Data value, risks, and security needs 11 are amplified by AI Furthermore, the integration of AI with For example, internal users may ask an disparate data sets can lead to blurred lines AI application about the salaries and around data ownership and stewardship, compensation for other employees and complicating the already complex issues of executives in the organizations or external privacy and intellectual property. Accidental attackers may ask AI what secret projects disclosures, whether through training the organization is working on. The AI may models or in retrieval-augmented generation provide answers to those unauthorized (RAG) applications, pose significant risks to users if the documents describing employee organizations. As AI continues to evolve, compensation and sensitive projects have safeguarding enterprise data becomes not been classified correctly, or the AI critical, not only for producing reliable application does not recognize or enforce AI outputs but also for ensuring that access rules based on these classifications. this valuable asset isn’t compromised or For the record, Microsoft Copilot respects weaponized by external threats. your identity model and permissions, inherits your sensitivity labels, applies your retention AI amplifies data security and policies, supports audit of interactions, and governance challenges follows your administrative settings. One of the strengths of GenAI is the ability Organizations must recognize these challenges to discover data and make it easily accessible. and update their data governance and security Because many organizations have not strategies, starting with clear policies and established or consistently applied a formal procedures for data classification. These must data classification strategy, introducing AI be supported with technical controls on the initiatives can make sensitive information data itself as well as the applications that use easily discoverable to unauthorized users the data (including AI applications). (which they weren’t previously aware of). As AI reshapes business roles and elevates While users may have access to these the importance of data, these changes create documents already, they often don’t know both opportunities and risks. However, it’s not how to find them or have the time to search all bad news as AI can also help discover and through them. mitigate data risks in addition to the value it creates for business.

AI security and Zero Trust - Page 11 AI security and Zero Trust Page 10 Page 12