Report an Incident Become a Partner Careers Contact
Book a Demo
Consultancy · AI governance

You cannot govern
what nobody is watching.

Most organisations have no record of what their people are pasting into AI, which services they are using, or what those services do with it afterwards. This is the work that turns that into something you can see, evidence and control.

AI activity review30 days, 1,200 users
SHADOW14 GenAI services in use, 3 approvedunsanctioned
PASTEClient data into a public assistantno policy hit
COPILOTLabelled content, processing allowedin policy
MCPDeveloper tooling reaching remote serversundocumented
AGENTSAgents built in Copilot Studiono owner
RECORDEvery interaction above, evidencedafter
What this actually is

Controls that fire,
not a policy document.

An AI use policy tells people what they should not do. This is the part that notices when they do it anyway, and decides whether to warn them, block it, or simply write it down.

It is delivered on the Microsoft stack you already own or can license: Purview for classification and data loss prevention, Defender for endpoint and AI workload protection, Entra for identity and network access, and Sentinel underneath it so the SOC sees AI activity beside everything else.

The value is not how many Microsoft features get switched on. It is being able to say how AI is being used, spot the moment something sensitive or risky happens, apply the right control at the right layer, and give your security, compliance and SOC teams enough context to act on it.

  • Who used which AI service, when, from what device, with what data.
  • Sensitive content caught on the way out, before it reaches a public model.
  • Approved AI kept usable while risky destinations are tightened, not a blanket block.
  • Evidence a regulator, a client questionnaire or an HR process can actually use.
  • AI activity in Sentinel, correlated with identity, endpoint and cloud.
Which one you need

Three packages.
Start at the layer that worries you.

Cumulative rather than alternative: each adds an observation point the one before it could not reach, and reuses the data classification built for the first. Most organisations start at one and move when the AI estate justifies it.

01

AI Data Protection Foundation

Protect sensitive data as people use Copilot and public AI from managed devices. The fastest route to practical control if you already hold Microsoft 365 E5.

  • Endpoint DLP on paste, upload and drag-and-drop
  • Different rules for different AI destinations
  • Microsoft 365 Copilot guardrails
  • User, device, file and classifier evidence

Best fit: adopting or expanding Copilot, and worried about what leaves with it.

02

Enterprise AI

Govern the AI you run yourself, and protect the Azure workloads behind it. Interaction-level evidence rather than aggregate usage statistics.

  • AI interactions collected into Purview DSPM
  • Prompt and response capture where supported
  • Defender for AI Services on Azure OpenAI and Foundry
  • Retention and eDiscovery over AI interactions

Best fit: running a private assistant or production AI on Azure, in a regulated setting.

03

AI Governance 360 — shadow AI

Everything the first two cannot see. Identity-aware control at the network layer, and discovery of the AI nobody told you about.

  • Shadow AI discovery across the estate
  • Entra Internet Access and TLS inspection
  • Network data security and content control
  • GenAI prompt and remote MCP telemetry

Best fit: broad AI use, developer tooling, and no confident answer to "what are we using?"

Microsoft 365 E7 sits alongside rather than above these. It adds Agent 365 and Entra Agent ID, which is the move from governing how people use AI to governing agents as identities that act on their own.

Why one control is never enough

Blocking ChatGPT
moves the problem.

The instinct is to block the obvious destination at the firewall. It takes an afternoon, it is visible to the board, and it pushes the same behaviour onto a phone, a personal laptop or the next service nobody has heard of yet.

AI use happens at three different layers and each one needs its own observation point. On the endpoint, where somebody pastes a client list into a browser. Inside the AI application, where a prompt to your own assistant asks something it should not be answering. And on the network, where traffic reaches a service nobody approved and no endpoint agent is watching.

A control at one layer cannot see the other two. Endpoint DLP does not know what your private assistant was asked. Network filtering does not know the file was labelled. That is why this is built as three cumulative packages rather than one product: you start at the layer where your risk actually is, and add the next when the estate justifies it.

E5 vs E7, explained

The endpoint
Paste, upload, drag and drop into a browser or app. Purview Endpoint DLP with destination-aware enforcement, so approved business use continues and high-risk destinations do not.
The interaction
What your own AI applications are being asked and what they answer. Collected into Purview, with prompt and response capture where the workload supports it, and available to retention and eDiscovery.
The network
Everything the first two cannot see. Identity-aware internet access through Entra, TLS inspection, network DLP, and discovery of the AI services and MCP servers nobody told you about.
The agents
Once AI stops being a chat window and starts acting on its own, the question becomes which agents exist, what they can reach and who owns them. That is the Microsoft 365 E7 layer.
What gets configured

Microsoft controls,
switched on properly.

