MUMBAI, India, Sept. 28 -- Intellectual Property India has published a patent application (202611099209 A) filed by Mr. Prateek Goli on August 17, 2026, for Context-Aware Ai System For Preventing Sensitive Enterprise Data Leakage Through Large Language Model Applications.

Inventor includes Mr. Prateek Goli.

The application for the patent was published on September 25, 2026, under issue no. 39/2026.

Abstract: The present invention relates to systems and methods in the field of enterprise data security and artificial intelligence governance, more specifically to a context aware artificial intelligence system that prevents unauthorized data leakage or exfiltration from enterprise data during large language model interactions. In the current enterprise environment, employees and users increasingly interact with large language model applications for various purposes including document writing, coding, analysis, research assistance, and decision support. These applications provide unprecedented convenience but pose serious risks as users may unintentionally or maliciously input enterprise data into large language model applications where it is at risk of being retained by the model or used to update the model, thus resulting in significant data leakage and potential harm to the enterprise. Current data loss prevention systems are largely ineffective in this scenario as they typically attempt to identify sensitive phrases or terms using simplistic pattern matching or other similar techniques that lead to numerous false positives and/or missed sensitive terms. Furthermore, previous systems did not consider the context of the conversation or interaction, which may involve the identity of the user, the activity being performed, the sensitivity of documents relevant to the activity, the recipient of the language model request, the history of the user's activity, and other factors. Artificial intelligence driven systems and particularly ones that attempt to prevent data loss require consideration of such contexts together with semantic analysis of the prompt. A context aware artificial intelligence system is required that can intelligently analyze and govern interactions with large language models in order to prevent data loss while at the same time minimizing disruption to the user. The present invention provides a context aware artificial intelligence system for managing interactions between enterprise users and large language model applications, wherein the system analyzes these interactions for potential data leakage from the enterprise, considering both the context and the content of the interaction. The system operates as an intermediary that analyses prompts to the large language model applications and responses from them, identifies potential data leakage, determines the risk associated with potential leakage, and mitigates the risk using appropriate response mechanisms. The system is comprised of several key components that perform content inspection, semantic analysis, context enrichment, risk assessment, and response and policy management, in order to minimize disruption to the user while maximizing protection against data leakage. When a user sends a request to a large language model application, an inspection component captures this request along with any relevant contextual information such as the user's identity, device, application, session, destination, timing, etc. A context assembly component uses this information in conjunction with additional enterprise information such as the identity and access management, data classification, document management, workflow management, threat intelligence, and other enterprise information in order to determine the context of the request. A semantic analysis component analyzes the content of the request in order to identify potential leakage, taking into consideration the user intent behind the request. The context and semantic analysis components provide input to a risk assessment component which determines the likelihood and impact of data leakage and the appropriate response to mitigate it. The system can provide a variety of protective responses including blocking the request, redacting particular terms or phrases while allowing the rest of the request to be processed, replacing particular terms or phrases as they are identified and allowing the rest of the request to be processed, prompting for additional or managerial approval, logging the request for further follow-up, or providing guidance to the user, among other possible responses. Depending on the assessed risk, the system can provide different levels of protection and different levels of disruption to the requesting user. The system includes a feedback loop that allows it to optimize its risk assessment and response mechanisms based on responses to previous requests, user overrides, incident follow-ups, and other factors. The system can be managed using a policy orchestration component that allows policy rules to be defined by the enterprise in order to further refine context assessment and risk assessment, and subsequently select an appropriate response. These policies can be defined in natural language and can be based on a variety of criteria including the user, their role, the data, the application, project, location, regulation, and other relevant factors. The policy orchestration component translates the business logic contained in the policy rules into executable operations that the risk assessment component can use in order to select an appropriate response. Since policies can apply different context factors, the same phrase or sentence may be assessed differently depending on the particular context. The system can also inspect responses from large language model applications to ensure that they do not contain data leakage, in some embodiments. The large language model may include information derived from training data that is sensitive or may contain confidential information previously provided by the enterprise, which the system needs to ensure is not returned to the enterprise, or may infer information from previous prompts and provide that as well. The system may be deployed in different enterprise environments, including local, cloud, and hybrid deployments, and can be integrated with enterprise applications, identity providers, data classification and data loss prevention systems, and security information and event management systems. The system includes extensive auditing and reporting features that assist enterprises in ensuring that their data is appropriately protected and that the system itself is being operated as intended. By analyzing both the context and the content of prompts and responses to large language model applications, the system can minimize data leakage and maximize user productivity. Each interaction can be used to train the system to better identify potential data leakage, understand the intent behind prompts, and determine the most appropriate response to minimize disruption to the user while maximizing protection. The overall system provides a practical solution to the problem of data leakage by large language model applications, allowing enterprises to benefit from these powerful new applications while minimizing the risk that they will cause unintended data loss or leakage.

Disclaimer: Curated by HT Syndication.