AI Data Security Copilot Readiness Shadow AI Discovery

Microsoft DSPM for AI Expert & Copilot Readiness Consultant

Data Security Posture Management for AI lives inside Microsoft Purview and answers the question every board is now asking: what is our AI actually touching. I work hands-on across discovery of Copilot, enterprise AI and shadow AI use, sensitive data in prompts, and the oversharing assessments that decide whether a Microsoft 365 Copilot rollout is safe or embarrassing.

Microsoft Purview DSPM for AI logo
Data Security Posture Management for AI
  • Oversharing fixed before Copilot goes live
  • Shadow AI made visible, not just banned
  • Current 2026 naming and portal experience

What is Microsoft DSPM for AI?

Data Security Posture Management for AI is a Microsoft Purview capability, not a separate product, and its name has moved twice. It launched as the AI hub in the Purview compliance portal, was renamed Data Security Posture Management for AI, and in 2026 Microsoft merged DSPM and DSPM for AI into one unified solution. In the Microsoft Purview portal today you go to Solutions and then DSPM. The predecessors are still visible, relabelled Data Security Posture Management (classic) and DSPM for AI (classic), and Microsoft has said new features are going to the unified version only. Everyone still says DSPM for AI when they mean the AI side of it, and that is fine. Just be aware that guidance written before the merge points at menus that have moved.

What it does is answer three questions in order. First, what AI is in use here. That splits into Copilot experiences and agents, enterprise AI apps such as registered ChatGPT Enterprise workspaces and applications built on Microsoft Foundry, and other AI apps, which is the polite name for staff pasting work into consumer chatbots. Copilot visibility needs only Purview Audit switched on. Third-party AI site visibility additionally needs the Purview browser extension and devices onboarded to Purview, and detection outside a managed browser needs network data security through a SASE or SSE integration. Second, what sensitive data is going into prompts. Activity explorer shows AI interactions with the prompts and responses, the sensitive information types detected, files referenced, and whether a DLP rule matched during the interaction. Third, what is overexposed before AI amplifies it, which is the part that actually decides whether your Copilot programme succeeds.

That third question is where the real work is. Generative AI does not create the oversharing problem, it removes the friction that was hiding it. A decade of inherited SharePoint permissions, sites shared with everyone in the organisation, and forgotten anyone-with-the-link sharing links means most users already have rights to material nobody intended them to see. Copilot simply makes it findable. DSPM runs a default weekly data risk assessment across the top 100 SharePoint sites by usage with no activation needed, and custom assessments add item-level scanning with remediation actions: apply a sensitivity label, notify the site owner, resolve as not at risk, or remove the sharing link. The limits are worth knowing before you promise a timeline, including a maximum of 10 SharePoint sites per item-level scan, a 200,000 item cap per location, and no OneDrive support for item-level scanning. Alongside that sit the enforcement controls: DLP scoped to the Microsoft 365 Copilot location so labelled content is not summarised, SharePoint Restricted Content Discovery to fence off whole sites, Communication Compliance policies that review AI interactions for unethical or non-compliant content, and Insider Risk Management templates that score risky AI usage.

Where I Can Help

The order matters here. Discover what AI is already in use, fix the oversharing, then enforce. Doing it in the other order produces a Copilot pilot that gets paused in week two.

AI Discovery & Shadow AI Visibility

Getting the prerequisites right so discovery is real rather than partial: Purview Audit enabled, the Purview browser extension deployed, devices onboarded to Purview, and one-click discovery policies activated. Then separating what you see into Copilot experiences and agents, enterprise AI apps, and consumer AI sites, so the shadow AI conversation is based on evidence instead of assumptions.

Sensitive Data in Prompts

Using Activity explorer and the AI reports to see which sensitive information types are actually being pasted into prompts, which files are being referenced, and where a DLP rule fired during an AI interaction. This is usually the moment a leadership team stops debating AI policy in the abstract and starts making decisions.

Oversharing Assessments & Remediation

The single biggest blocker to a safe Copilot rollout. Reading the default weekly assessment across the top 100 SharePoint sites, then designing custom assessments with item-level scanning around the real limits of 10 sites per scan and 200,000 items per location. Remediation is the deliverable: labels applied, sharing links removed where justified, site owners notified, and a phased plan for an estate too big for one pass.

