29% of employees have already used sanctioned AI agents for work tasks, according to Microsoft's Cyber Pulse report.
A 2026 study from LayerX Security found that 6% of employees pasted sensitive data into GenAI and 4% did so weekly, with certain platforms exceeding 12%. If you are running Microsoft 365 and do not have shadow AI controls in place, that data is leaving your environment every time someone pastes a contract into ChatGPT or uploads a spreadsheet to a consumer AI tool.
Microsoft has been building the tooling to address this across the browser, the network, and the data layer. Here is what is currently available and how it works.
Shadow AI refers to the use of generative AI tools by employees without organizational knowledge or governance. It follows a similar trajectory to shadow IT, but with a meaningful distinction. Shadow IT was about unapproved software operating on a network. Shadow AI is a data egress problem.
Whether it is a prompt containing client data, a file upload to an unmanaged platform, or customer information shared in an AI chat, organizational data is leaving the environment. That data may be retained by the AI provider, used in model training, or simply persist outside the organization with no record of its departure.
Standard security tooling is designed to detect threats. Shadow AI does not present as one.
It looks like normal HTTPS traffic to legitimate domains like ChatGPT, Claude, Gemini and DeepSeek. These are trusted TLS endpoints that most URL filters categorize as productivity tools. Most DLP policies monitor for credit card numbers or patient identifiers moving to known file-sharing sites. They are not evaluating content pasted into an AI chat interface.
A CASB helps to monitor sanctioned applications. It does not have visibility into what users type in a browser tab outside of those applications. Even with tools like Cloud App Security in the Microsoft stack, the various components often struggle to capture all of that activity.
This is not a misconfiguration. It is a category of data movement that did not exist when most security architectures were designed. According to Microsoft's 2026 Data Security Index, 86% of data security leaders now prefer integrated platforms over fragmented tools, and 47% of organizations are actively implementing GenAI controls, up 8% year over year.
Microsoft has recognized this gap and built a layered response directly within Microsoft 365.
A significant portion of shadow AI activity originates in the browser. A user opens a tab, navigates to an unmanaged AI platform, and begins submitting prompts.
Microsoft Edge for Business now includes in-browser managed DLP powered by Purview that monitors prompts being generated in the browser. Here is how it functions:
Prompts and file uploads are analyzed in real time.
Sensitive data triggers an immediate audit or block action.
Blocked users receive a policy-based notification explaining the restriction.
A redirect option routes the user to Microsoft 365 Copilot, where enterprise data protections are enforced.
Because these controls are integrated with Entra ID, they can be scoped precisely. They apply to Edge on both managed and unmanaged devices, provided users are signed into their Microsoft 365 account in Edge. Edge for Business settings also prevent users from bypassing controls by switching to an alternate browser.
Worth noting: This assumes Edge is being enforced as the primary browser. If it is not, additional controls through Intune or Conditional Access policies are necessary to address that gap.
Browser-level controls are valuable, but they do not provide full coverage. Microsoft Entra Internet Access, part of the Global Secure Access suite, introduces network-layer detection that became generally available in 2026.
This capability identifies previously unknown AI applications in use by analyzing traffic flowing to and from endpoints. It captures activity that endpoint management and browser controls cannot observe.
Global Secure Access accomplishes this by:
Once deployed, you gain visibility into which AI tools are in use. You can quantify the data volume moving to those tools. And you can determine the appropriate response from there.
On top of the browser and network layers, Microsoft announced additional Purview capabilities at RSA that extend protection across a broader surface area:
No single tool resolves the shadow AI problem in isolation. The value is in how these layers operate together:
|
Layer |
Tool |
What It Addresses |
|
Browser |
Edge for Business + Purview DLP |
Text prompts and supported file-upload scenarios |
|
Network |
Entra Internet Access (Global Secure Access) |
Traffic to AI applications that bypass browser controls |
|
Data |
Purview DLP |
PII, financial data, and IP in AI prompts across applications and agents |
Each layer addresses a distinct vector. Edge covers what happens in the browser. Global Secure Access covers what moves across the network. Purview DLP governs what sensitive data is permitted to reach AI tools in the first place.
If shadow AI governance is not yet on the roadmap, here is a good starting point:
The tooling is available and the deployment guidance is documented. Whether the starting point is discovery, DLP enforcement, or network-layer visibility, the controls within Microsoft 365 are ready to be deployed.
Shadow AI governance is quickly becoming a baseline exception, not a differentiator. Microsoft has invested heavily in giving organizations the tools to detect, monitor and block unsanctioned AI usage across the full Microsoft 365 environment. The gap between organizations that have these controls in place and those that do not is only getting wider, and the cost of closing it after a data incident is significantly higher than the cost of deploying them now.
If this is something your team has been thinking about, the Sourcepass Center of Excellence for Microsoft works with organizations every day on exactly this. We are happy to take a look at your environment and help you figure out where to start.