{"id":40108,"date":"2026-05-07T16:09:51","date_gmt":"2026-05-07T14:09:51","guid":{"rendered":"https:\/\/www.cloudmagazin.com\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/"},"modified":"2026-05-07T16:09:51","modified_gmt":"2026-05-07T14:09:51","slug":"microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents","status":"publish","type":"post","link":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/","title":{"rendered":"When Staff Feed Customer Data to ChatGPT"},"content":{"rendered":"<p style=\"color:#0bb7fd;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min. read<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>Sensitive customer data is ending up in public AI tools every day, often without anyone noticing. Microsoft is now building a protective layer directly into the prompt input, and IT managers in the SME sector must decide whether to jump on board or continue improvising.<\/strong><\/p>\n<p style=\"margin:8px 0 18px;color:rgba(255,255,255,0.5);font-size:0.85em;\"><em>06.05.2026<\/em><\/p>\n<div style=\"background:#004a59;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#0bb7fd;border-bottom:2px solid rgba(11,183,253,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#0bb7fd;\">DLP moves to the prompt layer:<\/strong> Sensitive Information Types are evaluated before the Copilot call is made. Those who have only mapped DLP to SharePoint and Exchange will not see the prompt traffic.<\/li>\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#0bb7fd;\">Agent 365 is GA, the telemetry is new:<\/strong> Agent inventory, risk classes per agent, and insider risk hooks go into production starting in May. Custom Copilot Studio agents are included, while external agent frameworks are not.<\/li>\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#0bb7fd;\">Shadow AI gets an audit trail:<\/strong> Network Data Security plus enterprise browser hooks capture prompts sent to unmanaged AI. The data lands in the same DSPM dashboard as the Copilot telemetry, which changes reporting obligations.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/25\/a2a-protocol-1-2-in-production-what-dach-cloud-architects-need-to-change-in-their-istio-setup-now\/\" style=\"color:#333;text-decoration:underline;\">A2A Protocol 1.2 in production<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/14\/aws-and-google-cloud-unveil-joint-multicloud-preview-what-it\/\" style=\"color:#333;text-decoration:underline;\">AWS and Google Cloud multicloud preview<\/a><\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What has really changed in May 2026<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>What is Microsoft Intelligent Purview?<\/strong> Microsoft uses the term Intelligent Purview to describe the data and compliance platform that became generally available in May 2026, bundling classification, DLP, posture management, and agent governance into a single console. New features include real-time evaluation of AI prompts and agent responses against Sensitive Information Types, combined with a unified DSPM view of Microsoft 365 and external data sources.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">While the headline is Intelligent Purview, the real leverage lies in two individual steps. First: DLP for Microsoft 365 Copilot has been generally available across the board since the end of April 2026, concluding the public preview status from November 2025. Second: May sees the arrival of the new, unified DSPM console alongside the GA of the Agent 365 compliance protection layer. Together, these form what Microsoft is positioning as a central AI security cockpit.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">For cloud architects, this is more than just a console refresh. DLP now operates before the model call, rather than just on the storage system. If an employee types a contract clause or a credit card number into a Copilot prompt, the policy blocks the prompt before it reaches the foundation model. This applies to M365 Copilot, Copilot Chat, and, via the inline DLP extension, to custom-built Copilot Studio agents as well.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">A small but significant detail: the licensing hurdles are gone. Until December 2025, you needed E5 or a dedicated compliance add-on to activate prompt DLP. With the April rollout, the feature is included in every Copilot license, including E1 and E3 tenants with a Copilot add-on. This changes the negotiation logic with Microsoft, as a frequently used argument for upselling has been removed.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Three architectural points where teams must now catch up<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Anyone who has viewed DLP primarily as file classification faces a conceptual problem. A prompt is not a file. It is ephemeral, often lasting less than two seconds, yet it is the exact point where plaintext data can leave the tenant. Three areas are shifting with this new interface.