DLP Policies for Generative AI

Configuring Data Loss Prevention scoped to the Microsoft 365 Copilot location so labelled content is not summarised by Copilot or agents, plus policies that detect and restrict sensitive information sent to third-party generative AI sites. Where a site is beyond remediating before go-live, SharePoint Restricted Content Discovery fences it off as a temporary measure rather than a permanent one.

Communication Compliance & Insider Risk for AI

Switching on the AI-aware compliance layer: Communication Compliance policies that review Copilot prompts and responses for unethical or non-compliant content, Insider Risk Management risky AI usage detections that feed user risk, and the retention and policy configuration needed for Copilot interactions to be captured and reviewable in the first place.

Copilot Readiness Programme

Pulling all of it into a sequenced programme with a gate before rollout: discovery baseline, oversharing remediation against agreed thresholds, label taxonomy and auto-labelling live, DLP and Restricted Content Discovery in place, monitoring configured, and a documented position for legal and the regulator. Then a phased user release rather than a tenant-wide switch.

Why Microsoft DSPM for AI for UAE Organisations?

The UAE has moved faster on AI regulation than most markets, and that is now a practical constraint rather than a talking point. DIFC issued Regulation 10 covering personal data processed through autonomous and semi-autonomous systems, which places obligations on the deployers and operators of such systems and requires an Autonomous Systems Officer where the system is high risk. If your DIFC-licensed entity is rolling out Microsoft 365 Copilot over data containing personal information, that is not a future concern. Alongside it sit the federal PDPL, Federal Decree-Law No. 45 of 2021, and the ADGM Data Protection Regulations 2021, both of which expect purpose limitation, data minimisation and a lawful basis. An AI assistant that can surface any document a user has rights to is a direct test of whether those principles are implemented or merely written down.

This is exactly why the oversharing assessment matters more here than the discovery dashboard. Regional organisations tend to run flat SharePoint estates built quickly during cloud migration, with generous sharing defaults and permissions inherited from site collections that nobody has revisited. In that environment Copilot will find the HR folder, the legal folder and the board pack, because the permissions already allow it. Under PDPL or DIFC rules, an employee retrieving personal data they had no legitimate business need to see is a data protection issue regardless of how they found it. Running the data risk assessments, remediating what they surface, and keeping the evidence of that remediation is the difference between a Copilot programme a regulator accepts and one you have to defend after the fact.

Data residency and sector rules complete the picture. The United Arab Emirates is on the Microsoft 365 Local Region Geography list, so a durable commitment on data location is available through the Advanced Data Residency add-on, though its scope covers a defined subset of Purview services and requires 100 percent coverage of eligible paid seats. NESA, the CBUAE requirements for financial institutions and the DESC Information Security Regulation all sit on top for the organisations they apply to. The practical output of an engagement here is not a dashboard screenshot. It is a defensible written position on which AI tools are in use, what data they reach, what controls restrict them, and what evidence you can produce when someone asks.

100
SharePoint sites in the default weekly assessment
10
Sites maximum per item-level scan
200k
Item cap per location in an assessment
2026
DSPM and DSPM for AI merged into one solution
Available for engagements

Talk to a DSPM for AI Expert

Whether you are gating a Microsoft 365 Copilot rollout on a data security sign-off, trying to see what shadow AI is really in use, or building a DIFC and PDPL position for AI, I can help.

  • Free initial scoping call
  • Oversharing remediation, not just reporting
  • PDPL, ADGM & DIFC context
  • OSCP-certified security background
Get in Touch

Frequently Asked Questions

The naming has moved twice, which is why so much published guidance is out of date. It launched as the AI hub in the Microsoft Purview compliance portal, was renamed to Data Security Posture Management for AI, usually shortened to DSPM for AI, and in 2026 Microsoft merged DSPM and DSPM for AI into a single solution. In the Microsoft Purview portal today you select Solutions and then DSPM. The two predecessors are still present but relabelled Data Security Posture Management (classic) and DSPM for AI (classic), and Microsoft has stated that most new features will only be added to the unified version. So the capability is very much alive, the AI-specific dashboards and data risk assessments are still there, and the phrase DSPM for AI is still how everyone refers to the AI side of it. The menu item you click has changed.

