Classical data loss prevention was built for one problem. Someone with access to sensitive data tries to email it out, upload it to a personal cloud, or copy it to a USB drive. DLP tools scan email and endpoints, look for credit card numbers and Social Security numbers, and block the exfiltration.
That model still works. It just is not the model that matters most anymore.
The new problem is that authorized users can now weaponize their own permissions at machine speed. Copilot cheerfully summarizes any document you already had access to, whether or not you remember what is in it. The sales rep who was accidentally added to the executive comp folder in 2023 now has an AI that will happily draft an email to a customer based on the salary spreadsheet if the prompt is worded a certain way.
Nothing about that is a malicious insider. It is a permissions and labeling problem that the AI does not know to solve. DLP for AI is the discipline of catching that failure mode.
What "DLP for AI" actually means in practice
Three things, roughly in order of impact.
- Sensitivity labels on the underlying data. If your finance folder is labeled "Confidential / Finance," the AI can be told not to ground responses on that content unless the user has an explicit business need. Purview handles this. So do most modern DLP platforms.
- AI-aware policies at the tool boundary. When someone asks Copilot to draft an email that quotes a labeled document, the DLP policy fires before the tool responds. The user sees a "content restricted" message, the labeled content is redacted from the response, and an admin sees the attempt in the audit log.
- Prompt-and-response inspection. For sensitive workloads, the AI's inputs and outputs are inspected in-line. A prompt that requests confidential financial data gets held. A response that would include a Social Security number gets masked. Vendors like Netskope, Zscaler, and Palo Alto's newer offerings ship this at the browser and network layer.
If you are a Microsoft shop, most of this lives in Purview and is licensed through the Purview Suite.
The Microsoft Purview picture
Microsoft's frame is that Copilot inherits your existing permissions. That is a strength when your permissions are clean. It is a landmine when they are not. Purview closes the gap in three specific ways.
- Sensitivity labels applied to Word, Excel, PowerPoint, PDF, and SharePoint documents. These labels can be manually applied by users or automatically applied by pattern-matching rules that Purview runs on the content.
- DLP for Copilot policies that tell Copilot not to include labeled content in its responses, or to strip specific data types (like Social Security numbers or bank routing numbers) from any answer regardless of source.
- Purview Data Security Posture Management for AI that surfaces where sensitive data is actually being touched by Copilot, which users are prompting it against sensitive material, and where the labeling gaps are.
The whole stack is included in the Purview Suite (approximately $10 per user per month; half that for the first year through December 31, 2026, per the current Copilot promotion). For most mid-sized businesses that are actually deploying Copilot across a real team, the Purview Suite is the pairing that makes the rollout safe. For smaller teams with a limited Copilot deployment, the labels and DLP policies that come with Business Premium alone can be enough. See Microsoft put Copilot in the box for how the Purview Suite stacks on top of Business Premium with Copilot.
What if you are not a Microsoft shop
The concepts are the same. The tools are different.
- Google Workspace + Gemini. Google's Data Loss Prevention for Gmail and Drive is the equivalent surface. Gemini for Workspace respects Drive permissions and label-based access. If you are running Google Workspace with Gemini, spend the time on labels and Vault before you widen Gemini access.
- Browser DLP. Netskope, Zscaler, Menlo, and Island all ship browser-level policies that fire on prompt content sent to ChatGPT, Claude, Perplexity, or any other web-based AI. This is the layer you want if your team uses AI outside of a corporate-managed suite.
- Endpoint DLP. For local AI agents (Claude Cowork, OpenClaw, self-hosted models), traditional endpoint DLP still applies. What Cowork is allowed to read is a permissions question. What it is allowed to send outside your network is a DLP question.
- API-level policies. If your team is calling models directly via API (see Beyond Cowork), your DLP boundary is the code, not the tool. Vendors like Portkey and LiteLLM sit in front of API calls and enforce content policies before requests leave your infrastructure.
The pattern across all of these: the DLP boundary needs to sit where the AI actually reads and writes. For Microsoft Copilot that is inside Microsoft. For browser-based AI that is at the browser. For self-hosted or local agents that is at the endpoint.
The starting move, if you have not started yet
Do not buy anything on day one. Do this instead.
- Inventory what your team is actually using. ChatGPT? Claude? Copilot? Gemini? Note-takers like Otter? Vibe-coding tools? The list is longer than most owners think.
- Identify the top three data categories you actually care about. Customer data. Financial records. Employee data. Do not try to label everything on day one.
- Apply sensitivity labels to those categories in the systems where they live. SharePoint, Drive, whatever your CRM is. Do not skip this step. It is what makes every other DLP policy work.
- Enable AI-aware DLP policies for one workflow first. Usually the finance folder is the fastest win. See if the labeling actually catches what you thought it would.
- Expand from there. Iterate on labels, watch the audit logs, and grow scope.
Doing this once is often enough to catch the ninety percent of accidental data exposure that AI has enabled. The remaining ten percent is where the real DLP investment goes.
What to buy, and what to do with what you already have
- On Business Premium, rolling Copilot to a small team. Use the labels and DLP that come in the box. That is enough to start.
- Deploying Copilot to a whole team (more than twenty users on the paid Copilot SKU). Add the Purview Suite. The five to ten dollars per user per month is cheap insurance against the audit finding that eventually surfaces.
- Using a mix of AI tools outside the Microsoft stack. Add a browser DLP layer. Netskope and Zscaler both have mature offerings. Prices vary widely by contract size. Get quotes from two.
- Building AI features into your own product. Put an API gateway with content policies in front of the model calls. Portkey and LiteLLM both do this cleanly.
Bottom line
DLP for AI is not a new product category so much as the classic DLP category grown up to a new failure mode. The failure mode is not the malicious insider. It is the authorized user with a helpful AI and a labeling gap they did not know existed.
Fix the labels first. Layer the AI-aware policies on top. Watch the audit logs for a month. That is the discipline that makes the AI rollout safe without turning your team into a set of compliance officers.
For the executive framework on evaluating any AI tool before you deploy it, see The AI Owner's Manual. For the M365 Copilot side of this specifically, see Microsoft put Copilot in the box.