Inventor(s)

Abstract

This idea introduces a method and system for preventing generative AI tools, agentic AI processes, and autonomous software agents from accessing sensitive files on an endpoint device while still allowing authorized human users to access those files through controlled decryption mechanisms. The disclosure extends endpoint file tagging to classify files as Personal/Personally Identifiable Information (PII), Enterprise Confidential, Trusted, or Untrusted, and applies access enforcement at the point of file access. Sensitive files are protected using asymmetric encryption, with private keys held within a Trusted Platform Module (TPM), secure enclave, microvisor, hypervisor, or equivalent protected control plane. Human users can access these files through approved user-mediated workflows, while AI agents, indexing services, and autonomous processes are denied access to plaintext content unless explicitly authorized by policy. The idea further supports centralized policy enforcement, audit logging, and optional exclusion of sensitive files from AI indexing and search systems. This approach reduces unintentional data exposure caused by AI systems operating with broad access privileges and weak sensitivity awareness, while preserving user productivity and enterprise governance.

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 4.0 License.

Share

COinS