Because SharePoint permissions have been accumulating quietly for a decade and nobody has had a reason to look. Inherited permissions, sites shared with everyone in the organisation, and old anyone-with-the-link sharing links mean the average user can already reach far more than anyone assumes. Before Copilot, that latent access stayed latent because finding the file required knowing it existed. Copilot removes that friction: it will happily surface a salary review or a draft acquisition memo the user technically had rights to all along. DSPM runs a default weekly data risk assessment across the top 100 SharePoint sites by usage, and you can run custom assessments with item-level scanning to see which specific items are potentially overshared and remediate them by applying a sensitivity label, notifying the site owner, or removing the sharing link. Item-level scanning currently has real limits, including a maximum of 10 SharePoint sites per scan, a 200,000 item cap per location, and no OneDrive support, so a large estate needs a phased plan rather than one scan.

Yes, with prerequisites that catch people out. Visibility over Microsoft 365 Copilot and agents needs only Purview Audit turned on, which is on by default for newer tenants. Visibility over third-party AI sites additionally requires the Microsoft Purview browser extension and devices onboarded to Purview, and the coverage is defined by Microsoft's list of supported AI sites rather than being universal. There are one-click policies that switch on discovery of users visiting generative AI sites and detection of sensitive information sent to them. For AI reached outside a managed browser, network data security through a SASE or SSE integration extends detection to applications, APIs and add-ins. Enterprise AI is handled separately again, including registering ChatGPT Enterprise workspaces so those interactions are visible.

There are two mechanisms and they solve different problems. The first is a Data Loss Prevention policy scoped to the Microsoft 365 Copilot location, which prevents Copilot and agents from processing or summarising content carrying sensitivity labels you nominate. That is a surgical control: label the material properly and Copilot leaves it alone while everything else stays available. The second is SharePoint Restricted Content Discovery, which exempts entire SharePoint sites from Copilot. That is the blunt instrument, and it is the right answer for a site you know is a mess and cannot remediate before go-live. In practice a workable rollout uses both: Restricted Content Discovery as a temporary fence around the worst sites, DLP by label as the permanent control, and auto-labelling running underneath so the labels the DLP policy depends on actually get applied.

DSPM for AI Sits Inside Microsoft Purview

Every control this page describes depends on the wider Purview platform: sensitivity labels, Data Loss Prevention, Insider Risk Management, Communication Compliance and Audit. If AI is your entry point, Purview is what you are really buying. The Microsoft Security portfolio page covers how it lines up with Defender, Sentinel and Entra.

Basim Ibrahim, Microsoft DSPM for AI Consultant in Dubai

If you are searching for a Microsoft DSPM for AI consultant in Dubai, a Microsoft DSPM for AI implementation partner in the UAE, or a Purview AI data security expert for GCC deployment, you have found the right person. I am Basim Ibrahim, a Dubai-based cybersecurity presales and technical consultant working hands-on with Microsoft Purview Data Security Posture Management for AI, formerly the Purview AI hub and now part of the unified DSPM solution.

I provide end-to-end Microsoft 365 Copilot readiness and AI data security services in Dubai and the UAE, covering AI app discovery including shadow AI and consumer chatbot use, detection of sensitive data in AI prompts, SharePoint oversharing data risk assessments and remediation, DLP policies for generative AI including the Microsoft 365 Copilot location, SharePoint Restricted Content Discovery, and Communication Compliance for AI interactions.

Based in Dubai with hands-on experience across UAE and GCC enterprise environments, including DIFC Regulation 10 for autonomous and semi-autonomous systems, UAE PDPL and ADGM data protection obligations. An OSCP-certified offensive security background means I look at a Copilot rollout the way an attacker looks at inherited permissions, which is usually where the real exposure turns out to be.

Weekly Cyber Insights

One email per week. UAE/GCC focused. No spam, unsubscribe any time.