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">First, classifier hygiene. Sensitive Information Types are now evaluated within the prompt. Those who have created custom SITs with overly loose regex patterns will trigger an avalanche of false positives in prompt DLP, as employees do not formulate their prompt language with the same control as a saved document. Before rollout, a stress test using the last 1,000 Copilot prompts from the audit logs is essential. Microsoft provides the Activity Explorer and Search-with-AI in Data Security Investigations for this purpose.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Second, the agent inventory. With Agent 365 GA, compliance teams receive a complete list of all Copilot Studio agents in the tenant, including a risk score, for the first time. This list is usually longer than expected. In typical DACH-region tenants with 5,000+ employees, 80 to 200 productive or semi-productive agents often appear. A data class, data source, and DLP profile must be assigned to each agent; otherwise, the tenant-default inheritance logic kicks in, blocking either too much or too little.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Third, the shadow AI layer. Network Data Security has been GA for third-party SASE since November 2025 and in public preview for Microsoft Entra GSA Internet Access. This brings ChatGPT, Claude, Mistral, or self-hosted LLM proxies into the same DSPM dashboard as Copilot. Pulling this lever provides, for the first time, a reliable picture of how many prompts are actually being sent to external models daily. The numbers are regularly uncomfortable.<\/p>\n<div style=\"background:#004a59;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#0bb7fd;letter-spacing:-0.03em;line-height:1;\">100<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">Top SharePoint sites per tenant that DSPM for AI has been automatically evaluating for data risks on a weekly basis since May 2026. Previously, sites had to be maintained manually.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: Microsoft Learn, Considerations for deploying DSPM for AI, May 2026<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What a 60-day activation looks like in practice<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">A full migration to prompt-centric DLP requires more than just setting a policy. The sequence is critical, because a false start in week one will fill the next six weeks with tickets. A realistic roadmap for mid-sized DACH tenants with 2,000 to 10,000 seats.<\/p>\n<div style=\"margin:28px 0;border:1px solid #e5e5e5;border-radius:6px;overflow:hidden;\">\n<div style=\"background:#004a59;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">60-day plan: Prompt-DLP plus agent governance<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#0bb7fd;\">Weeks 1 to 2<\/div>\n<div style=\"color:#333;line-height:1.55;\">Audit log export of the last 1,000 Copilot prompts. Test SITs against real prompt language, measure the false-positive rate per class. Set custom SITs with a hit rate over 12 percent to audit mode, not block mode.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#0bb7fd;\">Weeks 3 to 4<\/div>\n<div style=\"color:#333;line-height:1.55;\">Agent inventory via DSPM AI observability. Per agent: data source, data class, owner, DLP profile. Decommission agents without an owner instead of blocking them across the board.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#0bb7fd;\">Weeks 5 to 7<\/div>\n<div style=\"color:#333;line-height:1.55;\">Activate block mode for the two or three highest SIT classes, for example, credit cards and customer identifiers. Coordinate notification templates in-house, otherwise tickets will escalate to management.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:130px;font-weight:700;color:#0bb7fd;\">Weeks 8 to 9<\/div>\n<div style=\"color:#333;line-height:1.55;\">Activate network data security for shadow AI. Keep output in audit mode for four weeks, then hold policy discussions based on actual volumes, not gut feeling.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:130px;font-weight:700;color:#0bb7fd;\">From week 10<\/div>\n<div style=\"color:#333;line-height:1.55;\">Apply insider risk hooks to the risky agents template. Quarterly review of DSPM risk scores, documented handover to internal audits.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<blockquote style=\"margin:32px 0;padding:24px 28px;background:linear-gradient(135deg,#f0f7ff 0%,#e4f1fd 100%);border-left:4px solid #0bb7fd;border-radius:0 8px 8px 0;font-size:1.25em;line-height:1.5;color:#004a59;font-style:italic;font-weight:600;\"><p>\n&#8220;Sensitive customer data ends up in public AI tools every day without anyone noticing.&#8221;\n<\/p><\/blockquote>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What holds up, what breaks in the tenant<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">The pipeline is solid, but it has friction points that are often glossed over in roadmap documentation. Here are three examples from production setups that are delaying migration.