The surface across all three packages. Most of it is capability you already hold or can license rather than anything new to buy, and the work is deciding which of it earns its place in your estate.

1 · AI Data Protection Foundation

  • Microsoft 365 E5
  • Purview Endpoint DLP
  • Sensitivity labels
  • Destination-aware enforcement
  • Microsoft 365 Copilot guardrails
  • DLP alerts and Activity Explorer

2 · Enterprise AI

  • Purview DSPM for AI
  • AI interaction collection
  • Prompt and response capture
  • Defender for AI Services
  • Azure OpenAI and Foundry workloads
  • Retention and eDiscovery

3 · AI Governance 360

  • Entra Internet Access
  • Global Secure Access
  • Shadow AI discovery
  • Network data security
  • TLS inspection
  • GenAI and MCP telemetry

Nothing here is switched on because it exists. Each control is a decision about whether the evidence it produces is worth the noise, the licence and the consumption behind it.

How it runs

Discover, design, pilot,
tune, operationalise.

Every stage produces something you keep, and the pilot deliberately includes the things people should not be able to do as well as the things they should.

  1. 01

    Discover

    Licensing, endpoint coverage, which AI applications and agents are actually in use, the state of your data classification, Azure AI workloads and regulatory constraints. Produces a current-state picture and a package recommendation.

  2. 02

    Design

    Policy intent, what counts as approved AI, which data matters, the enforcement model, privacy requirements and the exception process. Produces a control matrix and a test plan.

  3. 03

    Pilot and validate

    Controls deployed to a contained group, then run against positive and negative scenarios: allowed business use that must keep working, and prohibited use that must be caught.

  4. 04

    Tune

    Thresholds, destinations, exceptions and reviewer access, adjusted against what the pilot actually produced rather than what the design assumed.

  5. 05

    Operationalise

    Roll out, train administrators, build the Sentinel content so AI activity reaches the SOC, and agree who owns what. You get the workbook and rule catalogue with it.

What drives the cost

The licences are yours.
The work is ours.

Worth separating, because most of the cost sits in your Microsoft agreement rather than in our engagement, and some of it is consumption-based rather than per-seat.

Which package you start at
Package 1 runs on the Microsoft 365 E5 you may already hold. Packages 2 and 3 need licensing you probably do not, so the starting point is a commercial decision as much as a technical one.
Purview pay-as-you-go
Several of the AI data-security and network data-security capabilities are consumption-billed and create Azure charges. Not a fixed per-seat cost, and worth modelling before it is switched on rather than after.
Defender for AI Services
A separate Defender for Cloud plan on the subscription hosting the workload. It is not included just because Purview pay-as-you-go is configured, which surprises people.
Sentinel ingestion
AI telemetry reaching the SOC is Sentinel data, and it is billed as Sentinel data. Part of designing this is deciding what is worth ingesting rather than connecting everything.
How much is custom
Packaged Microsoft AI applications are configuration. A bespoke internal assistant may need development work to pass user context through, which is the difference between configuring a control and building one.

We scope it against your tenant and your agreement before quoting, and the discovery is worth having on its own: most organisations have not seen a list of the AI services actually in use.

Questions

AI governance, answered.

We already have an AI use policy. Is that not enough?

A policy tells people what not to do. It does not tell you when they did it anyway. This is the part that notices, produces the evidence, and decides whether to warn, block or record.

Can you just block ChatGPT?

Yes, and it rarely works. Blocked at the firewall, the same behaviour moves to a phone, a personal laptop or the next service nobody has heard of. Destination-aware controls that keep approved AI usable are harder to set up and far more likely to survive contact with your staff.

Can you see what people actually typed?

For supported enterprise AI interactions with content capture enabled, yes — authorised investigators can review the prompt and the response. Not everywhere, and not by default: it depends on the workload, the licensing and your own privacy position, which is a conversation with Legal and HR before it is a configuration.

What about shadow AI we do not know about?

That is Package 3. Identity-aware internet access through Entra plus Defender for Cloud Apps gives you the list of AI services in use, including the ones nobody approved, and the remote MCP servers developer tooling is reaching.

Do we need Microsoft 365 E7?

Only if you are scaling agents. E7 adds Agent 365 and Entra Agent ID, which govern agents as identities. If you are protecting how people use AI rather than running agents that act on their own, the three packages cover it.

Does any of this reach our SOC?

That is the point of the last phase. AI DLP violations, workload alerts and shadow-AI activity land in Sentinel where they correlate with identity risk, endpoint activity and cloud incidents — so a sensitive upload from a compromised device reads as one story rather than three unrelated alerts.

Where to start

Find out what is already
being used.

The discovery stands on its own: most organisations have never seen a list of the AI services actually in use across their estate, or what has been sent to them. You keep that either way.