Copilot does not create an oversharing problem. It finds the one your file shares have had for a decade.
Microsoft states it directly: because of the power and speed AI can surface content, generative AI amplifies the problem and risk of oversharing or leaking data. Purview gives you the visibility and the controls, across Copilot, enterprise AI applications, and the consumer tools your staff use in a browser whether you sanctioned them or not.

- Three categoriesCopilot, enterprise AI apps, other AI apps
- EXTRACT rightWhat a label needs for Copilot to return data
- Prompts auditedCaptured in the unified audit log
- Browser DLPBlock pasting sensitive data into public AI sites
Seven things that determine whether your AI rollout is governed or merely deployed.
Three categories of AI application, not one
Copilot experiences and agents, covering Microsoft 365 Copilot, Security Copilot, Copilot in Fabric and Copilot Studio. Enterprise AI apps, covering non-Copilot applications connected through Entra registration, data connectors or Microsoft Foundry, and naming ChatGPT Enterprise and Anthropic Claude Enterprise. And other AI apps detected through browser activity, which is where consumer tools appear.
The shadow AI category, which is the one that worries people
Microsoft describes other AI apps as those detected through browser activity and categorised as generative AI in the Defender for Cloud Apps catalog, uniquely including applications from third-party large language models. It names ChatGPT, Google Gemini, the consumer version of Microsoft Copilot and DeepSeek. Most organisations have no visibility of any of this today.
Sensitivity labels, and the usage right that decides everything
Microsoft states that when a sensitivity label applies encryption, users must have the EXTRACT usage right as well as VIEW for AI apps to return the data. That single detail is what lets a label control whether Copilot can surface a document rather than only whether a person can open it, and it is frequently misconfigured or absent from existing label definitions.
A prerequisite most tenants have not met
Microsoft recommends enabling sensitivity labels for SharePoint and OneDrive, and states the consequence of not doing so plainly: when labels are not enabled for those services, the encrypted files Copilot and agents can access are limited to data in use from Office apps on Windows. That is a materially different protection posture from the one most organisations assume they have.
Endpoint DLP that reaches the browser
Windows computers onboarded to Purview can be configured with endpoint data loss prevention policies that warn or block users sharing sensitive information with third-party generative AI sites accessed through a browser. Microsoft published example is direct: a user is prevented from pasting credit card numbers into a public AI tool, or sees a warning they can override.
Prompts and responses are auditable, discoverable and retainable
Prompts and responses are captured in the unified audit log, including how and when users interact with the application, which Microsoft 365 service the activity took place in, references to files accessed during the interaction, and any sensitivity label on those files. They are stored in the user mailbox, which makes them searchable in eDiscovery and subject to retention policies.
Risky AI usage as an insider risk signal
Microsoft names a risky AI usage policy template in insider risk management, describing detection of risky usage including prompt injection attacks and accessing protected materials, with insights from those signals integrated into Microsoft Defender XDR. That gives AI misuse a route into the same investigation flow as any other insider risk indicator.
The permissions were always wrong. Copilot is just the first thing fast enough to notice.
Microsoft frames the risk precisely, and it explains why AI readiness work is almost entirely data governance work.
- Quoted: because of the power and speed AI can proactively surface content, generative AI amplifies the problem and risk of oversharing or leaking data.
- AI applications supported by Purview use existing controls to ensure data stored in your tenant is never returned to a user who does not have access to it. That is reassuring and it is not the problem. The problem is how many people already have access to things nobody intended.
- A SharePoint site shared with everyone in the organisation eight years ago was low risk when finding anything in it required knowing it existed. It is a different proposition when an assistant can summarise it in response to a plain-language question.
- The practical consequence is that the AI readiness project and the oversharing remediation project are the same project. Organisations that treat them separately deploy Copilot, discover the problem in week two, and pause the rollout.
Four things that keep an AI rollout moving rather than paused.
We look before we plan
Which AI applications are in use, what is overshared, and what sensitive data already appears in prompts. Every one of those answers changes the shape of the work, and building a rollout plan before knowing them produces a plan that gets revised in week two, usually in front of the people who approved it.
We check the label prerequisites nobody checks
Two specifically. Whether sensitivity labels are enabled for SharePoint and OneDrive, because without that the encrypted files Copilot can access are limited to data in use from Office apps on Windows. And whether encrypting labels grant the EXTRACT usage right, without which AI apps cannot return the data even to authorised users.
We warn before we block on consumer AI
Endpoint DLP can block pasting sensitive information into a third-party generative AI site, and it can also warn with an override. Starting with warn produces data about who needs what and why. Starting with block produces the same activity on a personal phone, where you have no visibility, no policy and no record.
