You cannot reliably stop it with policy alone — you make it technically impossible for the PII to reach the tool. The four options are: ban AI (usage moves to personal devices and you lose visibility), train staff (helps, but fails under deadline pressure), buy an enterprise AI contract (covers one tool only), or mask PII at the point of use, in the browser, before the prompt leaves. Masking is the only option that works regardless of which AI tool staff choose, without slowing them down — and it produces an audit record instead of a blind spot.
Why bans and training keep failing
Samsung’s experience is the canonical example: within roughly twenty days of allowing ChatGPT, engineers had pasted proprietary source code and meeting notes into it three times — not sabotage, just people trying to work faster. The company banned generative AI outright, trading the leak risk for a permanent productivity tax and zero visibility into what still happens on personal devices.
Training suffers a quieter failure: it depends on a busy person remembering the rule at the exact moment they paste. Data from DLP vendor Cyberhaven suggests a small fraction of employees account for the large majority of sensitive pastes — and they are usually the heaviest, most productive AI users.
What a point-of-use control looks like
A browser extension sits on the AI sites staff already use. When someone types or uploads content containing PII — names, emails, phone numbers, NI or NHS numbers, account references — the identifiers are detected and replaced with placeholders before submission. The person keeps working; the model still gets a coherent prompt; the identifying data never leaves.
Because the control runs at the point of use, it does not care which AI tool is involved, and it generates the thing bans and training never can: evidence. Category-level logs show what was protected, when, and under which policy — without storing the raw content.
The short version
- Bans push usage to personal devices — the risk goes invisible, not away.
- Training fails at the moment of deadline pressure; the heaviest AI users paste the most.
- Enterprise contracts cover one tool; staff use many.
- Masking at the point of use works on every tool and produces audit evidence.
Related questions
Does blocking AI sites at the firewall work?
Partially, on managed networks — and not at all on phones or home connections. The tribunal case and the Samsung leaks both happened around policies, not in their absence. Blocking also removes the productivity benefit rather than making it safe.
Will masking break the usefulness of the AI answer?
Rarely. Most legal, financial, and operational questions do not depend on real names — a structurally faithful placeholder preserves the reasoning task. Where the real values matter for reading the answer, reversible tokenisation restores them locally after the response returns.
How fast can this be deployed?
A browser extension installs in minutes per user, and enterprise policy tooling can force-install it across managed browsers. No network changes and no security team required.
This page is general information, not legal advice. Where third-party guidance or law is summarised, read the originals via the source links before relying on them. Last reviewed: 17 July 2026.
This is the control in action
Identifiable data is masked in the browser before the prompt ever leaves — try it yourself with a sample prompt, or bring one low-risk workflow to a 20-minute review.
Advise Sarah Thompson, NI AB123456C, on the settlement offer.
Advise <PERSON_7K9X>, NI <NI_8W1R>, on the settlement offer.