<\/p>\n<div style=\"display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:16px;margin:28px 0;\">\n<div style=\"background:#fafafa;border-top:3px solid #c0392b;padding:18px 20px;border-radius:4px;\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#c0392b;\">What breaks<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">Custom SITs from 2023 with coarse regex patterns trigger prompt false positives in routine texts.<\/li>\n<li style=\"margin-bottom:6px;\">External agent frameworks outside of Copilot Studio are invisible in the inventory; reporting appears complete, but it is not.<\/li>\n<li style=\"margin-bottom:6px;\">Inline DLP for Copilot Studio agents is still in public preview as of May, meaning it can only be used for regulated workloads with compliance approval.<\/li>\n<li>Network Data Security requires active Entra GSA or a third-party SASE; legacy environments without edge routing cannot see shadow AI traffic.<\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#fafafa;border-top:3px solid #2d7a3e;padding:18px 20px;border-radius:4px;\">\n<p style=\"margin:0 0 10px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.12em;color:#2d7a3e;\">What holds up<\/p>\n<ul style=\"margin:0;padding-left:18px;color:#333;line-height:1.55;font-size:0.95em;\">\n<li style=\"margin-bottom:6px;\">DLP for Copilot is available across all license tiers, which removes the licensing argument from the discussion.<\/li>\n<li style=\"margin-bottom:6px;\">DSPM for AI automatically scans the 100 top SharePoint sites, replacing a phase of manual classification.<\/li>\n<li style=\"margin-bottom:6px;\">Agent 365 telemetry provides risk scores per agent without requiring custom modeling, suitable for an initial audit inventory.<\/li>\n<li>Sentinel integration and partner hooks (Varonis, Salesforce, Snowflake, Databricks) expand the scope without the need for in-house development.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Where the effort is truly worth it<\/h2>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Three tenant profiles derive the clearest added value. Tenants with over 1,000 active Copilot licenses, because daily prompt volumes there reach the five-digit range, making manual audit spot checks hopeless. Regulated industries with DORA, NIS2, or BaFin backgrounds, because the <a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/14\/aws-and-google-cloud-unveil-joint-multicloud-preview-what-it\/\" style=\"color:#0bb7fd;text-decoration:underline;\">multicloud audit requirement<\/a> remains incomplete without prompt logging. And setups with custom Copilot Studio agents in productive business processes, because a single misclassified response there can trigger a data protection incident.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">Anyone ignoring this setup will be operating with a structural blind spot in 2026. Data classes protected in storage are flowing into third-party models via prompts. External audit readiness may remain formally established, but in practice, it is becoming increasingly porous.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">A second observation from the pilot tenants: friction does not primarily stem from the technology, but from the question of ownership. Each agent requires a clear owner, a clear data class scope, and a clear decommissioning date. These are three fields in an inventory that remain unmaintained in most setups. Microsoft provides the data structure and telemetry, but maintenance remains the responsibility of your own architecture function. Those who start the inventory in an Excel list and migrate it to a CMDB after three months will move significantly faster than a team waiting for a complete tooling solution.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">And one final note on reporting. DSPM posture reports provide a decent initial audit view but are only conditionally suitable for external auditors. Anyone needing to document for DORA, NIS2, or a BaFin audit should mirror the telemetry into their own logging pipeline early on\u2014most easily via Microsoft Sentinel with a two-year retention period. The audit trail in Purview itself defaults to 180 days, which is sufficient for internal reviews but not for regulated industries.<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\">And yes, I was skeptical at first. A central console that combines storage DLP, prompt DLP, agent inventory, and shadow AI into one dashboard sounds like classic marketing fluff. After three weeks of testing in a pilot tenant, my skepticism has diminished. The telemetry is consistent, the policies take effect as documented, and the false-positive rate is manageable if your SIT hygiene is on point. The leverage lies in the tenant setup, not the tool.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<details>\n<summary><strong>Is an existing DLP policy on SharePoint and Exchange sufficient, or must a new policy be created for Copilot?