BlogHeader-1920x750-Claude

Proofpoint Extends Real-Time DLP to Claude via New Inference Hooks

Share with your network!

From visibility to prevention—the DLP policies you already trust now can be applied to supported Claude conversations—and help stop the most sensitive prompts before the model ever sees them.

Closing the AI Data Protection Gap

AI usage and risk will continue to evolve as adoption accelerates. In May 2026, we introduced our integration with Anthropic’s Claude Compliance API. It gave security teams visibility into supported conversations with Claude, and the ability to act on them—like removing a flagged conversation when something sensitive is identified after the fact.

That was a real step forward for visibility, but there was still a gap. Sensitive data was still sent, processed by the model, and potentially accessed or used—all before security and compliance teams could identify and remove it. In those circumstances, sensitive information may already have been processed before security teams could intervene.

Today, we’re helping customers address that gap. This is one control point in Proofpoint's unified data security platform. The same policies that help to prevent unauthorized transmission of sensitive data—PII, source code, and regulated records—from leaving through email, endpoint, and cloud now can be applied to what reaches an AI model. Claude is the newest destination supported by these protections; the platform and the policies behind it stay the same.

Anthropic built inference hooks so a security check can run before a prompt reaches the model. Proofpoint’s integration with inference hooks brings your existing DLP policies into that check—so a prompt carrying sensitive data may be blocked in real time, consistent with your configured policies, before Claude ever processes it.

Why this matters now: our 2026 AI and Human Risk Landscape Report found that nearly nine in ten global organizations have moved AI assistants beyond pilot, and 42% have already had a suspicious or confirmed AI-related incident. The point isn't that AI is too risky to adopt—adoption has already happened. It's that controls may need to extend to new AI interaction surfaces as fast as the surface is growing. Most organizations aren't starting from zero; they already have data protection policies they trust. What many organizations haven't had, until now, is a way to apply those policies to an AI prompt before it's processed. As we uncover new challenges in securing AI adoption, we’ll continue to work closely with key AI vendors to architect solutions that help organizations adopt AI more securely.

How it works

When a prompt is submitted, Claude routes it to Proofpoint first. We check it against the same data protection rules you already use across email, endpoint, and cloud, and return a verdict. If the verdict is “allow,” Claude processes the prompt as usual. Claude does not process the prompt when the applicable policy returns a “deny” verdict, and the user sees a message explaining why the request was blocked. You also control what happens in the rare case a verdict doesn’t return in time — block the request or let it through unevaluated.

claude inference hooks demoimage-20260803221900-2

 Prevention and detection, working as one

Checking a prompt before the model sees it, instead of reviewing it after, sounds like a small change. In practice, it helps close an important gap between the two halves of the same package.

Detection, through Claude’s Compliance API, gives you visibility into supported conversations, an audit trail, and the ability to review and act. Prevention, through inference hooks, can block policy-defined sensitive prompts before the model processes them. You don't choose between them. They ship together and work together: detection provides visibility into supported activity, while prevention can block configured policy violations before model processing.

That combination changes the day-to-day in three ways. Policy-defined sensitive prompts can be blocked at the policy check, so the data does not reach the Claude model when the applicable policy returns a “deny” verdict. A blocked prompt typically does not generate a downstream alert, which may help reduce the review queue to cases that require human review. When a prompt is blocked, the employee sees an explanation immediately, which can help turn each block into a teachable moment that may encourage safer habits over time.

What this looks like day to day

  • For most employees, nothing changes. They use Claude in substantially the same way they do today, with typically nothing new to learn. The check runs in the background, and users typically notice it only if a prompt is blocked.
  • Coverage where network tools can’t reach. The check runs inside Claude’s infrastructure, rather than on your network, which can enable consistent policy evaluation whether someone is using a managed laptop or certain unmanaged devices.

What this means for your organization

For most organizations, the hard part of AI security isn’t writing new rules — it’s extending the ones you already trust to a new surface, fast enough to matter. That’s what this integration is designed to deliver: your existing Proofpoint DLP policies can be applied to Claude prompts in real time, helping block policy-defined sensitive prompts before model processing. In many deployments, no new console, no new policy language, and no separate AI security stack to stand up and maintain.

Proofpoint customers using Claude Enterprise may be able to deploy this capability today using their existing DLP policy, and availability is expected to continue expanding through the rest of the year. If you’d like to see it in action, reach out to your Proofpoint account team.

Frequently asked questions

  • What is inference hooks? Inference hooks is a capability from Anthropic that lets an organization check a Claude prompt against its own security policy before the model processes it, and can block the prompt if it violates that policy. Anthropic’s published inference hook documentation.
  • How does this relate to the Compliance API integration Proofpoint announced in May — does it replace it? They work together. The Claude Compliance API helps identify policy violations after Claude has already responded, giving you visibility, audit trails, and the ability to review and act after the fact. Inference hooks check the prompt before Claude processes it, so policy-defined prompts may be blocked in real time — before the model processes them. Inference hooks add prevention on top of the visibility the Compliance API already provides; it doesn’t replace it.
  • Does this check what Claude sends back, or only what employees send in? Inference hooks apply to what employees send in. The check runs on the prompt before the model processes it, enabling real-time blocking when a prompt matches configured policy. For the response side, the Compliance API provides visibility into what Claude returned, along with the ability to review and act on it. Used together, the two provide complementary visibility into the inbound and outbound portions of a conversation.
  • If a prompt is blocked, does it still leave the device? Where does it go? When enforcement is on, the prompt leaves the Claude client and travels to Anthropic’s infrastructure, which — as Anthropic describes it — forwards it to Proofpoint for a policy check before any model runs. If the verdict is deny, the Claude model does not process the prompt, no response is generated, and the request stops at the policy check. In other words, the check happens in the request path, and a blocked prompt does not reach the Claude model.
  • Does this add latency?  For most employees, any additional latency is expected to be minimal. The check runs while the prompt is already in transit to Claude, and the timeout is configurable, so the interaction is generally expected to remain responsive. If a verdict doesn't return in time, your configured failover applies: the request is either blocked or allowed through unevaluated. If you choose to allow, the Compliance API captures supported conversation data, so requests that pass without a verdict remain available for subsequent review.
  • What does an employee see if a prompt is blocked, and who controls that message? A plain-language message explaining that the request was blocked, rather than a Claude response. The wording comes from your policy — so instead of a generic error, it can point the employee to the right guidance.
  • Does this replace network-based AI security tools like a proxy or CASB? No. Those tools remain useful for other purposes. What inference hooks add is coverage for usage that some network tools may not fully observe—such as Claude Code sessions on unmanaged devices—because the check happens inside Anthropic’s own infrastructure rather than on the network.
  • Which Claude surfaces does this cover? Inference hooks are supported across Claude Enterprise products, including chat, Claude Cowork, Claude Code, and more.
  • Is this available now? Yes, for eligible Proofpoint customers using Claude Enterprise, with availability expected to continue expanding through the rest of the year.