The Question

Your SASE architecture was designed for the cloud-first enterprise of 2022. It routes users to Microsoft 365, Salesforce, Workday, and ServiceNow through your SSE stack. TLS inspection is enabled. CASB governs SaaS application access. DLP detects sensitive data in egress traffic.

Then your employees discover ChatGPT. Then your developers adopt GitHub Copilot. Then your data science team begins calling the OpenAI API and the Anthropic API from their development workstations. Then your enterprise deploys its own AI assistant, hosted internally, used by 3,000 employees.

Each of these represents a new traffic category that your 2022 SASE architecture was not designed to govern. AI assistant traffic contains sensitive data in natural language form — financial projections in a chat query, source code in a Copilot prompt, customer data in an API payload. Your DLP policy was designed to detect PII and financial data in structured formats. It was not designed to detect proprietary business logic described in natural language in an HTTPS POST request.

Your SASE architecture has not failed. But it has gaps. And those gaps are where your AI-related data loss events will occur.

SASE architectures that were built for SaaS access in 2022 need AI-specific policy layers in 2026 — and the vendors who have built those layers are moving ahead of those who have not.

Why This Matters Now

In early 2025, a management consulting firm with 6,000 employees discovered that consultants had been submitting client deliverables — strategy documents, financial models, competitive analysis — to ChatGPT for "polish and editing." The documents contained proprietary client data that the consulting firm was contractually obligated to protect under its client engagement agreements.

The firm's SASE deployment included TLS inspection and DLP. However, the DLP policy was configured to detect structured PII (names, addresses, financial account numbers) and did not have policies for detecting client-confidential strategy documents. The CASB had categorized ChatGPT as a productivity tool — the same category as Grammarly. No access restrictions applied.

When the firm's legal team learned of the data exposure, the investigation revealed that the behavior had been occurring for approximately 14 months — since ChatGPT's enterprise adoption curve accelerated in late 2023. The firm estimated that several hundred client documents had been processed through ChatGPT's platform.

The incident triggered contractual breach notifications to affected clients and resulted in a material contract termination from one client. The total cost, including legal fees and the lost contract, exceeded $4 million.

The firm's SASE deployment was technically sound. Its AI tool governance policy was absent. The result was a data loss event that was foreseeable, preventable, and expensive.

This pattern repeated across multiple industries in 2024 and 2025. Stackcurve tracked more than 40 documented AI-related data exposure events in which a functioning SASE deployment failed to prevent data exfiltration through AI tool traffic. In every case, the failure was a policy gap, not a technical failure.

What the CURVE™ Data Shows

The 2026 Stackcurve SASE/SSE CURVE™ Report included a dedicated AI governance capability dimension that evaluated how well each vendor's CASB and DLP tools address AI-specific traffic patterns.

Netskope led in AI-specific CASB coverage. Netskope has built AI tool DLP rules into its CASB application library, including specific policies for ChatGPT, Claude, Gemini, and Copilot traffic. Netskope's natural language DLP capability — detecting semantically sensitive content in AI query payloads — was the most mature of the evaluated platforms at the time of the CURVE™ assessment.

Zscaler introduced AI Security capabilities in 2024, adding detection of sensitive data in AI tool traffic to its DLP engine. Zscaler's AI tool CASB coverage has expanded significantly since 2023 and now includes a dedicated AI app category with granular access control options.

Palo Alto's AI Access Security module, available within Prisma SASE, provides CASB-layer AI tool governance with classification of AI tools by risk tier. The module integrates with Prisma's existing DLP engine and adds AI-specific content inspection rules.

Cato Networks' approach relies on its cloud firewall and CASB capabilities for AI tool control. AI-specific DLP rule coverage is nascent compared to the three leaders above, and natural language content inspection is not yet a production capability on the Cato platform.

The full vendor rankings are in the 2026 Stackcurve SASE/SSE CURVE™ Report — free to download.

The Gap Most Buyers Miss

AI tool traffic is not categorically different from SaaS traffic at the network layer. It is HTTPS. It flows through the SSE. It is subject to the same TLS inspection, DLP, and CASB controls. The architectural requirement — TLS inspection enabled, forward proxy active — is the same.

The difference is the content inspection challenge. Standard DLP pattern matching was designed for structured sensitive data: 16-digit credit card numbers, Social Security number patterns, IBAN formats, email address patterns. These patterns are unambiguous in structured data.

A consultant submitting a client strategy document to ChatGPT is sending unstructured natural language. The document does not contain a credit card number. It contains sentences like "The client's primary competitive vulnerability is..." and "Based on Q3 revenue data, we project..." and "The board has not disclosed this acquisition publicly." None of these sentences triggers a pattern-matching DLP rule. All of them are sensitive.

Here is how the AI governance challenge breaks down by traffic category.

