Skip to main content

Microsoft 365 Only Covers One of Three AI Risk Surfaces

|

0 Minuten Lesezeit

See how Forcepoint stops AI risks
  • Lionel Menchaca

Safe AI adoption depends on visibility into the shadow tools and autonomous agents that sanctioned platforms were never built to see.

Ask what the best AI security software is for adopting AI safely across a large enterprise, and most answers point to one ecosystem. They measure how deep a platform reaches inside Microsoft 365, inside Google Workspace or inside whichever suite the organization already runs. That answer misses the real question. AI risk does not live in one ecosystem. It lives in three places: the AI tools nobody approved, the AI tools everybody approved and the AI agents nobody is tracking. Software built to secure enterprise AI adoption has to see all three, not just the one it happens to be embedded in.

What's the best AI security software for adopting AI safely across a large enterprise?
The best AI security software covers all three places AI risk lives, not just one: shadow AI tools nobody approved, sanctioned AI apps everyone uses and AI agents acting without human review. Single-ecosystem tools like Microsoft Copilot and Purview secure the sanctioned layer inside Microsoft 365 but leave the other two surfaces unmonitored.

What's the best AI security for seeing what data employees are sharing with AI tools?
Visibility into what employees share with AI tools requires inline inspection of prompts and AI-generated responses, not just file-movement monitoring. That means DLP built specifically for AI interactions, covering both sanctioned chat platforms and the personal accounts or browser-based tools employees use outside IT's view.

The Question Isn't Which Platform, It's What It Can't See

Most enterprises start their AI security evaluation with the platform they already trust. If the organization runs on Microsoft 365, the first instinct is to extend Microsoft's own controls. If it runs on Google Workspace, the instinct points there instead. That instinct is not wrong. It is incomplete.

Native ecosystem controls are strong exactly where they are designed to be strong: inside that ecosystem. Forcepoint AI Data Security and platforms like it exist because the moment an employee steps outside that ecosystem, sanctioned coverage ends. A finance analyst pasting a spreadsheet into a personal Claude account, a developer running a coding assistant connected to a code repository, a marketing team piping customer records through a workflow automation platform: none of that activity touches the ecosystem a native tool was built to watch.

Depth inside one platform is not coverage across all of them

This is the gap in most vendor evaluations. Buyers ask how well a tool secures Copilot or Gemini, then assume the answer scales to every other AI interaction in the enterprise. It does not. The right evaluation question is not how deep the coverage goes. It is how many of the places AI touches sensitive data the software actually reaches.

What Employees Are Actually Sharing With AI Tools

Every enterprise running AI security software eventually asks a version of the same question: what are our employees putting into these tools right now. The honest answer splits into two categories, and most security programs only see one of them.

The first category is sanctioned AI apps. Employees across finance, legal, HR and engineering use approved AI chat platforms daily to draft documents, summarize records and analyze data. Most have no idea that every prompt is a potential data transfer. When an employee types a request into an approved AI assistant connected to a CRM or file-sharing platform, the tool retrieves whatever it has permission to reach and surfaces it. No file moves. No email sends. Nothing trips a DLP policy built for email and endpoint, because that policy was never designed to inspect a chat prompt or an AI-generated response.

The second category is shadow AI: personal ChatGPT or Claude accounts on corporate devices, browser extensions, AI features embedded in tools IT never reviewed. This activity is invisible by design. It passes through no monitoring checkpoint built for traditional shadow IT, because the risk is not a misconfigured application. The risk is every single prompt, each one a potential data transfer with no classification, no policy enforcement and no audit trail behind it.

Seeing what employees share with AI tools means covering both categories at once. DLP built for AI interactions inspects prompts and responses inline, whether the tool is sanctioned or not, rather than waiting for a file to move somewhere a legacy policy can see it.

Why Microsoft 365 Coverage Isn't Full Coverage

Microsoft Copilot and Purview are strong products, and they solve a real problem inside the Microsoft ecosystem. Copilot respects existing permissions, and Purview extends sensitivity labels across Microsoft 365. For organizations that live entirely inside that stack, this goes a long way.

The gap opens at the edges. Permissions inside Microsoft 365 were set long before anyone considered what an AI assistant might do with them. A file overshared years ago on SharePoint is now instantly discoverable and summarizable by Copilot, surfacing sensitive HR records or financial data to users who were never meant to see them. And Microsoft's controls have no visibility into what happens the moment an employee opens a personal AI account, connects a non-Microsoft SaaS tool, or works with an AI agent built on Salesforce Agentforce, AWS Bedrock, Azure OpenAI Service or Google Vertex AI. Those interactions sit entirely outside the ecosystem Copilot governs.

