AI Governance Evidence for Microsoft Copilot: What Microsoft Purview Cannot Give You
Microsoft 365 Copilot is the most widely deployed enterprise AI system in 2026. For most regulated financial services firms, it is also the AI system with the largest gap between deployment scale and governance evidence. Firms that deployed Copilot for productivity have Microsoft's administrative tooling: Purview, the Compliance Portal, Copilot usage reports, sensitivity label analytics.
What they do not have, and what Microsoft's tooling cannot provide, is the evidence of governance that FCA supervision, ICO audit, and EU AI Act Article 26 require. This article explains the specific gap between Microsoft's tooling and the regulatory evidence standard, and what fills it.
Microsoft Purview governs what Copilot can access. AI governance evidence infrastructure governs whether Copilot is being governed, and can prove it under regulatory examination.
What Microsoft Purview Provides
Microsoft Purview is the primary governance tooling for Microsoft 365 environments, including Copilot. It provides:
- Data classification and sensitivity labelling. Applying labels to content that Copilot can access, restricting what it can surface based on label policies
- Data Loss Prevention policies. Rules that prevent Copilot from including sensitive content in responses based on defined criteria
- Compliance portal reporting. Activity logs, usage reports, and audit records within the Microsoft 365 environment
- Insider risk management. Detection of unusual data access patterns by users, including Copilot-assisted access
- eDiscovery integration. Capability to include Copilot interaction records in legal hold and discovery processes
These are valuable capabilities for governing Copilot's behaviour within the Microsoft ecosystem. They are also within-Microsoft capabilities. They do not address what Copilot does in combination with AI agents on other platforms, they do not produce cryptographically signed evidence packs, and they do not generate the cross-platform governance artefacts that regulatory examination requires.
The Evidence Gap: What Purview Cannot Provide
Cross-platform visibility
Copilot operates within Microsoft 365. Many Copilot users also use Google Workspace, Salesforce, OpenAI Assistants, and other platforms. The governance risk (the toxic-combination pattern that Article 26's monitoring obligation is designed to catch) is the cross-platform pattern: a user who has Copilot access to broad Microsoft 365 data and also has a Google Apps Script automation and a Salesforce Agentforce configuration creates a combined risk profile that Purview's Microsoft-only view does not capture.
Regulatory evidence of AI governance cannot be Microsoft-only if the AI agent estate is cross-platform. It needs to cover what the agent did across all platforms it operates on, not just within Microsoft's administrative boundary.
Cryptographically signed evidence
Purview produces audit logs, activity reports, and compliance records. These are operational logs (records of what the system recorded). They are not cryptographically signed in a way that allows a third party to verify that the records have not been altered since generation.
The evidence standard under Article 26 and FCA supervision is verifiable. A supervisor or auditor needs to be able to confirm that the evidence presented is identical to the evidence as generated, not modified retrospectively. Purview's logs can be exported and presented, but they cannot be cryptographically verified as unaltered. HMAC-SHA256 signed evidence packs can be.
Regulatory framework mapping
Purview is designed for Microsoft compliance frameworks: GDPR, ISO 27001, SOC 2, and similar. It does not map Copilot's governance posture to Article 26 deployer obligations, FCA SYSC 8 oversight requirements, or ICO AI Governance Framework controls. The regulatory readiness scorecard that compliance teams need ("how does our Copilot deployment map to Article 26?") is not a Purview output.
Building Article 26-Grade Evidence for Copilot Deployments
For regulated firms that need to evidence their Copilot governance for Article 26, FCA, and ICO purposes, the evidence package requires:
- Copilot classification. A documented risk assessment of the Copilot deployment against Article 26 Annex III high-risk criteria, FCA SYSC 8 materiality thresholds, and Consumer Duty customer impact. This is a governance decision, not a Purview report.
- Cross-platform inventory. Copilot included in the firm's AI agent inventory alongside agents on other platforms, with cross-platform pattern detection identifying combined risk profiles.
- Permission scope documentation. What data Copilot can access, for which user populations, under what permission model. This uses Purview's sensitivity labelling and access control data as inputs but produces a governance-layer output.
- Human oversight evidence. Records showing that named individuals with appropriate authority are actively reviewing Copilot's operation, not just that oversight has been assigned.
- Signed evidence packs. Monthly evidence packs covering Copilot alongside other AI agents in the estate, signed at generation, covering cross-platform patterns, and verifiable under examination.
How AETHER Pulse Fills the Evidence Gap for Copilot
AETHER Pulse connects to Microsoft 365 through the Microsoft Graph API (the same API surface that Purview uses) and enumerates Copilot as part of its cross-platform AI agent discovery. Copilot's presence in the Microsoft 365 tenant is detected, classified using the five-dimensional risk framework, and included in cross-platform toxic-combination detection alongside agents on Google Workspace, Salesforce, and other platforms.
Critically, Copilot is included in AETHER Pulse's monthly signed evidence generation, so the firm's governance evidence for Copilot is a HMAC-SHA256 signed artefact, verifiable under FCA or ICO examination, covering Copilot in the context of the firm's full AI agent estate rather than in isolation within Microsoft's administrative boundary.
For regulated firms that have deployed Copilot and need Article 26-grade evidence, AETHER Pulse provides the evidence layer that Microsoft's own tooling cannot. Purview governs what Copilot can access. AETHER Pulse evidences that Copilot is being governed.
Further reading: The Hidden Risk of Microsoft Copilot Rollouts in Regulated Financial Services and What Good AI Governance Actually Looks Like.
Frequently Asked Questions
Does AETHER Pulse replace Microsoft Purview for Copilot governance?
No. Purview provides essential data governance controls within Microsoft 365: sensitivity labelling, DLP policies, activity logging. AETHER Pulse provides the cross-platform discovery, regulatory evidence generation, and signed evidence packs that Purview does not produce. The two are complementary: Purview governs Copilot's data access. AETHER evidences that the governance is operating.
Does Article 26 specifically apply to Microsoft Copilot?
The Article 26 classification depends on how Copilot is being used. Copilot used for general productivity is unlikely to meet the Annex III high-risk threshold. Copilot used to assist in credit assessment, customer communication, claims handling, or other Annex III contexts may meet it. The deployer (the regulated firm) is responsible for making this classification and evidencing the reasoning.
What specific evidence does an FCA supervisor want for a Copilot deployment?
An FCA supervisor will want: the Copilot risk classification with documented reasoning, the permission scope assessment, monitoring records showing active oversight of Copilot's operation in regulated contexts, evidence of Consumer Duty outcome monitoring where Copilot affects customer interactions, and a signed evidence pack demonstrating that monitoring occurred at the documented cadence.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation