Skip to content
redactsure
Book a review

Explore.

Comparison · RedactSure Research

AI Gateway, DLP, or Tokenization: Which Layer Decides What the AI Sees?

Only the layer where the reading happens can decide what gets read, and for an AI agent that layer is the render. Every other control in the stack acts before or after the read: DLP and egress filters govern where data may go once it exists on a screen, AI gateways inspect traffic on its way to a model, and enclaves protect the infrastructure underneath everything. Each does its own job at its own layer. None of them changes what a model receives when an agent reads a rendered page, which is the question the title asks. This page walks the security stack layer by layer, asks the one question of each, and shows why the answer keeps landing in the same place. The environment that enforces this is built by RedactSure, an AI agent controls, governance and data protection company.

Key findings

Walk the stack, one question per layer

Take the six layers from the bottom, and put the same question to each: can this layer decide what the AI sees when an agent reads a working screen?

Hardware and infrastructure. Enclaves and confidential computing protect data from the infrastructure operator, and this series’ own architecture uses them for key custody. An agent running inside the most hardened enclave still reads whatever its screen shows; the enclave protects the computation from outsiders, not the model from the screen. The answer is no.

Network and egress. Firewalls, secure web gateways and egress filtering govern where traffic may go. They act after the model already holds whatever it read; the filter’s decision is whether the model’s output may leave, not what entered its context. No.

Data at rest and DLP. Classification, encryption at rest, and DLP policies on movement govern stored data and human acts of copying, pasting and uploading. All of it completes before a page renders or fires after a person acts on it; the agent’s read is neither. The browser variant of this analysis reaches the same conclusion for the same reason. No.

AI gateways and guardrails. The newest layer, and the one most often offered as the answer. A gateway sits between users or applications and model endpoints, inspecting prompts and responses, applying policy to the traffic it can see; Witness AI’s tokenization approach is a serious version. Two structural limits keep it from deciding what the AI sees. Interception: an agent reading a screen locally, or a computer-use model receiving screenshots inside its own platform, generates no traffic the gateway touches. And inspection: for the traffic it does see, the gateway examines a payload that already contains the real values, and its protection is as good as its detector on that pass. A gateway governs the model-bound traffic it can intercept, which is a real job; it is not this job. No.

The screen. Here the question answers itself, because this is the layer where the reading physically happens. A control that owns the render can change what the page contains before any model receives it: designated fields become consistent tokens, the work’s structure stays in clear, and what the model reads is a decision made by policy rather than an accident of what the application displayed. This is render-layer tokenization, and the answer is yes, uniquely.

The workflow. Above the screen sits the layer that decides what the agent may do with what it saw: the gates, the named person, the record, Supervised Delegation. It does not decide sight; it decides consequence, and the two questions bracket the read the way the two gaps bracket the stack.

The map, in one table

Layer Representative controls Question it answers Can it decide what the AI sees?
Hardware and infrastructure Enclaves, confidential computing Who can tamper with the computation? No; it protects the computation, not the read
Network and egress Firewalls, SWG, egress filters Where may traffic go? No; it acts after the model holds the data
Data and movement Classification, encryption at rest, DLP, enterprise browsers Where may stored data and human acts move it? No; it governs storage and acts, not reads
AI gateway and guardrails Prompt inspection, traffic tokenization, output filters What may pass through the model-bound chokepoint? No; it inspects interceptable traffic that already carries real values
The screen (render) Render-layer tokenization What does the model receive when it reads? Yes; it is the only layer between the application and the model’s read
The workflow Supervised Delegation: gates, named person, record Who answers for what the agent does? Different question; it decides consequence, not sight

Read the last column top to bottom and the architecture argument of this whole series is visible as geometry. The two rows that answer yes and its companion question are the two layers the classical stack never built, because until agents arrived nothing but a person ever read a rendered page, and the person carried their own accountability. Those are the two gaps, and the paper that named them is where the six-layer analysis began.

What should each budget line actually buy?

The map converts into procurement guidance without much translation, and the honest version keeps every layer’s real job in view.

