Skip to content

Control 1.5: Sensitivity Label Taxonomy Review for Copilot

Control ID: 1.5 Pillar: Readiness & Assessment Regulatory Reference: GLBA §501(b), Sarbanes-Oxley §§302/404 (where applicable to ICFR), FFIEC IT Handbook (Information Security Booklet), SEC Regulation S-P Last Verified: 2026-08-02 Governance Levels: Baseline / Recommended / Regulated


Objective

Review and update the organization's Microsoft Purview sensitivity label taxonomy before deploying Microsoft 365 Copilot to address Copilot-specific scenarios including Copilot interaction restrictions, content-based auto-labeling for saved outputs, DLP integration with sensitivity labels, and label-based access controls that govern how Copilot processes and generates content. This control supports compliance with data classification requirements and helps prevent Copilot from processing or generating content with insufficient protection.


Why This Matters for FSI

  • GLBA §501(b): Sensitivity labels are a primary technical safeguard for classifying and protecting customer financial information. Without a Copilot-aware label taxonomy, AI-generated content may be created without appropriate classification, creating unprotected copies of regulated data.
  • Sarbanes-Oxley §§302/404 (where applicable to ICFR): Financial reporting data must be subject to internal controls including classification. Copilot can generate summaries, analyses, and reports from financial data -- these outputs must inherit appropriate sensitivity labels to maintain control integrity.
  • FFIEC IT Handbook (Information Security): Data classification is a foundational information security control. The introduction of AI content generation requires extending classification practices to cover AI-generated outputs.
  • SEC Regulation S-P: Labels that classify consumer financial information support privacy safeguards by enabling DLP policies that restrict how Copilot handles protected content.
  • FINRA Rule 3110 (supervisory systems and WSPs): Copilot-generated communications that reference client data must carry appropriate sensitivity classification to support supervisory review requirements.

Control Description

Why Existing Labels May Be Insufficient for Copilot

Most organizations implemented sensitivity labels for human-created content workflows. Copilot introduces new scenarios that existing taxonomies may not address:

Scenario Gap Risk
Copilot generates content from labeled sources Generated content may not inherit source labels AI-generated summaries of "Highly Confidential" documents may be created as "General"
Copilot processes labeled content for grounding No label-based restriction on Copilot access Copilot can read and cite "Highly Confidential" content if user has permission
Classification for saved Copilot outputs No inheritance, mandatory-labeling, or content-based auto-labeling controls for saved outputs AI-generated documents may be created without labels
DLP policies referencing labels DLP may not cover Copilot interaction channels Label-based DLP may not trigger on Copilot-generated responses
Label inheritance across workloads Labels on SharePoint files may not propagate to Copilot-generated Teams messages Cross-workload content generation bypasses label inheritance

Label Groups Transition

Microsoft is replacing parent labels with label groups. For qualifying and newly created tenants, the modern label-group scheme began rolling out automatically beginning October 1, 2025, but this migration is gradual and may not yet be available in a given tenant. When available, it is surfaced by a tenant-specific banner in the Microsoft Purview portal (Solutions > Information Protection > Sensitivity labels) and is irreversible once started. Labels inside a group remain individually selectable. Organizations should verify current availability in their tenant and plan for this transition when designing or updating their label taxonomy.

