Section 01 · Unit introduction

Compliance for AI at work

Deploying AI across an organisation raises the same compliance obligations as any handling of corporate and personal data — and adds a few of its own. Where is data processed and stored? How long is it kept? Who can see it, and how is sensitive information protected? And can you account for what the AI did?

Microsoft 365 answers these through data residency commitments, the EU Data Boundary, retention policies, sensitivity labels, data loss prevention (DLP), and Microsoft Purview — including Purview's specific integration with Copilot for auditing and eDiscovery.

By the end of this unit
  • Explain data residency and what the EU Data Boundary commits to for Microsoft 365.
  • Describe how sensitivity labels, retention policies, and DLP protect and govern data.
  • Explain how Microsoft Purview audits Copilot interactions and supports eDiscovery.

Four compliance questions every deployment must answer

  • Where is data processed and stored? — data residency
  • The EU Data Boundary commits to keeping data within the EU/EFTA
  • Residency is set largely by tenant and licensing geography
  • Relevant to GDPR and sector-specific obligations
  • How long is data kept, and when is it deleted? — retention
  • Retention policies keep data for compliance and remove it when no longer needed
  • Over-retention is a liability; under-retention breaches obligations
  • Applies to Copilot interaction history too
  • Who can access data, and how is sensitive content protected?
  • Sensitivity labels classify and protect; DLP prevents leakage
  • Purview governs, audits, and supports investigation
  • Together they enforce policy across the estate
Compliance for AI is not a separate discipline bolted on afterwards. It is the same data governance you already owe — now applied to a tool that reaches across your whole estate.
Working principle · AI compliance
Section 02

Data residency and the EU Data Boundary

Data residency is about where your data is stored and processed. For organisations subject to GDPR or to sector rules, this is often a hard requirement, and the EU Data Boundary is Microsoft's commitment that addresses it.

What data residency means

Residency is the geographic location where customer data is stored and processed at rest and, increasingly, in transit and during processing. For Microsoft 365 it is determined largely by where your tenant is provisioned. Knowing your residency commitments is the starting point for any compliance conversation.

The EU Data Boundary

The EU Data Boundary is Microsoft's commitment to store and process customer data for its major cloud services — including Microsoft 365, Azure, Dynamics 365, and Power Platform — within the EU and EFTA region for customers in those regions. It covers customer data and the personal data involved in providing the services, including the processing that supports Copilot, narrowing the cases where data leaves the boundary.

Why it matters for Copilot

When users invoke Copilot, prompts and responses are processed by Microsoft's services. The EU Data Boundary commitment means that, for in-scope customers, this processing stays within the region — important reassurance for GDPR compliance and for organisations with data-localisation obligations. Confirm scope and any documented exceptions for your specific services.

Practical note

Residency is not a single switch you flip — it is established by your tenant geography and licensing, and refined by configuration. Verify where your tenant is provisioned and review Microsoft's published documentation on EU Data Boundary scope before making firm commitments to stakeholders or regulators.

Knowledge check

An EU-based organisation needs assurance that data Copilot processes stays within the EU/EFTA. What addresses this directly?

Section 03

Labels, retention, and DLP

Three Purview capabilities do the day-to-day work of protecting and governing data. They are also the controls that determine how safely Copilot can operate across your content.

Sensitivity labels — classify and protect
Sensitivity labels (Confidential, Highly Confidential, and so on) classify content and can enforce protection: encryption, access restrictions, visual markings, and usage controls that travel with the file. Crucially for AI, labelling and protecting sensitive content directly shapes what Copilot can surface and how — protected content carries its restrictions into the AI experience. Good labelling is foundational AI governance, not just document hygiene.
Retention policies — keep and delete deliberately
Retention policies keep content for as long as compliance requires and dispose of it when it is no longer needed. Both ends matter: under-retention can breach legal or regulatory obligations; over-retention increases risk and discovery burden. Retention applies across Microsoft 365 — including, importantly, the record of Copilot interactions, which can be retained and disposed of under policy.
Data loss prevention (DLP) — stop leakage
DLP policies detect sensitive information (credit-card numbers, identifiers, custom patterns) and prevent it leaving through unsanctioned channels — blocking or warning on risky sharing, copying, or sending. DLP can extend to AI-relevant scenarios, helping prevent sensitive data being exposed inappropriately. It is the enforcement layer that turns classification into action.
How the three work together
Labels classify and protect; retention governs lifecycle; DLP enforces boundaries on movement. They reinforce one another: a labelled item can drive a DLP rule and a retention outcome. For AI, this combination is what lets Copilot reach across content confidently — sensitive material stays protected, retained correctly, and prevented from leaking.
Reflect

Look at your organisation's sensitivity labelling today. Is it applied consistently enough that you would trust it to govern what an AI surfaces? If labelling is patchy, that is the work that must precede — not follow — a broad Copilot rollout.

Section 04

Purview and Copilot

Microsoft Purview integrates with Copilot so that AI interactions are governed, auditable, and discoverable like any other corporate activity. This integration is what lets compliance teams treat Copilot as in-scope for the obligations they already manage.

Auditing Copilot interactions

Copilot user interactions — the prompts users submit and the responses returned — are captured in the Purview audit log. This gives compliance and security teams visibility into how Copilot is being used, supporting investigations and demonstrating accountability. AI use becomes an auditable activity, not a black box.

eDiscovery and content search

Copilot interactions can be surfaced through eDiscovery and content search, so that prompts and responses are discoverable for legal holds, regulatory requests, and investigations — the same way email and chat are. This means an organisation can place Copilot activity on hold and search it within its existing eDiscovery processes.

Retention and protection carried through

Retention policies can apply to Copilot interaction data, and the sensitivity labels and protection on the underlying content are honoured in the Copilot experience. Compliance does not stop at the edge of the AI — the same governance extends into and around it, which is what makes a defensible deployment possible.

End of Unit 10

You should now be able to:

  • Explain data residency and what the EU Data Boundary commits to, including for Copilot processing.
  • Describe how sensitivity labels, retention, and DLP protect and govern data — and AI use.
  • Explain how Purview audits Copilot interactions and makes them discoverable for eDiscovery.
Section 05

Unit review

Question 1 of 4

What does the EU Data Boundary commit Microsoft to?

Question 2 of 4

Why is consistent sensitivity labelling foundational before a broad Copilot rollout?

Question 3 of 4

Which control prevents sensitive information from leaving through unsanctioned channels?

Question 4 of 4

How does Purview's integration with Copilot support compliance investigations?

End of module

You have completed Course 10: Compliance and Data Residency — and the Deploy pillar's architecture, integration, and operations track. You can now build agents, extend Copilot, and govern AI deployments securely and compliantly.

Craig Stanley Studio · Deploy — Architecture, Integration & Operations · Compliance and Data Residency · Access by direct link only.