Detect & Respond to AI Data Risk

Updated

Turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response — bridged into Microsoft Defender XDR and Microsoft Sentinel.

Preventing data loss reduces AI risk but never eliminates it. This topic closes the loop on the data that still moves. It captures the prompt-and-response audit trail every investigation starts from, identifies users whose AI behavior signals risk, flags regulated or inappropriate content in prompts and responses, and drives response when an agent is attacked or sensitive data is exposed. Insider-risk and threat signals correlate into Microsoft Defender XDR, and Copilot and AI activity join broader telemetry in Microsoft Sentinel for end-to-end hunting and response.

How to address Detect & Respond to AI Data Risk

  1. Detect and Respond to Risky AI Data Activity

    Close the loop — turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response, bridged into Defender XDR and Sentinel.

Control coverage

Control coverage for Detect & Respond to AI Data Risk — where its 7 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Monitoring
6
Compliance
3

Controls that help organisations meet regulatory and policy obligations for AI systems, including audit trails, data residency, and policy enforcement.

Incident Response
2

Capabilities that support detection, investigation, containment, and recovery for security incidents involving AI workloads — including automated response playbooks, forensic telemetry, and remediation guidance.

Threat Detection
2

Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.

Discovery
1

Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.

Governance
1

Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.