Wednesday, August 19, 2026 · Week 34 DE · EN · FR · ES Dark
Expert Opinions

When Staff Feed Customer Data to ChatGPT

Sensitive customer data ends up in public AI tools daily without anyone noticing.

By Alec Chizhik May 6, 2026 8 min read
When Staff Feed Customer Data to ChatGPT

8 min read

Sensitive customer data lands daily in public AI tools without anyone noticing. Microsoft is now adding a protective layer directly to the prompt entry, and IT leaders in mid-sized businesses must decide whether to take action or continue improvising.

06.05.2026

Key Takeaways

  • DLP moves to the prompt layer: Sensitive information types are evaluated before the Copilot call. If you only mapped DLP to SharePoint and Exchange, you won’t see prompt traffic.
  • Agent 365 is GA, with new telemetry: Agent inventory, risk classes per agent, and insider risk hooks go live in May. Custom Copilot Studio agents are included, but external agent frameworks are not.
  • Shadow AI gets an audit path: Network data security plus enterprise browser hooks capture prompts to unmanaged AI. The data lands in the same DSPM dashboard as Copilot telemetry, changing reporting requirements.

Related:A2A Protocol 1.2 in Production  /  AWS and Google Cloud Multicloud Preview

What really changed in May 2026

What is Microsoft Intelligent Purview? Microsoft consolidates the generally available data and compliance platform introduced in May 2026 under Intelligent Purview, combining classification, DLP, posture management, and agent governance in a console. New is the real-time evaluation of AI prompts and agent responses against sensitive information types, combined with a unified DSPM view across Microsoft 365 and external data sources.

While the headline is Intelligent Purview, the real game-changer happens in two steps. First: DLP for Microsoft 365 Copilot has been generally available since the end of April 2026, concluding the public preview that started in November 2025. Second: In May, the new unified DSPM console is launched alongside the general availability of the Agent 365 compliance protection layer. Together, these form what Microsoft calls its central AI security cockpit.

For cloud architects, this is more than a console refresh. DLP now works before the model call, not after storage. If an employee types a contract clause or credit card number into the Copilot prompt, the policy blocks the prompt before it reaches the foundation model. This applies to M365 Copilot, Copilot Chat, and inline DLP extensions for custom-built Copilot Studio agents.

A small but significant detail change: Licensing hurdles are gone. Until December 2025, you needed E5 or a dedicated compliance add-on to activate prompt DLP. With the April rollout, the feature is available in every Copilot license, including E1 and E3 tenants with Copilot add-on. This changes the negotiation dynamics with Microsoft, as a commonly used upsell argument disappears.

Three Architecture Points Teams Need to Catch Up On Now

If you’ve been thinking of DLP as file classification, you have a conceptual issue. The prompt is not a file. It’s fleeting, often lasting under two seconds, and is the point where clear text data can leave the tenant. Three areas are shifting with the new cut.

Firstly, classifier hygiene. Sensitive Information Types (SITs) are now evaluated within the prompt. If you’ve set up custom SITs with loose regex patterns, you’ll produce a flood of false positives in prompt DLP because employees don’t phrase their prompts as strictly as they do in stored documents. A stress test with the last 1,000 Copilot prompts from the audit logs helps before rollout. Microsoft provides the Activity Explorer and Search-with-AI in Data Security Investigations for this purpose.

Secondly, the agent inventory. With Agent 365 GA, compliance teams gain a complete list of all Copilot Studio agents in the tenant for the first time, including risk scores. This list is often longer than expected. In typical DACH tenants with over 5,000 employees, 80 to 200 productive or semi-productive agents may appear. Each agent must be associated with a data class, data source, and a DLP profile; otherwise, the tenant default inheritance logic will either block too much or too little.

Thirdly, the shadow AI layer. Network Data Security has been generally available (GA) for third-party SASE since November 2025 and is in public preview for Microsoft Entra GSA Internet Access. This means ChatGPT, Claude, Mistral, or self-hosted LLM proxies will appear in the same DSPM dashboard as Copilot. Those who pull the trigger will get a tangible picture for the first time of how many prompts actually go to external models each day. The numbers are often uncomfortable.

100
Top SharePoint Sites per Tenant Automatically Assessed Weekly for Data Risks by DSPM for AI Since May 2026. Previously, sites had to be manually maintained.
Source: Microsoft Learn, Considerations for Deploying DSPM for AI, May 2026

What a 60-Day Activation Looks Like in Practice

A full migration to prompt-centric DLP requires more than just setting a policy. The sequence is crucial because a misstep in the first week can fill the next six weeks with tickets. A realistic timeline for medium-sized DACH tenants with 2,000 to 10,000 seats.

60-Day Plan: Prompt-DLP plus Agent-Governance
Week 1-2
Audit log export of the last 1,000 Copilot prompts. Test SITs against real prompt language, measure false-positive rate per class. Move custom SITs with hit rate over 12% to audit mode, not block mode.
Week 3-4
Agent inventory via DSPM AI observability. For each agent: data source, data class, responsible party, DLP profile. Decommission agents without owners, rather than blocking them outright.
Week 5-7
Activate block mode for the two or three highest SIT classes, such as credit cards and customer identifiers. Customize notification templates in-house to avoid tickets escalating to the management team.
Week 8-9
Enable network data security for shadow AI. Keep output in audit mode for four weeks, then discuss policy based on actual volume, not intuition.
From Week 10
Lay insider risk hooks on risky agent templates. Conduct quarterly review of DSPM risk scores, document and transfer to internal audits.

