Back to Blog
    Compliance

    AI Prompt Logging: What IT Teams Need to Record

    Prompt-level logging promises complete visibility, but for most IT decisions it captures far more than necessary. Here is what to record instead.

    Fendr SecurityAugust 7, 20263 min read
    AI Prompt Logging: What IT Teams Need to Record

    The instinct when AI tools appear across a business is to get visibility, and the most complete visibility available is prompt-level.

    The useful distinction is between knowing what happened vs knowing what was said.

    What follows is less straightforward. A private equity firm we work with had run that at a previous point in their setup. It surfaced an odd piece of sensitive information. It also surfaced a great deal of personal use, in volume, attributable to named individuals. None of that was what the IT team went looking for nor was theirs to act on. They now had a personnel matter, an awkward conversation with HR, and a tool nobody trusted. When they came back to the problem they were explicit that they wanted auditability first and selective controls second, and that they wanted the personal browser left alone.

    The useful distinction is between knowing what happened vs knowing what was said. For almost every decision an IT Director actually needs to make, the first is sufficient. It also aligns with the GDPR principle of data minimisation - you collect only what is strictly necessary. Which AI tools are in use, how widely, and whether files are being uploaded to any of them tells you what to sanction, what to redirect, and where the real exposure sits.

    It also affects whether the controls survive contact with the business. The same firm rolled out an approved AI tool while deliberately leaving personal browsing untouched, on the reasoning that staff will accept a control they understand the limits of. Blanket enforcement tends to produce workarounds whilst the all-or-nothing app controls in most endpoint tooling are a poor fit here for the same reason, since the only options they offer are permit everything or block everything.

    There is a narrower version we believe works better. Detect which tools are in use and surface them for review. Allow prompting into a sanctioned tool while blocking file uploads and pastes into everything else. Redirect people to an approved alternative rather than showing them a wall. That typically operates on actions and domains rather than content, which means it never produces a transcript of anything an employee typed.

    A free audit shows which AI tools are in use across your browsers, without recording what anyone typed into them.

    Ready to see what your team is actually using?

    Tags

    ComplianceGDPRAI Governance

    Ready to Take Control of AI in Your Organisation?

    Join security-conscious teams who are enabling safe AI adoption without becoming the "department of no."

    Watch Demo