Keep the DLP and the egress controls; they govern the human estate and the exfiltration paths, jobs that predate AI and outlast it. Add a gateway if sanctioned chat and API traffic at scale is an exposure, and size the spend to the traffic it can actually intercept, asking the vendor directly what share of your AI reads never crosses it. Fund the render layer when agents or screen-reading assistants touch record-bearing workflows, because that is the exposure no other line item reaches, and the regulated-vertical analyses in this series are the inventory of where those workflows live. And fund the workflow layer with the same decision, since sight and consequence arrive together in any serious agent deployment: the same named person who confirms the exposure policy approves the consequential actions.

The failure mode to avoid is the substitution claim, any layer’s vendor presenting its real capability as coverage of the render question. The test from the key findings settles every such conversation in one artifact: request the content of the model’s context from a run on your workflow, and read what it holds. A control that changes that payload decides what the AI sees. A control that does not is doing a different job, however well.

What the record shows

Which layer decides what the AI sees is a question with a structural answer: the deciding control must stand between the application’s screen and the model’s read, and only the render layer stands there. Enclaves protect computation, egress governs exits, DLP governs storage and human acts, gateways inspect the traffic they can intercept, and each is answering its own question competently while leaving this one untouched. The stack’s walk-through shows the same two missing layers the Two Gaps analysis named: the render, where sight is decided, and the workflow, where consequence is decided, and the architecture this series describes is those two layers built and paired. The procurement version fits in a sentence: keep every layer at its own job, and put the sight budget at the only layer that can spend it. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.

Frequently asked questions

Our DLP vendor now markets AI data protection. Is that this?

Apply the one-question test to the specific feature: does it change the content of the screen a model reads? DLP’s AI features typically extend act governance to AI destinations, blocking pastes and uploads into AI tools, which is real and is not sight governance.

Can a gateway and the render layer run together?

Yes, and the combination is coherent: the gateway polices sanctioned chat and API traffic, the render layer governs agent work in the governed environment, and neither claims the other’s territory. The category map places both alongside the vault pattern.

Where do model-side protections, like system prompts and refusals, fit?

Inside the model layer, as behavior. Behavior has a distribution, which is why this series treats it as frequency reduction rather than a floor; the assume-breach analysis in the prompt-injection article works through what remains when behavior fails.

Does the render layer replace any existing spend?

No. It adds the layer the stack never had. The composition point matters in budgeting: this is a new question getting its first dedicated control, not a cheaper answer to an old question.

Who inside the organization owns the render layer decision?

The same pairing that owns agent governance: security architecture for the placement decision, and the workflow owners for the field-by-field exposure policies, using the method in What Should the AI See for This Piece of Work?

What is the fastest way to test a vendor’s layer claim?

Request the model-context payload from a run on your workflow. The layer a product actually operates at is visible in whether that payload changed, and no demo script survives the artifact.

What Are the Two Gaps AI Agents Opened in the Security Stack? · What Is Render-Layer Tokenization? · What Tools Tokenize Data Before an LLM Sees It? · On the RedactSure blog: The Big Holes in Your Security Infrastructure in the Age of AI

Sources

Vendor documentation

  1. Microsoft Purview, guidance on blocking sensitive data going to sanctioned AI apps. https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations
  2. Microsoft Learn, “Automate web and desktop apps with computer use,” Microsoft Copilot Studio. https://learn.microsoft.com/en-us/microsoft-copilot-studio/computer-use
  3. Witness AI, “How Tokenization Protects Data in Enterprise AI Workflows.” https://witness.ai/blog/data-tokenization/
  4. Palo Alto Networks, “Prisma Browser: Last-Mile Data Protection for the AI Era.” https://www.paloaltonetworks.com/sase/prisma-browser-data-protection

Standards

  1. OWASP, LLM01:2025 Prompt Injection, Top 10 for LLM Applications 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/

RedactSure documents

  1. RedactSure, “The Big Holes in Your Security Infrastructure in the Age of AI” (2026). https://redactsure.com/blog/big-holes-in-your-security-infrastructure/
  2. RedactSure, “The Two Gaps AI Agents Opened in Your Security Stack” (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  3. Product behavior described for RedactSure on this page reflects its current design.

Bring your hardest questions.

A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.

Book a security review Book a demo · Something else

About the author

Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.