// Key point

Sensitive customer data lands in public AI tools every day without anyone noticing.

What Breaks, What Works in Tenant

The pipeline is solid, but there are friction points often depicted in the roadmap documentation. Three examples from productive setups that delay migration.

What Breaks

  • Custom-SITs from 2023 with broad regex patterns generate prompt false positives for routine texts.
  • External agent frameworks outside of Copilot Studio are invisible in the inventory, even though the reporting appears complete.
  • Inline DLP for Copilot Studio agents is still in public preview in May, so it can only be used for regulated workloads with compliance function approval.
  • Network Data Security requires active Entra GSA or a third-party SASE; the environment without edge routing does not see shadow AI traffic.

What Works

  • DLP for Copilot is available across all license classes, removing the license argument from the discussion.
  • DSPM for AI automatically scans the top 100 SharePoint sites, replacing a manual classification phase.
  • Agent 365 telemetry provides risk scores per agent without additional modeling, suitable for initial audit inventory.
  • Sentinel integration and partner hooks (Varonis, Salesforce, Snowflake, Databricks) expand the scope without custom development.

What the Investment Truly Pays Off For

Three tenant profiles see the clearest value. Tenants with over 1,000 active Copilot licenses, where daily prompt volume reaches the five-digit range and manual audit samples are futile. Regulated sectors with DORA, NIS2, or BaFin backgrounds, as the multicloud audit requirement remains incomplete without prompt logging. And setups with custom Copilot Studio agents in productive business processes, as a single misclassified response can trigger a data breach.

Ignoring the setup will leave you with a structural blind spot by 2026. Data classes protected in storage flow through prompts into foreign models. While external audit readiness remains formally established, it becomes functionally weaker in practice.

A second observation from the pilot tenants: The friction primarily comes from ownership, not technology. Each agent requires a clear owner, a defined data class scope, and an explicit retirement date. Three fields in an inventory that are not yet maintained in most setups. Microsoft provides the data structure and telemetry, but the upkeep falls to your own architecture team. Starting an inventory in an Excel list and transitioning to a CMDB after three months is more effective than waiting for a complete tooling solution.

And a final note on reporting. DSPM posture reports offer a decent initial audit view but are only conditionally suitable for external auditors. For DORA, NIS2, or BaFin audits, you should early on reflect telemetry in your own logging pipeline, simplest via Microsoft Sentinel with a two-year retention. The audit path in Purview itself holds a 180-day standard, sufficient for internal reviews but not for regulated sectors.

And yes, I was initially skeptical. A central console combining storage DLP, prompt DLP, agent inventory, and shadow AI in a dashboard sounds like classic marketing spin. After three weeks of testing in a pilot tenant, skepticism has diminished. The telemetry is consistent, policies function as documented, and the false-positive rate is manageable with proper SIT hygiene. The lever lies in the tenant setup, not the tool.

Frequently Asked Questions

Is an existing DLP policy sufficient for SharePoint and Exchange, or is a new policy required for Copilot?

A separate policy is mandatory. While DLP-for-Copilot uses the same Sensitive Information Types, the location selection is independent. A policy without explicitly enabled Copilot locations will not apply in the prompt layer, even if the classification has been active in storage for a long time.

How can agents outside of Copilot Studio be added to the DSPM inventory?

Agents on Microsoft Foundry are captured through the Risky-Agents policy in Insider Risk Management, which is in preview since November 2025. External frameworks like LangGraph or n8n are not covered; here, only network data security collection over edge traffic plus a custom CMDB maintenance for owner and data classes can help.

Which license is required for an E3 tenant to achieve full functionality?

For DLP-for-Copilot, any Copilot license will suffice starting April 2026, including E1, E3, and E5. Agent 365 is licensed separately, ranging from $15 to $30 per agent slot per month, depending on the tenant. DSPM for AI in the new version is available in the E5 Compliance Bundle and through pay-as-you-go.

What happens to historical prompt logs before the rollout?

Microsoft 365 Copilot stores prompt and response data in the audit log since the general availability in early 2024. To review these data retrospectively, you can load them through Search-with-AI in Data Security Investigations and scan them against SIT classes. Retention is based on the configured audit policy, which defaults to 180 days or can be extended up to ten years with Premium eDiscovery.

How can prompt DLP be implemented in a multicloud strategy with AWS Bedrock or Google Vertex AI?

Not directly. Purview DLP operates at the Microsoft 365 layer, affecting Copilot, Copilot Studio agents, and Agent 365. For AWS Bedrock and Google Vertex AI, protection must be implemented either at the application layer of your own application or through network data security when requests traverse a controlled edge. A native platform symmetry from Microsoft is not expected in 2026.

About the Author

Adrian Garcia-Kunz is a Web Developer at Evernine. He reads release notes for breakfast and observes the interface between cloud platforms, frontend architecture, and the cost implications of new features before they go live.

Source Title Image: AI-generated via imagen

Image source: AI-generated (Juli 2026)

Also available in

FrançaisEspañolDeutsch
MBF Media Newsletter

The monthly briefing for decision-makers

Once a month, the MBF Media Newsletter gathers what matters from cloudmagazin, MyBusinessFuture, Digital Chiefs and SecurityToday, curated by the editorial team.

25,000 IT and business decision-makers read this newsletter. Read along.

Subscribe for free
MBF Media Newsletter, aktuelle Ausgabe auf dem iPhone
A magazine by Evernine Media GmbH