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">A separate policy is mandatory. While DLP-for-Copilot uses the same Sensitive Information Types, the location selection is independent. A policy without an explicitly activated Copilot location will not take effect at the prompt layer, even if the same classification has long been active in storage.<\/p>\n<\/details>\n<details>\n<summary><strong>How can agents outside of Copilot Studio be added to the DSPM inventory?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Agents on Microsoft Foundry are captured via the Risky-Agents policy in Insider Risk Management, which has been in preview since November 2025. External frameworks like LangGraph or n8n are not covered; here, only network data security capture via edge traffic, combined with manual CMDB maintenance for owners and data classes, will help.<\/p>\n<\/details>\n<details>\n<summary><strong>Which license does an E3 tenant require for full functionality?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">For DLP-for-Copilot, any Copilot license will suffice starting in April 2026; this applies to E1, E3, and E5. Agent 365 is licensed independently, costing between 15 and 30 USD per agent slot per month, depending on the tenant. DSPM for AI in the new version is available in the E5 compliance bundle and via pay-as-you-go.<\/p>\n<\/details>\n<details>\n<summary><strong>What happens to historical prompt logs from before the rollout?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Microsoft 365 Copilot has been storing prompt and response data in the audit log since its GA in early 2024. Those wishing to audit data retrospectively can load it via Search-with-AI in Data Security Investigations and scan it against SIT classes. Retention is based on the configured audit policy, i.e., the standard 180 days or up to ten years with premium eDiscovery.<\/p>\n<\/details>\n<details>\n<summary><strong>How can prompt DLP be mapped in a multicloud strategy using AWS Bedrock or Google Vertex AI?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Not directly. Purview DLP operates at the Microsoft 365 layer, i.e., Copilot, Copilot Studio agents, and Agent 365. For AWS Bedrock and Google Vertex, the protection point remains either in the application layer of your own software or in the network data security hop if requests run through a controlled edge. Microsoft will not provide native platform symmetry in 2026.<\/p>\n<\/details>\n<div style=\"background:#f5f5f7;padding:24px 28px;margin:48px 0 24px 0;border-radius:8px;\">\n<p style=\"margin:0 0 8px 0;font-size:0.78em;font-weight:800;color:#004a59;text-transform:uppercase;letter-spacing:0.14em;\">About the author<\/p>\n<p style=\"margin:0;font-size:0.98em;line-height:1.7;color:#333;\"><strong>Adrian Garcia-Kunz<\/strong> is a Web Developer at Evernine. He reads release notes for breakfast and monitors the intersection between cloud platforms, frontend architecture, and the question of what a new feature actually costs a tenant before it goes live.<\/p>\n<\/div>\n<div style=\"margin:32px 0 24px 0;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:800;color:#004a59;text-transform:uppercase;letter-spacing:0.14em;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p style=\"margin:0;\"><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/25\/a2a-protocol-1-2-in-production-what-dach-cloud-architects-need-to-change-in-their-istio-setup-now\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">A2A Protocol 1.2: What DACH cloud architects need to change in Istio now<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #aa8ac2;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#aa8ac2;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p style=\"margin:0;\"><a href=\"https:\/\/mybusinessfuture.com\/risikoprofil-april-2026-vorsicht-mittelstand\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Risk Profile 2026: Where caution becomes the most expensive strategy<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p style=\"margin:0;\"><a href=\"https:\/\/www.digital-chiefs.de\/drei-konzern-spinoffs-april-2026-continental-infineon-thyssenkrupp\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Three Corporate Spinoffs: Continental, Infineon, ThyssenKrupp<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #69d8ed;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#69d8ed;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">securitytoday<\/div>\n<p style=\"margin:0;\"><a href=\"https:\/\/www.securitytoday.de\/2026\/04\/29\/litellm-cve-2026-42208-cvss-9-3-warum-sql-injection-in-ki-proxy-infrastruktur-andere-incident-response-braucht-als-klassische-web-apps\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">LiteLLM CVE-2026-42208: SQL Injection in the AI proxy layer<\/a><\/p>\n<\/div>\n<\/div>\n<p style=\"text-align:right;\"><em>Source cover image: Pexels \/ Brett Sayles (px:1597776)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<span class=\"evm-reading-time\" style=\"display:inline-block;padding:3px 12px;border-radius:14px;background:#0bb7fd;color:#fff;font-size:0.78em;font-weight:600;letter-spacing:0.02em;line-height:1.4;vertical-align:middle;\">~12 