Label Enhancement Purpose Implementation
"Copilot Restricted" sublabel Mark content that should be excluded from Copilot grounding Apply the label as a business classification, then enforce the exclusion with a DLP policy using the Microsoft 365 Copilot and Copilot Chat location (Content contains > Sensitivity labelsPrevent Copilot from processing content). Label encryption rights (VIEW/EXTRACT) govern whether Copilot can process content, but do not by themselves create a Copilot-specific block. This rule does not cover files a user uploads directly into a Copilot prompt — see the limitation callout below
"AI-Assisted" marking (optional) Identify content users attest was created with Copilot for supervisory review Use a user-applied label or a mandatory labeling workflow with clear instructions. Auto-labeling can classify content by SITs or trainable classifiers, but Microsoft doesn't document a "Copilot-generated" origin attribute that can apply this marking automatically
Auto-labeling for saved outputs Classify content saved from Copilot workflows Auto-labeling policies use content-based conditions (SITs, trainable classifiers) on saved or emailed content in supported locations — there is no "Copilot-generated" detection attribute. Generated files can also inherit the highest-priority source label in supported creation experiences (Word, PowerPoint, Outlook, Edit in Pages)
DLP-integrated labels Enable DLP policies that exclude labeled content from Copilot DLP rules using the Microsoft 365 Copilot and Copilot Chat location that reference sensitivity labels to prevent Copilot from processing that content. Files uploaded directly into a Copilot prompt are not evaluated by this rule; pair it with a compensating control (see limitation callout below)
Mandatory labeling enforcement Require labels on all content including Copilot-generated content Mandatory labeling policy in Microsoft Purview

Limitation: DLP does not scan files uploaded directly into a Copilot prompt

Microsoft documents that when a user uploads a file directly into a Copilot prompt (rather than referencing a file already stored in SharePoint, OneDrive, or Exchange), DLP can't scan the contents of that uploaded file — evaluation of the uploaded file for sensitive data doesn't occur, and only the text typed into the prompt itself is checked. This means the Microsoft 365 Copilot and Copilot Chat DLP location's sensitivity-label rule (and the "Copilot Restricted" label design above) is not complete coverage: a user who holds VIEW/EXTRACT rights to a "Highly Confidential" (or "Highly Confidential - Copilot Restricted") labeled file can still upload it directly into a prompt, bypassing the DLP exclusion entirely.

Do not represent the sensitivity-label DLP rule as blocking all paths by which highest-sensitivity content could reach Copilot. Treat it as covering files/emails already stored in supported locations, and require a compensating control for the direct-upload gap:

  • Baseline: Document this limitation in the taxonomy review and in user-facing guidance for the highest-sensitivity label(s).
  • Recommended / Regulated: Implement at least one additional, verifiable control alongside the DLP rule — for example, an acceptable-use policy and mandatory user training that explicitly prohibits uploading files carrying the highest-sensitivity label(s) directly into Copilot prompts, combined with periodic review of Copilot interaction activity (see Control 3.1: Copilot Audit Logging) to detect violations after the fact. Evaluate additional preventive controls (for example, endpoint DLP or Microsoft Defender for Cloud Apps session controls covering upload activity) against your tenant's configuration before relying on them, since Microsoft does not currently document a DLP or label-based control that prevents the direct-upload path itself.

Label Taxonomy Review Checklist

Review Area Questions to Answer Impact on Copilot
Current label coverage What percentage of content has labels? Are there gaps in specific workloads? Unlabeled content is invisible to label-based Copilot controls
Label granularity Are labels granular enough to distinguish content that Copilot should/should not process? Overly broad labels cannot provide precise Copilot access control
Encryption settings Which labels apply encryption? What usage rights are configured? Encryption settings determine whether Copilot can process labeled content
Auto-labeling policies Are content-based auto-labeling policies configured for saved Copilot output locations? Missing inheritance, mandatory labeling, or content-based auto-labeling means saved output may be unclassified
DLP integration Do DLP policies reference sensitivity labels? Are Copilot channels covered? Label-based DLP is a primary control for governing Copilot interactions
Label priority and order Is the label priority order correct for Copilot scenarios (higher sensitivity takes precedence)? Incorrect priority could result in Copilot-generated content receiving lower classification than source material
Sublabel structure Do sublabels provide sufficient granularity for Copilot governance? Sublabels enable fine-grained Copilot restrictions within broader classification categories

