AI Security Protection Matrix

Generative AI

ChatGPT, Claude, Gemini
  • Shadow AI usage
  • Sensitive data leakage
  • Compliance gaps

Microsoft 365 Copilot

Word, Excel, Teams
  • Data exposure
  • Insider misuse
  • Auditability gaps

Custom AI agents

Copilot Studio, Bot Framework
  • Prompt injection
  • Unauthorized data access
  • Policy non‑adherence

Local LLMs

Llama, Mistral, self‑hosted GPT
  • Model tampering/poisoning
  • Infrastructure vulnerabilities
  • Data exfiltration

AI development tools

GitHub Copilot, VS Code
  • Insecure code suggestions
  • Secrets in code
  • Dependency risk

AI‑powered business apps

Power Platform, custom apps
  • Sensitive data exposure
  • Citizen dev sprawl
  • Policy violations

Multi‑cloud AI

AWS Bedrock, GCP Vertex AI
  • Inconsistent controls
  • Over‑permissioned APIs
  • Fragmented monitoring

Edge & IoT AI

Smart cameras, robotics, vehicles
  • Adversarial inputs
  • Device compromise
  • Safety failures

AI in security operations

Security Copilot, anomaly detection
  • False positives/negatives
  • Model drift
  • Adversarial evasion

Data & analytics (RAG)

Enterprise knowledge bots
  • Sensitive data retrieval
  • Hallucinated citations
  • Source poisoning

Creative & media AI

Image/video gen, synthetic voice
  • IP misuse
  • Deepfake risks
  • Authenticity gaps

Industry‑specific AI

Healthcare, finance, manufacturing
  • Regulatory compliance
  • Safety‑critical accuracy
  • Domain data leakage

AI supply chain & lifecycle

Model marketplaces, embeddings, OSS weights
  • Poisoned datasets
  • Malicious model updates
  • Dependency tampering

AI governance & compliance

Responsible AI, audit trails, policies
  • Explainability gaps
  • Accountability issues
  • Regulatory misalignment
View: Microsoft
Domain â–¼ / Product â–¶ Defender for Cloud Apps Purview IP/DLP Purview Endpoint DLP Purview DSPM for AI Entra Conditional Access Sentinel Security Copilot Insider Risk Mgmt Defender for Cloud Defender for Endpoint Defender for DevOps Defender for Containers Azure AI Content Safety Power Platform Admin Compliance Manager
Generative AI●●●●●●◐●○○○○●○●
M365 Copilot◐●●●●●●●○○○○◐○●
Custom agents●◐◐◐●●◐○◐○○○●○●
Local LLMs○◐●●◐●○○●●◐●◐○◐
AI dev tools○○◐◐◐●○○◐◐●●○○◐
Business apps●●●●●●○◐○○◐○○●●
Multi‑cloud AI◐○◐●●●◐○●○○◐○○○
Edge & IoT AI○◐●◐◐●○○◐●○○○○○
SecOps AI○○◐◐◐●●○○○○○◐○○
Data & RAG●●●●◐●○○○○○○●○●
Creative & media●●●◐◐●○◐○○○○◐○○
Industry AI◐●●●●●◐◐●○○○○◐●
Supply chain & lifecycle○◐◐●○●○○●◐●●○○◐
Governance & compliance◐●●●●●◐●◐○○○◐●●
Legend:
â— Prevention
â— Detection
â—‹ Discovery / Not applicable