Bsides Exeter 2026

Shadow AI Is Your New Data Exfiltration Channel
2026-04-25 , Seminar Room 7

Being responsible for designing and implementing DLP policies in my organisation, I have seen first hand how companies suffer data loss without even realising it. The individuals exfiltrating the data are unaware what they are doing is even exfiltration of data through legitimate workflows.

Traditional Data Loss Prevention programs were built to monitor email gateways, USB devices, and cloud storage. But generative AI has introduced a new and largely unmonitored exfiltration channel.

In many organisations, AI adoption is outpacing governance. Employees restricted from using approved AI tools often turn to personal accounts or unsanctioned platforms pasting sensitive board packs, proprietary source code, and client data into public models in order to work more efficiently.

Existing DLP controls frequently fail to detect this behaviour because the activity appears legitimate and encrypted within normal web traffic.

In this talk, I explore:

How generative AI creates blind spots in traditional DLP architectures
Real-world scenarios where sensitive data leaves the organisation without triggering alerts
How red teams and malicious insiders can weaponize legitimate AI usage
Why most DLP programs measure activity instead of risk
Practical approaches to regaining visibility without shutting down innovation

This session bridges red, blue, and governance perspectives to challenge what data loss prevention really means.


URL:

https://linkedin.com/in/chijioke-okoye

Technical Level: 5 - Highly advanced / niche and technical

Chijioke Okoye is a Security Analyst with hands-on experience supporting organisations to manage risk, protect data, and build trust into technology from the ground up. With a background spanning information security, governance, and AI-enabled systems, their work focuses on translating complex security concepts into practical, real-world solutions that developers and businesses can actually apply.

Chijioke has worked across compliance-driven and fast-moving environments, helping teams embed security, risk awareness, and responsible AI practices into everyday workflows. As a speaker, Chijioke brings a grounded, accessible approach to security, combining technical insight with real examples from building and securing modern digital systems.