Short answer
If your workforce is standardized on a properly configured Microsoft 365 Copilot environment, and your controls actually prevent staff from using other AI services, you may already have strong protection for that workflow.
AI Leak Guard is not a replacement for Microsoft Purview or Microsoft 365 Copilot's controls. It addresses a different problem: what staff do in the next browser tab.
Microsoft 365 Copilot runs inside your tenant. Prompts, retrieved content, and generated responses are handled inside the Microsoft 365 service boundary. Microsoft does not use your organizational data to train the foundation models, and administrators have real controls over data residency, retention, and access.
On top of that, Microsoft Purview provides Data Loss Prevention, Information Protection labels, Insider Risk Management, and audit for the Microsoft 365 estate. These are enterprise-grade controls and, correctly configured, they can significantly reduce the risk of PHI reaching an unmanaged AI service through Microsoft's tools. See Microsoft Learn: Data, privacy, and security for Microsoft 365 Copilot.
The Microsoft 365 boundary ends at the browser tab. It does not follow staff into the next tab. In small and mid-size practices we have seen the same four patterns repeatedly:
Purview does not see any of that. It is not designed to. That is the gap AI Leak Guard is designed for.
AI Leak Guard is a browser-installed control on the sites listed below. It runs on the device, not in the tenant, and it does not need admin cooperation on Microsoft 365 to be effective. It complements Microsoft controls by covering the tabs those controls cannot reach. As of v1.3, it also checks the message you are about to send on ChatGPT, Claude, and Gemini, so typed or dictated content is caught even without a paste.
| Site | Send-time | Paste | Document upload |
|---|---|---|---|
| ChatGPT | Protected | Protected | Protected |
| Claude | Protected | Protected | Protected |
| Gemini | Protected | Protected | Protected |
| Perplexity | Planned | Protected | Protected |
| Microsoft Copilot (copilot.microsoft.com) | Planned | Protected | Protected |
| Microsoft 365 Copilot (m365.cloud.microsoft) | Not supported | Not supported | Not supported |
Send-time protection on Perplexity and Microsoft Copilot is planned for a later release. Microsoft 365 Copilot (m365.cloud.microsoft) is not interceptable by a browser extension at all; that environment is governed by the tenant's Microsoft 365 and Purview controls, not by AI Leak Guard.
Where AI Leak Guard does not fit
AI Leak Guard does not scan document uploads on Microsoft 365 Copilot (the work or school version at m365.cloud.microsoft). We tested it. Uploads in that environment are handled by Microsoft 365 itself and are not interceptable by a browser extension. Those files are governed by your Microsoft 365 and Purview controls, which is the appropriate place for them.
We also do not scan Copilot Chat inside desktop Office apps, Teams, or Outlook. The extension is scoped to the browser, and to the specific consumer AI hostnames in the matrix above.
| Concern | Microsoft controls | AI Leak Guard |
|---|---|---|
| PHI in Microsoft 365 Copilot chats and uploads | Purview DLP, sensitivity labels, tenant configuration | Not in scope |
| PHI in tenant-managed apps (Outlook, SharePoint, Teams) | Purview DLP, Insider Risk Management | Not in scope |
| PHI pasted into consumer AI (ChatGPT, Claude, Gemini, Perplexity, personal Copilot) | Limited (endpoint DLP only where deployed) | Protected |
| PDF, Word, Excel, PowerPoint or text attachments to consumer AI (4 sites) | Limited | Protected |
| Personal devices used off-hours | Out of tenant | Install per user |
A 14-person primary-care practice runs Microsoft 365 Business Standard with Copilot licenses for the two administrators. The clinical staff do not have Copilot but use ChatGPT (personal accounts) daily to draft insurance appeals and predetermination narratives. The practice configured Purview DLP on Exchange and SharePoint, but has no visibility into the ChatGPT tab.
The practice deploys AI Leak Guard to every staff device (individual install; no admin push required). Microsoft continues to protect the Copilot workflow. The extension protects the ChatGPT tab. The compliance advisor now has a two-line story: Microsoft covers the managed AI, AI Leak Guard covers the unmanaged AI, and both are documented.
Microsoft protects the approved AI environment. AI Leak Guard covers the unmanaged edge. If your controls make sure staff cannot use any other AI service, you may already be covered. If they cannot make that promise honestly, the extension is what closes the gap.