Tenzing logoTenzing

    Definition

    What is Microsoft Purview for AI?

    Definition

    Microsoft Purview for AI is the set of Purview capabilities that discover, protect and audit AI usage across Microsoft 365 Copilot, Copilot Studio agents and third-party AI applications. It gives organisations visibility of AI interactions, control over the data those interactions can reach and evidence of how AI is being used.

    Last updated: 21 July 2026

    Key points

    • Discovery: AI Hub and Data Security Posture Management surface which AI tools are being used across the organisation, including shadow AI.
    • Protection: sensitivity labels, DLP for Copilot and endpoint DLP prevent regulated data from reaching AI prompts and outputs.
    • Auditing: unified audit, Communication Compliance and eDiscovery capture Copilot and agent interactions as evidence.
    • Insider risk: Purview Insider Risk Management can flag risky AI-related behaviour such as bulk downloads before a Copilot session.
    • It is a toolset, not a governance model. Purview provides the controls. A governance framework decides how to use them.

    The capabilities that matter for AI

    Not every Purview module is relevant to AI governance. The high-value modules cluster around discovery, data protection and evidence.

    • AI Hub and DSPM for AI: usage visibility across Copilot and third-party AI apps.
    • Information Protection: sensitivity labels applied by default, with encryption for high-risk labels.
    • Data Loss Prevention: policies scoped to Copilot interactions and endpoint DLP for the browser.
    • Audit: unified audit logs covering Copilot prompts, responses and agent activity.
    • Communication Compliance: policy-driven review of Copilot content against defined risk categories.
    • Insider Risk Management: behavioural signals that combine with AI usage to flag risk.

    How Purview supports Copilot governance

    Purview provides the technical controls that make Copilot governance defensible. Sensitivity labels decide what Copilot can summarise. DLP decides what a user can paste into a prompt. Audit and eDiscovery decide what an investigator can see afterwards. Without Purview, Copilot governance is largely policy on paper.

    Licensing and prerequisites

    Most Purview for AI capabilities require Microsoft 365 E5 or the equivalent add-ons. AI Hub and DSPM for AI have their own licensing terms. Before implementation, confirm the licence position and the labelling maturity of the tenant.

    Frequently asked questions

    Is Purview for AI a separate product?

    No. Purview for AI is a way of describing the Purview capabilities that apply to AI use cases, rather than a distinct product. The underlying modules are the standard Purview offerings, some of which have specific AI-oriented features such as DLP for Copilot and AI Hub.

    Do we need E5 to use Purview for AI?

    Most of the useful capabilities require Microsoft 365 E5 or the Compliance and Information Protection add-ons. Some AI Hub features are licensed separately. A licensing review is a standard part of a Copilot Readiness Assessment.

    Can Purview see third-party AI usage?

    Yes to a point. Purview's AI Hub and endpoint capabilities can detect access to popular third-party AI tools through the browser and network signals. It will not see everything, but it is enough to identify where shadow AI is happening and target intervention.

    Where do most organisations start with Purview for AI?

    Two moves. First, turn on AI Hub and DSPM for AI to get visibility. Second, apply default sensitivity labels and a DLP policy for Copilot. That gives you a defensible baseline while a full labelling and DLP programme runs in parallel.

    Related reading

    Speak with Tenzing

    A 30-minute discovery call to review your Microsoft environment and set a safe path forward with Copilot and AI agents.

    Book a 30-minute discovery call