Skip to main content

AI — Artificial Intelligence (Copilot)

Copilot and AI security controls. 5 controls in total — 3 automatic, 2 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
AI-01 Idle Copilot licenses
L1
Checks for assigned but unused Copilot licenses. Idle licenses are both a needless cost and an unmanaged AI access surface.✅ Active usage 60% or higher · ⚠️ 30–59% · ❌ Below 30%Auto
N/A if no data
AI-02 Copilot usage trend
L1
Checks how Copilot usage trends over time. Without watching it you cannot tell adoption from idleness, and access goes unmanaged.✅ Usage steady or rising (drop under 10%) · ⚠️ Drop over 10%Auto
N/A without enough data (at least 2 days)
AI-03 Retention policy for Copilot and Teams meetings
L1
Checks whether a retention policy covers the Teams meeting recordings, transcripts and chats that Copilot summarizes. This content holds sensitive information.✅ Retention policy defined · ❌ Not definedAuto
N/A if no data
AI-06 AI Acceptable Use Policy (AUP)
L2
Checks whether an acceptable use policy for AI has been published. Without one, staff can move corporate data into external AI tools with no control.Attested
Customer attestation (not measured automatically)
AI-07 DLP policy for Copilot Studio plugins
L2
Checks whether a data loss prevention (DLP) policy covers the AI agents built in Copilot Studio. Otherwise the agents can reach unauthorized sources and move corporate data out.Attested
Customer attestation (not measured automatically)