Microsoft Dataverse - Run Prompt Columns on existing records in bulk

🚨 The Signal: Dataverse will allow bulk execution of generative AI prompts on existing records, enabling automated data summarization, classification, and extraction. This introduces new risks for data governance and potential for AI-driven data manipulation.

The Impact

Security teams and data owners are affected by new risks of AI-driven data manipulation and potential for sensitive data exposure.

  • Security teams face new risks from AI-generated content and potential for prompt injection.
  • Data owners must assess integrity of AI-enriched data and potential for misuse.
  • Compliance officers need to review data handling policies for AI-generated information.
  • Administrators must understand new AI capabilities and their security implications.

The Action

  1. Review Dataverse security roles and permissions for users interacting with prompt columns.
  2. Develop or update policies for acceptable use of generative AI in Dataverse.
  3. Implement data validation processes for AI-generated or enriched data.
  4. Monitor Dataverse audit logs for unusual activity related to bulk prompt execution.
  5. Assess potential for prompt injection attacks on custom AI models in Dataverse.

Domain: Agentic-AI · Impact: high · Workload: Other