DLP and several unique features:
- Application Risk Index (Cloud Confidence Index). Hundreds of genAI applications and tens of thousands of SaaS applications are assessed for risk: whether they use customer data to train models, whether they share data with third parties, and whether they meet compliance requirements. This forms the basis for making informed decisions about security policies.
- Semantic DLP instead of pattern matching alone. Netskope explicitly points out that traditional rule-based DLP fails when AI rewrites or transforms content while preserving its meaning. That’s why the platform evaluates the intent and context of the data, not just its format—the AI Guardrails component verifies every prompt and response in real time.
- Instance awareness. The platform distinguishes between corporate and personal instances of the application and applies different policies to each—for example, full access to a corporate account while restricting access to a personal account on the same service.
- Real-time user coaching. Netskope’s signature mechanism: Instead of being blocked, the user sees a message and is directed to an approved corporate AI tool. This is complemented by user and entity behavior analytics (UEBA) and sensitive data protection management (DSPM).
Strengths: semantic, context-aware DLP; distinguishing between personal and corporate instances; coaching as an alternative to blocking; a comprehensive catalog of data classifiers.
What to look for: The solution requires inline implementation and traffic inspection, and the „coaching instead of blocking” approach requires a certain level of process maturity within the organization.
Microsoft Entra – Identity and Access Management with the Global Secure Access module
Best for: organizations that are deeply embedded in the Microsoft 365 ecosystem and want to manage AI using the same identity policies as the rest of their resources.
It's important to be precise here: Entra itself is not a DLP tool. This is an identity and access layer that controls external LLMs through the Global Secure Access / Microsoft Entra Internet Access module (i.e., Microsoft’s own SSE) and Conditional Access. Key mechanisms:
- Web content filtering based on traffic to AI. Entra Internet Access functions as a web gateway: it allows you to block or allow specific AI websites (ChatGPT, Gemini, DeepSeek, etc.) for selected groups—for example, to block access for the finance department while allowing it for the engineering department.
- Conditional Access as the glue. Web filtering rules are enforced through conditional access policies that take into account the user, the device (Entra-joined or hybrid-joined), the risk level, and the session context.
- Prompt Injection Protection (Prompt Shield). At the network layer, Entra verifies text prompts and blocks prompt injection and jailbreak attempts before they reach the model. This mechanism extends Azure AI Prompt Shields to the network layer and is preconfigured for popular LLMs (ChatGPT, Claude, Cohere, DeepSeek, Gemini, Grok, Meta AI, Mistral, Perplexity, Pi, Qwen); and it can also be extended to custom APIs.
- File Scan with Purview classification. File scanning rules, integrated with Microsoft Purview classification, detect and block the sending of sensitive content in files to AI applications.
- Just-in-time access via Access Packages. Instead of a permanent lockout—a default AI lockout and a temporary, self-service access window (e.g., two hours), approved by a supervisor within Entra Identity Governance.
Strengths: Native integration with M365 and identity management, a single policy framework for AI and other resources, just-in-time (JIT) access, and logs in Sentinel.
What to look for: These are directly based on Microsoft's documentation. Web content filtering does not apply to Copilot Chat—Microsoft officially advises against and does not support managing it via network blocks, as it is deeply integrated with Microsoft 365 applications (it is controlled by Conditional Access, not a network filter). TLS inspection does not work for QUIC traffic, which is used by most AI websites—this requires disabling QUIC on the client side (e.g., via GPO or browser policy). Prompt Shield supports only text prompts, not files. Logging into AI via a private account (e.g., „Continue with Google”) can, in practice, bypass some Conditional Access policies. Full DLP for prompt content and data posture analysis fall under Microsoft Purview, while Defender for Cloud Apps additionally supports advanced shadow AI detection—Entra is just one important piece of a larger puzzle here. Putting all these components together under Microsoft licenses isn’t cheap, though it’s usually less expensive than building a comparable solution on Zscaler or Netskope.
SentinelOne Prompt Security – AI-native runtime security for applications and agents
Best for: organizations that want to protect not only traffic to chatbots, but also AI agents, coding assistants, and their own LLM applications, using agent-based implementation and browser extensions rather than relying solely on network proxies.
This solution works slightly differently than Zscaler’s Zero Trust Exchange or Netskope One, where all traffic passes through the vendor’s node. With Prompt Security, some of the data entered by the user is sent to an LLM system managed and maintained by SentinelOne. For organizations with a large budget, an on-premises option is also available—though in this case, you’ll need to factor in the cost of dedicated hardware, which can run into the millions of zlotys or more. By comparison, in the ISCG approach, LLM models are managed by the customer—either in the Azure cloud or, similar to SentinelOne’s on-premises option, on the customer’s own infrastructure.
