Extend Microsoft Purview when your AI risk lives inside Microsoft's surfaces — Microsoft 365 Copilot and Edge for Business. Buy AI-native DLP when desktop apps, non-Edge browsers, ChatGPT Enterprise enforcement, or non-Microsoft data stores matter. Most enterprises need both.
That is the direct answer to the question security teams are literally typing into search: "Is it better to extend Microsoft Purview or buy a dedicated AI security product?" The rest of this post shows the working — what Purview actually enforces for AI today according to Microsoft's own documentation, where those documents draw hard limits, and a decision table you can apply to your estate. This is not a Purview hit piece. Purview is the right tool for a well-defined set of jobs; the point is to name that set precisely. All Microsoft documentation facts below — last verified: September 5, 2026.
What does Purview DLP actually enforce for AI today?
For Microsoft 365 Copilot and Copilot Chat, Purview now has a dedicated DLP policy location with four real controls: block web-search grounding when a prompt contains sensitive info types, block Copilot from processing sensitive prompts (in preview, rolling out to all tenants), exclude files and emails carrying sensitivity labels from Copilot processing, and block external email from grounding (also preview). These are genuine enforcement capabilities, and if M365 Copilot grounding is your primary AI risk, they are the shortest path to control.
The fine print in the same document deserves equal billing. Microsoft states plainly: "DLP can't scan the contents of files that you upload directly into prompts, so evaluation of the uploaded file for sensitive data doesn't occur. DLP only checks the text you type into the prompt itself." Policy changes are not instant: "Updates to a DLP policy can take up to four hours to reflect in Microsoft 365 Copilot and Copilot Chat experience." You also "can't use both content contains sensitive info types and content contains sensitivity labels conditions in the same rule," calendar invites aren't supported, the location is only available in the custom policy template, it doesn't support admin units, and selecting it disables every other location in that policy. Label-excluded files still show up: "Identified items still appear in the citations of the response, but the content of the item isn't used in the response." None of this makes the controls useless. It makes them narrow — and four hours of policy latency is a long time in an incident.
Can Purview enforce DLP inside ChatGPT Enterprise?
No — and this is the single most concrete, checkable proof point in the whole extend-vs-buy debate. Microsoft's own documentation for managing ChatGPT Enterprise with Purview includes a capabilities table. Here it is, reorganized:
| Purview capability | ChatGPT Enterprise support |
|---|---|
| DSPM and DSPM for AI (classic) | Supported |
| Auditing | Supported |
| Data classification | Supported |
| Insider Risk Management | Supported |
| Communication compliance | Supported |
| eDiscovery | Supported |
| Data Lifecycle Management | Supported |
| Compliance Manager | Supported |
| Sensitivity labels | Not supported |
| Encryption without sensitivity labels | Not supported |
| Data loss prevention | Not supported |
Read the split carefully: Purview can capture, audit, retain, and investigate ChatGPT Enterprise interactions — after they happen. It cannot block or redact anything inside ChatGPT Enterprise. The integration also requires the ChatGPT Enterprise connector ("You must run the connector scan before Microsoft Purview can manage the AI interactions") and pay-as-you-go billing on top of licensing. If your compliance story for ChatGPT Enterprise is Purview, your story is visibility, not prevention. That may be enough — see the honest section below — but it should be a decision, not an assumption. The sibling assessment post covers the visibility side in more depth.
Where does Purview's browser DLP stop?
Purview's inline protection for consumer AI apps is built into Edge for Business — "the two latest stable versions," starting with version 144 — and covers a fixed catalog of 19 unmanaged AI apps: ChatGPT (consumer), Google Gemini, DeepSeek, Perplexity, Grok, Meta AI, Notion AI, Otter.ai, Adobe Firefly, CapCut, Runway, and eight others. Three scoping limits follow directly from Microsoft's documentation:
- Edge only. Chrome and Firefox need the Purview browser extension; everything else is handled by exclusion: "If users try to access an unmanaged app in an unprotected browser, they're blocked and must use Edge for Business." That is control by blocking, not inspection.
- Managed Windows only for the unmanaged-app scenarios. Consumer-AI policies require Windows 10/11 devices managed by Intune. BYOD, macOS outside Edge work profiles, and unmanaged devices fall outside.
- Enforcement is best-effort against evasive apps. Microsoft's own caveat: "Some unmanaged AI apps like Runway and Meta AI might intermittently send content in encoded form to dynamically generated endpoints, which can impact policy enforcement."
Add the boundary cases: "Microsoft Purview browser and network data security policies don't apply to B2B guest users," desktop AI clients such as the ChatGPT and Claude native apps appear nowhere in the published DLP-for-AI docs, local models are not addressed at all, and network-level AI visibility exists only through SASE partner integrations, some still in preview. A 19-app catalog is also a denominator problem: the AI app universe is orders of magnitude larger, and every app outside the catalog is invisible to the policy engine rather than governed by it.
What does AI-native DLP add?
