Microsoft DSPM for AI Expert & Copilot Readiness Consultant
Data Security Posture Management for AI lives inside Microsoft Purview and answers the question every board is now asking: what is our AI actually touching. I work hands-on across discovery of Copilot, enterprise AI and shadow AI use, sensitive data in prompts, and the oversharing assessments that decide whether a Microsoft 365 Copilot rollout is safe or embarrassing.
- Oversharing fixed before Copilot goes live
- Shadow AI made visible, not just banned
- Current 2026 naming and portal experience
What is Microsoft DSPM for AI?
Data Security Posture Management for AI is a Microsoft Purview capability, not a separate product, and its name has moved twice. It launched as the AI hub in the Purview compliance portal, was renamed Data Security Posture Management for AI, and in 2026 Microsoft merged DSPM and DSPM for AI into one unified solution. In the Microsoft Purview portal today you go to Solutions and then DSPM. The predecessors are still visible, relabelled Data Security Posture Management (classic) and DSPM for AI (classic), and Microsoft has said new features are going to the unified version only. Everyone still says DSPM for AI when they mean the AI side of it, and that is fine. Just be aware that guidance written before the merge points at menus that have moved.
What it does is answer three questions in order. First, what AI is in use here. That splits into Copilot experiences and agents, enterprise AI apps such as registered ChatGPT Enterprise workspaces and applications built on Microsoft Foundry, and other AI apps, which is the polite name for staff pasting work into consumer chatbots. Copilot visibility needs only Purview Audit switched on. Third-party AI site visibility additionally needs the Purview browser extension and devices onboarded to Purview, and detection outside a managed browser needs network data security through a SASE or SSE integration. Second, what sensitive data is going into prompts. Activity explorer shows AI interactions with the prompts and responses, the sensitive information types detected, files referenced, and whether a DLP rule matched during the interaction. Third, what is overexposed before AI amplifies it, which is the part that actually decides whether your Copilot programme succeeds.
That third question is where the real work is. Generative AI does not create the oversharing problem, it removes the friction that was hiding it. A decade of inherited SharePoint permissions, sites shared with everyone in the organisation, and forgotten anyone-with-the-link sharing links means most users already have rights to material nobody intended them to see. Copilot simply makes it findable. DSPM runs a default weekly data risk assessment across the top 100 SharePoint sites by usage with no activation needed, and custom assessments add item-level scanning with remediation actions: apply a sensitivity label, notify the site owner, resolve as not at risk, or remove the sharing link. The limits are worth knowing before you promise a timeline, including a maximum of 10 SharePoint sites per item-level scan, a 200,000 item cap per location, and no OneDrive support for item-level scanning. Alongside that sit the enforcement controls: DLP scoped to the Microsoft 365 Copilot location so labelled content is not summarised, SharePoint Restricted Content Discovery to fence off whole sites, Communication Compliance policies that review AI interactions for unethical or non-compliant content, and Insider Risk Management templates that score risky AI usage.
Official Product Portfolio
- DSPM (current unified solution)
- DSPM for AI (classic)
- DSPM for AI considerations
- Classic to unified task mapping
- Oversharing data risk assessments
- Supported third-party AI sites
- DLP for Microsoft 365 Copilot
- Network data security
- Restricted Content Discovery
- Communication Compliance
- Risky AI usage policy templates
- Permissions for AI insights
- Security Copilot agents in Purview
- Sensitivity labels
Where I Can Help
The order matters here. Discover what AI is already in use, fix the oversharing, then enforce. Doing it in the other order produces a Copilot pilot that gets paused in week two.
AI Discovery & Shadow AI Visibility
Getting the prerequisites right so discovery is real rather than partial: Purview Audit enabled, the Purview browser extension deployed, devices onboarded to Purview, and one-click discovery policies activated. Then separating what you see into Copilot experiences and agents, enterprise AI apps, and consumer AI sites, so the shadow AI conversation is based on evidence instead of assumptions.
Sensitive Data in Prompts
Using Activity explorer and the AI reports to see which sensitive information types are actually being pasted into prompts, which files are being referenced, and where a DLP rule fired during an AI interaction. This is usually the moment a leadership team stops debating AI policy in the abstract and starts making decisions.
Oversharing Assessments & Remediation
The single biggest blocker to a safe Copilot rollout. Reading the default weekly assessment across the top 100 SharePoint sites, then designing custom assessments with item-level scanning around the real limits of 10 sites per scan and 200,000 items per location. Remediation is the deliverable: labels applied, sharing links removed where justified, site owners notified, and a phased plan for an estate too big for one pass.
