Data governance & privacy
Microsoft Purview Data Security Posture Management for AI
Microsoft's Purview module that reports on how organizational data is used by Copilot experiences, agents and third-party AI sites, surfaces oversharing risk, and applies ready-made data-loss policies to AI prompts. Coverage of non-Microsoft AI sites depends on device onboarding and a browser extension, so unmanaged endpoints stay invisible.
commercial · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Data governance & privacy · Agent discovery & inventory · Runtime authorization & controls
Useful conversation with: CISO, Data protection officer, Microsoft 365 administrator.
Ask for a demonstration
Show me the Apps and agents dashboard listing every agent in my tenant, the sensitive data each one accessed, and which Purview policy protected it.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
Provides reports on Copilot experiences and agents, enterprise AI apps and other AI apps, including an Apps and agents dashboard showing sensitive data accessed by each agent.
Limit: Documentation does not quantify detection accuracy or state which agent frameworks outside Microsoft are inventoried.
Source s1
Documented by provider
Includes data risk assessments to identify, remediate and monitor potential oversharing of data to AI apps.
Limit: Source does not describe remediation guarantees or scope beyond Microsoft 365 content.
Source s1
Documented by provider
Discovery of user activity on third-party generative AI sites requires the Purview browser extension and devices onboarded to Purview.
Limit: Implies no coverage for unmanaged or non-onboarded devices.
Source s1
Documented by provider
Where AI apps support agents, those agents inherit the same security and compliance capabilities as the parent AI app.
Limit: Source lists supported AI app categories but does not enumerate per-agent control differences.
Source s2
Limitations to discuss
- The primary documentation page is labelled '(classic)', so feature parity with any newer DSPM for AI experience is unclear.
- Depth of coverage for non-Microsoft agent runtimes is not established by the sources fetched.
Sources
- Learn about Data Security Posture Management for AI · Microsoft Learn · official docs
Access date reported by researcher: 2026-09-06 - Microsoft Purview data security and compliance protections for Microsoft 365 Copilot and other generative AI apps · Microsoft Learn · official docs
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction