Back to Blog
    Security

    Securing DeepSeek and Emerging AI Models: A Browser-Level Guide for IT Teams

    DeepSeek and the next wave of low-cost AI models are already inside your organisation. Here is how to identify the data leak risks of emerging LLMs - and how browser-level controls shut them down without blocking innovation.

    Fendr SecurityJune 25, 20268 min read

    DeepSeek arrived in early 2025 and reset expectations for what a free, frontier-grade AI model could do. Within weeks it was the most downloaded app in multiple countries and the subject of urgent advisories from regulators in Italy, Ireland, Australia and the US. For IT teams, the question is no longer "will our staff try it?" - they already have.

    DeepSeek's terms confirm prompts can be stored on servers in the People's Republic of China and used to train future models. For UK organisations, that single sentence is the compliance problem.

    This guide breaks down the specific risks of DeepSeek and the broader wave of emerging LLMs - Qwen, Kimi, Mistral, Grok, Perplexity, and the long tail of open-weight derivatives - and explains why browser-level controls are the only practical way to manage them.


    Why DeepSeek Is a Different Kind of Shadow AI Risk

    Shadow AI is not new. What is new is the speed at which a single model can become a household name. DeepSeek's R1 release combined frontier-level reasoning with a free consumer app, a free web interface, and an API priced at a fraction of OpenAI's. That combination removed every traditional barrier to adoption: cost, capability, and friction.

    The result is a specific set of risks UK and EU IT teams should plan for:

    Jurisdiction and Data Residency

    DeepSeek's published privacy policy states user inputs, chat history, and device information are processed and stored in the People's Republic of China. Under UK GDPR, transferring personal data to a third country without an adequacy decision or appropriate safeguards is a compliance issue regardless of how useful the tool is.

    Training on User Prompts

    The free consumer tier explicitly permits inputs to be used to improve the model. Anything pasted in - client names, financial figures, source code, internal strategy - may be retained and surfaced indirectly in future model outputs.

    A Confirmed Security Incident

    In January 2025, security researchers at Wiz disclosed a publicly accessible ClickHouse database belonging to DeepSeek that exposed over a million log lines, including chat history, API keys, and backend service details. The incident demonstrated that emerging providers often ship before their security posture catches up.

    Open-Weight Derivatives Multiply the Surface

    DeepSeek's models are open weights. Within days of release, dozens of hosted wrappers appeared - some legitimate, some not. Each wrapper is a new domain, a new privacy policy, and a new place your staff can paste data. A blocklist that names "deepseek.com" misses all of them.

    The Same Pattern Applies to Every Emerging Model

    DeepSeek is the headline, but the pattern repeats. Qwen (Alibaba), Kimi (Moonshot), Mistral's Le Chat, Grok, Perplexity, and a steady stream of new entrants share the same characteristics: free or near-free, browser-accessible, capable enough to be genuinely useful, and operating under privacy terms most users never read.

    The IT team's challenge is not picking which one to block. It is accepting that a new high-profile model will appear every quarter, and building a control model that handles all of them automatically.


    Why Traditional Controls Fall Short

    Most organisations reach for the tools they already own. Each has a specific gap when faced with emerging AI:

    ControlWhat It CatchesWhat It Misses
    Network / DNS blocklistKnown model domains on the corporate networkNew domains, hosted wrappers, mobile tethering, home Wi-Fi
    Endpoint DLPFile transfers, USB, clipboard at OS levelText typed or pasted into a browser prompt
    Edge / browser policies (Purview)AI prompts inside Microsoft Edge on enrolled devicesChrome, Firefox, Safari, contractor and BYOD machines
    Acceptable use policyProvides a paper trailNo enforcement, no visibility, no evidence of compliance

    The common thread is the browser. Every emerging AI model is reached through a browser tab. Controls that do not see inside the browser cannot see the risk.


    A Browser-Level Approach to Emerging AI

    The only control surface that scales with the pace of new model launches is the browser itself. A lightweight extension running inside Chrome and Edge can see exactly what is being typed, pasted, or uploaded into any AI tool - sanctioned or not - and apply policy in real time.

    A practical browser-level programme for emerging AI looks like this:

    Discover First, Block Second

    Before writing a single rule, get visibility into which AI tools your staff are actually using. Most organisations discover three to five times more tools in use than IT had assumed. Discovery without blocking surfaces the real workflows you need to support.

    Categorise by Risk, Not by Brand

    Group AI tools by their data handling posture, not their logo. A self-hosted Mistral instance and a free DeepSeek consumer app may run the same underlying weights, but the risk profiles are entirely different. Policy should follow the data flow, not the model name.

    Apply Content-Aware Rules at the Prompt

    Block paste actions matching client identifiers, source code patterns, or document classification labels into untrusted AI domains. Allow general queries. The aim is to prevent the specific risk - sensitive data leaving the organisation - not to ban a category of tool that staff will route around.

    Redirect, Don't Just Deny

    When a user opens DeepSeek to summarise a document, the productive response is to redirect them to your approved alternative with one click and a short explanation. A blocked tab teaches users to find a workaround. A guided redirect teaches them the right tool to use.

    Generate an Audit Trail by Default

    Every blocked paste, every redirect, every policy trigger should be logged with the who, what, when and where. Under UK GDPR Article 32, "appropriate technical and organisational measures" is the standard, and an automated log of intercepted prompts is exactly the kind of evidence regulators look for.

    What Good Looks Like in 30 Days

    A focused rollout, rather than a multi-quarter project, is what closes the gap before the next model launches.

    • Week 1 - Visibility. Deploy the browser extension to a single department that handles sensitive data (finance, legal, or product). Run in monitor-only mode. Record which AI tools are in use, how often, and what kinds of data are reaching them.
    • Week 2 - Policy. Based on what discovery showed, write three to five focused rules. Typical first rules: block paste of client identifiers into any AI domain outside the approved list; redirect DeepSeek and similar consumer AI tabs to the sanctioned enterprise alternative; alert on uploads of files tagged confidential to any AI domain.
    • Week 3 - Pilot enforcement. Switch the pilot department from monitor to enforce. Gather feedback. Tune the false positives that will inevitably appear in the first few days.
    • Week 4 - Expand. Roll the extension and tuned policies to the wider organisation. Set a quarterly review cadence to add new high-profile models to the policy as they emerge.

    The Compliance Angle for UK IT Directors

    For organisations regulated by the FCA, SRA, or ICO, the question is not whether DeepSeek is a useful tool. It is whether you can demonstrate that personal data and regulated content are not being transferred to providers without appropriate safeguards.

    A browser-level control that intercepts the prompt before it leaves the device gives you three things a policy document alone cannot:

    • Evidence that sensitive data was not transferred, in the form of blocked-action logs.
    • Visibility into which staff and which workflows depend on AI tools, so training and approved alternatives can be targeted.
    • Speed to respond when the next DeepSeek-scale launch happens, without waiting for a procurement cycle.

    The Bottom Line

    DeepSeek is not the last emerging model that will spread faster than your procurement process. The right posture is not a perpetual game of blocklist whack-a-mole. It is a browser-level control surface that sees every AI tool, applies content-aware policy in real time, and produces the audit trail you need - regardless of which logo is on the tab.

    Visibility comes first. A short, focused audit will tell you which emerging models are already in use in your organisation. From there, the policy work is straightforward.

    Ready to see what your team is actually using?

    Ready to Take Control of AI in Your Organisation?

    Join security-conscious teams who are enabling safe AI adoption without becoming the "department of no."

    Watch Demo