Microsoft has expanded its security controls for AI agents, including a generally available capability designed to stop sensitive data reaching unsanctioned AI services over the network. The update combines Microsoft Purview classification and policy with Entra Global Secure Access so rules can be enforced across both human activity and on-behalf-of agent traffic.
Microsoft says organisations can detect sensitive files and text in real time and block transfers to risky destinations before the data leaves. The same September security update also adds an inventory view for local AI agents and new Security Copilot support for explaining email detonation results during investigations. In Purview, Microsoft says auto-labelling simulations can now cover up to 20 million items and 50,000 sites. Those scale figures are company-reported product limits.
The direction matters more than any single feature. Enterprise AI governance is moving out of policy documents and into enforcement points that already control identities, networks and data. That is important because an agent does not become safer simply because it acts for an authorised employee. If it can upload files, invoke services or move information between systems, its traffic needs classification, access policy, logging and containment just as human traffic does.
