Enterprises Shift From Blocking AI to Securing Sessions

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- A prominent U.S. law firm blocked DeepSeek's domain over data sovereignty concerns, but a subsequent visibility exercise revealed 70% of users had installed AI 'wrapper' extensions that silently routed corporate traffic through servers in China — invisible to both the firewall and the endpoint agent.
- Endpoint agents carry a heavy performance 'tax' — they hook into the OS kernel, break during macOS updates, and degrade high-performance machines — driving users to evade controls by moving files to personal Gmail and pasting prompts into unmanaged AI tools.
- SSL inspection in firewalls, SWGs, and SASE/SSE solutions creates a binary trade-off: turn it on and break tools like Slack, WhatsApp, and high-performance GenAI interfaces, or turn it off and remain blind to encrypted traffic — a trade-off the source calls 'architecturally untenable' for modern web work.
- EDR and legacy DLP see machine-level processes and files at rest, but the live browser session remains a 'black box' — especially on contractor laptops, partner browsers, and unmanaged home devices, which the source identifies as the places where sensitive data is most likely to leak.
- The 2026 standard is shifting to Session-Level Governance: prompt-level DLP that redacts sensitive code or PII in the buffer before 'Send,' extension risk-scoring for silent data harvesters, and agentless clipboard/upload controls that work on any device including BYOD and contractors.
- Security leaders are evolving from 'gatekeepers' who say 'No' to 'visibility layers' that enable the business to say 'Yes' — the framing is that the question is no longer whether users are using AI, but whether the security stack helps them do it safely or forces them into the shadows.
Why it matters: The 70% bypass rate at a major law firm demonstrates that domain-level blocking creates the illusion of compliance while pushing sensitive data into invisible browser sessions — and for CISOs, the 2026 shift to session-level governance reframes security from gatekeeping to enabling, with the explicit tradeoff of dropping invasive kernel-level agents that have long been the enforcement backbone.




