← Back to the blog

Blog

AI sharing controls and DLP before rollout

Enterprise AI rollouts do not first stall over model access. They stall when answers, files, and analysis results are shared without a clear decision chain. AWS currently lists sharing approval policies and a Microsoft Purview DLP integration for Amazon Quick. This highlights a frequently overlooked prerequisite: sharing is a controlled business decision, not an assistant’s default output.

What the new capabilities signal

AWS announcements dated August 13 cover three closely connected areas: Microsoft 365 extensions for Amazon Quick, approval policies for sharing, and data loss prevention with Microsoft Purview. These entries are not a general AI strategy. They concern the point at which a research or analysis result leaves the protected working environment.

This matters to CIOs because every additional data connection increases the number of possible recipients, formats, and approvals. A helpful assistant can combine information from multiple sources; that is precisely why it must be clear in advance which results remain internal, which may enter a business process, and which may only be shared after confirmation.

DLP is the technical layer, not the complete answer

Microsoft Purview describes DLP as a policy framework that can identify, monitor, and protect sensitive information. Policies can, for example, warn on sharing, block it, or allow an exception with a justification. Microsoft recommends evaluating policies in simulation mode and tuning them before activating restrictive controls.

This is a useful operating model for AI workflows. DLP can control data classes and transmission paths. It does not by itself decide whether an AI result is factually correct, contractually permitted, or appropriate for a particular recipient. That responsibility remains with process owners and approval authorities.

Four decisions before production use

Before connecting an assistant to Microsoft 365, line-of-business applications, or external tools, document four rules:

  • Data class: Which content may the assistant read, summarise, or export?
  • Recipient: Which teams, roles, and external parties are allowed?
  • Exception: Who may override a warning, and with what justification?
  • Evidence: Where are the request, policy decision, approval, and delivery recorded?

Start with a bounded workflow and a DLP simulation, rather than an organisation-wide enablement. Review false positives, genuine matches, and legitimate exceptions together with the business unit, data protection, and IT security. Only then does technical scale make sense.

The key maturity test is therefore not whether AI finds information. It is whether your organisation can justify and trace every relevant disclosure.

← Back to the blog