Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler: Protecting Generative AI Usage in Your Organization

Zscaler
06/19/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


As we know, data has become the most critical digital asset for all organizations, and it is becoming more and more difficult to protect them for three simple reasons. The first is that they grow continuously and without control. The second is that there are more and more regulations that organizations have to comply with. And the third is that the use of Gen AI has become massive and often without control. Gen AI can be our best ally, but it can also be our worst enemy. Why? Because there are three risks associated mainly with Gen AI. One is the low visibility that we can have of both applications and data that circulate on these platforms. The second is because there is a high risk of data leaking. And the third, as I mentioned at the beginning, is because more and more regulations have to be followed. This means that Gen AI allows us, on the one hand, to increase productivity, but on the other hand, it brings us the risk that more and more of these platforms are used to generate cyber threats and cyber attacks. This means that more and more Gen AI is used to generate cyber attacks. What do we want to achieve? We want to find this specific point, which is the balance between allowing our users to use Gen AI, but safely. And that's where Cscaler can help you. Using four basic principles that I'm going to explain to you. The first is to gain data visibility, both in motion and in rest. The second is to mitigate risks proactively. The third is to protect data, especially those that are in motion and those that go to Gen AI platforms. And the fourth principle is to monitor and automate workflow in case of an incident. These four principles are based on our Zero Trust architecture. Through our cloud called Zero Trust Exchange, which is present in more than 150 countries worldwide, this cloud acts as a broker between entities that can be workloads or users and Gen AI platforms. The first thing we do is provide visibility of the data that is passing through our cloud, using artificial intelligence tools such as LLM or some more advanced tools like OCE. Then the second step would be to mitigate potential threats related to what is data in rest. There we use solutions like DSPM that allow us to provide this type of solution. The third step, which is more related to data in motion, would be solutions more related to DLP, URL filtering, Cloud App Control, among others, such as Browser Isolation as well. And finally, with data monitoring. Not only monitoring, but also being able to automate through integrations with ITSM systems to be able to resolve incidents in case they occur proactively and easily. Now, if we take a user as an example, the first thing we have to think about is how we connect this user safely to our cloud. That's where the principles of Zero Trust architecture come in. Let's say this user wants to use an application like ChatGPT to upload a document and be able to make an analysis of it. What is the first thing our platform would do? The first thing is to be able to have visibility and be able to detect what type of documentation it is, and if it contains any sensitive information. For that, we could use technologies like OCR. The next step would be, well, this is information that is in motion. Therefore, it would apply some of the principles that I mentioned earlier. For example, DLP. We don't want sensitive information to leave our organization or to be exposed. And finally, no less important, is the continuous monitoring of this traffic and being able to detect potential threats and resolve incidents. So, in this case, for example, if this user wants to be able to use ChatGPT, but without the risk of being able to exfiltrate data, we are going to allow them to use it, but under a restricted use. All this while educating users about the safe use of data. In short, Syscaler allows us to provide a complete and holistic data protection solution based on three criteria. Scalability, simplicity and agility to resolve incidents in case they occur proactively and quickly. That's all for now. Thank you for joining me in this video and I hope to see you next time. Bye!

TL;DR

  • Generative AI adoption creates three critical security risks: lack of visibility into AI applications and data flows, high potential for data leakage, and increasing regulatory compliance challenges that organizations must address.
  • Zscaler's Zero Trust Exchange platform secures Gen AI usage through four principles: gaining data visibility (in motion and at rest), proactively mitigating risks, protecting data with DLP and isolation technologies, and automating incident response workflows.
  • The solution acts as a security broker between users and Gen AI platforms, using AI-powered tools like OCR and LLM to detect sensitive content, enforce policies, and enable restricted Gen AI usage that prevents data exfiltration while maintaining productivity.
  • Organizations can achieve the critical balance between enabling Gen AI productivity and maintaining security through Zscaler's scalable, simple, and agile data protection approach that educates users while enforcing controls.

The Gen AI Security Challenge

Organizations face a critical balancing act as generative AI adoption accelerates across enterprises. While Gen AI platforms like ChatGPT offer significant productivity gains, they introduce three fundamental security risks: lack of visibility into applications and data flows, high potential for data exfiltration, and increasing regulatory compliance requirements. Data has become the most critical digital asset, yet protecting it grows more complex as data volumes expand uncontrollably and Gen AI usage often occurs without proper governance. The challenge is finding the equilibrium between enabling users to leverage Gen AI capabilities while maintaining robust security controls that prevent sensitive information exposure and intellectual property leakage.

Zscaler's Zero Trust Approach to AI Security

Zscaler addresses Gen AI security through four core principles implemented via its Zero Trust Exchange cloud platform, which operates across 150+ countries. The solution provides comprehensive data visibility for both data in motion and at rest using AI-powered tools including LLM and OCR technologies. It proactively mitigates risks through Data Security Posture Management (DSPM) for stored data, protects data in transit through DLP, URL filtering, Cloud App Control, and Browser Isolation, and enables automated incident response through ITSM system integrations. The platform acts as a security broker between users or workloads and Gen AI platforms, applying Zero Trust principles to every connection. For example, when a user attempts to upload a document to ChatGPT, Zscaler's OCR technology identifies the content type and detects sensitive information, DLP policies prevent unauthorized data exfiltration, and continuous monitoring tracks potential threats while educating users on safe data practices.

Chapters

0:00 - Introduction and Data Protection Challenges
0:40 - Three Primary Gen AI Security Risks
1:54 - Four Core Security Principles
2:24 - Zero Trust Exchange Architecture
4:05 - User Workflow Example with ChatGPT
5:39 - Complete Data Protection Solution

Key Quotes

0:40 "Gen AI can be our best ally, but it can also be our worst enemy."
1:33 "We want to find this specific point, which is the balance between allowing our users to use Gen AI, but safely."
2:32 "Through our cloud called Zero Trust Exchange, which is present in more than 150 countries worldwide, this cloud acts as a broker between entities that can be workloads or users and Gen AI platforms."
5:21 "If this user wants to be able to use ChatGPT, but without the risk of being able to exfiltrate data, we are going to allow them to use it, but under a restricted use."

FAQ

How does Zscaler prevent sensitive data from being exposed to Gen AI platforms like ChatGPT?

Zscaler's Zero Trust Exchange acts as a security broker between users and Gen AI platforms, using OCR and AI technologies to detect sensitive information in documents before upload. DLP policies automatically enforce restrictions, allowing users to access Gen AI tools under controlled conditions that prevent data exfiltration while maintaining productivity. The platform provides continuous monitoring and can enable restricted usage modes that block sensitive data sharing.

What are the main security risks organizations face when adopting generative AI?

Organizations face three fundamental risks with Gen AI adoption: lack of visibility into which AI applications are being used and what data flows through them, high potential for data leakage as users upload sensitive information or intellectual property to external platforms, and increasing regulatory compliance requirements that must be met. These risks are compounded by uncontrolled data growth and often ungoverned Gen AI usage across the enterprise.


Categories:
  • » Webinar Library » Zscaler
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Data Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Data Protection
  • Zero Trust
  • Cloud Security
  • Compliance & Governance
  • Technical Deep Dive
  • Generative AI Security
  • Data Loss Prevention
  • Zero Trust Architecture
  • Data Visibility and Control
  • Regulatory Compliance
  • AI-Powered Threat Detection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler: Protecting Generative AI Usage in Your Organization

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version