We settle the retention and discovery questions early
Prompts and responses sit in the user mailbox, which makes them discoverable through eDiscovery and subject to retention policies. Deciding how long they are kept, and testing the eDiscovery query path before anybody needs it, is a small piece of work that is very awkward to do for the first time under legal pressure.
Four phases, and the visibility phase changes the plan every time.
- 01Weeks 1 to 3
See what is actually happening
Which AI applications are in use across all three published categories, including the browser-detected consumer tools nobody sanctioned. What data is genuinely overshared. Which sensitive information types appear in prompts and responses. This phase is deliberately observational, and it consistently produces the finding that reframes the project.
- Inventory across Copilot experiences, enterprise AI apps and browser-detected apps
- Oversharing exposure identified against the data that matters
- Sensitive information types found in prompts and responses
- A realistic picture of shadow AI usage, not an assumed one
- 02Weeks 4 to 8
Fix the data before enabling more AI
Sensitivity labels enabled for SharePoint and OneDrive, since without that the encrypted files Copilot can access are limited to data in use from Office apps on Windows. Label definitions checked for the EXTRACT usage right where encryption is applied. Then the oversharing remediation itself, which is the majority of the work.
- Sensitivity labels enabled for SharePoint and OneDrive
- EXTRACT usage right reviewed on every encrypting label
- Oversharing remediated on the highest-exposure sites first
- Labelling extended to the content that matters most
- 03Weeks 9 to 12
Put controls around consumer AI
Endpoint DLP policies on onboarded Windows devices that warn or block sharing sensitive information with third-party generative AI sites accessed through a browser. We generally start in warn mode with a business justification, because a hard block on day one drives people to a personal device where you have no visibility at all.
- Endpoint DLP policies scoped to the sensitive types that matter
- Warn with justification before any hard block
- Policy tips written so people understand rather than route around
- Approved alternatives communicated alongside the restriction
- 04Ongoing
Govern it like any other data
Prompts and responses audited in the unified audit log, discoverable through eDiscovery because they sit in the user mailbox, retained or deleted through retention policies, and reviewable through communication compliance. Risky AI usage detected as an insider risk signal, with insights integrated into Defender XDR.
- Retention decided for prompts and responses, not left undefined
- eDiscovery query path tested before it is needed
- Risky AI usage policy enabled where appropriate
- Compliance Manager AI regulatory templates assessed
Six UAE situations where AI data posture is the blocking issue.
A group that paused its Copilot rollout after the pilot
The most common story we hear. The pilot worked, somebody asked a question that surfaced a document they should not have seen, and the programme stopped. The remediation is oversharing work rather than AI work, and framing it that way is what lets the rollout resume with a defensible position rather than a delay.
A regulated firm that cannot let client data reach a public model
Endpoint DLP on Windows devices onboarded to Purview can warn or block users sharing sensitive information with third-party generative AI sites accessed through a browser. Combined with visibility of which AI applications are being used, that converts a policy statement into an enforced control with evidence behind it.
A firm asked what its staff have typed into AI tools
Prompts and responses are captured in the unified audit log, including how and when users interacted, which Microsoft 365 service the activity took place in, references to the files accessed, and any sensitivity label on those files. That is a real answer rather than a policy quotation, and it is available whether or not anybody has looked yet.
An organisation facing an eDiscovery request that touches AI use
Because prompts and responses are stored in the user mailbox, an eDiscovery case can search them when the mailbox is selected as a source. Microsoft publishes the exact query condition path, using a Copilot activity type condition that includes all Copilot and other AI application activity. Testing that path before it is needed is worth an hour.
A business worried about prompt injection and misuse
Insider risk management includes a risky AI usage policy template, which Microsoft describes as detecting risky usage including prompt injection attacks and accessing protected materials, with insights integrated into Defender XDR. That gives AI-specific misuse the same investigation path as any other insider risk signal rather than a separate process.
An organisation preparing for AI regulation
Compliance Manager provides regulatory templates to assess, implement and strengthen compliance requirements for generative AI applications, with Microsoft naming examples such as monitoring AI interactions and preventing data loss in AI applications. Which templates apply to a UAE organisation is a question we work through against your actual obligations.
