How to stop AI from seeing files a user can't open
Short answer: open files as the person, not with a service account. If the AI reads your shares with its own account, it can find anything that account can, including folder names like "Layoffs 2027". When every file call carries the asking person's own Windows identity, the NTFS rights you already set decide, exactly as they do in Explorer. Add Access-Based Enumeration so names of folders they can't open are hidden too.
Step 1: see what a person can actually open
Start from the rights that already exist. On the file server:
- Right-click the folder (for example
HR) → Properties → Security → Advanced → Effective Access. - Select a user, pick the person, then View effective access. That is exactly what their AI should be able to do.
- For the share itself: Server Manager → File and Storage Services → Shares, right-click the share → Properties → Permissions.
Command line
# Who may open the HR folder, and how (NTFS) icacls "D:\Shares\Data\HR" # The share's own permissions Get-SmbShareAccess -Name Data # Is Access-Based Enumeration on? (AccessBased = hidden when you can't open it) Get-SmbShare -Name Data | Select-Object Name, FolderEnumerationMode
Which drives does Group Policy give them? In Group Policy Management, edit the drive-mapping policy and look under User Configuration → Preferences → Windows Settings → Drive Maps (check each map's Common → Item-level targeting for the groups it applies to). On the person's PC, File Explorer → This PC shows the result.
Command line
net use gpresult /r /scope:user
Step 2: hide what people can't open
Without Access-Based Enumeration, Windows lists every folder name in a share, even ones the person can't open. A human shrugs at a locked folder; an AI that lists the share learns the name and may repeat it. Turn ABE on for shares that hold sensitive folders:
- Server Manager → File and Storage Services → Shares.
- Right-click the share → Properties → Settings.
- Tick Enable access-based enumeration and click OK. Takes effect at once.
Command line
Set-SmbShare -Name Data -FolderEnumerationMode AccessBased -Force
Step 3: make the AI open files as the person
This is the part most AI file connectors skip. They index or read the share with one powerful account, then try to filter the results afterwards. Filtering after the fact misses things: cached text, file names in search results, snippets in a summary.
Acutis Gate takes the other route. On the on-prem editions (Linux appliance or Windows Server) every folder listing, search and file read is made with the asking person's own Windows identity, through Kerberos constrained delegation set up by the installer. So:
- Your NTFS rights decide. If they couldn't open it in Explorer, their AI can't read it.
- Only their mapped drives. Gate reads the drive maps you already publish (Group Policy drive maps with their targeting, home drives, simple
net uselines in logon scripts) and refuses paths outside them, even on a share they could technically reach. - Hidden means hidden. On shares without ABE, Gate removes folders and files the person can't open from listings and searches before the model sees them, names included. The audit trail records only a count.
Here is the same question from two people, answered by their own permissions:
msmith (Finance) list S:\ -> Finance\ (1 hidden)
search "layoff" -> 0 matches
trail: decision=allow ran_as=CORP\msmith hidden: 1
lchen (HR) list S:\ -> HR\ (1 hidden)
search "layoff" -> HR\Layoffs 2027\layoff-list.txt
trail: decision=allow ran_as=CORP\lchen
To check your setup in Gate, open Health check → Run all checks: it reads a share as a real person, names the shares that need ABE switched on, and marks the first problem Start here with the fix. Every file call lands in the Audit trail, which you can stream to your SIEM.
Each person's AI sees their drives, only what they can open
Gate opens file shares as the person, only on the drives Group Policy maps for them, and keeps hidden names away from the model.
Start a 14-day trial Tour the live GateFrequently asked questions
Can an AI assistant respect NTFS permissions?
Only if it opens files with the asking person's identity. A connector that reads shares with a service account sees what that account sees. Acutis Gate opens each file as the person through Kerberos delegation, so NTFS decides.
What is Access-Based Enumeration?
A Windows share setting that hides files and folders a person cannot open from directory listings. Turn it on with Set-SmbShare -FolderEnumerationMode AccessBased. Without it, people (and their AI) can see the names of folders they cannot open.
Will the AI learn the names of folders I can't open?
Not through Gate. Gate removes them from listings and searches before the model sees them, and the audit trail records only how many were hidden.
Does this need a file indexer or a copy of our data?
No. Gate reads shares live, as the person, when the AI asks. Nothing is copied into a separate index.
Acutis