KI-Governance und verantwortungsvolle KI

← AI governance

Copilot governance and Shadow AI

Place Copilot use on a reliable data, authorisation and operational basis.

This page covers Microsoft Copilot, Microsoft 365 Copilot, Copilot Chat and agents where they are used in or connected to the Microsoft 365 environment. A controlled introduction begins not with licence assignment but with readiness in terms of data, access, responsibilities and use. Microsoft 365 Copilot can reference content within existing permissions and policies; inappropriate sharing may therefore become more visible. Plugins, agents, connectors and additional data sources each require their own assessment. Governance therefore combines permission clean-up, information protection, policies, training, monitoring and a controlled lifecycle.

Relationship to services and technologies

KI-Governance und verantwortungsvolle KI

This is about the regulatory and operational control issues when using Copilot that is already planned or ongoing: permissible data, approvals, evidence and the handling of Shadow AI. You can find the start of the consultation and introduction in the solution AI Readiness / Copilot Governance.

Background

Departments often use generative AI before central specifications, data classification or approval processes are established. Shadow AI refers here to non-coordinated or non-controlled AI use; the term is not a fixed legal term. It can lead to unclear data flows, incomprehensible decisions and inconsistent usage. A blanket ban rarely solves the underlying needs; An uncontrolled rollout, on the other hand, reinforces existing weaknesses in approvals and content ownership.

Microsoft describes the data access architecture for Microsoft 365 Copilot and the consideration of existing permissions, sharing settings and policies. Governance must therefore address both the AI scenario and the quality of the existing data and access control.

Technical context

Abstrakte Illustration: Shield/Check und Dokumente in Blau.

Copilot Governance is the control of the entire usage cycle: needs and target image, data and authorisation readiness, release, secure use, monitoring, adjustment and orderly termination. It differs from a pure product configuration. The classification according to the EU AI Act or other requirements must also be assessed on a case-by-case basis and by the responsible specialist and legal functions.

Oversharing is a key operational risk: Content is not necessarily accessible without authorisation, but may be too widely visible due to historically broad groups, sharing links, unclear ownership, or broken permission inheritance. Microsoft describes, among other things, reports on data access governance, access restrictions and limited content recognition as possible technical aids.

What companies need to clarify specifically

  • Which copilot and AI use cases have a comprehensible benefit and a responsible owner?
  • Which data sources, groups, sites, agents and connectors are in the respective scope?
  • Where are wide sharing, anonymous links, inactive or ownerless sites, and complex permissions?
  • What content needs classification, protection or limits on discoverability?
  • Who approves new use cases, checks exceptions and is responsible for training, monitoring and regular re-evaluation?

From requirements to implementation

Abstrakte Illustration: KI‑Netzwerk und Datenplattform in Blau.
Assess readiness

Risk: Copilot makes existing oversharing visible
Organisational measure: Define scope, owner and risk criteria
Technical implementation: Authorisation and approval evaluation
Possible evidence: Readiness report, action list

Limit data access

Risk: Inappropriate discoverability of sensitive content
Organisational measure: Access and Sharing Rules, Access Reviews
Technical implementation: SharePoint/OneDrive controls, group controls
Possible evidence: Review protocols, authorisation statuses

Apply information protection

Risk: Sensitive data is used uncontrollably
Organisational measure: Classification and DLP model
Technical implementation: Labels, DLP, appropriate protection policies
Possible evidence: Policy tests, incident reports

Control usage

Risk: Unsafe prompts or external AI use
Organisational measure: AI Policy, Training, approval process
Technical implementation: Tenant and app policies as needed
Possible evidence: Training and approval records

Monitor operations

Risk: New risks remain undiscovered
Organisational measure: Metrics, review and escalation process
Technical implementation: Audit and security assessments
Possible evidence: Review results, tickets

Limitations and dependencies

Copilot can take existing permissions and policies into account, but does not automatically correct inappropriate access models. Technical controls must work together with data quality, ownership, training and specialist processes. The scope of licenses and functions as well as the specific data connection must be checked before each implementation in the client.

Orientation

Frequently asked questions

Does Copilot have access to all company data?

Microsoft describes that Microsoft 365 Copilot can reference content to which the individual has authorized access. This does not mean that every release is technically appropriate. Permissions, sharing links, and content ownership should be checked before and during rollout.

How can Shadow AI be reduced?

With a combined approach: understandable permitted usage paths, prioritised business use cases, training on data and prompts, clear approvals for tools and an escalation path for new needs. Monitoring and regular feedback show where rules or technical controls need to be adjusted.

Which pages complement this topic?

GDPR and cloud practice GDPR in IT and cloudClassification and Purview treated Data classification and Microsoft Purview, identity and devices Entra, Conditional Access and Intune. The existing solution leads for AI readiness scenarios AI Readiness / Copilot Governance on.

Next sensible step

Abstrakte Illustration: Shield/Check und Dokumente in Blau.

The existing solution provides commercial entry into prioritised copilot scenarios AI Readiness / Copilot Governance on.