Perspicuity Insights

Navigating Compliance Challenges with Copilot and Microsoft Purview

Written by Jodie Lawrance | Oct 1, 2024 10:45:58 AM

Many organisations are now rolling out Copilot to business users, and over 70% of users are reaping the benefits of this tool to increase not only productivity but the quality of their work. However, a rollout of Copilot should come with careful consideration and comes with new compliance challenges and risks. This is where Purview can help.

Purview's AI Hub

The new Purview AI Hub can aid the rollout of CoPilot by providing a centralised management location to secure data and monitor AI use. Out-of-the-box policies in the AI Hub can be used to protect sensitive information shared through AI tools prevent sensitive data loss and maintain compliance.

Gaining Insights and Managing Risks

The tool also allows you to gain valuable insights into how Copilot and other AI tools are being leveraged across your organization and the risk level to your organisation from this. Additionally, it is possible to see what sensitive data is being shared in your AI tools and other valuable insights such as how many users are utilising AI. Understanding how many people in the organization are using their Copilot licence is crucial for maximising the investment in this AI tool. By tracking usage, organisations can identify areas for further training and support, ensuring that the capabilities of Copilot are fully leveraged.

Enhanced Protections with Microsoft Purview

Purview also offers additional protections such as when Copilot is used to create new content based on an item with a sensitivity label, this label will be applied to the new content an example of this could be when a user drafts a new Word document and references a file with a sensitivity label applied, this label will be applied to the new word document.

Starting with Information Protection

Suppose your organisation is still in the process of starting to use information protection. In that case, the AI Hub can help by surfacing unlabelled files and sites in SharePoint that Copilot has been asked to reference. This can help with identifying potential vulnerabilities and ensure that sensitive information is not inadvertently shared or exposed. By providing visibility into the data sources and collaboration spaces Copilot interacts with, organisations can better enforce data protection policies and respond to emerging compliance needs effectively.

Getting Ready with Perspicuity

At Perspicuity we can help you get your business ready for Copilot with sessions geared towards training and education. As well as reviewing your organisation for Copilot readiness by reviewing your M365 estate to highlight any potential risk and provide recommendations for a smooth rollout, we can also review your Microsoft Purview so that you are gaining full value out of the tools available within your licence and help you easily put protections in place to avoid loss of sensitive information outside your organisation and avoid compliance violations.