Every conversation we have with a Microsoft-heavy security team reaches this question within twenty minutes, so let's answer it in public and answer it honestly: if your AI estate is entirely Microsoft, your sensitivity labels are mature, and your concern is data-at-rest governance feeding Copilot — Purview covers more of this problem than any third-party vendor likes to admit. The moment any of those three conditions breaks, it doesn't. And in the enterprises we see, all three break.
This is the honest assessment: what Purview genuinely does well, the five places it structurally stops, and how to decide which side of the line your organization is on.
Last verified: August 6, 2026. A vendor writing about a partner-competitor: read with the appropriate eyebrow raised, and test every claim in your own tenant.
What Purview genuinely does well
- Data-at-rest classification at Microsoft scale. Sensitivity labels, trainable classifiers, and DLP policies across SharePoint, OneDrive, Exchange, and Teams — nothing third-party matches its reach inside the M365 estate.
- Copilot-specific controls that keep improving. DSPM for AI's oversharing assessments with item-level remediation, label-aware grounding restrictions, and — new in the July 2026 wave — a control excluding external-sender emails from Copilot grounding (preview), directly addressing email as a prompt-injection vector.
- Audit and eDiscovery integration. Copilot interactions land in the compliance ecosystem your legal team already operates.
- Cost story. Much arrives with E5 licensing you may already own. "Turn on what you have first" is advice we give in our own Copilot-readiness roundup, and we mean it.
The five structural gaps
1. Non-Microsoft AI is out of scope for real-time control
ChatGPT, Claude, Gemini, Perplexity, and the other ~1,400 tools your employees touch are where most shadow usage lives — and Purview's answer there is thin. The ChatGPT Enterprise integration is a Compliance API connector: post-hoc archiving for eDiscovery, not inline DLP. Nothing is redacted before transmission; the data has already left. For the consumer tiers and everything else, there is no answer at all.
2. Runtime beats index-time — and Copilot is going runtime
Purview's model classifies content at rest, then controls what grounding can retrieve. But Microsoft's own July 2026 Copilot updates added MCP-based federated connectors that access external data at runtime with no indexing — which means no label evaluation on what flows through. The architecture Purview polices is being bypassed by the platform it polices.
3. The endpoint layer does not exist
Desktop AI apps, AI-native IDEs shipping repository context, local models via Ollama, CLI agents, stdio MCP servers — none of it touches Purview's estate. This is the blind spot we just shipped a product for, and IBM's finding that shadow AI featured in 43% of 2026 breaches says it is not a rounding error.
4. Prompts are not files
Purview's DLP grew up on files and messages. AI leakage is fragments — six rows of a table pasted as context, a name and diagnosis in a question. Fragment-aware, prompt-boundary classification with redact-and-continue as the default action is a different discipline from block-the-upload, and it is the difference between a control employees tolerate and one they route around.
5. Labels are the load-bearing assumption
Every Purview AI control inherits the quality of your classification. Enterprises entering Copilot readiness with sparse label coverage get thin protection until a multi-quarter labeling program catches up — and the AI adoption curve does not wait for it.
The honest decision framework
| Your situation | Answer |
|---|---|
| Pure M365 AI estate, mature labels, Copilot-only concern | Purview may be enough. Run DSPM for AI, fix oversharing, revisit quarterly. |
| Copilot + any other assistant in real use | Purview for the Microsoft estate, plus a cross-platform inspection layer for everything else — the combination, not a replacement. |
| Developers with AI IDEs, agents, or local models | Purview does not play here. Endpoint-level AI governance is the missing control. |
| Regulated data + auditors asking about "AI" (not "Copilot") | Evidence must cover the whole estate; a Purview-only answer documents the gap it leaves. |
The framing we would want as a buyer: Purview governs your data inside Microsoft's walls. The AI problem of 2026 is that your data now exits through fifty doors that are not Microsoft's. Both layers are real; neither substitutes for the other.
FAQ
Does Purview do DLP for ChatGPT?
Not in the preventive sense. The ChatGPT Enterprise connector archives conversations after the fact for compliance review. Real-time inspection and redaction before data leaves the browser requires a boundary-level control.
We have E5. What should we turn on before buying anything?
DSPM for AI's oversharing assessment, sensitivity-label auto-labeling, the Copilot grounding controls, and the new external-email exclusion. Genuinely: do this first. What remains uncovered afterward is your real gap list.
Doesn't Microsoft Defender cover the AI attack side?
Increasingly, for Microsoft agents — with the significant caveat that as of July 1, 2026, agent discovery and posture in Defender require Agent 365-eligible licensing. That is its own honest-assessment post.
Is this just a vendor telling us we need their product?
It is a vendor showing its reasoning. If your estate matches row one of the table, you do not need us, and the post above says so. The rows below it are why we exist.
Sources: Microsoft Learn — DSPM for AI oversharing assessments · Microsoft Learn — Purview ChatGPT Enterprise integration · What's New in Microsoft Security, July 2026 · What's New in Microsoft 365 Copilot, July 2026 · IBM Cost of a Data Breach Report 2026.
Related: 7 Tools That Find Overshared Content Before Copilot Rollout · Does Copilot Respect Permissions? · Microsoft Copilot Data Security · AI DLP vs Legacy DLP.