Prompt Security is a company being acquired by SentinelOne—the transaction was announced in August 2025. (estimated value of approximately $250 million), and the deal closed in September 2025. The product is being integrated into the Singularity platform. Unlike the three previous approaches, its starting point is not the network or identity, but the runtime layer of the interaction with the AI itself—the moment when the prompt is sent and the response (or the agent’s action) is returned. Key mechanisms:
- Discovery Shadow AI operates wherever the user works. The lightweight agent and browser extensions automatically detect both approved genAI applications and shadow AI—in browsers, desktop IDEs, terminal assistants, APIs, and custom applications. Coverage of developer tools (e.g., Cursor) is what sets it apart from purely web-based solutions.
- Real-time policy checks. Enforces safe usage, blocks high-risk prompts, and prevents data leaks on the fly, with the manufacturer’s claimed detection time of less than 200 ms for prompt injection, jailbreaks, and exfiltration.
- Semantic DLP for prompts. Detecting and redacting personal, medical, and financial data, as well as source code, before it is sent to an external AI tool.
- Protection against attacks on AI. Prompt injection, model response manipulation, and model abuse are treated as separate attack vectors.
- Model-agnostic and agent security. Support for major LLM providers (OpenAI, Anthropic, Google) and self-hosted/on-prem models (the vendor claims support for over 250 models), as well as securing the MCP gateway between AI applications and agents.
- Flexible implementation. SaaS, on-premises, or a browser extension distributed via Intune/MDM; we recommend starting in monitor-only mode to first map the shadow AI. Its multi-tenant architecture makes the solution a good candidate for delivery as a managed service (MSSP).
Strengths: runtime and AI agent protection, MCP gateway, coverage of development tools (IDE, terminal, code assistants), rapid deployment via a browser extension, model-agnostic approach.
What to look for: This is a newly integrated solution—it’s worth assessing how well it integrates with the rest of the Singularity platform and validating it in a PoC. The browser extension requires deployment and maintenance on endpoints, and its full value is only realized when combined with the endpoint and cloud components of SentinelOne. It’s also worth considering the entry threshold in the form of the minimum project size required by the vendor (it’s best to verify commercial details directly with the vendor, as they may change).
The ISCG Approach – Integrator with AI Proxy
Best for: organizations that want to start using public AI models securely as quickly as possible and without any roadblocks, while having a single point of contact for selecting and implementing the right layer.
ISCG AI Proxy isn’t just another product that forwards data to yet another external node; it’s a solution that combines a process-oriented approach with ISCG’s expertise in securely managing the Microsoft 365 environment —ensuring that AI does not introduce new risks related to data and access. A key feature here is the sequence of actions: first, measures that deliver quick results, followed by more advanced controls. In practice, ISCG organizes protection against the misuse of external LLMs into three layers:
- AI Proxy – a secure gateway to public models (the core of the solution). A layer that acts as an intermediary between the user and the public model. The public model runs in the customer’s own Azure environment, and the system filters queries, restricts the transmission of sensitive data, and—most importantly—anonymizes the data before sending the query. Queries are routed from the proxy exclusively to models defined in the configuration, and data is not passed on to subsequent external LLMs. This is complemented by security rules tailored to the organization’s policies, as well as monitoring of logins and AI usage. The gateway does not blindly block anything—it allows employees to continue working with the models of their choice, without the risk of sensitive information leaving the company.
- AI Governance – Principles and Control of Shadow AI. The policy layer defines who can use AI, in which tools and on what data, what the exceptions are, the roles and responsibilities (business / IT / security / compliance), and the procedures for approving new use cases and responding to incidents.
- AI Hub – isolated environments for the most sensitive data. An isolated AI environment (on-premises or in a private cloud) for data that cannot be stored in the public cloud. Full control over the data and reduced risk of it leaving the organization’s infrastructure.
As an integrator, ISCG builds these layers on its own lightweight gateway, which is based on open-source solutions and—for security—containerized. After implementation, the customer bears only the costs of using Azure and optional ISCG support services, which include updating models, adding rules, and including or excluding internal data.
