Business value
Six places where AI use costs money.
We see five of them in every audit. Nobody sees the sixth while it lasts. Each exposure carries what it means commercially.
Five places your data leaks into AI today.
Every prompt is a potential breach. These are the patterns we see across every audit.
- A
PII in employee prompts.
Names, addresses, IDs pasted into ChatGPT — often without realising. Cloud training risk, GDPR risk.
- B
Trade secrets in “draft this for me…”.
Roadmaps, pricing models, M&A drafts — sent to public LLMs as helpful context. No mask, no log.
- C
Patient IDs to external APIs.
Clinical workflows that touch OpenAI or Anthropic without on-prem masking. PHI exposure, audit nightmare.
- D
Source code uploads.
Developers debug with Copilot or Claude. IP leaves the building. No vault, no provenance.
- E
Contract clauses to summarisers.
Legal teams paste NDAs and MSAs into AI summarisers. Terms become training data for foreign models.
The sixth: shadow AI
- F
Unapproved tools that nobody sees
In roughly 42 percent of German companies private AI use is observed or suspected, while only 26 percent provide official AI access — at 20 to 99 employees only 23 percent (Bitkom, October 2025). Network blocking does not prevent this fully: it does not reach personal smartphones, copy-paste, or AI features embedded in SaaS tools. A plain ban moves the usage to where IT can no longer see it.
Business impact: no log, no forensics, no basis for evidence. The German data protection conference also recommends internal usage rules over uncontrolled open systems (guidance "KI und Datenschutz", 2024).
What a control layer does not remove
Four sentences this page states plainly. Each is the negative form of a statement made positively elsewhere — and a page that names its limits is the one you can rely on.
- 01
What is inspected is the way in, not what happens after
BRANE inspects what goes into the AI — not what a human does with the answer afterwards. That is the defining property of a pre-inference control, not a gap in scope.
- 02
The channel is AI use, not every channel
BRANE covers the AI channel — not email, USB, cloud share or a photographed screen. Firewalls protect networks, DLP protects files; if you must cover those channels, solve it there.
- 03
Enforcing is not writing
BRANE enforces policy — it does not write it. Which data classes exist and what applies to them is your decision; the layer makes sure that decision applies everywhere.
- 04
What is evidenced is receipt, not use
BRANE evidences what the model received — not what the provider does with it afterwards. That is exactly why masking sits before egress: what leaves masked is not cleartext even beyond your reach.
