Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Survey Report Tag

DLP in the AI Era

Released: 10/09/2026

DLP in the AI Era
Data loss prevention (DLP) is widely deployed, but many programs struggle to stop sensitive data from leaving the organization. Generative AI (GenAI) tools, cloud storage, and unmanaged devices are exposing coverage gaps, while false positives and business pressure limit effective enforcement.

Based on a survey of 433 IT and security professionals, this publication examines how organizations deploy and operate DLP programs in the AI era. Among respondents who experienced data loss, only 16% reported that DLP blocked their most significant incident before data left the organization. GenAI was the most frequently selected exfiltration risk, yet only 29% of respondents could routinely produce a 30-day report showing sensitive data sent to GenAI tools.

The report explores the gap between perceived visibility and demonstrated capability, uneven enforcement across data channels, and the operational impact of alert fatigue. It also examines how business pushback shapes enforcement decisions and how organizations sequence DLP, data classification, and data security posture management (DSPM). These findings help security leaders assess where their programs fall short and identify priorities for improving coverage, reducing noise, and sustaining effective enforcement.

Key Takeaways:

  • Why DLP often detects data loss after the fact rather than preventing it
  • Where GenAI visibility claims fall short of measurable reporting capabilities
  • How enforcement across GenAI, cloud storage, and other channels compares with perceived risk
  • How false positives and alert fatigue affect analyst workload and team retention
  • How business pressure, data classification, and DSPM shape DLP program effectiveness

Download this Resource


Best For IconBest For:
  • CISOs & IT decision-makers
  • Data security architects & engineers
  • DLP program owners & administrators
  • Security operations leaders & analysts
  • AI security & governance teams
  • Compliance officers & risk managers

About the Sponsor

Jazz Security Logo
DLP’s rule-based framework is broken, creating noise instead of security. Jazz, winner of the 2026 CrowdStrike / AWS / NVIDIA Startup Nest, is the new model. Jazz combines a forensic endpoint agent for total visibility with an Agentic Investigator that deeply understands context & intent. It delivers clear, pre-investigated answers instead of alerts — and does it without browser extensions or rules. Finally, DLP that works.

Explore More of CSA

Research & Best Practices

Stay informed about the latest best practices, reports, and solutions in cloud security with CSA research.

Upcoming Events & Conferences

Stay connected with the cloud security community by attending local events, workshops, and global CSA conferences. Engage with industry leaders, gain new insights, and build valuable professional relationships—both virtually and in person.

Training & Certificates

Join the countless professionals who have selected CSA for their training and certification needs.

Industry News

Stay informed with the latest in cloud security news - visit our blog to keep your competitive edge sharp.