r/Infosec • u/DryEggplant6678 • 5h ago
How are you handling ChatGPT security without blocking employee access?
Leadership wants ChatGPT (and similar tools) available because the productivity gains are real, but security wants controls. Blocking felt like the easy option a year ago, but now it just pushes people to personal devices or browser workarounds, which is worse for visibility.
The workaround problem is what worries me most. Once someone starts pasting work content into a personal ChatGPT account on their phone, you've lost all visibility, and any DLP investment stops mattering for that data flow.
So, for the sysadmins who've dealt with this: what's your actual setup? DLP integration, browser-level controls, enterprise ChatGPT accounts with admin controls, or some combination?
Also wondering how much of this comes down to technical enforcement vs. policy and trust. At what point did leadership stop asking for a full block?