AI Assistant Traffic (ChatGPT, Claude, Gemini, Perplexity)

These are HTTPS sessions to well-known cloud endpoints. SWG categorizes them as AI tools or productivity tools depending on CASB library coverage. The control options are:

  • Block all AI tool access (operationally disruptive; employees use personal devices instead)
  • Allow with DLP inspection (requires semantic content inspection capability)
  • Allow with category-based controls (allow productivity AI, block high-risk AI)
  • Allow enterprise-approved tools, block unapproved tools

The last option is the most common enterprise approach in 2025–2026. It requires an approved AI tool list and CASB enforcement. The challenge is that the approved tool list must be maintained as the AI tool landscape changes, which it does monthly.

AI Coding Tools (GitHub Copilot, Cursor, Tabnine)

IDE extensions use background processes that often operate outside the standard browser proxy. GitHub Copilot Business and Copilot Enterprise route through the Microsoft 365 data plane — CASB for M365 is the appropriate control layer. Cursor and similar tools that use background HTTP clients may bypass proxy-dependent SWG unless the endpoint agent is configured to redirect all outbound HTTPS traffic.

The source code exposure risk in AI coding tools is significant. A developer's prompt to Copilot may contain proprietary algorithms, API credentials embedded in code, or architectural details of systems that are confidential.

AI API Traffic (OpenAI API, Anthropic API, Hugging Face)

Enterprise developers and data science teams calling AI model APIs represent the highest-risk AI traffic category for data loss. API calls carry proprietary data in request payloads — often customer data, proprietary models, or confidential business logic. The payloads are JSON, not HTML, which means they do not trigger HTML-based DLP rules.

TLS inspection must be enabled to inspect API payloads. CASB forward proxy mode is required. API traffic destined for OpenAI, Anthropic, and Hugging Face endpoints should be classified as a distinct CASB category with DLP policies applied to the request payload, not just the response.

Enterprise AI Deployments

Enterprise-internal AI assistants — built on Azure OpenAI Service, Amazon Bedrock, or internally deployed open-weight models — are accessed via internal HTTPS. They typically flow through ZTNA rather than SWG. The data governance challenge is that internal AI tools aggregate data from multiple enterprise systems and make it accessible in a conversational interface that does not respect the data classification controls of the source systems.

The SASE architecture question for enterprise AI is: does ZTNA access policy for the AI tool reflect the data classification of the information it can surface? An employee who should not have access to HR compensation data may be able to query it through an AI assistant that was trained on HR data. This is an authorization problem that ZTNA can help constrain but cannot fully solve without integration with the AI platform's own access controls.

Questions Your Buying Team Should Be Asking

1. How does your CASB classify AI tools, and what is your current app library coverage for the following specific tools: ChatGPT Enterprise, Claude for Enterprise, GitHub Copilot Business, Cursor, and the OpenAI and Anthropic API endpoints?

Provide the specific tool list for your environment and ask the vendor to confirm coverage. CASB library coverage varies significantly by vendor and is updated continuously. A vendor who cannot confirm coverage for your specific tools has a gap.

2. Does your DLP engine have rules for detecting semantically sensitive content in natural language — not just pattern-matched PII — in AI tool query payloads?

This question separates vendors with AI-specific DLP capability from vendors who are applying legacy pattern-matching rules to AI traffic. The answer reveals whether the vendor has actually built AI-aware content inspection or is marketing existing capabilities as AI-ready.

3. How does your endpoint agent handle AI coding tools like GitHub Copilot and Cursor that use background HTTP clients outside the browser? Does your agent intercept all outbound HTTPS or only browser traffic?

The answer reveals whether your SASE deployment will actually see AI coding tool traffic. An endpoint agent that only redirects browser traffic has a significant visibility gap for IDE-based AI tools.

4. What is your recommended SASE architecture for governing developer access to OpenAI and Anthropic API endpoints, including payload-level DLP inspection of API request bodies?

This is a specific, technical architecture question. The vendor should be able to describe a deployment pattern — TLS inspection on, forward proxy mode for API traffic, specific DLP policy for API payload inspection — not a general capability statement.

5. How do you approach AI tool governance for enterprise-internal AI deployments that are accessed via ZTNA rather than SWG? What access control integration do you support with Azure OpenAI Service and Amazon Bedrock?

Internal AI platforms are a governance gap that most SASE vendors have not fully addressed. The vendor's answer reveals whether they have a strategy for enterprise AI governance or are still focused on shadow AI blocking.

The Stackcurve Take

The AI-augmented enterprise of 2026 is not a future state — it is the current state for most knowledge-work organizations. Your employees are using AI tools today. Some of those tools are sanctioned. Many are not. The data flowing through those tools includes sensitive business information, client data, and intellectual property that your security and legal teams would classify as confidential.

Your SASE architecture is the control layer for this traffic. Whether it actually controls AI tool traffic depends on three decisions: whether TLS inspection is enabled, whether your CASB has coverage for the AI tools your employees are actually using, and whether your DLP engine has rules that can detect sensitive content in natural language payloads.

The vendors who have built AI-specific governance capabilities into their SASE stacks are ahead of those who have not. The gap between leaders and laggards in AI governance will widen in 2026 as enterprise AI adoption accelerates.

The 2026 Stackcurve SASE/SSE CURVE™ Report covers AI governance capability across all major SASE vendors, including CASB coverage depth and DLP policy maturity for AI tool traffic. Download it free →


← Back to Research Library

Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.