Protect Enterprise Data Used by AI

Updated

Control what enterprise data AI can read and share — discover where sensitive data and oversharing create AI risk, classify and label it, prevent its loss to AI apps and agents, and govern its lifecycle.

When Copilot and AI agents ground on your organization's data, every weakness in data security becomes an AI risk: oversharing surfaces sensitive files in a prompt, and unsanctioned AI apps become an exfiltration path. This topic works the data itself as a single motion. Start by discovering where sensitive data, oversharing, and AI usage create risk. Classify and label that data so protection travels with it. Enforce data-loss boundaries across Copilot, agents, managed endpoints, the Edge browser, and the non-Microsoft browsers and apps users reach on their own. Finally, govern how long AI interactions and their source content are retained, archived, or deleted. Detecting and responding to risky AI data activity builds on this foundation and is covered under Prevent, detect & respond.

How to address Protect Enterprise Data Used by AI

  1. Discover Sensitive Data and AI Risk

    Start with visibility — find where sensitive data, oversharing, AI interactions, and unsanctioned AI usage create risk before choosing controls.
    Discover Sensitive Data and AI Risk
    Microsoft Purview Data Security Posture Management
    SharePoint Advanced Management
    Microsoft Purview
    Microsoft Purview Compliance Manager
    Microsoft 365 Admin Center
    Purview DSPM AI Interaction Discovery Users Oversharing Discovery Reports Data AI and Agent Activity Audit Agents Users Data AI Regulation Assessments Agents Data Copilot Security Dashboard Users Data
  2. Classify and Label Data Feeding AI

    Establish the information-protection foundation AI controls depend on — classify sensitive data and apply labels so protection travels with the content agents and Copilots ground on.
  3. Prevent Data Loss to AI Apps and Agents

    Turn classification and labels into enforcement boundaries for Copilot, agents, prompts, grounding data, and the browser-based AI apps users reach on their own.
  4. Govern AI Data Lifecycle and Retention

    Decide how long AI prompts, responses, and related evidence are kept, deleted, preserved, or removed from active AI grounding.

Control coverage

Control coverage for Protect Enterprise Data Used by AI — where its 19 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Data Protection
14
Compliance
7
Governance
6
Monitoring
5
Discovery
2

Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.

Identity & Access
2

Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.

Network Protection
1

Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.