Your data is already leaving the building.
Employees paste contracts, customer records, and source code into public LLMs because the sanctioned path is slower than the rogue one. Security can’t audit what it can’t see, and a blanket ban only pushes it further underground.