Work IQ: ExpandedContextIQ

🚨 The Signal: Copilot's Context IQ now allows users to select more agents, skills, and content sources when prompting. This expands the potential for data exposure and unapproved information access via AI agents.

The Impact

All users are affected, increasing the risk of sensitive data exposure and unapproved information access through expanded AI agent capabilities.

  • End-users: Increased risk of inadvertently exposing sensitive data to AI agents.
  • Security Teams: New vectors for data exfiltration and compliance breaches.
  • Data Owners: Potential for unauthorised access to restricted information.
  • Compliance Officers: Greater challenge in maintaining data governance and audit trails.

The Action

  1. Review and update Copilot data access policies in Microsoft 365 Admin Center.
  2. Implement or refine data loss prevention (DLP) policies for Copilot interactions via Microsoft Purview.
  3. Educate users on responsible AI prompting and data handling best practices.
  4. Monitor Copilot usage logs for unusual data access patterns via Microsoft Puripurview Audit.
  5. Assess and classify data sources accessible by Copilot agents to identify sensitive information.

Domain: Agentic-AI · Impact: high · Workload: Other