Somebody in your finance team pasted a forecast into a chatbot this month. You can find out which chatbot, roughly when, and whether it happened twice, using a license you renewed in July. The tooling is bought. It’s switched off.
Three ways this goes
Some companies have kept AI out entirely. That’s rare now, and usually regulated, and those people should move this quarter because the moment one department starts on its own the choice stops being theirs.
Some opened it six months ago. A director said yes, nobody wrote anything down, and it’s been fine. That’s the easy one to fix.
And some opened it a year ago and have stopped asking questions about it, because the answers arrive faster than anyone can file them. People have built chatbots into how they work. There’s no policy. There’s no record.
I’ve walked into the third kind maybe a dozen times.
The numbers
Four figures worth putting in front of a board.
Roughly 67% of all enterprise AI use runs through accounts the company doesn’t hold, and the figures come from browser telemetry. LayerX, 2025 ↗
63% of breached organizations either had no AI policy or were still drafting one. IBM, 2025 ↗
Read the 82 percent as a data question. Every paste leaves your boundary for a service outside your agreements, beyond your audit, with no way to pull anything back.
What you paid for and left switched off
| Capability | What you get | E3 | E5 |
|---|---|---|---|
| Entra Cloud App Discovery | Inventories and risk-scores 31,000+ cloud apps | Yes | Yes |
| Purview DLP: Exchange, SharePoint, OneDrive | Data controls across core Microsoft 365 | Yes | Yes |
| Purview DSPM for AI | Sensitive material turning up in prompts | Limited | Yes |
| Copilot Chat | A corporate chatbot inside your identity boundary | Free | Free |
| Defender for Cloud Apps | Anomaly detection, activity policies, session control | No | Yes |
| Purview Endpoint DLP | Warns or blocks pasting into AI sites | No | Yes |
| Insider Risk Management | Risky-AI-usage policy template, Adaptive Protection | No | Yes |
| Microsoft Security Copilot | 400 SCUs a month per 1,000 licenses, to a cap of 10,000 | No | Included |
E3 runs $39 and E5 runs $60 per user each month. Microsoft moved both on 1 July 2026.
Two rows deserve a paragraph.
Copilot Chat is included at no added charge on any eligible Microsoft 365 subscription. Web-grounded chat, file upload, image generation, page summaries in Edge, and declarative agents pointed at instructions and public sites. All of it inside your identity boundary. (Point an agent at Graph or SharePoint content and it starts metering. Watch that line.)
Now think about why people opened personal accounts. Most of them wanted a chatbot and nobody gave them one. You have one. It’s on. Most companies have yet to send the email. One email, and a real slice of the problem walks back inside the boundary on its own.
Security Copilot ships with E5. Microsoft dates that to November 2025, though most tenants only saw it during the rollout through the first half of this year. I have yet to walk into an E5 tenant with it switched on.
Do these five in order
The order carries more weight than the tooling. Most governance programs I’ve seen fail because somebody ran them backwards.
01 · Look. Don’t survey. A survey tells you what people will admit to. Cloud App Discovery tells you what’s happening. On E5, Defender for Cloud Apps scores it and lets you act. Filter the catalogue to generative AI and you’ll have the list before lunch. It’s longer than the one your team would write from memory. It always is.
02 · Find where the material went. Purview’s AI posture tooling surfaces sensitive content sitting in prompts. This is the step that produces the quiet meeting.
Go into that meeting without a list of names. Whoever pasted the customer file into a chatbot was trying to finish something. Punish that and the behavior moves to phones, beyond your view.
03 · Sanction. Don’t ban. Pick two or three tools and fund them properly. If your approved option is worse than what people already use, they’ll route around it, and you’ll have spent three months buying visibility you then threw away.
04 · Guard the edges. Endpoint DLP and browser DLP in Edge warn or block on specific content heading to specific places. Edge 144 and later does it natively ↗ with no extension and no Purview onboarding, though unmanaged apps need the device under Intune. Pick the twelve categories that would wreck a quarter and guard those. A policy that blocks everything gets switched off within a month by somebody senior enough to demand it.
05 · Now write it down. Everyone starts here, because it’s the step you can finish without talking to anybody. Written after the other four, the policy describes your company as it stands, names tools people recognize, and has something behind it.
Sixty-second check
Read these out. Every “no” is something you can close with a license you hold.
Four or more “no” answers is the ordinary result. It’s also about two weeks of work.
What it costs when it costs
I’d rather say this now than have you find it in a quote.
No added cost, if you’re already licensed: app discovery, the AI inventory, the Copilot Chat rollout, core Purview DLP, baseline AI posture visibility. E5 adds Defender for Cloud Apps, Endpoint DLP, Insider Risk Management, Adaptive Protection and Security Copilot on top.
Money:
Third-party AI monitoring in Purview and unmanaged-app DLP in Edge bill through Azure consumption. Microsoft publishes no flat rate. Get a quote against your headcount and don’t trust a number you read somewhere.
Endpoint DLP needs E5, or the Purview suite bolted onto E3. On E3 and want enforcement? That’s the conversation.
Agent 365 runs $15 per user each month, on top of an E5, Business Premium or A5 prerequisite since June.
So “you don’t have to buy anything” holds for most of this and stops short of all of it. Anyone who tells you it holds for all of it wants something.
Thirty days
For anyone who needs to show a board something before the tooling is finished.
A month, most of it already paid for. The hard part is deciding what you’ll allow, and that decision only gets harder with time.
What Agent 365 governs
These get conflated constantly, sometimes by people selling both.
Agent 365 went GA on 1 May. It keeps a registry of the agents running in your environment, controls their lifecycle and access through Entra and Purview, blocks malicious coding agents at runtime, and spots local ones through Defender and Intune. If your company is heading toward dozens of agents built by four different teams, and the fifteen-times number above says it is, that’s your control plane.
The forecast pasted into a personal Claude account sits outside its view; that belongs to the Purview and Defender stack in section 03.
Two things to know before somebody quotes you a renewal. Agent 365 costs $15 per user each month standalone, with an E5, Business Premium or A5 prerequisite since June. Microsoft 365 E7 at $99 wraps it together with E5, Copilot and the Entra Suite, and E7 is one of several routes to Agent 365.
Say it out loud
Don’t turn around in six months and ask what you did.
Every company I’ve seen end up badly placed on this got there the same way, and none of them were careless. They were keen. And they assumed somebody else was thinking about the governance side.
Usually nobody was. That’s the job, and it’s two weeks at the front or a quarter of cleanup at the back.
If your own team has the two weeks, take this and go do it. I’d rather it got done than got done by me.
Sources
Next in Field Notes: Workday and on-prem Active Directory. What Entra already does between them, what it leaves you to build, and why Microsoft’s own documentation answers the hardest part with “write a PowerShell script and schedule it.”