On May 25, 2026, Microsoft Copilot Cowork Exfiltrates Files was published on Hacker News, sending shockwaves through enterprise IT departments and security teams. Researchers demonstrated an attack technique in Microsoft 365 Copilot Cowork (a collaboration feature involving external participants) that combined indirect prompt injection with Copilot's internal file access permissions to allow "an invited guest to simply prompt Copilot to extract and externally transmit file contents from internal SharePoint, OneDrive, and Teams environments." Around the same time, InfoQ published Microsoft Introduces MDASH for Large-Scale AI Vulnerability Research, framing "AI-mediated data leakage" as one of the premier enterprise risks of 2026.
For custom development firms supporting AI governance and data loss prevention at mid-market enterprises, this reflects the reality that legacy DLP (Data Loss Prevention) focused on "file-level access permissions and audit logs" cannot address the new attack surface where "AI extracts data across contexts." Connecting with the Cowork governance covered in Claude Cowork Enterprise Adoption Engagements, the enterprise-wide AI rollout in non-IT sectors in Hyatt × ChatGPT Enterprise Engagements, and the Workspace governance in Google Workspace Security Engagements, we package "DLP architecture to prevent AI-mediated data leakage" into a custom development offering.
Why AI DLP is a watershed moment
| Dimension | Existing DLP (file-centric) | DLP in the AI era (context-centric) |
|---|---|---|
| Detection unit | Files / attachments / emails | Prompts + responses + contextual references |
| Permission Model | Access permissions / sharing settings | + LLM reference scope / context history |
| Indirect prompt injection | Unanticipated | Treated as a first-class risk |
| Guest users | Restricted by file viewing permissions | + Restricted querying permissions via AI |
| Data extraction pathways | Copying / downloading / emailing | + AI summarizing, translating, and formatting output |
| Auditing | Access logs | + Prompt / response logs |
| Target LLMs | None | Copilot / Gemini / Claude / Bedrock |
| Affected scope | Exfiltrated files | All operational knowledge referenced cross-functionally |
In other words, AI DLP represents a structural shift that abandons the assumption that "having access permissions equals safe," making "what the AI combined and generated, and under whose context," the primary subject of audits.
Three structural changes beneficial to custom development projects
Structure 1: From "file DLP" to "context DLP"
Security departments at mid-sized companies have historically been content with deploying file DLP solutions such as Symantec, Microsoft Purview, or Forcepoint. However, with AI-mediated data extraction like that in Copilot Cowork, situations frequently occur where traditional DLP fails to trigger because "the user has access permissions, the query appears legitimate, but confidential data is blended into the response." In our custom development, we design an AI DLP layer alongside existing DLP that detects and blocks leaks crossing contextual boundaries. This serves as an AI extension of the file and email controls covered in our custom Google Workspace security development.
Structure 2: From "excluding guests" to "controlling guest AI usage"
An operating policy of "disallowing" guest participation features across Cowork, Claude Cowork, or Gemini for Workspace stalls business agility. In our custom development, we deliver designs where "guests can interact with AI, but reference targets are restricted according to data sensitivity." This is a redesign from a DLP perspective of the Cowork governance addressed in our custom Claude Cowork enterprise implementation.
Structure 3: From "incident response" to "a culture of prompt auditing"
The core of AI DLP is an infrastructure capable of storing, searching, and analyzing audit logs of prompts and responses. This enables "governance explainable to executive management," even during company-wide AI deployments in non-IT industries as explored in our custom Hyatt × ChatGPT Enterprise development.
The five phases of "Enterprise AI DLP" provided in our custom development services
Phase 1: Current state assessment (2–3 weeks)
- Inventory of active AI services (Copilot / Gemini / Claude / Bedrock / internal RAG)
- Audit of AI usage scope among guests and external contractors
- File DLP and IRM configuration review
- Sensitive data classification (PII / executive management data / trade secrets)
- Incident history review
- Risk scoring + prioritization mapping
Phase 2: Policy design (2–3 weeks)
- AI usage policies categorized by sensitivity tier (Red / Yellow / Green)
- AI reference scope for guests and external contractors
- Prompt injection defense guidelines
- Audit log retention periods and encryption requirements
- Incident escalation workflows
- Governance KPIs
Phase 3: Technical control implementation (4–6 weeks)
- IdP integration (Entra ID / Okta / Google Workspace)
- Microsoft Purview DLP + AI extension policies
- Copilot Cowork configuration (guest restrictions / access perimeters)
- Prompt and response audit log aggregation (SIEM / Splunk)
- Dedicated AI DLP tooling (Nightfall / Lakera / in-house)
- Injection detection rules
Phase 4: Organization-wide rollout (3–4 weeks)
- Departmental usage guidelines
- Employee training (30-minute e-learning)
- Revisions to contractor agreements (AI usage clauses)
- Help desk FAQ establishment
- Monthly executive management reporting
Phase 5: Monthly operational reviews (ongoing)
- Trend monitoring for incident and detection counts
- Review process for onboarding new AI services
- Policy violation trend analysis
- Audits during contractor agreement renewals
- Semi-annual threat model updates
Standard technology stack set for custom development
| Layer | Recommended technology | Alternative |
|---|---|---|
| IdP | Microsoft Entra ID / Okta / Google Workspace | Auth0 |
| File DLP | Microsoft Purview / Symantec DLP | Forcepoint |
