Why Preventing Data Leakage Requires Understanding Intent
Data creates value only when people can use it. Employees need access to keep work moving, while customers and partners rely on the services that access supports. Yet the same access that enables the business can expose sensitive information when it reaches the wrong person or application. The challenge is not simply locking data down. It is protecting data without standing in the way of legitimate work.
Today, data moves through more channels than many existing security tools were built to protect. Employees send files through chat applications and paste information into AI assistants. They take screenshots or use personal cloud accounts. While some of these tools are approved, others operate as shadow IT or shadow AI. This leaves security teams with little visibility into how data is being used. AI agents add another layer by moving and manipulating information on behalf of users.
The scale of this challenge is already becoming clear. According to Netskope’s 2026 Cloud and Threat Report, incidents involving users sending sensitive data to generative AI applications doubled in 2025. The average organization experienced 223 incidents each month. Rule-based DLP can struggle to keep pace with an environment that continues to expand.
Closing that gap requires more than another rule set. Security teams need context about what the data contains, who or what is moving it, and where it is going. They must also understand whether the action fits the person’s role and what happened before it. That broader context helps teams recognize when normal activity begins to shift. Unusual data access may be one signal. Off-hours activity or the use of a new external channel may provide another.
Together, these signals help security teams infer the intent behind the movement. The same action can be routine work or a serious incident depending on who is taking it and why. That distinction matters because data leakage can result from deliberate exfiltration or an accidental exposure that goes unnoticed. The Google and Toyota incidents illustrate both sides of that risk and show how data leakage can begin within workflows that initially resemble legitimate work.
Deliberate data exfiltration through trusted access
Between approximately May 2022 and April 2023, a Google software engineer stole more than 2,000 pages containing Google’s AI trade secrets. The material covered the company’s Tensor Processing Unit systems, GPU systems, networking technology, and software used to train and serve large AI models. During that time, he was secretly affiliated with two technology companies in China. He also founded his own AI company and served as its CEO.
According to evidence presented at trial, the engineer copied information from Google source files into Apple Notes on his company-issued laptop. He converted the notes into PDFs and uploaded them to a personal Google Cloud account.
Each step involved a common application or file operation. Viewed separately, the actions could resemble ordinary work. Together, however, they formed a deliberate sequence that moved confidential source material into another application, converted it into a different format, and transferred it to a personal account over several months.
Google had data loss prevention controls in place, but the method the engineer used allowed the activity to evade immediate detection. The engineer was charged in 2024. In January 2026, a federal jury convicted him on seven counts of economic espionage and seven counts of theft of trade secrets.
The case illustrates the type of risk that rule-based tooling can struggle to detect. No individual action revealed the full threat. It became clear only when the sequence of activity and the intent behind it were considered together.
Accidental data exposure through routine development work
Not every instance of data leakage begins with malice. Some begin with a routine mistake.
Toyota disclosed that a contractor developing its T-Connect customer website mistakenly uploaded part of the site’s source code to a publicly accessible GitHub repository. Embedded in that code was an access key for a server that stored customer email addresses and customer management numbers.
The key remained exposed from December 2017 until Toyota discovered it on September 15, 2022. It could have provided access to information associated with 296,019 customers.
Toyota attributed the incident to improper handling of the source code by the contractor. The company issued a public apology and notified potentially affected customers. Toyota said its access logs did not confirm that a third party had accessed the information, but the company could not rule out that possibility.
Although the circumstances differ from the Google case, both incidents show why individual actions rarely tell the full story. In the Toyota case, the customer data itself was not published to GitHub. An embedded access key created a path to that information. The risk depended on both the content of the code and its public destination. Identifying that risk requires understanding what the code contains at the moment it moves.
Where Rule-Based Tools Alone Fall Short
Traditional DLP still protects important channels, including email, file transfers, USB drives, and printing. The limitations emerge when data moves through applications, AI tools, or workflows that static policies do not cover well.
Rules can identify known content patterns or block prohibited destinations. However, they can struggle when risk depends on the user’s role, the destination, or the sequence of activity.
Without enough context, these policies can generate noise and make it harder for security teams to identify the events that matter most. They may also miss risks that depend on the purpose behind an action. The same upload may be expected for one employee but unusual for another. Sharing a file through an approved service may be safe when the recipient is authorized but risky when that recipient is external. Pasting text into an AI assistant may be acceptable until the content contains customer data or proprietary source code.
This lack of context can produce one of two outcomes. Broad rules interrupt legitimate work and generate alerts that security teams must investigate. Narrow rules allow risky activity because no single event violates a policy.
The Google and Toyota cases demonstrate the consequences of this limitation. Google involved deliberate data exfiltration spread across several ordinary actions. Toyota involved accidental exposure during a routine development workflow. In both cases, the risk became clear only when the actions were examined as part of a broader workflow. By then, Google’s trade secrets had already left the organization, while Toyota’s access key had remained publicly exposed for nearly five years.
Closing the Gap by Understanding Intent
Preventing data leakage requires identifying risk while the action is still underway, before sensitive information leaves the organization.
Ent’s Intent-Aware Workspace Security platform addresses this challenge by connecting human and AI agent activity at the endpoint with organizational context and policy. Instead of evaluating each action in isolation, Ent considers what data is moving and where it is going. It understands the user’s role and examines the sequence leading to the action. These signals allow Ent to infer intent and recognize when normal work becomes risky.
When sensitive data is about to move in violation of policy, Ent can intervene before the action is completed. It can warn the user or request justification. It can block the action when necessary and guide the user toward an approved path so work can continue safely.
This approach supports a more human-centered security model. Ent allows security teams to respond based on the actual risk instead of treating every action the same. Legitimate work can continue when the context supports it, while risky data movement can be interrupted before sensitive information leaves the organization. This provides stronger protection against data leakage without adding unnecessary friction to everyday work.
Gartner predicts that by 2027, 50% of large-enterprise CISOs will have adopted human-centric security design practices to reduce security-related friction and improve control adoption. Data protection must account for how people and AI agents work, what information they use, and where they send it. That context gives security teams an opportunity to stop harmful data movement without blocking the legitimate work that supports the business.
For more information on how Ent prevents data leakage across human and AI-driven work, explore the Ent datasheet or request a demo.