Copilot-Specific Label Recommendations for FSI

Classification Level Copilot Behavior Configuration
Public Copilot can freely process and generate content No restrictions
General / Internal Copilot can process; generated content inherits "Internal" label Auto-labeling on Copilot outputs; DLP prevents external sharing
Confidential Copilot can process with DLP monitoring; generated content labeled "Confidential" DLP logs Copilot interactions; auto-labeling on outputs
Highly Confidential Copilot can process if user has permission; generated content labeled "Highly Confidential" with encryption DLP restricts external sharing and monitors access; encryption prevents unauthorized access to outputs
Highly Confidential - Copilot Restricted Copilot is blocked from processing this content when it is already stored in a supported location (SharePoint, OneDrive, Exchange) or opened in Word/Excel/PowerPoint DLP policy using the Microsoft 365 Copilot and Copilot Chat location (Content contains > Sensitivity labelsPrevent Copilot from processing content) excludes labeled files and emails from grounding; content stays visible to the user and may still appear in response citations. This does not cover files uploaded directly into a Copilot prompt — require a compensating control (acceptable-use policy/training plus activity-log review; see limitation callout above) for that path

Label Inheritance Model for Copilot

Source Content (Labeled) ──> Copilot Processing ──> Generated Output

Inheritance Rules (automatic inheritance is documented for Copilot in Word, PowerPoint, and Outlook, with Edit in Pages as an example; other surfaces vary — verify per Copilot surface):
1. If single source: Output inherits the source label in supported creation experiences
2. If multiple sources: Output inherits the highest-priority (most restrictive) source label where supported
3. If no source labels: Output receives organization default label (if configured)
4. If mandatory labeling: User prompted to apply label before saving; a user may override an inherited label unless mandatory labeling prevents its removal
5. If auto-labeling configured: Label applied automatically based on content conditions

Copilot Surface Coverage

Copilot Surface Label Relevance Key Consideration
Microsoft 365 Copilot Chat Critical Cross-workload responses may combine content from multiple label levels
Word Critical Document generation must respect and apply sensitivity labels
Excel High Data analysis outputs should inherit labels from source workbooks
PowerPoint High Presentations generated from labeled content need label inheritance
Outlook Critical Copilot-drafted emails referencing labeled content need classification
Teams High Copilot responses in Teams chat should respect channel sensitivity settings
SharePoint High Copilot-generated content in SharePoint libraries must be labeled
OneDrive High Auto-labeling must cover Copilot-created files saved to OneDrive
Copilot Pages High New content type that requires label governance from inception
Copilot Notebooks High No standalone Notebook-level or container sensitivity label exists — Notebooks share a user-owned container with Copilot Pages and Loop My workspace, and automatic/recommended Notebook-level labeling is not a supported control (verify the current Pages-label support state in Control 2.11). This does not mean labeling stops applying to Notebook content: sensitivity labels already on referenced/source content still govern that content. Treat DLP (Microsoft 365 Copilot and Copilot Chat location) as the primary compensating control for Notebook-specific governance
Loop Medium Loop components with Copilot-generated content need labeling

Governance Levels

Level Requirement Rationale
Baseline Review existing sensitivity label taxonomy for Copilot readiness. Ensure mandatory labeling is enabled. Verify that labels with encryption settings are correctly configured for Copilot scenarios. Document any gaps identified, including the direct-upload limitation of the Copilot DLP location (see limitation callout above). Minimum review to identify critical gaps in label taxonomy that could result in unclassified AI-generated content.
Recommended All Baseline requirements plus: implement "Copilot Restricted" sublabel for highest-sensitivity content. Configure auto-labeling policies covering content saved from Copilot workflows. Integrate sensitivity labels with DLP policies using the Microsoft 365 Copilot and Copilot Chat location. Implement a compensating control for files uploaded directly into Copilot prompts (acceptable-use policy/training plus periodic activity-log review). Achieve >75% label coverage across in-scope workloads, measured by cross-referencing Content Explorer labeled-item exports with workload inventory totals, or by using the framework's coverage-scanning tooling (not Information Protection Reports — see Step 2). Document label taxonomy decisions and Copilot-specific configurations. Provides active label-based governance of Copilot interactions with auto-labeling, DLP integration, and a compensating control for the direct-upload gap.
Regulated All Recommended requirements plus: achieve >90% label coverage using the same inventory-based measurement as Recommended. Use label reporting (Microsoft Purview Information Protection > Reports, in preview) to monitor labeling activity and adoption trends for content produced through Copilot workflows — this report's 30-day rolling window does not provide the content-inventory denominator needed to compute coverage percentage. Conduct quarterly label taxonomy reviews that include Copilot scenario testing and re-validation of the direct-upload compensating control. Validate that label inheritance behaves as documented across each in-scope Copilot surface. Document label governance in regulatory examination file. Engage compliance team in label taxonomy decisions for regulated data categories. Comprehensive label governance that supports examination readiness and provides documented evidence of AI content classification controls.