| Dedicated AI DLP | Nightfall / Lakera Guard / Cyera | In-house + LLM evaluation |
| Injection detection | Lakera / Protect AI / in-house | promptfoo + rules |
| SIEM | Microsoft Sentinel / Splunk / Datadog | Sumo Logic |
| Audit log integration | Azure Monitor / Splunk / Loki | Elastic |
| Access control | Conditional Access / Okta Workflows | SailPoint |
| Training platform | KnowBe4 / internal LMS | SafeTitan |
Which projects need this and which do not
| Projects requiring this | Projects not requiring this |
|---|---|
| Using Copilot / Cowork / Gemini with external participants | Fully closed network / no external contractors |
| Handling customer PII / executive confidential data | Publicly available information only |
| Audit requirements (ISO 27001 / SOC2 / FISC) | Internal tools exempt from audits |
| High presence of contractors, temp staff, and vendors | Direct employees only |
| Incident response SLAs in place | Immediate response not required |
Six clauses to include in client contracts
| Clause | Details | What the client should verify |
|---|---|---|
| Covered AI services | Copilot / Gemini / Claude / Bedrock / internal RAG | Handling of out-of-scope services |
| Data sensitivity classifications | Red / Yellow / Green classification criteria | Statutory and client requirements |
| Treatment of guests and contractors | Access perimeters + AI usage boundaries | Contract revision responsibilities |
| Prompt audit retention | Retention period + encryption + access control | Regulatory requirements |
| Handover Upon Project Completion | Policies / audit infrastructure / training content | Internal operational continuity |
| Incident operations | Escalation + emergency kill switch | 24/7 / business hours |
Client-side ROI projection (assuming 500 employees / company-wide Copilot rollout / guest access enabled)
| Item | Existing (file DLP only) | After AI DLP implementation | Difference |
|---|---|---|---|
| Risk of data exfiltration via AI | Estimated 2–3 incidents/year | 0–1 incidents/year | -2 incidents |
| Incident response effort (annual) | 240 hours | 60 hours | -180 hours |
| Contractor AI usage governance effort | 40 hours/month | 10 hours/month | -360 hours/year |
| Audit response hours | 200 hours/year | 60 hours/year | -140 hours |
| AI adoption rate (suppressed due to lack of governance) | 30% adoption rate | 75% adoption rate | +45pt |
| Annual benefit | — | — | Equivalent to approx. 22 million JPY + productivity gains from doubling adoption |
At 8,000 JPY per hour, this yields over 15 million JPY annually in labor savings, incident avoidance, and the benefits of expanded AI adoption. Using this labor cost reduction as a benchmark makes evaluating the governance investment straightforward.
Five common pitfalls
Pitfall 1: Governance based solely on "banning Copilot"
Opting for a blanket ban out of fear pushes frontline staff to use personal ChatGPT, personal Claude, or shadow Gemini for business tasks, accelerating ungoverned shadow IT. The prerequisite is an architecture that enables phased usage under proper controls.
Pitfall 2: Relying solely on tightening file DLP
Simply tightening configuration on existing Purview or Symantec tools without adding AI DLP leaves operations exposed, running with zero visibility into attacks like those seen in Copilot Cowork. Always integrate a dedicated AI DLP layer alongside them.
Pitfall 3: Flatly disabling guest access across the board
Blanket disabling Cowork guest functionality chokes business agility, driving teams to turn to alternative shadow IT tools. Operate instead with time-bound access tiered by data sensitivity.
Pitfall 4: Failing to retain prompt audit logs
Deciding against logging under the premise of privacy protection makes it impossible to trace root causes when incidents occur. Designing a compliant system that legally retains logs using encryption, retention windows, and access controls is indispensable.
Pitfall 5: Omitting AI clauses from contractor agreements
Even if you establish AI policies for direct employees, omitting AI terms from contracts with external contractors, temporary personnel, and vendors leaves the highest-risk leak vector completely unaddressed. Incorporate contract revisions into the initial implementation phase.
90-day action plan
| Week | Action |
|---|---|
| Week 1〜3 | AI service inventory + sensitivity classification + guest audit |
| Week 4〜5 | Policy design + contractor agreement revision strategy |
| Week 6〜9 | IdP + DLP + AI audit infrastructure setup + Sentinel/Splunk integration |
| Week 10〜11 | Pilot department rollout + training content |
| Week 12 | Company-wide rollout + help desk FAQs |
| Week 13 | First monthly review + KPI dashboard launched |
Summary — Enterprise security evolving from "file DLP" to "AI DLP"
The data exfiltration attacks on Microsoft Copilot Cowork demonstrate that the premise of "it is secure because access permissions are configured correctly" has collapsed as of 2026. From our position supporting AI governance for mid-sized enterprises through client engagements, "enterprise AI DLP"—which packages policy, technical controls, auditing, training, and contractor governance into a unified offering—has become our new flagship service.
Measures against data leakage via AI vary significantly depending on the configuration of the AI services in use, guest user involvement, and audit requirements. If you have concerns such as "worried about leakage risks following Copilot adoption," "file DLP cannot protect AI channels," or "unable to control AI usage by contractors," we provide tailored estimates based on your current setup. Please feel free to reach out via our contact form.
Sources
- Microsoft Copilot Cowork Exfiltrates Files(Hacker News 2026-05-25)
- Microsoft Introduces MDASH for Large-Scale AI Vulnerability Research(InfoQ 2026-05-25)
- Claude Cowork Enterprise Implementation for Clients (GH Media)
- Hyatt × ChatGPT Enterprise Client Project (GH Media)
- Google Workspace Security for Clients (GH Media)









