Word: Legal plugins in Copilot

🚨 The Signal: Copilot in Word now supports third-party legal plugins, allowing AI to process and generate legal documents using external data. This expands AI's access to sensitive legal information, increasing data leakage and compliance risks.

The Impact

Legal teams and security administrators are affected by increased data exposure risks and the need for new governance policies for AI plugin usage.

  • Legal Professionals: Risk of inadvertent disclosure of privileged information through AI processing.
  • Security Administrators: Increased attack surface for data exfiltration via third-party plugins.
  • Compliance Officers: New challenges in maintaining regulatory compliance and data sovereignty.
  • IT Administrators: Need to manage and secure access to third-party AI services and data connectors.

The Action

  1. Review and approve all third-party Copilot plugins via the Microsoft 365 admin center or Copilot admin portal.
  2. Implement Data Loss Prevention (DLP) policies in Microsoft Purview to monitor and restrict sensitive legal data processed by Copilot and its plugins.
  3. Establish clear organizational policies for the use of AI legal plugins, including data handling, review processes, and acceptable use.
  4. Conduct security assessments of any third-party legal plugins before deployment to understand their data access and security posture.
  5. Educate legal professionals on the risks associated with AI plugin usage, emphasizing data privacy and the need for human review of AI outputs.

Domain: Agentic-AI · Impact: high · Workload: M365 Apps