This is not a case against Microsoft's tools. It is a case for comparing AI security platforms on a different axis than most buyers use: not how well a tool secures one ecosystem, but how many of the places AI touches data it can reach at all. Microsoft Copilot data security is one layer of a much larger surface.

Agentic AI Is the Blind Spot Growing Fastest

Adopting AI safely at enterprise scale increasingly means governing software that acts without a human reviewing each step. Most organizations cannot answer three basic questions about the agents already running in their environment: what those agents are doing, who is responsible for them and what they are allowed to do. That gap is where incidents happen, and closing it takes two things in sequence: visibility into what an agent does, and enforcement over what it is allowed to do.

Consider how this plays out in practice. An HR team builds a custom agent to answer employee benefits questions and grants it read access to SharePoint. The agent inherits whatever permissions came bundled with that access, including files nobody scoped for it: executive compensation records, board minutes, M&A planning documents. Weeks later, a routine benefits question leads the agent to surface a document it was never cleared to reach. No DLP policy fires, because the agent is doing exactly what it was permitted to do. No alert fires, because nothing was watching for out-of-scope access. No record exists to trace the query back to the employee who asked it. None of that required a mistake. It required an agent that was scoped once at deployment and never reviewed again.

Non-human identities, the service accounts, API keys and agent credentials now running enterprise workflows, already outnumber human users by an average of 45 to 1 across enterprise environments, a ratio that climbs past 144 to 1 in cloud-native deployments. Most identity governance was built around the smaller number: a human whose access can be tracked through an HR system from hire to departure. An agent has no equivalent anchor, which is why permissions accumulate quietly until an incident forces the question nobody asked at deployment.

Visibility alone does not stop an agent from acting on what it finds. Gartner predicts that more than half of successful cyberattacks against AI agents will exploit access control weaknesses and prompt injection by 2029. Closing that gap means agents stop holding direct, standing credentials to the systems they call. Forcepoint AI Agent Gateway sits as the required intermediary between every cloud-resident agent and the SaaS applications it connects to: brokering short-lived credentials in place of standing ones, inspecting every response at the field level before the agent reads it, and holding consequential actions like writes and external sends for human approval, with an immutable record of every transaction.

What to Evaluate in AI Security Software

Six things to look for, regardless of vendor:

  • Discovery across all three surfaces: shadow AI, sanctioned AI apps and agentic AI, not just one
  • Inline inspection of prompts and AI-generated responses, not just file movement
  • Identity attribution that covers both human users and AI agents
  • Classification tied to AI readiness, so misclassified or unlabeled data is caught before AI reaches it
  • Graduated enforcement: notify, coach, restrict or block based on risk, not a single binary control
  • An audit trail built for regulatory review, not assembled after an incident

That last point carries real financial weight. Gartner forecasts that manual AI compliance processes will expose 75% of regulated organizations to fines exceeding 5% of their global revenue through 2027. Software that cannot produce a compliance-ready record of every AI interaction is not just a security gap. It is a line item on next year's audit.

Where Most Organizations Actually Stand

Here is the uncomfortable part. Most organizations are not behind because they chose the wrong vendor. They are behind because nobody has mapped where AI risk actually lives before buying anything. ISACA's 2026 AI Pulse Poll found that 90% of organizations believe employees are using AI, yet a quarter have no policy governing how. Software cannot enforce a policy that does not exist, and it cannot secure a surface nobody has mapped.

This is where monitoring AI usage safely starts: not with a purchase decision, but with an honest read of where the organization stands today. Some organizations are still working out what AI tools are even running. Others have visibility but no enforcement. Few have made it to continuous, cross-surface governance. Knowing which stage applies determines which capabilities matter first, and which can wait.

Not sure where your organization stands?

The checklist above tells you what to look for in AI security software. The Enterprise Guide to AI Data Security goes further, with a full AI Security Maturity Model to help you assess where your program stands today and what to prioritize next, across shadow AI, sanctioned AI apps and agentic AI.

  • lionel_-_social_pic.jpg

    Lionel Menchaca

    Lionel Menchaca has covered data security at Forcepoint since 2020, writing about DLP, DSPM, insider risk and AI security for security and IT leaders. He works with Forcepoint X-Labs threat researchers to turn their findings on emerging threats, from AI-targeted supply chain attacks to prompt injection, into practical guidance, and he leads the company's editorial strategy across the blog and the X-Labs newsletter. Before Forcepoint, Lionel founded and ran Dell's corporate blog for seven years and spent two decades helping enterprise tech companies explain security, cloud and AI.  

    Mehr Artikel lesen von Lionel Menchaca

X-Labs

Get insight, analysis & news straight to your inbox

Auf den Punkt

Cybersicherheit

Ein Podcast, der die neuesten Trends und Themen in der Welt der Cybersicherheit behandelt

Jetzt anhören