Copy & Paste is the new data breach
Why the most important security question of the AI era is no longer where data is stored, but where it is heading
Use AI. Boost security. Guidance on your next steps.
Do you want to deploy AI solutions such as Microsoft Copilot and AI agents securely and profitably within your organisation? Or would you like to review your security strategy, governance and protective measures in light of new threats posed by AI?
Our experts will help you assess your specific situation, evaluate the opportunities and risks, and identify the most appropriate next steps. Why not take advantage of our free initial consultations?
When data leaves the secure context
An employee copies a confidential piece of customer text into an AI tool. No malware. No hacker. No compromised account. Just copy and paste.
This is one of the most significant changes of the AI era. These days, data does not only leave organisations through traditional attacks. It also leaves them during everyday work activities: via prompts, file uploads, web forms, private cloud storage and other applications that employees use to work faster, better and more productively.
That is precisely where the real problem lies: in most cases, it is not a question of misconduct. It is about the new reality of digital work.
This is shifting the security paradigm of the AI era. The key question is no longer simply where sensitive data is stored and who is authorised to access it. It is increasingly:
What data is transferred, by whom, in what context, and to where?
The new security boundary therefore no longer runs solely through the data centre, the endpoint or the firewall. It arises the moment data is in motion. What for years was regarded primarily as a technical process is thus becoming a business-critical risk issue. This is because data is increasingly rarely losing its protection where it is stored. It is lost where the data is in motion.
What’s actually happening right now
The debate about AI often centres on models, functions and product announcements. This fails to capture the full picture. The real change has long since been taking place in everyday working life.
Employees use AI because they want to solve specific problems: they draft proposals, summarise contracts, analyse customer situations, review code, improve presentations or try to understand complex information more quickly. This is productive. It is transparent. And that is precisely why it is relevant to security.
AI is not only used via centrally deployed enterprise solutions. It is also finding its way into everyday working life via browsers, web applications, SaaS services, personal cloud storage and other digital tools.
In the process, data moves between controlled and less controlled environments, including sensitive information that is entered into prompts, transferred via copy and paste, or uploaded as a file.
The key question is therefore no longer simply: Which AI tools do we allow?
The more crucial question is: What data may be shared, by whom, in what context, and where?
Why this matters to those in charge
Many companies want to make productive use of AI whilst protecting sensitive data. It is precisely this tension that gives rise to a key management challenge.
When an employee copies confidential information into an external AI tool, this is not, in most cases, a malicious act. It is an attempt to get work done more quickly and efficiently. The risk therefore does not arise on the fringes of the organisation. It arises right at the heart of the productive workflow.
That is why traditional bans are not enough. A policy can stipulate that certain data should not be transferred to external systems. However, it does not automatically prevent this from happening anyway. Even awareness campaigns reach their limits when speed, time pressure and convenience take precedence over regulations.
Enterprise AI is therefore not made safe by bans. It is made safe by safeguards that operate directly within the workflow. That is the difference between an AI strategy on paper and an AI strategy that works in everyday practice.
The most common fallacy
Many companies still regard AI security as an extension of traditional data loss prevention. That is true and important. But it is no longer enough.
Traditional security models were highly effective at protecting data in known locations: in applications, on endpoints, in databases, files or email systems. The AI era is changing this approach.
Nowadays, a prompt can be just as sensitive as a document. Text entered by a customer can be just as critical as a file upload. And a response from an AI system may contain information that needs to be checked, logged or blocked. A user may have full authorisation to access a file. The actual risk may only arise seconds later, when content from that file is transferred to an external AI tool.
The question is therefore no longer simply: Who is allowed to access data?
Rather: Who is transferring which data to where, in what context and with what level of risk?
Microsoft’s Network Data Security: A new approach to security in data flow
At first glance, Microsoft’s new Network Data Security appears to be just another security feature. However, its strategic significance lies less in the individual feature itself than in the paradigm shift behind it.
Microsoft brings together three areas that are still treated as separate in many organisations: data classification with Microsoft Purview, identity-based enforcement with Microsoft Entra , and investigation and traceability with Microsoft Defender and Purview.
This approach extends data security to the network layer. The aim is to detect, restrict or block sensitive data in transit whilst it is being transferred via browser sessions, SaaS applications or AI interactions. Purview provides context regarding the value and sensitivity of the data. Entra brings identity and context closer to the moment of transfer. Defender and Purview make processes investigable, traceable and auditable.
This shifts the security decision from static access to dynamic data flow. It is no longer simply a question of: ‘Is this user permitted to access this application?’
Rather: Is this user now permitted to transfer this type of data to this destination? It is precisely this question that will be crucial in the AI era.