Min. Lesezeit<\/span><span class=\"evm-meta-sep\" style=\"display:inline-block;margin:0 8px;color:#999;font-size:0.85em;vertical-align:middle;\">&#8211;<\/span> <span class=\"evm-reading-time\" style=\"display:inline-block;padding:3px 12px;border-radius:14px;background:#0bb7fd;color:#fff;font-size:0.78em;font-weight:600;letter-spacing:0.02em;line-height:1.4;vertical-align:middle;\">~12 Min. Lesezeit<\/span><span class=\"evm-meta-sep\" style=\"display:inline-block;margin:0 8px;color:#999;font-size:0.85em;vertical-align:middle;\">&#8211;<\/span> Sensitive customer data ends up in public AI tools daily without anyone noticing.","protected":false},"author":83,"featured_media":39261,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_focuskw":"","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"ngg_post_thumbnail":0,"pre_headline":"","bildquelle":"","teasertext":"","language":"de","footnotes":""},"categories":[12],"tags":[],"industry":[],"class_list":["post-40108","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-expertenmeinungen"],"evm_reading_time_minutes":12,"wpml_language":"en","wpml_translation_of":39262,"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>When Staff Feed Customer Data to ChatGPT - cloudmagazin<\/title>\n<meta name=\"description\" content=\"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"When Staff Feed Customer Data to ChatGPT - cloudmagazin\" \/>\n<meta property=\"og:description\" content=\"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\" \/>\n<meta property=\"og:site_name\" content=\"cloudmagazin\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cloudmagazincom\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-07T14:09:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1880\" \/>\n\t<meta property=\"og:image:height\" content=\"1253\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Adrian Garcia-Kunz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cloudmagazin\" \/>\n<meta name=\"twitter:site\" content=\"@cloudmagazin\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Adrian Garcia-Kunz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\"},\"author\":{\"name\":\"Adrian Garcia-Kunz\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/da099322400ca238eb7c80feea5c685b\"},\"headline\":\"When Staff Feed Customer Data to ChatGPT\",\"datePublished\":\"2026-05-07T14:09:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\"},\"wordCount\":1976,\"publisher\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg\",\"articleSection\":[\"Expert Opinions\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\",\"url\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\",\"name\":\"When Staff Feed Customer Data to ChatGPT - cloudmagazin\",\"isPartOf\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg\",\"datePublished\":\"2026-05-07T14:09:51+00:00\",\"description\":\"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage\",\"url\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg\",\"contentUrl\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg\",\"width\":1880,\"height\":1253,\"caption\":\"Microsoft Intelligent Purview im Mai 2026: Was Echtzeit-DLP f\u00fcr KI-Prompts und Agent-Outputs f\u00fcr DACH-SaaS-Architekten \u00e4\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cloudmagazin.com\/en\/home\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"When Staff Feed Customer Data to ChatGPT\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#website\",\"url\":\"https:\/\/www.cloudmagazin.com\/en\/\",\"name\":\"cloudmagazin\",\"description\":\"Inspiration f\u00fcr Businessentscheider\",\"publisher\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cloudmagazin.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#organization\",\"name\":\"cloudmagazin\",\"url\":\"https:\/\/www.cloudmagazin.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg\",\"contentUrl\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg\",\"width\":150,\"height\":150,\"caption\":\"cloudmagazin\"},\"image\":{\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/cloudmagazincom\/\",\"https:\/\/x.com\/cloudmagazin\",\"https:\/\/www.linkedin.com\/showcase\/cloudmagazin\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/da099322400ca238eb7c80feea5c685b\",\"name\":\"Adrian Garcia-Kunz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/adrian-garcia-kunz.jpg\",\"contentUrl\":\"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/adrian-garcia-kunz.jpg\",\"caption\":\"Adrian Garcia-Kunz\"},\"description\":\"Adrian Garcia-Kunz is an editor at cloudmagazin, covering web development, cloud infrastructure, and modern software architecture. With expertise in full-stack development and cloud-native technologies, he bridges the gap between developer perspective and business relevance. His focus includes Kubernetes, serverless computing, DevOps pipelines, and AI-assisted development tools.