Employees routinely interact with generative AI platforms such as ChatGPT, Google Gemini, Claude, Grok, Mistral, and other platforms directly from company devices, often sharing sensitive business information in their prompts without IT oversight. Without visibility into this activity, organizations face risks such as data leakage, shadow AI usage, and regulatory non-compliance.
DataSecurity Plus can track GenAI apps accessed across endpoints, data that is shared as prompts and files to select GenAI platforms, and helps analyze overall genAI usage across your organization.
With DataSecurity Plus, you can:
- Audit employee prompts across various genAI platforms
- Analyze employee genAI usage across your organization
Audit employee genAI prompts using the steps listed below:
- Select Cloud Protection from the applications drop‐down menu.
- Navigate to Reports > GenAI Insights > GenAI Prompts.
- Set the reporting period using the Periods filter.
- Review the Domain Name, Actor, Time Generated, and Prompt columns to identify who is using which genAI platform and what they are sharing.
- To drill into a specific platform, select the corresponding sub-report such as ChatGPT Prompts, Google Gemini Prompts, or Claude Prompts.
Analyze employee GenAI usage across your organization using the steps listed below:
- Select Cloud Protection from the application drop-down menu.
- Navigate to Reports > GenAI Insights.
- Gain detailed insights into genAI apps usage using the following reports:
- Most Used GenAI Apps: Find genAI applications consuming the most bandwidth across your organization, broken down by vendor, upload size, download size, and total data transferred.
- Actors Using GenAI Apps: Identify the endpoints driving the highest AI-related bandwidth consumption and get a clear picture of how broadly genAI tools are being adopted.
- Shadow GenAI Usage: Spot access to AI applications that are not officially sanctioned or banned by IT team, with details on the domain, vendor, reputation score, and data transferred.
- GenAI Usage Trend: Get a snapshot of GenAI app usage over time, including daily bandwidth consumption and apps used most consistently.
- GenAI Usage Outside Business Hours: Surface and investigate AI
activity that falls outside configured business hours.
You now have a broader picture of GenAI usage in your organization including the platforms accessed, actors involved, and the exact prompts submitted, available for audit, compliance review, or policy enforcement.
With ManageEngine DataSecurity Plus, you can also block access to ChatGPT and other GenAI applications.
Frequently asked questions
To identify which AI tools employees are accessing and using, combine network visibility, identity monitoring, and employee disclosures to build a clearer picture of AI adoption across the organization. You can:
- Deploy a CASB (Cloud Access Security Broker) tool to monitor network traffic for connections to known generative AI platforms such as ChatGPT, Google Gemini, Grok, and Mistral.
- Check your SSO and SaaS management platforms — employees who register for AI tools using their work email will typically show up in identity provider logs.
- Conduct an internal survey, paired with a clear and non-punitive AI usage policy, which often encourages employees to consider the tools that they are using.
Tracking and controlling ChatGPT usage requires visibility into employee activity and controls that can prevent access where necessary.
- Network-level monitoring is your most reliable starting point. Configure your firewall or proxy to log and alert on outbound connections to chat.openai.com and api.openai.com.
- If SSL inspection is enabled, you can gain deeper visibility into request frequency and volume.
- Pair this with endpoint monitoring agents on managed devices to track time spent and usage patterns.
- Use DNS filtering, CASB policies, or application control rules to restrict access to ChatGPT on unmanaged devices or non-approved user groups. With CASB tools such as ManageEngine DataSecurity Plus, you can easily block access to ChatGPT and other genAI applications.
The EU AI Act classifies AI systems by risk level and sets compliance obligations for each tier. It applies to any organization deploying AI within the EU, regardless of where they're based.
For generative AI specifically, compliance goes beyond having a usage policy. A complete framework should cover:
- Risk assessment: Classify each GenAI tool your organization uses by risk level before allowing employee access.
- Vendor due diligence: Ensure the GenAI tools you procure meet EU AI Act requirements; providers of general-purpose AI models have their own obligations under the Act.
- Usage policy: Define which tools are approved, what tasks they can be used for, and prohibit entering personal, confidential, or regulated data into generative AI tools.
- Human oversight: Require employees to review and verify AI-generated outputs before use, especially for high-stakes decisions.
- Employee training: Staff must understand the limitations, risks, and responsible use expectations of the AI tools they use.
- Logging and auditability: Maintain records of how generative AI tools are used to demonstrate compliance.
- Incident response: Establish a process for reporting and handling errors or harm caused by GenAI outputs.
The EU AI Act's obligations are phasing in through 2026, so organizations should start with risk classification and build their framework from there.
The risk is broader than most organizations realize. Employees routinely paste sensitive content into AI prompts without pausing to consider where that data goes. The most commonly leaked data types include:
- Customer PII: Names, email addresses, account details, and transaction histories pasted in for summarization or email drafting
- Source code: Proprietary codebases shared for debugging, refactoring, or documentation, often in their entirety
- Financial data: Revenue figures, forecasts, M&A details, and budget models submitted for analysis or presentation drafting
- Legal documents: Contracts, NDAs, litigation strategy, and regulatory filings uploaded for simplification or review
- HR data: Performance evaluations, compensation details, and candidate assessments used in AI-assisted writing
The critical point is that most public-facing AI tools, unless explicitly configured, transmit this data to external servers outside your organization's control. Even tools with a no training option process the data in transit.
An effective AI acceptable use policy needs to address the specific risks generative AI introduces. At minimum it should cover:
- Approved and prohibited tools: Enumerate which platforms are sanctioned, under what conditions, and which are explicitly off-limits. Ambiguity here creates shadow AI.
- Data handling rules: Define clearly what categories of data may never be entered into AI tools: customer PII, source code, financial projections, legal documents, and anything subject to regulatory controls.
- Monitoring disclosure: Explicitly inform employees that AI tool usage on company systems and devices is monitored, what is captured, and how that data is used internally.
- Approval process for new tools: Give employees a fast, low-friction path to request approval for AI tools they want to use. Without this, employees will resort to shadow AI usage.
- Consequences: Define what constitutes a violation and what the response looks like.
Review the policy at least every six months. The AI tool landscape moves fast enough that a policy written 12 months ago is likely already out of date.