Strengths: the fastest, non-blocking startup; a model-agnostic approach (operating on selected LLMs, including running two models in parallel to compare results); a single partner responsible for selection, implementation, and maintenance; the ability to scale from the gateway, through governance, to isolated environments; based on a well-organized M365 environment (DLP/Purview, structured permissions).
What to look for: This is a custom-designed (bespoke) solution, so the scope of inspection depends on the scope of implementation. For very large-scale deployments, or when hard inline inspection of all traffic or browser isolation is required, it is worth considering integrating the gateway with a dedicated SSE platform or runtime—which ISCG can also integrate.
Are you wondering which tier is right for your organization?
Tool Comparison: CTIM vs. ShareGate vs. BitTitan vs. Quest
Below is a summary of the key differences in the area of identity migration. The features of these tools are constantly evolving, so it’s always a good idea to check the manufacturer’s documentation for the current scope.
| Dimension | Zscaler | Netskope | Microsoft Entra (+ Purview) | SentinelOne Prompt Security | ISCG (AI Gateway) |
|---|---|---|---|---|---|
| Category | SSE / Secure Web Gateway | SSE / CASB | Identity + SSE (Global Secure Access) | AI-native runtime security | Integrator + intermediary layer (Gateway/Governance/Hub) |
| Checkpoint | Network traffic (inline) | Network Traffic + SaaS (inline) | Identity, Access, and Traffic | AI Interaction Runtime Layer | A gateway that acts as an intermediary between the user and the model in Azure |
| Discovery Shadow AI |
Yes Categorization of AI Applications |
Yes Risk Index (CCI) |
Yes Internet Access / Defender for Cloud Apps |
Yes Client/browser, as well as IDE/terminal/API |
Yes As part of AI Governance |
| A Philosophy on Blocking | A possible approach: „allow, but restrict" | Coaching Instead of a Mental Block | Block/Allow + JIT | Real-Time Policies | It doesn't block—it filters and anonymizes |
| DLP at the prompt level |
Yes Inline |
Yes Semantic | Partially (File Scan); full DLP in Purview |
Yes Semantic, with data editing |
Yes Filtering and anonymization before sending |
| Protection Against Prompt Injection | Indirectly (content review) |
Yes AI Guardrails |
Yes Prompt Shield (text only) |
Yes Core of the product | Rules Based on Policies (Depending on the Project) |
| Agent Safety / MCP | Limited | Expandable | Blocking MCP Servers |
Yes Product Highlight | Depending on the project / integration |
| Working on „Your Own" LLMs |
Yes Audited |
Yes Audited |
Yes Audited |
Yes Model-agnostic |
Yes Model-agnostic, no lock |
| The Most Sensitive Data | DLP + browser isolation | DLP + DSPM | Purview + Access Policies | Editing + runtime policies | AI Hub / Isolated Environments (On-Prem/Private) |
| Implementation Model | Inline Cloud (SSL) | Inline Cloud | Part of the M365 stack | SaaS / on-prem / extension | Gateway + optional AI Hub, Quick Start |
| The strongest point | Inline scaling + browser isolation | Semantic DLP + Coaching | Nativeness in M365 + Identity | Runtime + agents + development tools | Fastest, non-blocking startup + layer selection |
How to Choose the Right Approach? Practical Scenarios
- You have scattered traffic, a lot of shadow AI, and you want a single fixed checkpoint. → Zscaler: the largest inline inspection cloud and browser isolation as a barrier against data exfiltration. This is a fairly significant change in how the internet is accessed, but it also solves other problems—such as those related to remote access.
- You prioritize precision, distinguishing between personal and business accounts, and educating users rather than blocking them. → Netskope: semantic DLP, instance awareness, and real-time coaching. An additional advantage is its close collaboration with Microsoft, which facilitates integration.
- You're deeply integrated with Microsoft 365 and want to manage AI using the same identity policies as the rest of your resources. → Microsoft Entra + Purview: Global Secure Access for lockouts and Prompt Shield, Conditional Access for access conditions, Purview for content DLP, and Access Packages for temporary access.
- You’re protecting not only chatbots, but also AI agents, coding assistants, and your own LLM applications, and you want a quick deployment without having to rebuild your network. → SentinelOne Prompt Security: runtime security via an agent and browser extension, an MCP gateway, and coverage for developer tools—particularly useful where SentinelOne is already in use on endpoints. It’s worth noting that Prompt Security is a product that is still being integrated following the acquisition and will eventually be incorporated into shared management consoles. Currently, as a standalone solution, it can also be integrated with ISCG AI Proxy—providing custom LLM models and robust blocking of attempts to circumvent corporate policies at the browser and application levels.
