
In Short: Copilot Is a Permissions Audit You Did Not Schedule
Microsoft 365 Copilot answers from whatever the asking user can access. Not what they should access: what they can. Which means every casually shared site, every "Everyone" link from years past, every HR spreadsheet parked in the wrong library is now one well-phrased prompt away from a summary. The permissions did not change; the retrieval got better, and that is precisely the problem.
Purview DSPM for AI (Data Security Posture Management for AI) is Microsoft's tooling for facing that reality before users do: visibility into AI interactions, assessments that locate oversharing, and policies to close the gaps. Treat it as the security workstream of any Copilot rollout, not an optional extra.
What DSPM for AI Actually Shows You
The capability answers three questions security teams could not previously answer.
- Who is using AI, and which AI? Interactions with Copilot experiences and, importantly, with third-party AI sites, so shadow usage becomes visible instead of anecdotal
- What sensitive data is reaching AI? Prompts and responses evaluated against sensitive information types: credit cards, identifiers, credentials, whatever your classifiers detect
- Where is the oversharing? Assessments that scan the estate for the structural risks Copilot amplifies: sites shared too broadly, sensitive content without labels, permissions that drifted far from intent
From the findings, recommended policies apply the fixes: DLP for AI interactions, adaptive protection tied to insider risk levels, restrictions on unlabelled content reaching AI surfaces.
The Pre-Rollout Fix List
Across estates we have reviewed, the same short list does most of the work.
Find and fix broad sharing. The assessments surface the sites and libraries whose sharing says Everyone or the whole company. Most are historical accidents. Fixing the worst fifty is usually a fortnight of unglamorous work that removes the majority of realistic exposure.
Label the estates that matter. Finance, HR, legal, executive, M&A: sensitivity labels with protection on these estates mean Copilot's behaviour degrades gracefully even when permissions are wrong, because label-based encryption keeps protected content out of answers. Labelling everything is a multi-year programme; labelling the four estates that end up in headlines is a quarter.
Put DLP on the AI channel. Policies that block or warn when sensitive types flow into prompts - especially to consumer AI sites - convert an invisible leak into a coaching moment.
Verify, then pilot. Roll Copilot to a pilot group whose data posture you have actually checked, watch the DSPM telemetry, and expand on evidence. This is the same staged discipline we recommend for Copilot in the BI estate, applied to documents.
The Fabric Side of the Same Coin
Everything above has a structured-data twin. Fabric and Power BI AI features honour workspace permissions, row-level security and Purview policies, so the exposure question becomes: are those correct? An RLS gap that once produced a quiet support ticket now produces a fluent conversational answer, which is why testing security under AI access belongs in every rollout plan, and why agent identity governance matters as agents join the population of things that can ask.
Purview is the connective tissue: labels classify, policies protect, and the governance framework spans documents and data. AI did not create the need; it removed the comfortable assumption that badly governed data would at least stay hard to find.
The Honest Framing for Leadership
The uncomfortable truth worth saying in the steering meeting: Copilot readiness is mostly data security debt repayment. The AI is ready; the estate usually is not. The good news is that every fix - permissions, labels, DLP - was worth doing anyway, protects against more than AI, and comes with tooling that finds the problems for you. The organisations that skip this step become the cautionary tales that make everyone else's business case.
Sources and Further Reading
- Microsoft Purview data security posture management for AI
- Microsoft 365 Copilot overview
- Sensitivity labels overview
Frequently asked
Data Security Posture Management for AI: the Purview capability that gives security teams visibility into AI interactions - which users prompt which AI apps, what sensitive data flows through those interactions - plus assessments that surface oversharing risk and one-click policies to reduce it.
Copilot answers from everything the user technically can access, including the finance folder shared to Everyone in 2019 that nobody remembered. Search made that data findable in theory; Copilot summarises it on request in practice. The permissions did not get worse; the retrieval got dramatically better.
No. Copilot honours permissions and label protections: content a user cannot open does not inform their answers, and label-based encryption keeps protected content out of scope. The risk is not bypass; it is that existing permissions are far looser than anyone believed, and labels are missing where they matter.
Run the DSPM for AI assessments, find the sites and libraries shared too broadly, fix the worst permissions, label the sensitive estates (finance, HR, legal, M&A), and put DLP policies on the labels. Then pilot Copilot with a group whose data posture you have verified and expand from evidence.
Yes. Purview labels and policies extend across Fabric, and AI features there respect workspace permissions and row-level security. The same principle holds everywhere: AI access is governed access, so the governance itself has to be correct before AI makes it fast.