Setup & Configuration

Step 1: Review Current Label Taxonomy

Navigate to Microsoft Purview portal > Solutions > Information Protection > Sensitivity labels and inventory:

  • All active sensitivity labels and sublabels
  • Encryption settings per label
  • Auto-labeling configurations
  • Label policies (scope, mandatory labeling, default labels)

Step 2: Assess Label Coverage

Measure the percentage of content with labels applied using both a labeled-item numerator and a complete workload denominator:

  • Microsoft Purview > Solutions > Data Classification > Content explorer — export the items that have surfaced with sensitivity labels by workload and label. Content Explorer isn't a complete inventory of unlabeled content, counts can take up to 7 days to update (14 days for SharePoint), and encrypted sensitivity labels don't surface in Content Explorer for SharePoint and OneDrive
  • A workload inventory (e.g., SharePoint/OneDrive site and item counts from the SharePoint admin center or Graph API) supplies the total-item denominator and must be cross-referenced against the labeled-item numerator, including a separate source for encrypted-label items that Content Explorer can't surface
  • The framework's own coverage-scanning tooling, where available, for a repeatable per-workload percentage

Use Microsoft Purview > Solutions > Information Protection > Reports (in preview; reports use a 30-day rolling window) only for labeling activity and adoption trend data:

  • Label distribution and adoption trends over time
  • Auto-labeling policy activity
  • Sensitivity label activity (who is applying/removing labels)

Reports is not a coverage-percentage source

The Information Protection Reports page reports labeling activity over its 30-day rolling window — it does not inventory the total (unlabeled + labeled) content in a workload, so it cannot supply the denominator required to compute a coverage percentage against the >50%/>75%/>90% targets. Cross-reference Content Explorer's labeled-item data with a complete workload inventory, or use the coverage-scanning tooling above, and reserve Reports for trend/adoption monitoring.

Step 3: Create Copilot-Specific Labels

If gaps are identified, create or modify labels:

Navigate to Microsoft Purview > Solutions > Information Protection > Sensitivity labels, then select + Create > Label (use + Create > Label group for the modern label-group scheme).

Key configuration for a "Copilot Restricted" classification: - Create the label (or sublabel) as a business classification for content that should be excluded from Copilot grounding - Enforce the exclusion with a DLP policy using the Microsoft 365 Copilot and Copilot Chat location (Content contains > Sensitivity labelsPrevent Copilot from processing content) — encryption usage rights alone do not create a Copilot-specific block - If the label applies encryption, users need VIEW and EXTRACT usage rights for Copilot to process the content

Step 4: Configure Auto-Labeling Policies

Navigate to Microsoft Purview > Solutions > Information Protection > Policies > Auto-labeling policies, select + Create auto-labeling policy, and configure conditions for:

  • Content matching financial SITs (SSN, account numbers, credit card numbers)
  • Content in specific SharePoint sites containing regulated data
  • Content saved to supported locations (SharePoint, OneDrive, Exchange) matched by trainable classifiers

Auto-labeling matches on content conditions (SITs, trainable classifiers) in supported locations; there is no "Copilot-generated" detection attribute. For content created through Copilot, rely on label inheritance in supported creation experiences (Word, PowerPoint, Outlook, Edit in Pages) and on client-side auto-labeling in Office apps.