- You want to get started as quickly as possible, avoid holding people back with AI, and have both selection and implementation handled by a single team. → ISCG AI Proxy: a proxy gateway that filters and anonymizes data before sending it to the internet—to the user, it looks like a regular chat interface, and only queries to predefined models are sent to the network, with logging, monitoring, and the ability to escalate to AI Governance and isolated environments (AI Hub).
- The most common reality: these layers are not mutually exclusive. Many organizations combine Microsoft’s identity management (Entra/Purview) with a dedicated SSE platform (Zscaler or Netskope) or a runtime solution (SentinelOne Prompt Security) where they need deeper inspection, isolation, or agent protection. The integrator’s role—as in the case of ISCG—is to select and tie these elements together into a cohesive whole, starting with the fastest, non-blocking deployment.
Frequently Asked Questions (FAQ)
Blocking eliminates risks along with benefits and fuels shadow AI—users are switching to private devices and accounts. All the approaches described recommend a „monitor, don’t blindly block” model: visibility → conditional access → DLP → coaching/governance. ISCG AI Proxy goes the furthest in this regard; by design, it does not block anything, but rather filters and anonymizes data, allowing users to continue working with selected models.
Classic DLP based on pattern matching (regex) fails when the model rewrites content while preserving its meaning. That is why approaches such as Netskope’s semantic inspection evaluate the intent and context of the data, rather than just the pattern.
No. Entra controls access and traffic (Global Secure Access, Conditional Access, Prompt Shield, File Scan). Microsoft Purview provides comprehensive DLP for prompt content and data posture, while Defender for Cloud Apps offers advanced AI-powered shadow discovery.
Entra Prompt Shield blocks malicious instructions at the network level (text-only, no files); Netskope addresses this through AI Guardrails; Zscaler through prompt content inspection; and SentinelOne Prompt Security treats this as the core of its product (with claimed detection times under 200 ms for prompt injection and jailbreaks). This is a growing class of threats, increasingly treated as a separate attack vector—especially in the context of AI agents and MCP gateways.
Instead of inspecting traffic at the proxy or network level, it operates at the runtime layer of AI interactions—via an agent and a browser extension. As a result, it also covers AI agents, MCP gateways, and developer tools (IDEs, terminals, code assistants), which are more difficult to control with a standard web filter.
AI Proxy is the fastest, non-blocking entry point: a gateway that provides an interface similar to public tools like ChatGPT or Claude, with rules aligned with organizational policies and monitoring—without the need to rebuild the network or take tools away from users. As needs grow (strict inline inspection, isolation, agent protection), ISCG, as an integrator, adds governance, isolated environments (AI Hub), or a dedicated platform. This is the „start fast, then scale control” approach.
Summary
There is no single best tool for protecting against the misuse of external LLMs—there is an appropriate layer for each organization’s specific architecture and maturity level. Zscaler and Netskope address the issue from the perspective of traffic and data (SSE/CASB, inline DLP), differing in their focus: Zscaler emphasizes scale and isolation, while Netskope emphasizes semantics and guidance. Both also address many other threats—not only those related to LLMs, but also ransomware and remote access. Microsoft Entra approaches the issue from the perspective of identity and access, and achieves full data protection only when combined with Purview. SentinelOne Prompt Security enters from a fourth angle—as a runtime layer—and is the only solution among those described that focuses on protecting AI agents, MCP gateways, and developer tools. ISCG adds a fifth, integration-focused perspective: as the fastest, non-blocking solution, it offers an AI Proxy that filters and anonymizes data, processed under the customer’s own supervision and according to their own rules.
There is one common thread: start with visibility, not blocking. You can’t protect what you can’t see—and blocking too strictly only exacerbates the shadow AI phenomenon.
Are you planning to adopt AI in your company? We’d be happy to share our project experience with the process of safely and thoughtfully implementing AI—including details about the ISCG AI Proxy solution tailored to your environment.
Are you wondering which tier is right for your organization?
Schedule a free consultation and discuss a specific implementation scenario—from a quick start with AI Proxy to a full-scale control architecture.
Learn about our other services

Business applications
Services for applications and turnkey solutions in the area of process digitization and modern work environment.

Full support and optimization of IT infrastructure, ensuring stable development of your business.
IT infrastructure

Security of deployment and maintenance of Microsoft 365 and Azure services that enable flexible management and cost optimization.



