Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

File Exfiltration in Microsoft Copilot Cowork: Designing Enterprise AI DLP in Custom Development for 2026

Table of contents · 11 items

On May 25, 2026, Microsoft Copilot Cowork Exfiltrates Files was published on Hacker News, sending shockwaves through enterprise IT departments and security teams. Researchers demonstrated an attack technique in Microsoft 365 Copilot Cowork (a collaboration feature involving external participants) that combined indirect prompt injection with Copilot's internal file access permissions to allow "an invited guest to simply prompt Copilot to extract and externally transmit file contents from internal SharePoint, OneDrive, and Teams environments." Around the same time, InfoQ published Microsoft Introduces MDASH for Large-Scale AI Vulnerability Research, framing "AI-mediated data leakage" as one of the premier enterprise risks of 2026.

For custom development firms supporting AI governance and data loss prevention at mid-market enterprises, this reflects the reality that legacy DLP (Data Loss Prevention) focused on "file-level access permissions and audit logs" cannot address the new attack surface where "AI extracts data across contexts." Connecting with the Cowork governance covered in Claude Cowork Enterprise Adoption Engagements, the enterprise-wide AI rollout in non-IT sectors in Hyatt × ChatGPT Enterprise Engagements, and the Workspace governance in Google Workspace Security Engagements, we package "DLP architecture to prevent AI-mediated data leakage" into a custom development offering.

Why AI DLP is a watershed moment

DimensionExisting DLP (file-centric)DLP in the AI era (context-centric)
Detection unitFiles / attachments / emailsPrompts + responses + contextual references
Permission ModelAccess permissions / sharing settings+ LLM reference scope / context history
Indirect prompt injectionUnanticipatedTreated as a first-class risk
Guest usersRestricted by file viewing permissions+ Restricted querying permissions via AI
Data extraction pathwaysCopying / downloading / emailing+ AI summarizing, translating, and formatting output
AuditingAccess logs+ Prompt / response logs
Target LLMsNoneCopilot / Gemini / Claude / Bedrock
Affected scopeExfiltrated filesAll operational knowledge referenced cross-functionally

In other words, AI DLP represents a structural shift that abandons the assumption that "having access permissions equals safe," making "what the AI combined and generated, and under whose context," the primary subject of audits.

Three structural changes beneficial to custom development projects

Structure 1: From "file DLP" to "context DLP"

Security departments at mid-sized companies have historically been content with deploying file DLP solutions such as Symantec, Microsoft Purview, or Forcepoint. However, with AI-mediated data extraction like that in Copilot Cowork, situations frequently occur where traditional DLP fails to trigger because "the user has access permissions, the query appears legitimate, but confidential data is blended into the response." In our custom development, we design an AI DLP layer alongside existing DLP that detects and blocks leaks crossing contextual boundaries. This serves as an AI extension of the file and email controls covered in our custom Google Workspace security development.

Structure 2: From "excluding guests" to "controlling guest AI usage"

An operating policy of "disallowing" guest participation features across Cowork, Claude Cowork, or Gemini for Workspace stalls business agility. In our custom development, we deliver designs where "guests can interact with AI, but reference targets are restricted according to data sensitivity." This is a redesign from a DLP perspective of the Cowork governance addressed in our custom Claude Cowork enterprise implementation.

Structure 3: From "incident response" to "a culture of prompt auditing"

The core of AI DLP is an infrastructure capable of storing, searching, and analyzing audit logs of prompts and responses. This enables "governance explainable to executive management," even during company-wide AI deployments in non-IT industries as explored in our custom Hyatt × ChatGPT Enterprise development.

The five phases of "Enterprise AI DLP" provided in our custom development services

Phase 1: Current state assessment (2–3 weeks)

  • Inventory of active AI services (Copilot / Gemini / Claude / Bedrock / internal RAG)
  • Audit of AI usage scope among guests and external contractors
  • File DLP and IRM configuration review
  • Sensitive data classification (PII / executive management data / trade secrets)
  • Incident history review
  • Risk scoring + prioritization mapping

Phase 2: Policy design (2–3 weeks)

  • AI usage policies categorized by sensitivity tier (Red / Yellow / Green)
  • AI reference scope for guests and external contractors
  • Prompt injection defense guidelines
  • Audit log retention periods and encryption requirements
  • Incident escalation workflows
  • Governance KPIs

Phase 3: Technical control implementation (4–6 weeks)

  • IdP integration (Entra ID / Okta / Google Workspace)
  • Microsoft Purview DLP + AI extension policies
  • Copilot Cowork configuration (guest restrictions / access perimeters)
  • Prompt and response audit log aggregation (SIEM / Splunk)
  • Dedicated AI DLP tooling (Nightfall / Lakera / in-house)
  • Injection detection rules

Phase 4: Organization-wide rollout (3–4 weeks)

  • Departmental usage guidelines
  • Employee training (30-minute e-learning)
  • Revisions to contractor agreements (AI usage clauses)
  • Help desk FAQ establishment
  • Monthly executive management reporting

Phase 5: Monthly operational reviews (ongoing)

  • Trend monitoring for incident and detection counts
  • Review process for onboarding new AI services
  • Policy violation trend analysis
  • Audits during contractor agreement renewals
  • Semi-annual threat model updates

