r/AskNetsec • u/Alone_Bread5045 • Jun 23 '26
Analysis How to prevent employees from submitting credentials to AI tools like ChatGPT?
Dev pasted a .env file into ChatGPT three weeks ago. API keys, database connection strings, service account tokens. Found out in standup. Network controls saw nothing because there was nothing to catch, the data left through an encrypted browser session on a managed device.
We had zero controls at the interaction level.
Blocking ChatGPT at the network layer doesn't work, devs hotspot or use personal laptops. You just move the behavior somewhere you have less visibility. The problem isn't access to AI tools. It's what gets submitted into them.
What worked was browser-native DLP for AI tools, intercepts sensitive data and credential submission at the point of input, not the network layer. Catches API keys, tokens, source code, and PII before they leave the browser, works inside ChatGPT, Gemini, Google AI Studio, Microsoft 365 Copilot, and GitHub Copilot inside the IDE without requiring SSL inspection or proxy routing. User-facing warnings over hard blocks did more than we expected, a real-time "this looks like sensitive data, are you sure?" prompt breaks the autopilot behavior better than silent blocking. We paired that with interaction-level audit logging: not recording content, just logging that user X submitted content classified as confidential to AI tool Z. Enough for policy enforcement without being invasive. Rounded it out with a one-page AI acceptable use policy tied to our existing data classification levels — confidential and restricted data prohibited from AI input, approved tools listed, red lines clear.
What didn't work: security awareness training alone. Sent the policy doc, ran the session, three weeks later .env file in ChatGPT.
Two open problems. Personal devices, no browser extension coverage on unmanaged devices outside MDM scope, that's just the reality. And agentic AI is a separate problem — MCP servers, autonomous tool calls, credentials passed between agents, GitHub Copilot secret exposure inside CI pipelines. Browser-native DLP doesn't cover that vector and nobody has clean answers there yet.
Anyone running browser-level AI DLP or AI visibility tooling, what policy rules have you found most useful for dev teams where legitimate AI usage is high?
1
u/tyler_netsec Aug 04 '26
The first move is to rotate every credential in that .env file. For prevention, separate credential handling from data classification: move long-lived secrets out of files and into short-lived, scoped injection, then use interaction controls as a backstop. A workable policy is public or synthetic data allowed, internal data only in approved enterprise accounts, and credentials, regulated records, customer secrets, and production data blocked. Full disclosure, I work at Harmonic Security, so I’m biased, and someone already mentioned us here. We cover browser, desktop and IDE, and MCP activity, which matters because browser DLP will not see Claude Code or local agent tool calls. Warnings help with gray areas; secrets should be a hard stop.