Answers
The questions that come before the brand.
Anyone asking how to stop data leaking into AI is not searching for a product name. These pages answer the question, not the brand.
- Does my data stay in the EU if I use ChatGPT Enterprise?
EU residency covers storage. Inference is a different statement, and it is the one that concerns the prompt.
- Can Microsoft 365 Copilot move my prompts out of the EU?
Yes, at capacity peaks. Flex Routing is on by default for tenants created after 2026-03-25.
- Does Microsoft Purview see what staff type into AI?
Partly, and the conditions decide. Purview's prompt detection depends on the endpoint; network-side inspection is in preview per Microsoft's own docs.
- Is classical DLP enough for AI prompts?
DLP protects files and channels. An AI conversation is neither. What mature DLP suites do well, and where they stop.
- How do I prove what the AI did with which data?
A perimeter you cannot evidence is not one. What a per-prompt decision record holds, and what it deliberately does not.
- Staff are pasting company data into ChatGPT. What can I do?
The leak is not a hack, it is the working day. Four sourced numbers, the five usual places, and the control that sits in front of them.
- Can I use AI without prompts leaving my network?
Yes. Five deployment modes, from fully local to air-gapped, and the choice follows your risk profile, not the product.
- What happens to masked data in the AI's response?
It comes back. Sensitive entities leave as stable tokens, the model works with the context, and cleartext is restored on the way back.
- What is an AI Interaction Firewall?
A security layer between your staff and AI models. It inspects every prompt before the model sees it and decides per data class.
- Which AI models may which employee use?
The answer is a policy, not a list. It follows the data class and the role, and it is enforced at runtime.
