Microsoft Copilot (Microsoft 365): CSV and TSV references in Copilot Notebooks
🚨 The Signal: Copilot Notebooks now ingest CSV/TSV files, expanding data sources for AI-generated content. This increases the potential for sensitive structured data to be processed by Copilot, requiring enhanced data governance.
The Impact
All users are affected, increasing the risk of sensitive data exposure through Copilot's expanded data ingestion capabilities.
- End-users: Risk of inadvertently exposing sensitive data by uploading unclassified CSV/TSV files.
- Security Teams: Increased surface area for data loss prevention (DLP) monitoring and policy enforcement.
- Data Owners: Need to re-evaluate data classification and labeling for structured data used with Copilot.
- Compliance Teams: Potential for non-compliance with data handling regulations if sensitive data is mishandled.
The Action
- Review and update Microsoft Purview Data Loss Prevention (DLP) policies to include CSV and TSV file types for Copilot interactions.
- Implement or refine Microsoft Purview Information Protection (MIP) sensitivity labels for structured data, ensuring proper classification before Copilot ingestion.
- Educate users on responsible data handling practices when using CSV/TSV files with Copilot, emphasizing sensitive data.
- Monitor Copilot usage logs for unusual activity related to structured data ingestion and sharing.
- Assess existing data governance frameworks to ensure they adequately cover AI-driven data processing of structured files.
Domain: Agentic-AI · Impact: high · Workload: Microsoft Purview