AI — Artificial Intelligence (Copilot)
Copilot and AI security controls. 5 controls in total — 3 automatic, 2 attested.
How to read
Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.
| Control | What it checks | Result criteria | Status |
|---|---|---|---|
AI-01 Idle Copilot licenses L1 | Checks for assigned but unused Copilot licenses. Idle licenses are both a needless cost and an unmanaged AI access surface. | ✅ Active usage 60% or higher · ⚠️ 30–59% · ❌ Below 30% | Auto N/A if no data |
AI-02 Copilot usage trend L1 | Checks how Copilot usage trends over time. Without watching it you cannot tell adoption from idleness, and access goes unmanaged. | ✅ Usage steady or rising (drop under 10%) · ⚠️ Drop over 10% | Auto N/A without enough data (at least 2 days) |
AI-03 Retention policy for Copilot and Teams meetings L1 | Checks whether a retention policy covers the Teams meeting recordings, transcripts and chats that Copilot summarizes. This content holds sensitive information. | ✅ Retention policy defined · ❌ Not defined | Auto N/A if no data |
AI-06 AI Acceptable Use Policy (AUP) L2 | Checks whether an acceptable use policy for AI has been published. Without one, staff can move corporate data into external AI tools with no control. | Attested Customer attestation (not measured automatically) | |
AI-07 DLP policy for Copilot Studio plugins L2 | Checks whether a data loss prevention (DLP) policy covers the AI agents built in Copilot Studio. Otherwise the agents can reach unauthorized sources and move corporate data out. | Attested Customer attestation (not measured automatically) |