← All articlesPurview

Microsoft Purview DSPM for AI: Governing Copilot Prompts and Data Exposure

Ishfaq Nazir · Microsoft & Azure Cloud Security Architect 10/10/2026 11 min read

The new data boundary: prompts and responses

Every Copilot prompt and response is a new data flow. Users can paste confidential data into third-party AI tools, and Microsoft 365 Copilot can surface any content a user already has access to. Microsoft Purview Data Security Posture Management (DSPM) for AI — formerly the AI Hub — gives you visibility and control over that flow.

1. What DSPM for AI provides

  • Discovery of AI usage: Microsoft 365 Copilot, Copilot Studio agents, and 100+ third-party generative AI sites (ChatGPT, Gemini and others).
  • Reports on sensitive information types in prompts, sensitivity labels referenced in responses, and risky users.
  • One-click policies that deploy DLP, Insider Risk and Communication Compliance controls.
  • Data assessments that identify overshared SharePoint sites before Copilot exposes them.

2. Prerequisites

  1. Microsoft 365 E5 or E5 Compliance (some features pay-as-you-go).
  2. Unified audit log enabled.
  3. Devices onboarded to Endpoint DLP for browser-based AI monitoring.
  4. Microsoft Purview browser extension for Edge/Chrome to capture third-party AI activity.
  5. Roles: Purview Compliance Administrator or Data Security AI Admin.

3. Quick-start: recommended policies

In the Purview portal go to DSPM for AI → Recommendations and enable:

  • "Detect sensitive info added to AI sites" – a collection policy capturing prompts sent to third-party AI.
  • "Detect risky AI usage" – an Insider Risk policy for prompt injection attempts and access to protected materials.
  • "Detect unethical behaviour in AI apps" – Communication Compliance for harmful content.
  • "Block sensitive info from AI sites" – Endpoint DLP to block pasting or uploading sensitive data to unmanaged AI.

Start in audit mode for two weeks, review the activity explorer, then switch to block-with-override.

4. Sensitivity labels and Copilot

Copilot honours sensitivity labels and encryption:

  • Copilot only uses labelled content if the user has EXTRACT and VIEW usage rights.
  • Responses and newly created documents inherit the most restrictive label of the source content.
  • Labels are shown as citations in Copilot Chat.

Recommended actions:

  1. Enable default labelling for SharePoint document libraries.
  2. Configure auto-labelling for credit card, national ID and health data.
  3. Use a DLP policy with the Microsoft 365 Copilot location to exclude items labelled Highly Confidential from Copilot processing entirely.

5. Oversharing assessments

Copilot does not change permissions — it simply makes existing oversharing discoverable. Run a data risk assessment in DSPM for AI to find the top 100 SharePoint sites by usage and flag:

  • Sites shared with Everyone except external users.
  • Files with anyone-links.
  • Sensitive content without labels.

Remediate with SharePoint Advanced Management: restricted access control, site access reviews, and Restricted Content Discovery to hide specific sites from Copilot.

6. Auditing and investigation

Copilot interactions are recorded as CopilotInteraction events in the unified audit log, including the app, accessed resources and labels. Use:

  • Activity explorer for trends.
  • eDiscovery (Premium) to search and hold prompts and responses.
  • Data lifecycle management retention policies for Copilot interactions.

Example audit search via PowerShell:

Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-7) -EndDate (Get-Date) `
  -RecordType CopilotInteraction -ResultSize 5000 |
  Select-Object CreationDate, UserIds, Operations

7. Operating model

| Cadence | Activity | |---|---| | Weekly | Review DSPM for AI reports and DLP alerts | | Monthly | Oversharing assessment, label coverage metrics | | Quarterly | Review AI app allow/block list and policy tuning |

Conclusion

Copilot is only as safe as your data estate. DSPM for AI gives you a single place to see AI usage, apply labels and DLP, and prove to auditors that sensitive data is governed — before, during and after Copilot rollout.

#Purview#Copilot#DSPM for AI#DLP#Data Security

Related articles