Standard technology stack set for custom development

LayerRecommended technologyAlternative
IdPMicrosoft Entra ID / Okta / Google WorkspaceAuth0
File DLPMicrosoft Purview / Symantec DLPForcepoint
Dedicated AI DLPNightfall / Lakera Guard / CyeraIn-house + LLM evaluation
Injection detectionLakera / Protect AI / in-housepromptfoo + rules
SIEMMicrosoft Sentinel / Splunk / DatadogSumo Logic
Audit log integrationAzure Monitor / Splunk / LokiElastic
Access controlConditional Access / Okta WorkflowsSailPoint
Training platformKnowBe4 / internal LMSSafeTitan

Which projects need this and which do not

Projects requiring thisProjects not requiring this
Using Copilot / Cowork / Gemini with external participantsFully closed network / no external contractors
Handling customer PII / executive confidential dataPublicly available information only
Audit requirements (ISO 27001 / SOC2 / FISC)Internal tools exempt from audits
High presence of contractors, temp staff, and vendorsDirect employees only
Incident response SLAs in placeImmediate response not required

Six clauses to include in client contracts

ClauseDetailsWhat the client should verify
Covered AI servicesCopilot / Gemini / Claude / Bedrock / internal RAGHandling of out-of-scope services
Data sensitivity classificationsRed / Yellow / Green classification criteriaStatutory and client requirements
Treatment of guests and contractorsAccess perimeters + AI usage boundariesContract revision responsibilities
Prompt audit retentionRetention period + encryption + access controlRegulatory requirements
Handover Upon Project CompletionPolicies / audit infrastructure / training contentInternal operational continuity
Incident operationsEscalation + emergency kill switch24/7 / business hours

Client-side ROI projection (assuming 500 employees / company-wide Copilot rollout / guest access enabled)

ItemExisting (file DLP only)After AI DLP implementationDifference
Risk of data exfiltration via AIEstimated 2–3 incidents/year0–1 incidents/year-2 incidents
Incident response effort (annual)240 hours60 hours-180 hours
Contractor AI usage governance effort40 hours/month10 hours/month-360 hours/year
Audit response hours200 hours/year60 hours/year-140 hours
AI adoption rate (suppressed due to lack of governance)30% adoption rate75% adoption rate+45pt
Annual benefitEquivalent to approx. 22 million JPY + productivity gains from doubling adoption

At 8,000 JPY per hour, this yields over 15 million JPY annually in labor savings, incident avoidance, and the benefits of expanded AI adoption. Using this labor cost reduction as a benchmark makes evaluating the governance investment straightforward.

Five common pitfalls

Pitfall 1: Governance based solely on "banning Copilot"

Opting for a blanket ban out of fear pushes frontline staff to use personal ChatGPT, personal Claude, or shadow Gemini for business tasks, accelerating ungoverned shadow IT. The prerequisite is an architecture that enables phased usage under proper controls.

Pitfall 2: Relying solely on tightening file DLP

Simply tightening configuration on existing Purview or Symantec tools without adding AI DLP leaves operations exposed, running with zero visibility into attacks like those seen in Copilot Cowork. Always integrate a dedicated AI DLP layer alongside them.

Pitfall 3: Flatly disabling guest access across the board

Blanket disabling Cowork guest functionality chokes business agility, driving teams to turn to alternative shadow IT tools. Operate instead with time-bound access tiered by data sensitivity.

Pitfall 4: Failing to retain prompt audit logs

Deciding against logging under the premise of privacy protection makes it impossible to trace root causes when incidents occur. Designing a compliant system that legally retains logs using encryption, retention windows, and access controls is indispensable.

Pitfall 5: Omitting AI clauses from contractor agreements

Even if you establish AI policies for direct employees, omitting AI terms from contracts with external contractors, temporary personnel, and vendors leaves the highest-risk leak vector completely unaddressed. Incorporate contract revisions into the initial implementation phase.

90-day action plan

WeekAction
Week 1〜3AI service inventory + sensitivity classification + guest audit
Week 4〜5Policy design + contractor agreement revision strategy
Week 6〜9IdP + DLP + AI audit infrastructure setup + Sentinel/Splunk integration
Week 10〜11Pilot department rollout + training content
Week 12Company-wide rollout + help desk FAQs
Week 13First monthly review + KPI dashboard launched

Summary — Enterprise security evolving from "file DLP" to "AI DLP"

The data exfiltration attacks on Microsoft Copilot Cowork demonstrate that the premise of "it is secure because access permissions are configured correctly" has collapsed as of 2026. From our position supporting AI governance for mid-sized enterprises through client engagements, "enterprise AI DLP"—which packages policy, technical controls, auditing, training, and contractor governance into a unified offering—has become our new flagship service.

Measures against data leakage via AI vary significantly depending on the configuration of the AI services in use, guest user involvement, and audit requirements. If you have concerns such as "worried about leakage risks following Copilot adoption," "file DLP cannot protect AI channels," or "unable to control AI usage by contractors," we provide tailored estimates based on your current setup. Please feel free to reach out via our contact form.

Sources

Share this articleXFacebook
Kakeru Suzuki

Fascinated by the possibilities of technology, has had a deep interest in programming and digital art since student days

Turn this article's theme into your company's next step

Thinking together, starting from the work you entrust to AI.

We organize your current operations and data to define the scope entrusted to AI, what humans should review, and how to run trials.

  • Target operations
  • Data to use
  • How to verify effectiveness
Consult on AI adoption for your business

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email