top of page

Microsoft Purview for AI: A Practical Guide to Sensitivity Labels Before Copilot

  • Writer: Matt Lazarus
    Matt Lazarus
  • Jun 11
  • 5 min read

Ask most Australian IT teams whether they classify sensitive information and the answer is yes - there is a policy, a schema, a PDF. Ask how many files in the tenant actually carry a sensitivity label and the answer is quieter.

 

That gap was tolerable when humans were the only readers. Copilot closes the tolerance: an AI assistant treats the board pack and the lunch menu identically unless something machine-readable tells it not to.

 

Sensitivity labels are that something. Here is how to deploy them with Copilot in mind - pragmatically, in weeks, without boiling the ocean.

 

Key Takeaways

 

  • Unlabelled estates have governance documents, not governance - policy only counts when it is machine-readable.

  • Labels change Copilot's behaviour mechanically: access, encryption and extraction restrictions travel with the file.

  • Roll out pragmatically: a four-label taxonomy, auto-labelling for the backlog, crown-jewel sites first.

 

Why Do Sensitivity Labels Matter More Once Copilot Arrives?

 

Labels matter more because Copilot is the first reader in your tenant that consumes everything, instantly, and reproduces it on request. Human readers were rate-limited by attention and obscurity; an AI assistant is limited only by permissions and labels. Labels are the policy layer it actually obeys.

 

Mechanically, a label is metadata with consequences. Depending on configuration, it can encrypt the file, restrict who opens it, watermark it, block extraction and copying, and signal data loss prevention policies to intercept it in motion. Critically, those consequences travel with the file - into email, into downloads, into AI retrieval.

 

For Copilot specifically: content protected with the right label settings is either excluded from what the assistant can use for a given user, or constrained in how its content can be reproduced. The policy stops being a hope and becomes a property of the data itself.

 

What Does a Label Taxonomy That Actually Works Look Like?

 

A working taxonomy has four labels, names users understand in one read, and a default. More granularity feels rigorous and dies in practice - when staff face nine options, they choose none, and an unlabelled estate defeats the entire exercise.

 

The structure that survives contact with real users:

 

  • Public: approved for external release - the rare, deliberate case.

  • Internal (default): everyday business content; applied automatically so the baseline is never blank.

  • Confidential: commercially sensitive - contracts, pricing, strategy; restricted sharing, no external access.

  • Highly Confidential: the crown jewels - board, payroll, legal, personal information; encrypted, tightly scoped, extraction blocked.

 

Resist sub-labels until the base four are embedded. The goal at this stage is coverage, not taxonomy elegance - a tenant that is 95 per cent sensibly labelled beats one that is 20 per cent exquisitely labelled.

 

One naming discipline pays for itself many times over: labels describe sensitivity, never audience or location. "Confidential" survives reorganisations; "Finance Team Only" becomes wrong the first time the finance team changes shape, and wrong labels are worse than none because they certify the error.

 

How Do You Label Fifteen Years of Existing Content?

 

You do not label the backlog by hand - you combine default labels for new content, auto-labelling for the archive, and targeted manual passes on crown-jewel locations. The sequencing matters more than the tooling: protect what Copilot must never mishandle first, then let automation grind through the long tail.

 

The pragmatic sequence:

 

  • Week one - defaults: every new and edited file gets Internal automatically; the bleeding stops.

  • Weeks two to four - crown jewels: manually label and lock the board, HR, payroll, legal and executive libraries; this is a bounded list, not the whole tenant.

  • Ongoing - auto-labelling: service-side policies detect sensitive information types (financial identifiers, personal information, credentials) and label the archive without user effort.

  • Quarterly - tuning: review auto-label hits and misses, adjust detection, and audit label coverage as a standing metric.

 


How Do Labels, DLP and Copilot Fit Together?

 

Labels classify, DLP enforces, and Copilot inherits both: classification decides what a file is, loss-prevention policies decide what may happen to it, and the AI layer respects the result. Designed together, they form a single control surface; designed separately, they leave seams an assistant will find.

 

The integration is where an AI-era governance review pays for itself - DLP rules written for email in 2019 rarely contemplate AI-bound flows, and label configurations chosen before Copilot existed may permit extraction patterns you would no longer accept. Aligning the three is core scope in a Copilot Readiness Assessment, and the durable home for the resulting policy set is a properly engineered data governance architecture.

 

What Are the Most Common Labelling Mistakes?

 

Four mistakes account for most failed label programmes: taxonomies designed for auditors instead of users, mandatory labelling without defaults, protection settings that punish legitimate work, and treating deployment as the finish line rather than the baseline.

 

  • The nine-label taxonomy: built to mirror the classification policy precisely, abandoned by users completely. Granularity that exists on paper but not on files protects nothing.

  • Mandatory-without-default: forcing a label choice on every save without a sensible default trains users to click the first option - which corrupts the data the whole system depends on. Default to Internal; require choices only where it matters.

  • Over-protection: encryption and extraction blocks applied so broadly that ordinary collaboration breaks - at which point staff route around the labels entirely, usually via the very channels you were protecting against.

  • Deploy-and-walk-away: auto-label policies left untuned drift in both directions - false positives that annoy, false negatives that expose. The quarterly tuning review is part of the system, not optional hygiene.

 

The pattern beneath all four is the same: labels succeed as a usability programme wearing a security badge. Every decision should be tested against one question - will a busy, well-meaning employee do the right thing by default? When the answer is yes, coverage follows, and coverage is what Copilot actually reads.

 

How Long Does a Purview Labelling Rollout Actually Take?

 

For a typical mid-market tenant, plan on a quarter to reach meaningful coverage - not the multi-year programme the enterprise horror stories suggest. The sequence: two to three weeks to settle the taxonomy and publish policies, a pilot on one business-critical site to tune auto-labelling, then waves across the crown-jewel sites while default labels handle everything newly created.

 

The long tail of legacy content does not block Copilot readiness. Once high-sensitivity locations are labelled and defaults govern new material, the residual risk sits in cold storage that retrieval rarely surfaces - and archival policies shrink it month by month. Perfect coverage is not the gate; coverage of what matters is.

 

Two accelerators are worth knowing. Microsoft 365 E5 tenants already own most of the capability and simply haven't switched it on - check entitlements before budgeting for add-ons. And the pilot site's tuning pays forward: false-positive rates drop sharply once the first site's lessons are encoded, so wave two through five run faster than wave one.

 

Governance That Executes at Machine Speed

 

The promise of Purview done properly is simple: your classification policy stops depending on memos and starts executing at machine speed - on every file, for every reader, including the artificial ones. Sensitive content is protected from AI mishandling by configuration, and the evidence trail satisfies the auditor without a scramble.

 

Deploy the labels before the licences. The order is the whole strategy.

 
 
bottom of page