DLP Policies for Generative AI
Configuring Data Loss Prevention scoped to the Microsoft 365 Copilot location so labelled content is not summarised by Copilot or agents, plus policies that detect and restrict sensitive information sent to third-party generative AI sites. Where a site is beyond remediating before go-live, SharePoint Restricted Content Discovery fences it off as a temporary measure rather than a permanent one.
Communication Compliance & Insider Risk for AI
Switching on the AI-aware compliance layer: Communication Compliance policies that review Copilot prompts and responses for unethical or non-compliant content, Insider Risk Management risky AI usage detections that feed user risk, and the retention and policy configuration needed for Copilot interactions to be captured and reviewable in the first place.
Copilot Readiness Programme
Pulling all of it into a sequenced programme with a gate before rollout: discovery baseline, oversharing remediation against agreed thresholds, label taxonomy and auto-labelling live, DLP and Restricted Content Discovery in place, monitoring configured, and a documented position for legal and the regulator. Then a phased user release rather than a tenant-wide switch.
Why Microsoft DSPM for AI for UAE Organisations?
The UAE has moved faster on AI regulation than most markets, and that is now a practical constraint rather than a talking point. DIFC issued Regulation 10 covering personal data processed through autonomous and semi-autonomous systems, which places obligations on the deployers and operators of such systems and requires an Autonomous Systems Officer where the system is high risk. If your DIFC-licensed entity is rolling out Microsoft 365 Copilot over data containing personal information, that is not a future concern. Alongside it sit the federal PDPL, Federal Decree-Law No. 45 of 2021, and the ADGM Data Protection Regulations 2021, both of which expect purpose limitation, data minimisation and a lawful basis. An AI assistant that can surface any document a user has rights to is a direct test of whether those principles are implemented or merely written down.
This is exactly why the oversharing assessment matters more here than the discovery dashboard. Regional organisations tend to run flat SharePoint estates built quickly during cloud migration, with generous sharing defaults and permissions inherited from site collections that nobody has revisited. In that environment Copilot will find the HR folder, the legal folder and the board pack, because the permissions already allow it. Under PDPL or DIFC rules, an employee retrieving personal data they had no legitimate business need to see is a data protection issue regardless of how they found it. Running the data risk assessments, remediating what they surface, and keeping the evidence of that remediation is the difference between a Copilot programme a regulator accepts and one you have to defend after the fact.
Data residency and sector rules complete the picture. The United Arab Emirates is on the Microsoft 365 Local Region Geography list, so a durable commitment on data location is available through the Advanced Data Residency add-on, though its scope covers a defined subset of Purview services and requires 100 percent coverage of eligible paid seats. NESA, the CBUAE requirements for financial institutions and the DESC Information Security Regulation all sit on top for the organisations they apply to. The practical output of an engagement here is not a dashboard screenshot. It is a defensible written position on which AI tools are in use, what data they reach, what controls restrict them, and what evidence you can produce when someone asks.
Talk to a DSPM for AI Expert
Whether you are gating a Microsoft 365 Copilot rollout on a data security sign-off, trying to see what shadow AI is really in use, or building a DIFC and PDPL position for AI, I can help.
- Free initial scoping call
- Oversharing remediation, not just reporting
- PDPL, ADGM & DIFC context
- OSCP-certified security background
Frequently Asked Questions
DSPM for AI Sits Inside Microsoft Purview
Every control this page describes depends on the wider Purview platform: sensitivity labels, Data Loss Prevention, Insider Risk Management, Communication Compliance and Audit. If AI is your entry point, Purview is what you are really buying. The Microsoft Security portfolio page covers how it lines up with Defender, Sentinel and Entra.
Basim Ibrahim, Microsoft DSPM for AI Consultant in Dubai
If you are searching for a Microsoft DSPM for AI consultant in Dubai, a Microsoft DSPM for AI implementation partner in the UAE, or a Purview AI data security expert for GCC deployment, you have found the right person. I am Basim Ibrahim, a Dubai-based cybersecurity presales and technical consultant working hands-on with Microsoft Purview Data Security Posture Management for AI, formerly the Purview AI hub and now part of the unified DSPM solution.
I provide end-to-end Microsoft 365 Copilot readiness and AI data security services in Dubai and the UAE, covering AI app discovery including shadow AI and consumer chatbot use, detection of sensitive data in AI prompts, SharePoint oversharing data risk assessments and remediation, DLP policies for generative AI including the Microsoft 365 Copilot location, SharePoint Restricted Content Discovery, and Communication Compliance for AI interactions.
Based in Dubai with hands-on experience across UAE and GCC enterprise environments, including DIFC Regulation 10 for autonomous and semi-autonomous systems, UAE PDPL and ADGM data protection obligations. An OSCP-certified offensive security background means I look at a Copilot rollout the way an attacker looks at inherited permissions, which is usually where the real exposure turns out to be.