Detecting Risky AI Use with Purview Insider Risk Management
Most AI-security controls are about data — classify it, restrict it, block it. But some of the most important risk in an AI deployment isn’t about a file; it’s about a person and a pattern of behaviour. That’s the gap Microsoft Purview Insider Risk Management fills, and it’s routinely the last control teams think about when rolling out Copilot.
Risky files vs. risky users
DLP and sensitivity labels answer “is this piece of content sensitive, and should this action be allowed?” That’s necessary — but it treats every user the same. It won’t tell you that a departing employee is suddenly asking Copilot to summarize customer lists, or that one account is generating a steady drip of DLP matches that individually look benign.
Insider Risk Management shifts the lens from the file to the actor: it correlates signals over time to surface users whose behaviour warrants a closer look. In an AI context, that’s the difference between blocking one bad prompt and noticing the pattern behind a hundred of them.
How it works, at a glance
Insider Risk Management builds risk signals from indicators you enable — and importantly, it can consume DLP-driven events as indicators. So the runtime guardrails you configure for Copilot don’t just block; they can also feed behavioural risk scoring. Layer in device, browser, and cloud indicators and you get a rounded picture of how a user is actually behaving around sensitive data and AI.
Two design points I always raise:
- Privacy is built in. Insider Risk Management pseudonymizes users by default, so analysts investigate behaviour patterns without unnecessary exposure of identity until an investigation genuinely warrants it. That’s not a footnote — it’s what makes the capability acceptable to works councils, privacy officers, and employees.
- Adaptive Protection closes the loop. Elevated-risk users can automatically receive stronger controls — tighter DLP, more restrictive policies — while everyone else keeps a frictionless experience. Security that scales with risk rather than punishing the whole population.
Start small and template-driven
You don’t build this from scratch. Microsoft ships policy templates — data leaks, risky activity, departing users — that give you a sensible starting point. My approach for an AI rollout:
- Start with priority users (privileged accounts, departing employees, high-sensitivity teams) rather than the whole org.
- Wire in DLP-triggered indicators so Copilot-related policy matches contribute to risk scoring.
- Tune thresholds before you widen scope — like DLP, a noisy insider-risk program gets ignored.
- Define, in advance, what elevates a user from “behavioural anomaly” to “adaptive restriction,” and who reviews it.
A practical note from the field: risk scoring and alerts aren’t instantaneous. In a workshop or demo, preload a captured alert or activity trace so live latency doesn’t derail the story.
Where it fits
Insider Risk Management is the “detect risky users” half of the monitoring phase in the secure Copilot launch — the natural complement to the “prove what happened” half covered by audit, eDiscovery, and retention. Together they turn “we hope people use AI responsibly” into “we can see when they don’t, and respond proportionately.”
If you want help standing up an insider-risk program for AI that detects real risk without alienating your workforce, let’s talk.