No AI control closes 100%
Let me say the part suppliers usually skip: there is no AI control that closes everything. And anyone promising it closes is selling what they cannot deliver.
There is always a way around. The personal phone, on mobile data, outside the company network. The AI embedded in a tool that was already under contract and nobody noticed. The person who copies the text on screen and types it into the device beside them.
No configuration reaches those routes. And that is not a failure of whoever set it up — it is the nature of the thing.
Why that is not a reason to give up
Because the alternative to "closing everything" is not "closing nothing".
Security does not work like a door, locked or open. It works like a perimeter: each layer closes one route, and whatever gets past one meets the next. None of them solves it alone; together, they change the question from "is somebody doing this?" to "we know what went through, and we can show it."
The common mistake is choosing between blocking everything and doing nothing — and since blocking everything is impossible, many companies end up with the second option by elimination.
The layers, from technical to human
The network. The cheapest point of all: the company's outbound traffic denies everything by default, and opens only the official route. Whoever is at the office, on a company machine, goes through where they should — without having to want to.
The devices. The computer the company hands out can carry its own rule, independent of the network. That covers whoever works from home.
Identity. AI tools accessed with the company account, never a personal one. It sounds like a detail and is not: it is what separates "the company contracted this" from "someone signed up on their own" — including when it comes to knowing where the data went.
And the last one, which is human. The written rule, the signed acknowledgement, and the conversation explaining why. It is the layer that covers exactly what the other three cannot reach: the phone in someone's pocket.
The layer most companies skip is the only free one
Notice the order in which this usually gets done: the technical part is bought first, and the written part waits — for when there is time.
But the first three layers cost money and cover what is inside. The fourth costs nothing beyond deciding, and it is the only one that reaches what is outside. It is the cheapest and the most postponed.
Holes are admitted, not hidden
There is a practical difference between a company that knows where it does not reach and one that believes it reached everywhere.
The first can tell a client or an auditor: we cover this, this and this; here we do not reach technically, and that is why this part is handled by rule and by training. That is an answer.
The second says everything is under control — until the day it was not. And then, on top of the problem, there is the earlier claim.
The test
Ask whoever looks after your technology: where can AI still leave the company without passing through anything?
If the answer is "nowhere", the conversation has not finished — it has not started. If a list comes back, however short, you are on your way: it is from that list that you decide what to close with technology and what to cover with rules.