AI/ICT

[Information Security Solutions Conference] “Data Leaks Through Prompts ... Filtering and De-identification Needed”

IT DAILY ·

한태동 안랩 책임매니저가 9일 서울 양재 엘타워에서 열린 ‘2026 정보보호 솔루션 컨퍼런스’에서 생성형 AI 시대의 프롬프트 보안 전략을 주제로 발표하고 있다. (사진: 양승갑 기자)

✦ AI Summary

As generative AI spreads, prompts are emerging as a new channel for data leaks.

At the '2026 Information Security Solutions Conference' held on the 9th, AhnLab Senior Manager Han Tae-dong presented standards for enterprise prompt security.

He said that instead of an outright ban, controlled use, filtering, de-identification, and detailed logging are needed.

As generative AI spreads, prompts are emerging as a new channel for data leaks, prompting calls for a framework to screen and control input and output data.

Han Tae-dong, a senior manager at AhnLab, gave a presentation at the '2026 Information Security Solutions Conference' held on the 9th at EL Tower in Yangjae, Seoul, hosted by IT Daily, under the title 'Is Your Prompt Safe? New Standards for Enterprise Prompt Security in the Age of Generative AI.'

Han Tae-dong, a senior manager at AhnLab, said generative AI has become an everyday search tool. Related statistics from the Ministry of Science and ICT showed that 60% of generative AI users have replaced more than half of their existing searches with AI.

Statistics from the Ministry of Science and ICT also showed that 'everyday information search' accounted for 42.5% of generative AI use cases. Meanwhile, the photo shows Han Tae-dong, a senior manager at AhnLab, delivering his presentation, and it was taken by reporter Yang Seung-gap.

As generative AI use increases, the risk of sensitive information contained in prompts being leaked externally is also growing. According to a Harmonic survey, 8.5% of input prompts to major generative AI tools contained personal, sensitive, or confidential information.

Such data leaks can also occur unintentionally when users copy and paste documents. The manager pointed out that personal and confidential information can be included when copying and pasting original work materials. He also explained that cases involving personal information and the like are more common during copy-and-paste than when entering text directly.

Data that users cannot see is also considered a risk factor. For example, data can be inserted in HTML comments, metadata, CSS areas not rendered on screen, or hidden in an image's white space by using characters of the same color. Information that people do not recognize can still be read and used by LLMs.

Many general users see generative AI as little different from existing search services. Accordingly, companies need to review related security gaps. The manager explained that threats of personal information leaks through prompts are emerging.

However, blocking the use of generative AI itself is not a practical option. Although one example of a reason for restricting LLM use is the risk of data leakage, blocking LLM use could lead to lower productivity in the workplace. The manager said that instead of an outright ban, what is needed is a safe environment and controlled permission for use.

To that end, the manager said it is necessary to identify the data in prompts and the user's intent. He also explained that problematic content needs to be blocked. In addition, he said it is necessary to secure logs that can confirm whether sensitive information has been leaked.

Built-in guardrails in general-purpose AI services such as ChatGPT, Gemini, and Claude are limited in preventing the leakage of corporate personal information and confidential data. Native guardrails focus on blocking clearly malicious requests such as weapon-making or attack code generation. It is difficult to apply company-specific policies for work-related personal data and corporate secrets using native guardrails alone.

As an alternative that does not require separate software to be installed on endpoints, an Agentless configuration was proposed. In this approach, the user's outbound internet traffic is routed through a Secure Web Gateway (SWG) for filtering.

This Agentless configuration is characterized by not requiring a separate agent installation and allowing users to keep using their existing browsers. Through this, data sent to external AI services can be controlled. The manager explained that because prompts go out over the internet, that segment needs to be controlled.

At the site, examples were introduced of such controls being used to block the leakage of personal and confidential information, respond to prompt injection, and monitor and audit AI usage history. As a means of providing such responses, AhnLab's generative AI security solution, 'SecureBridge,' was presented.

SecureBridge detects personal and confidential information and then blocks or masks it, and it also detects and blocks malicious prompt injection before it is sent to the LLM. It also records prompt input and output, detection history, and user information, and that record data is used for monitoring AI usage status and supporting audits.

The manager said companies need to establish a filtering system to block data leaks as a protection and management measure for handling data, and that they should also have a system capable of de-identification when necessary. He added that the use of enterprise-only services is recommended and that detailed logging is also needed for transparent history management.

Source: IT DAILY · Yang Seung-gap
Original: https://www.itdaily.kr/news/articleView.html?idxno=241494

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.