Resource · positioning

We already use Microsoft 365 Copilot. Where does AI Leak Guard fit?

Short answer

If your workforce is standardized on a properly configured Microsoft 365 Copilot environment, and your controls actually prevent staff from using other AI services, you may already have strong protection for that workflow.

AI Leak Guard is not a replacement for Microsoft Purview or Microsoft 365 Copilot's controls. It addresses a different problem: what staff do in the next browser tab.

What Microsoft already protects

Microsoft 365 Copilot runs inside your tenant. Prompts, retrieved content, and generated responses are handled inside the Microsoft 365 service boundary. Microsoft does not use your organizational data to train the foundation models, and administrators have real controls over data residency, retention, and access.

On top of that, Microsoft Purview provides Data Loss Prevention, Information Protection labels, Insider Risk Management, and audit for the Microsoft 365 estate. These are enterprise-grade controls and, correctly configured, they can significantly reduce the risk of PHI reaching an unmanaged AI service through Microsoft's tools. See Microsoft Learn: Data, privacy, and security for Microsoft 365 Copilot.

Where a gap can remain

The Microsoft 365 boundary ends at the browser tab. It does not follow staff into the next tab. In small and mid-size practices we have seen the same four patterns repeatedly:

Purview does not see any of that. It is not designed to. That is the gap AI Leak Guard is designed for.

Where AI Leak Guard fits

AI Leak Guard is a browser-installed control on the sites listed below. It runs on the device, not in the tenant, and it does not need admin cooperation on Microsoft 365 to be effective. It complements Microsoft controls by covering the tabs those controls cannot reach. As of v1.3, it also checks the message you are about to send on ChatGPT, Claude, and Gemini, so typed or dictated content is caught even without a paste.

Coverage matrix. Three protections, one row per site.
SiteSend-timePasteDocument upload
ChatGPT Protected Protected Protected
Claude Protected Protected Protected
Gemini Protected Protected Protected
Perplexity Planned Protected Protected
Microsoft Copilot (copilot.microsoft.com) Planned Protected Protected
Microsoft 365 Copilot (m365.cloud.microsoft) Not supported Not supported Not supported

Send-time protection on Perplexity and Microsoft Copilot is planned for a later release. Microsoft 365 Copilot (m365.cloud.microsoft) is not interceptable by a browser extension at all; that environment is governed by the tenant's Microsoft 365 and Purview controls, not by AI Leak Guard.

Where AI Leak Guard does not fit

AI Leak Guard does not scan document uploads on Microsoft 365 Copilot (the work or school version at m365.cloud.microsoft). We tested it. Uploads in that environment are handled by Microsoft 365 itself and are not interceptable by a browser extension. Those files are governed by your Microsoft 365 and Purview controls, which is the appropriate place for them.

We also do not scan Copilot Chat inside desktop Office apps, Teams, or Outlook. The extension is scoped to the browser, and to the specific consumer AI hostnames in the matrix above.

Scope comparison, framed as complementary

What each control was designed for.
ConcernMicrosoft controlsAI Leak Guard
PHI in Microsoft 365 Copilot chats and uploadsPurview DLP, sensitivity labels, tenant configuration Not in scope
PHI in tenant-managed apps (Outlook, SharePoint, Teams)Purview DLP, Insider Risk Management Not in scope
PHI pasted into consumer AI (ChatGPT, Claude, Gemini, Perplexity, personal Copilot)Limited (endpoint DLP only where deployed) Protected
PDF, Word, Excel, PowerPoint or text attachments to consumer AI (4 sites)Limited Protected
Personal devices used off-hoursOut of tenant Install per user

Deployment example

A 14-person primary-care practice runs Microsoft 365 Business Standard with Copilot licenses for the two administrators. The clinical staff do not have Copilot but use ChatGPT (personal accounts) daily to draft insurance appeals and predetermination narratives. The practice configured Purview DLP on Exchange and SharePoint, but has no visibility into the ChatGPT tab.

The practice deploys AI Leak Guard to every staff device (individual install; no admin push required). Microsoft continues to protect the Copilot workflow. The extension protects the ChatGPT tab. The compliance advisor now has a two-line story: Microsoft covers the managed AI, AI Leak Guard covers the unmanaged AI, and both are documented.

Bottom line

Microsoft protects the approved AI environment. AI Leak Guard covers the unmanaged edge. If your controls make sure staff cannot use any other AI service, you may already be covered. If they cannot make that promise honestly, the extension is what closes the gap.