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/adrian-garcia-kunz\/\"],\"url\":\"https:\/\/www.cloudmagazin.com\/en\/author\/adrianninebrackets\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"When Staff Feed Customer Data to ChatGPT - cloudmagazin","description":"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/","og_locale":"en_US","og_type":"article","og_title":"When Staff Feed Customer Data to ChatGPT - cloudmagazin","og_description":"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.","og_url":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/","og_site_name":"cloudmagazin","article_publisher":"https:\/\/www.facebook.com\/cloudmagazincom\/","article_published_time":"2026-05-07T14:09:51+00:00","og_image":[{"width":1880,"height":1253,"url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg","type":"image\/jpeg"}],"author":"Adrian Garcia-Kunz","twitter_card":"summary_large_image","twitter_creator":"@cloudmagazin","twitter_site":"@cloudmagazin","twitter_misc":{"Written by":"Adrian Garcia-Kunz","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#article","isPartOf":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/"},"author":{"name":"Adrian Garcia-Kunz","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/da099322400ca238eb7c80feea5c685b"},"headline":"When Staff Feed Customer Data to ChatGPT","datePublished":"2026-05-07T14:09:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/"},"wordCount":1976,"publisher":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#organization"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg","articleSection":["Expert Opinions"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/","url":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/","name":"When Staff Feed Customer Data to ChatGPT - cloudmagazin","isPartOf":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg","datePublished":"2026-05-07T14:09:51+00:00","description":"Microsoft Purview blocks sensitive data in prompts. Discover what IT leaders in DACH SMEs need to decide now.","breadcrumb":{"@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#primaryimage","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/05\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents-dach-hero.jpg","width":1880,"height":1253,"caption":"Microsoft Intelligent Purview im Mai 2026: Was Echtzeit-DLP f\u00fcr KI-Prompts und Agent-Outputs f\u00fcr DACH-SaaS-Architekten \u00e4"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/07\/microsoft-intelligent-purview-mai-2026-dlp-ki-prompts-agents\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cloudmagazin.com\/en\/home\/"},{"@type":"ListItem","position":2,"name":"When Staff Feed Customer Data to ChatGPT"}]},{"@type":"WebSite","@id":"https:\/\/www.cloudmagazin.com\/en\/#website","url":"https:\/\/www.cloudmagazin.com\/en\/","name":"cloudmagazin","description":"Inspiration f\u00fcr Businessentscheider","publisher":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cloudmagazin.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cloudmagazin.com\/en\/#organization","name":"cloudmagazin","url":"https:\/\/www.cloudmagazin.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2020\/04\/cloudmagazin-logo-klein_menu.jpg","width":150,"height":150,"caption":"cloudmagazin"},"image":{"@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/cloudmagazincom\/","https:\/\/x.com\/cloudmagazin","https:\/\/www.linkedin.com\/showcase\/cloudmagazin\/"]},{"@type":"Person","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/da099322400ca238eb7c80feea5c685b","name":"Adrian Garcia-Kunz","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cloudmagazin.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/adrian-garcia-kunz.jpg","contentUrl":"https:\/\/www.cloudmagazin.com\/wp-content\/uploads\/2026\/03\/adrian-garcia-kunz.jpg","caption":"Adrian Garcia-Kunz"},"description":"Adrian Garcia-Kunz is an editor at cloudmagazin, covering web development, cloud infrastructure, and modern software architecture. With expertise in full-stack development and cloud-native technologies, he bridges the gap between developer perspective and business relevance. His focus includes Kubernetes, serverless computing, DevOps pipelines, and AI-assisted development tools.","sameAs":["https:\/\/www.linkedin.com\/in\/adrian-garcia-kunz\/"],"url":"https:\/\/www.cloudmagazin.com\/en\/author\/adrianninebrackets\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/40108","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/users\/83"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/comments?post=40108"}],"version-history":[{"count":0,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/posts\/40108\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/media\/39261"}],"wp:attachment":[{"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/media?parent=40108"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/categories?post=40108"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/tags?post=40108"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.cloudmagazin.com\/en\/wp-json\/wp\/v2\/industry?post=40108"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}