SAIL-LLM: A Risk-Aware Architecture for Preventing Employee-Driven Data Leakage in Enterprise LLM Deployments
Abstract
Enterprise employees increasingly use Large Language Models (LLMs) to summarize documents, analyze business data, and support daily work, creating a pre-inference leakage risk when confidential content is submitted before organizational policy controls are applied. This paper proposes SAIL-LLM, a situational awareness-driven inline governance architecture for preventing employee-driven data leakage in enterprise LLM deployments. The architecture inserts a governance layer between the enterprise interface and the LLM, classifies submitted content, checks role authorization, evaluates execution context, computes a formal risk score, sanitizes RAG context, and routes requests to Allow, Restrict, Redirect, or Block. Because the artifact is an early-stage governance architecture, a scenario-based proof-of-concept evaluation was selected and strengthened with a small computational benchmark over 24 labeled enterprise scenarios across finance, human resources, operations, and strategic/technical knowledge management. Results: The evaluation used policy-routing accuracy, macro precision, macro recall, macro F1-score, false positives, false negatives, sanitization coverage, and pre-inference latency overhead. The prototype achieved 91.7% routing accuracy, 0.93 macro precision, 0.92 macro recall, 0.92 macro F1, one false positive, one false negative, 97.1% sanitization coverage for restricted cases, and a median governance-layer overhead of 96 ms excluding LLM generation.