Step 5: Integrate Labels with DLP

Navigate to Microsoft Purview > Solutions > Data Loss Prevention > Policies and, using a Custom policy with the Microsoft 365 Copilot and Copilot Chat location, verify:

  • The rule uses Content contains > Sensitivity labels with the action Prevent Copilot from processing content to exclude labeled files and emails from grounding
  • Coverage applies to Microsoft 365 Copilot, Copilot Chat, and Copilot in Word, Excel, PowerPoint; it supports stored and open files plus emails sent on or after January 1, 2025 (calendar invites are not supported)
  • Selecting the Copilot location disables all other locations in that policy; excluded items may still appear in response citations
  • Licensing requirements apply — verify entitlements against the Microsoft Purview service description
  • This rule does not evaluate files uploaded directly into a Copilot prompt — Microsoft documents that DLP only checks the text typed into the prompt in that case, not the uploaded file's contents. Implement the compensating control described in the limitation callout above (acceptable-use policy/training plus activity-log review) alongside this DLP rule for the highest-sensitivity label(s)

Financial Sector Considerations

  • NPI Classification: Labels must cover Gramm-Leach-Bliley Non-Public Personal Information categories. Ensure labels for customer financial data, account information, and transaction histories are appropriately mapped to Copilot governance actions.
  • MNPI Handling: Material non-public information used in trading, investment banking, and research activities should carry labels that restrict Copilot processing in contexts outside the designated information barrier segment.
  • Board and Committee Materials: Board reports, audit committee materials, and executive compensation data often lack sensitivity labels despite high sensitivity. Review label coverage for these content categories before Copilot deployment.
  • Client Communication Labels: Copilot-drafted client communications (emails, presentations, proposals) must carry labels that enable supervisory review workflows required by FINRA Rule 3110.
  • Regulatory Report Labels: Content used in regulatory filings (SEC 10-K, Call Reports, FINRA FOCUS) should carry labels that prevent Copilot from incorporating pre-release regulatory data into non-regulatory contexts.
  • Cross-Entity Label Consistency: Multi-entity financial organizations should harmonize label taxonomies across legal entities to ensure consistent Copilot governance, particularly where content is shared across entity boundaries.

Verification Criteria

  1. Existing sensitivity label taxonomy has been reviewed for Copilot readiness with gaps documented
  2. Mandatory labeling is enabled for all in-scope M365 workloads
  3. Encryption settings on high-sensitivity labels are confirmed compatible with intended Copilot behavior (block or allow processing)
  4. "Copilot Restricted" sublabel (or equivalent) and its DLP exclusion policy (Microsoft 365 Copilot and Copilot Chat location) are configured and tested for highest-sensitivity content stored in supported locations (Recommended and Regulated levels); this test does not cover files uploaded directly into a Copilot prompt
  5. Auto-labeling policies are configured for content saved from Copilot workflows (Recommended and Regulated levels)
  6. DLP policies using the Microsoft 365 Copilot and Copilot Chat location exclude labeled content from Copilot processing (Recommended and Regulated levels)
  7. Label coverage meets governance level targets (>50% Baseline / >75% Recommended / >90% Regulated), measured by cross-referencing Content Explorer labeled-item data with a complete workload inventory, or by using the coverage-scanning tooling — not Information Protection Reports
  8. A compensating control for files uploaded directly into Copilot prompts (acceptable-use policy/training plus activity-log review, or an equivalent verified preventive control) is documented and implemented (Recommended and Regulated levels)
  9. Label inheritance behavior has been tested across Copilot surfaces (Regulated level)
  10. Label taxonomy review cadence is established (annual minimum; quarterly for Regulated)
  11. Label governance decisions and configurations are documented and accessible for regulatory examination

Additional Resources


FSI Copilot Governance Framework v1.8.0 - July 2026