Somebody in your finance team pasted a forecast into a chatbot this month. You can find out which chatbot, roughly when, and whether it happened twice, using a license you renewed in July. The tooling is already paid for and sits switched off.
Three ways this goes
A few companies have kept AI out entirely. That is rare now and usually regulated, and those organizations should move this quarter, because the moment one department starts on its own the choice stops being theirs.
Others opened it six months ago: a director said yes, nobody wrote anything down, and so far it has been fine. That is the easy case to fix.
The third group opened it a year ago and has stopped asking questions about it, because the answers arrive faster than anyone can file them. People have built chatbots into how they work, with no policy and no record.
I have walked into the third kind perhaps a dozen times.
The numbers
Four figures worth putting in front of a board.
Roughly 67% of all enterprise AI use runs through accounts outside the company's control, and the figures come from browser telemetry. LayerX, 2025
63% of breached organizations either had no AI policy or were still drafting one. IBM, 2025
Read the 82 percent as a data question. Every paste leaves your boundary for a service outside your agreements, beyond your audit, with no way to pull anything back.
What you paid for and left switched off
| Capability | What you get | E3 | E5 |
|---|---|---|---|
| Entra Cloud App Discovery | Inventories and risk-scores 31,000+ cloud apps | Yes | Yes |
| Purview DLP: Exchange, SharePoint, OneDrive | Data controls across core Microsoft 365 | Yes | Yes |
| Purview DSPM for AI | Sensitive material turning up in prompts | Limited | Yes |
| Copilot Chat | A corporate chatbot inside your identity boundary | Free | Free |
| Defender for Cloud Apps | Anomaly detection, activity policies, session control | No | Yes |
| Purview Endpoint DLP | Warns or blocks pasting into AI sites | No | Yes |
| Insider Risk Management | Risky-AI-usage policy template, Adaptive Protection | No | Yes |
| Microsoft Security Copilot | 400 SCUs a month per 1,000 licenses, to a cap of 10,000 | No | Included |
E3 runs $39 and E5 runs $60 per user each month. Microsoft moved both on 1 July 2026.
Two rows deserve a paragraph.
Copilot Chat is included at no added charge on any eligible Microsoft 365 subscription. Web-grounded chat, file upload, image generation, page summaries in Edge, and declarative agents pointed at instructions and public sites. All of it inside your identity boundary. (Point an agent at Graph or SharePoint content and it starts metering. Watch that line.)
Now consider why people opened personal accounts. Many of them wanted a chatbot and nobody gave them one. You have one, and it is already on. In the tenants I have reviewed, the announcement email has rarely gone out. One email brings a real slice of the problem back inside the boundary on its own.
Security Copilot ships with E5. Microsoft dates that to November 2025, though most tenants only saw it during the rollout through the first half of this year. I have yet to walk into an E5 tenant with it switched on.
Do these five in order
The order carries more weight than the tooling. The governance programs I have seen fail usually failed because somebody ran them backwards.
01 · Look before you survey. A survey tells you what people will admit to, while Cloud App Discovery tells you what is happening. On E5, Defender for Cloud Apps scores it and lets you act. Filter the catalog to generative AI and you will have the list before lunch. In every tenant I have run this on, the list was longer than the one the team would have written from memory.
02 · Find where the material went. Purview’s AI posture tooling surfaces sensitive content sitting in prompts. This is the step that produces the quiet meeting.
Go into that meeting without a list of names. Whoever pasted the customer file into a chatbot was trying to finish something. Punish that and the behavior moves to phones, beyond your view.
03 · Sanction a short list. Pick two or three tools and fund them properly. If your approved option is worse than what people already use, they will route around it, and you will have spent three months buying visibility you then threw away.
04 · Guard the edges. Endpoint DLP and browser DLP in Edge warn or block on specific content heading to specific places. Edge 144 and later does it natively with no extension and no Purview onboarding, though unmanaged apps need the device under Intune. Pick the twelve categories that would wreck a quarter and guard those. A policy that blocks everything gets switched off within a month by somebody senior enough to demand it. Where devices sit outside Intune, Cloudflare One covers the same edge: it inventories the AI services people reach and applies DLP to what goes into them.
05 · Now write it down. This is where policies usually start, because it is the step you can finish without talking to anybody. Written after the other four, the policy describes your company as it stands, names tools people recognize, and has something behind it.
Sixty-second check
Read these out. Every “no” is something you can close with a license you hold.
Four or more “no” answers is the ordinary result, and it represents about two weeks of work.
What it costs when it costs
I would rather say this now than have you find it in a quote.
No added cost, if you are already licensed: app discovery, the AI inventory, the Copilot Chat rollout, core Purview DLP, baseline AI posture visibility. E5 adds Defender for Cloud Apps, Endpoint DLP, Insider Risk Management, Adaptive Protection and Security Copilot on top.
Money:
Third-party AI monitoring in Purview and unmanaged-app DLP in Edge bill through Azure consumption. Microsoft publishes no flat rate, so get a quote against your headcount rather than relying on a figure you read somewhere.
Endpoint DLP needs E5, or the Purview suite added to E3. If you are on E3 and want enforcement, that is the conversation to have.
Agent 365 runs $15 per user each month, on top of an E5, Business Premium or A5 prerequisite since June.
So the promise that everything is already covered holds for most of this and stops short of all of it. Anyone who tells you it covers all of it is selling something.
Thirty days
For anyone who needs to show a board something before the tooling is finished.
A month, most of it already paid for. The hard part is deciding what you will allow, and that decision gets harder with time.
What Agent 365 governs
These get conflated constantly, sometimes by people selling both.
Agent 365 went GA on 1 May. It keeps a registry of the agents running in your environment, controls their lifecycle and access through Entra and Purview, blocks malicious coding agents at runtime, and spots local ones through Defender and Intune. If your company is heading toward dozens of agents built by four different teams, and the fifteen-times number above says it is, that is your control plane.
The forecast pasted into a personal Claude account sits outside its view; that belongs to the Purview and Defender stack in section 03.
Two things to know before somebody quotes you a renewal. Agent 365 costs $15 per user each month standalone, with an E5, Business Premium or A5 prerequisite since June. Microsoft 365 E7 at $99 wraps it together with E5, Copilot and the Entra Suite, and E7 is one of several routes to Agent 365.
Say it out loud
Six months from now, you will want a record of what you decided.
The companies I have seen end up badly placed on this got there the same way, and none of them were careless. They were keen, and they assumed somebody else was thinking about the governance side.
Usually nobody was. That is the job, and it takes two weeks at the front or a quarter of cleanup at the back.
If your own team has the two weeks, take this and go do it. I would rather it got done than got done by me.
Sources
Next in Field Notes: Workday and on-prem Active Directory. What Entra already does between them, what it leaves you to build, and why Microsoft’s own documentation answers the hardest part with “write a PowerShell script and schedule it.”