How UAE organisations are governing AI use today.
| Feature | Governed AI posture | Copilot deployed, consumer AI banned on paper | No AI governance |
|---|---|---|---|
Copilot interactions audited | Yes | Available but unused | No |
Consumer AI usage visible | Yes | No | No |
Oversharing assessed before rollout | Yes | Rarely | No |
Sensitivity labels control AI access | Yes | Partly | No |
Pasting sensitive data into public AI blocked | Yes | No | No |
Prompts discoverable in eDiscovery | Yes | Untested | No |
Prompt retention decided | Yes | No | No |
Risky AI usage detected | Yes | No | No |
AI regulatory position assessed | Yes | No | No |
Answer to what did staff share with AI | Evidence | Assumption | None |
How each protection method behaves with AI applications.
| Protection method | Behaviour with AI apps | |
|---|---|---|
| Sensitivity label with encryption | Users need the EXTRACT usage right as well as VIEW for AI apps to return the data | |
| Sensitivity labels not enabled for SharePoint and OneDrive | Encrypted files Copilot and agents can access are limited to data in use from Office apps on Windows | |
| Azure Rights Management encryption without a label | VIEW and EXTRACT rights are still checked, but there is no automatic inheritance of protection for new items | |
| S/MIME protected email | Not returned by Copilot, and Copilot is not available in Outlook while such an email is open | |
| Password-protected documents | Cannot be accessed by AI apps unless already opened by the user in the same app, and the password is not inherited | |
| Customer Key or bring your own root key | Supported, and items are eligible to be returned by Copilot | |
| Endpoint DLP on onboarded Windows devices | Can warn or block sharing sensitive information with third-party generative AI sites accessed via a browser | |
| Sensitive information types and trainable classifiers | Used to find sensitive data in prompts and responses, surfacing in Purview reports and activity explorer |
Five steps, and the first one is where the surprises live.
- 1
Assess AI usage across all three categories
Copilot experiences and agents, enterprise AI applications connected through Entra registration, data connectors or Foundry, and other AI apps detected through browser activity and categorised as generative AI. That third category is where the uncomfortable findings sit, and most organisations have never looked at it.
- 2
Assess the data exposure that AI would amplify
What is overshared, what carries a label, what carries none, and what sensitive information types appear in prompts and responses today. Microsoft frames the risk as AI amplifying an existing oversharing problem rather than creating a new one, and the assessment is written that way so the remediation is scoped honestly.
- 3
Fix the protection prerequisites
Sensitivity labels enabled for SharePoint and OneDrive, since without that the encrypted files Copilot and agents can access are limited to data in use from Office apps on Windows. Encrypting labels checked for the EXTRACT usage right. Content protected by Rights Management without a label identified, since there is no automatic inheritance for new items.
- 4
Put controls around unsanctioned AI
Endpoint data loss prevention on onboarded Windows devices, warning or blocking the sharing of sensitive information with third-party generative AI sites accessed through a browser. Warn with business justification first, block where there is no legitimate use, and always with an approved alternative communicated at the same time.
- 5
Govern the interactions as data
Retention policies applied to prompts and responses, with conflicts resolved by the principles of retention. The eDiscovery query path tested. Communication compliance policies extended to AI interactions where message supervision applies. The risky AI usage insider risk template enabled. Compliance Manager AI regulatory templates assessed against your obligations.
What organisations ask about AI data security posture.
Fifteen questions worth answering honestly.
Visibility
- Which AI apps are actually in use?All three published categories.
- Do you see browser-based consumer AI use?That is the third category.
- What sensitive data appears in prompts?Classifiers surface this.
- What is overshared today?The answer predates Copilot.
- Are AI activities visible in activity explorer?There is a dedicated tab.
Protection
- Are sensitivity labels enabled for SharePoint and OneDrive?Without it, coverage is limited.
- Do encrypting labels grant EXTRACT?Required for AI apps to return data.
- Is any content protected without a label?No automatic inheritance for new items.
- Are endpoints onboarded to Purview?Required for browser DLP.
- Is there an approved AI tool people can use?Blocking without an alternative fails.
Governance
- How long are prompts and responses retained?Retention policies apply to them.
- Can you find them in eDiscovery?They sit in the user mailbox.
- Are AI interactions in scope for message review?Communication compliance covers them.
- Is risky AI usage monitored?There is a policy template for it.
- Which AI regulations apply to you?Compliance Manager has templates.
The pages around this one.
Find out what your staff are already typing into AI tools you never approved.
The third application category exists precisely for that question, and almost no organisation has looked. It is a short assessment and the result usually determines how the rest of the AI programme is sequenced.
Related Services
Explore more solutions that work great with this service
Data Discovery Audit
Where the sensitive data is, and who can reach it
Sensitivity Labels
Classification that travels with the file, and governs what Copilot sees
Endpoint DLP
USB, print, clipboard and browser controls on devices
Microsoft Copilot
AI-powered productivity with Copilot
Insider Risk Management
Data theft by departing staff, detected with users pseudonymised
Communication Compliance
Message review with pseudonymised usernames
Data Lifecycle Management
Retention policies, labels and defensible deletion
Microsoft Purview
Data governance and compliance solutions