Why ‘Copy & Paste’ is becoming a symbol of a wider problem
Copy and paste seems harmless. That’s why it’s so dangerous. It doesn’t look like a security incident. It doesn’t sound like an attack. It doesn’t create a dramatic moment. And yet this is precisely where a data leak can occur.
An employee copies customer data into an AI tool to generate a summary. A sales team uploads a working file to an external service to produce an analysis more quickly. A project team uses webmail or private cloud storage because it seems the most practical option. Situations like these are not unusual. They are part of everyday digital working life.
The AI era turns this into a structural risk. After all, the more AI is integrated into day-to-day work, the more frequently data movements occur that were not previously a central focus of the security architecture. ‘Copy & Paste’ is therefore not just a keyboard shortcut. It is a symbol of a new category of risk.
The key lever
The most important task for businesses is not to prevent the use of AI. It is to ensure that AI can be scaled safely.
To achieve this, data context, identity and technical implementation must be considered together:
- If you look only at identity, you know who is acting, but not necessarily whether the content is critical.
- Anyone who focuses solely on data classification is aware of the need for protection, but not necessarily of the context in which the data is used.
- Those who rely solely on monitoring may not identify risks until data has already been compromised.
The key lies in combining these perspectives. Data must not only be classified; its use must also be assessed at the moment it is transmitted. This is a new checkpoint in the AI era.
Five recommendations for decision-makers
1. Make Shadow AI visible
Companies should not only know which AI tools are officially permitted; they must understand which tools are actually being used. The reality of usage forms the basis of any robust governance framework.
2. Take a critical look at your data classification
Technical enforcement is only as good as the data context behind it. If sensitivity labels, classifiers, DLP rules and responsibilities are unclear, precise control cannot be achieved. In that case, uncertainty becomes automated.
3. Consider governance and technical implementation together
AI guidelines without technical safeguards remain mere declarations of intent. Technical controls without clear governance, on the other hand, create friction. The strength lies in the combination of clear rules, understandable communication and effective enforcement directly within the workflow.
4. Distinguish between approved enterprise AI and unregulated consumer AI
The business case is not to stop AI. It is to provide staff with safe alternatives. When organisations enable the controlled use of AI through Microsoft 365 Copilot, Copilot Chat or other approved solutions, they reduce the pressure towards uncontrolled ‘shadow’ use.
5. Define an operational model for data flows
It is not enough simply to activate a policy. Organisations need clear lines of responsibility for alerts, false positives, escalations, exceptions, audits and management reporting. Otherwise, a sound security approach can quickly give rise to operational complexity.
What is positive
This approach tackles a real bottleneck faced by many AI programmes: companies want to use AI without losing sensitive data.
The logic behind real-time monitoring is particularly relevant. Microsoft describes its aim as identifying and protecting sensitive data in transit before it is exposed. This is an important step away from reactive post-incident management and towards preventive control within the workflow.
Platform logic is also a key factor. When existing classifications, DLP policies, identity signals and investigation results work together, this can lead to less tool fragmentation and greater controllability. For organisations that rely heavily on Microsoft technologies, this very integration can be a strategic advantage.
What remains a critical issue
The solution looks promising. However, it is no substitute for data governance.
If you don’t have a clear data classification system, network enforcement won’t automatically make you more mature. If you don’t have clear lines of responsibility, additional alerts won’t automatically lead to better decisions. And if you don’t have a robust operating model, you may end up creating new friction between security and the business.
Furthermore, a public preview does not constitute a production commitment. For regulated organisations, this approach must therefore be implemented within a controlled framework: involving pilot schemes, clear success criteria, a defined risk tolerance and a thorough architectural review. Licensing, coverage, integrations and data protection issues must also be addressed.
It is precisely this level-headed assessment that marks the difference between enthusiasm for a product and its responsible introduction.
Conclusion
Many companies are currently asking: Which AI solution should we use?
This is an important question. But it is not the most important one.
The more crucial question is: How do we foster trust in a working world where data is constantly flowing between people, applications and AI systems?
The next generation of cyber security will not be judged solely on how well it protects data in known locations. It will be judged on how intelligently it understands data movements and addresses risks at the right moment. After all, the AI era is not just about models, productivity or automation. It is about the ability to combine speed and control.
If you want to scale enterprise AI securely, you don’t need to ban copy and paste. You need to understand when it becomes a risk and be able to intervene at precisely that moment.
Author: Julien Cléro
Julien Cléro is a sought-after expert and speaker specialising in Microsoft AI and security. With 25 years of professional experience in the IT and telecommunications industry, Julien brings a wealth of knowledge and expertise to the table. Benefit from his extensive experience, including major projects with top clients.