Aller au contenu principal

Use Cases by Sector

Noxys is the first European sovereign AI Firewall — it sits between employees and AI services, detecting sensitive data exfiltration in real time without storing raw prompts.

These use cases show how Noxys enforces your data-loss-prevention policies in the three sectors with the highest Shadow AI exposure.

SectorPrimary RiskKey Regulations
Banking & FinanceClient portfolio data via ChatGPTMiFID II, DORA, GDPR Art. 30
HealthcarePatient records pasted for AI summariesHDS, HIPAA, GDPR
LegalContracts uploaded for AI reviewAttorney-client privilege, GDPR, Bar rules

What Shadow AI looks like in 2026

Shadow AI is the unsanctioned use of AI services (ChatGPT, Claude, Gemini, Copilot, etc.) by employees to perform their job faster — without security review, data classification, or audit trail.

The pattern is always the same:

  1. Employee faces a complex or time-consuming task
  2. Employee copy-pastes work content into an AI chatbot
  3. Sensitive data leaves the perimeter — GDPR Art. 5(1)(f) breach, potential confidentiality violation
  4. No log exists — CISO has zero visibility

Noxys intercepts at step 3, in the browser, before the HTTP request leaves the machine.

How Noxys stops it

Employee browser

├─ Tier 1 detection (extension, offline, <2.5ms)
│ Regex patterns: IBAN, NIR, contract refs, SWIFT codes...

├─ Tier 2 detection (API, Presidio NER, <30ms)
│ Context-aware: names + dates + amounts = financial record

└─ Policy engine
Block → HTTP request cancelled, user coached
Coach → Warning shown, user can acknowledge or cancel
Log → Silent audit trail for SIEM

Raw prompts are never stored — only SHA-256 hash + risk metadata per GDPR by-design principle.