“Do you have a data classification policy?” Almost every IT director I ask says yes. Then I ask a follow-up: “Can you open a document right now that carries a sensitivity label?” That one gets a longer pause. The policy exists. It was written for an audit, approved, and filed. Nothing in Microsoft 365 or anywhere else actually knows which files are confidential.
That gap was tolerable for years. It isn’t anymore. Sensitivity labels and data loss prevention (DLP) are how AI tools learn what’s sensitive, and how you stop sensitive content from flowing into places it shouldn’t. If you’re planning DLP for AI in Microsoft 365 or any other suite, this is the foundation, and it takes about a month to put in place properly.
Why labels matter more once AI arrives
Without labels, every file looks the same to software. An AI assistant can’t tell the board deck from the cafeteria menu except by reading them, and by then it has already used both. Labels give systems a machine-readable answer to “how sensitive is this?”, and that answer is what the controls key off.
In Microsoft 365, Microsoft documents that Copilot honors sensitivity labels, including the encryption permissions a label applies, and that content Copilot generates from labeled files can carry the label forward. Purview also includes DLP controls aimed specifically at Copilot. Which of those your tenant can use depends on your license, so check your plan before you buy anything. Google Workspace has its own Drive labels and DLP rules that play a similar role.
There’s a second reason, and it has nothing to do with the assistant you license. Employees paste work content into public AI tools every day. That’s a new path for data to leave the company, and it runs through the browser, not email. DLP that only watches email misses it entirely. That’s also why a shadow AI policy needs technical controls behind it.
Here’s how the assessment asks the question, and the 0 to 4 ladder I score it against:
S2. How do you classify and protect sensitive data?
- No classification scheme
- A classification policy exists on paper only
- Sensitivity labels applied to some data, mostly by hand
- Labels plus DLP enforced on email, endpoints, and cloud storage
- Labels and DLP also cover AI tools (prompts, uploads, and AI-generated content)
Level 1 is the most common answer I see, and it’s the one people are least comfortable admitting. Level 3 is a realistic 90-day target for a mid-size team. Level 4 is where AI-specific coverage kicks in, and it’s much easier to reach from 3 than to build separately.
Three decisions to make before you touch the admin center
- How many labels? Four. Public, General, Confidential, Highly Confidential. You can add sub-labels later. Teams that start with ten labels get users who pick randomly, and random labels are worse than none because they look trustworthy.
- What’s the default? Set a default label, usually General, so new documents aren’t unlabeled. Users only have to think when something is more sensitive than the default.
- Which data is radioactive? Pick the two or three data types where a leak would actually hurt: customer records, payment data, employee records, pricing. These are the ones you’ll auto-detect and protect first. Everything else can wait.
The asset: a 30-day labels and DLP rollout
Week 1: define and decide
- Write a one-sentence definition and three examples for each of the four labels. If a user can’t pick the right label in five seconds from that sentence, rewrite it.
- Pick your radioactive data types and match each to a built-in sensitive information type (national ID numbers, payment card numbers) or a custom one (your customer ID format).
- Name an owner for the label taxonomy, usually security, with the data owners from each business area signing off on the definitions.
Week 2: pilot in audit mode
- Publish the labels to a pilot group: IT plus one business team that handles sensitive data.
- Turn on DLP policies for email, SharePoint and OneDrive, and endpoints, in audit or simulation mode. Don’t block anything yet.
- Run auto-labeling for your radioactive data types in simulation, so you can see what it would label before it does.
Week 3: tune
- Review the DLP matches from week 2. Expect false positives; tune the rules until most matches are real.
- Switch on policy tips, the in-app warnings that tell users why something looks sensitive. Warning before blocking teaches people the system.
- Fix the obvious oversharing the DLP reports reveal. If a lot of confidential files turn up in broadly shared sites, the SharePoint oversharing cleanup is your next priority.
Week 4: enforce and extend to AI
- Publish labels to everyone, with training that fits on one screen.
- Enforce blocking for Highly Confidential content leaving the organization by email or external sharing.
- Add the AI paths: block or warn when labeled content is pasted or uploaded to unapproved AI sites, using endpoint DLP or your browser controls, and apply the AI-specific protections your licenses include for your approved assistant.
- Turn auto-labeling from simulation to enforcement for your radioactive data types.
At the end of 30 days you’re at level 2 for most content and level 3 for the data that matters most, with the AI coverage that moves you toward 4 already switched on.
Mistakes I see at this stage
Blocking on day one. DLP in enforcement mode before tuning generates a flood of blocked emails, a flood of complaints, and a leadership request to turn it off. Audit first, warn second, block third.
Relying on users to label everything by hand. Manual labeling works for the documents people know are sensitive. It misses the spreadsheet export someone made at 5 p.m. on a Friday. Auto-labeling for your radioactive data types is what closes that gap.
Forgetting the browser. Email DLP was the whole game ten years ago. Today the biggest uncontrolled path for sensitive data is a paste into a browser tab. If your controls don’t reach the endpoint or the browser, they don’t reach AI.
Ignoring AI-generated content. A summary of a Highly Confidential document is Highly Confidential. Make sure your label settings and your approved assistant handle label inheritance, and test it with a real file before rollout.
Treating this as a security-only project. Security owns the tooling. The business owns the definitions. If sales doesn’t agree that the price list is Confidential, the label won’t stick.
How this fits with the rest of AI security
Labels and DLP are one of four security questions in the readiness assessment, alongside shadow AI, identity, and vendor review. They’re also the piece that makes an assistant rollout defensible to your auditors, because they show you can say what’s sensitive and prove it’s protected. For the full security picture, see AI security readiness, and if you’re specifically preparing a Microsoft 365 Copilot rollout, the five things to fix before Copilot puts labels in sequence with the other prerequisites.
Where does your team actually stand?
Classification and DLP is one of 24 questions in the AI Readiness assessment, which covers six dimensions: data, security, infrastructure, skills, use cases, and governance. The free version is 10 questions and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want to see what the full assessment covers first? Flip through a complete 38-page sample report.
Related guides
- The Shadow AI Policy Your IT Team Actually Needs (With Template)
- Fix SharePoint Oversharing Before You Turn On Copilot
- AI Security Readiness: Closing the Gaps AI Exposes
- Copilot Readiness: The 5 Things to Fix Before Rollout
- The 6-Dimension AI Readiness Framework, Explained
Frequently asked questions
How many sensitivity labels should we start with?
Four: Public, General, Confidential, and Highly Confidential. You can add sub-labels later. Starting with many labels leads users to pick them at random, which is worse than having no labels, because the result looks trustworthy when it isn't.
Should DLP block sensitive content from day one?
No. Run DLP in audit or simulation mode first, tune out false positives, switch on in-app warnings, and only then enforce blocking. Blocking before tuning floods people with false alarms and usually ends with the policy being turned off.
Does Microsoft 365 Copilot respect sensitivity labels?
Microsoft documents that Copilot honors sensitivity labels, including the encryption permissions a label applies, and that content it generates from labeled files can carry the label forward. Check which related controls your own license includes before buying add-ons.
Why does DLP need to cover the browser?
Much of today's AI-related risk comes from content pasted or uploaded into web-based AI tools, not from email. Controls that only watch email miss that path. Endpoint DLP or browser controls let you warn or block when labeled content heads to unapproved AI sites.