Four things Purview's published architecture does not attempt. First, surface coverage: any browser, native desktop apps, IDE assistants, and enterprise AI apps like ChatGPT Enterprise — with enforcement, not just audit. Second, catalog breadth: AccuroAI's workforce AI governance, for example, governs against a catalog of 1,400+ AI applications rather than 19, classifying prompts inline with 40+ data classifiers and 60+ secret-type detectors at under 38ms p99 — fast enough to redact rather than block, which is why redact-don't-block is viable at this layer. Third, label independence: Purview's strongest Copilot control excludes content by sensitivity label, which means enforcement quality equals labeling quality; AI-native tools classify content at the moment of use instead of trusting labels applied months ago. Fourth, non-Microsoft scope: classification across stores like Snowflake, S3, Salesforce, and Slack that M365-anchored DLP does not reach.
Notably, the AI-native vendors closest to Microsoft do not pitch rip-and-replace. Concentric AI positions itself as a complement — its published stance is that Purview enforces policy while Concentric supplies accurate, consistently applied classification underneath it, writing results back into Microsoft labels. That "extend and augment" posture, coming from a vendor with every incentive to say otherwise, is a useful signal about where the real boundary sits. The AI DLP vs legacy DLP comparison unpacks the architectural difference further.
Extend or buy: how do you decide?
Map your actual AI surface against what Purview enforces, what it merely observes, and what it ignores:
| AI surface | What Purview does today | Verdict |
|---|---|---|
| M365 Copilot and Copilot Chat | Enforces — four DLP controls, with the caveats above | Extend |
| Consumer AI in Edge, on Intune-managed Windows | Enforces — for the 19 cataloged apps | Extend |
| Consumer AI in Chrome/Firefox or on macOS/BYOD | Partial — extension-dependent or blocked, not inspected | Buy if you can't standardize on Edge |
| ChatGPT Enterprise | Observes — audit, eDiscovery, IRM; DLP and labels not supported | Buy for enforcement; keep Purview for records |
| Native desktop AI apps | Not covered in published DLP-for-AI docs | Buy |
| Local models (Ollama, LM Studio) | Not addressed | Buy |
| Non-Microsoft data stores (Snowflake, S3, Salesforce, Slack) | Outside M365 DLP scope | Buy or augment |
The pattern in the verdict column is the framework: extend where you are inside Microsoft's walls, buy where you are not. Count your rows. An estate that is genuinely Edge-standardized, Intune-managed, and Copilot-centric lands mostly on "extend." A mixed estate — and most are mixed — cannot get to enforcement with Purview alone.
When is extending Purview the right call?
Honestly: often. Extend Purview when your organization is Microsoft-first with E5 or Copilot licensing already paid; when M365 Copilot grounding and Edge-based consumer AI are your dominant risks; when Intune-managed Windows plus Edge standardization is achievable rather than aspirational; and when audit, eDiscovery, and retention of AI interactions — the things Purview does support for ChatGPT Enterprise — are what your regulator actually asks for. One budget note before calling it "free with E5": several of Purview's AI protections, including the ChatGPT Enterprise connector and the Edge unmanaged-app scenarios, are metered pay-as-you-go on top of licensing. Model the consumption before you model the comparison. For the broader control-plane picture, see the prompt DLP pillar guide and the enterprise AI DLP guide.
FAQ
Does Purview DLP work with ChatGPT Enterprise?
No. Microsoft's capabilities table for ChatGPT Enterprise marks data loss prevention, sensitivity labels, and encryption without labels as not supported. Purview can audit, classify, retain, and investigate ChatGPT Enterprise interactions via the connector — it cannot block or redact them. Last verified: September 5, 2026.
Does Purview scan files uploaded into Copilot prompts?
No. Per Microsoft's documentation, "DLP can't scan the contents of files that you upload directly into prompts" — only the typed prompt text is evaluated.
How many AI apps does Purview's browser DLP cover?
The unmanaged AI app catalog for Edge for Business inline protection lists 19 apps, and the block scenarios require Intune-managed Windows devices. Apps outside the catalog, and browsers other than Edge (or Chrome/Firefox with the extension), are outside inspection.
How fast do Purview DLP policy changes take effect for Copilot?
Microsoft documents that updates "can take up to four hours to reflect in Microsoft 365 Copilot and Copilot Chat experience." AI-native inline tools enforce policy changes at the interception point, without a propagation window.
Should we replace Purview with AI-native DLP?
For most organizations, no — the realistic end state is extend and augment. Keep Purview for M365 Copilot enforcement, audit, eDiscovery, and retention; add AI-native DLP for the surfaces Purview observes or ignores: enterprise AI apps, non-Edge browsers, desktop clients, and non-Microsoft stores.
Sources: Microsoft Learn, "Use Microsoft Purview to manage data security & compliance for ChatGPT Enterprise" (updated Jul 29, 2026) · Microsoft Learn, "Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat" (updated Jul 17, 2026) · Microsoft Learn, "Data Loss Prevention for Cloud Apps in Edge for Business" (updated Aug 31, 2026) · Microsoft Learn, Purview extension for Chrome · Microsoft Security Blog, Purview innovations at RSA 2026 · Concentric AI, "Microsoft Purview and Concentric AI: working better together". All sources accessed September 5, 2026.
Related: Workforce AI Governance · Is Microsoft Purview Enough for AI Security? · AI DLP vs Legacy DLP for GenAI Workflows · Redact, Don't Block.