Protect Enterprise Data Used by AI
Control what enterprise data AI can read and share — discover where sensitive data and oversharing create AI risk, classify and label it, prevent its loss to AI apps and agents, and govern its lifecycle.
When Copilot and AI agents ground on your organization's data, every weakness in data security becomes an AI risk: oversharing surfaces sensitive files in a prompt, and unsanctioned AI apps become an exfiltration path. This topic works the data itself as a single motion. Start by discovering where sensitive data, oversharing, and AI usage create risk. Classify and label that data so protection travels with it. Enforce data-loss boundaries across Copilot, agents, managed endpoints, the Edge browser, and the non-Microsoft browsers and apps users reach on their own. Finally, govern how long AI interactions and their source content are retained, archived, or deleted. Detecting and responding to risky AI data activity builds on this foundation and is covered under Prevent, detect & respond.
How to address Protect Enterprise Data Used by AI
-
Discover Sensitive Data and AI Risk
Start with visibility — find where sensitive data, oversharing, AI interactions, and unsanctioned AI usage create risk before choosing controls. -
Classify and Label Data Feeding AI
Establish the information-protection foundation AI controls depend on — classify sensitive data and apply labels so protection travels with the content agents and Copilots ground on.Classify and Label Data Feeding AI Microsoft PurviewMicrosoft Purview Information ProtectionMicrosoft Purview Data Security Posture ManagementSensitive Information Types and Classifiers Data Users Sensitivity Labels for AI Data Protection Data Users Purview DSPM AI Interaction Discovery Users -
Prevent Data Loss to AI Apps and Agents
Turn classification and labels into enforcement boundaries for Copilot, agents, prompts, grounding data, and the browser-based AI apps users reach on their own.Prevent Data Loss to AI Apps and Agents Microsoft Purview Data Loss PreventionSharePoint Advanced ManagementMicrosoft Purview Insider Risk ManagementMicrosoft Purview Information ProtectionDLP for Microsoft 365 Copilot and Agents Data Agents Endpoint DLP for AI App Uploads Users Data Browser Data Security for AI Prompts in Edge Users Data Network Data Security for AI Traffic Users Data Restricted Content Discovery Data Agents Restricted Access Control Data Users Agents Adaptive Protection for AI Risk Users Copilot Response Label Inheritance Data Agents Users -
Govern AI Data Lifecycle and Retention
Decide how long AI prompts, responses, and related evidence are kept, deleted, preserved, or removed from active AI grounding.Govern AI Data Lifecycle and Retention Microsoft Purview Data Lifecycle ManagementMicrosoft PurviewMicrosoft 365 ArchiveMicrosoft Purview Compliance ManagerAgent Interaction Retention Agents eDiscovery for Agent Interactions Agents Data Communication Compliance for AI Interactions Users Data Inactive Content Archiving Data AI Regulation Assessments Agents Data
Control coverage
Data Protection14
Mechanisms that protect data confidentiality and integrity at rest, in transit, and during processing within AI workloads — including encryption, sensitivity labeling, and data loss prevention.
Compliance7
Controls that help organisations meet regulatory and policy obligations for AI systems, including audit trails, data residency, and policy enforcement.
Governance6
Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.
Monitoring5
Continuous observability of AI workload behaviour, usage, and anomalies through logging, metrics, and alerting — enabling detection of drift, misuse, and security events.
Discovery2
Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.
Identity & Access2
Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.
Network Protection1
Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.