Microsoft Adds DLP Controls for Copilot External Email

Let's Data Science – AI Governance(Global) 29 Jul 2026 60

Agencies deploying Microsoft 365 Copilot gain a configurable control to reduce external-email prompt-injection risk - a known grounding vulnerability.

  • Microsoft Purview now offers a preview DLP control blocking external email from grounding Microsoft 365 Copilot responses.
  • APS agencies using Microsoft 365 Copilot should note this as a concrete prompt-injection risk mitigation option.
  • General availability is January 2027; the control addresses one untrusted-input path, not a complete prompt-injection defence.
  • Consider Agencies already deploying or piloting Microsoft 365 Copilot could assess whether enabling this DLP control aligns with their AI risk and data-handling requirements.
  • Monitor Security and AI governance teams may want to monitor the general-availability rollout in January 2027 and review Microsoft's updated guidance on Copilot DLP at that time.

Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.

View original source