Data Security & AI Report — July 2026
Autonomous agents don’t wait for approval, so control has to live within their code.
TL;DR
Local, always-on agents (“claws”) now run on your enterprise endpoints as normal processes; most security teams can’t see them.
Builder speed and central control both have to work at runtime.
What shipped since the last report: Microsoft Agent 365 (GA), Purview insights in Foundry (GA), and the Microsoft Purview SDK (GA). Still preview: Foundry prompt-processing DLP, and local-agent discovery and blocking (Microsoft Defender + Microsoft Intune).
The agent already runs on your endpoint
Alongside the assistant that answers a prompt, there’s a persistent, always-on class of local agent (what today’s lingo calls “claws”) that executes on both desktop computers and cloud IT. They run with the device user’s own access and permissions, and because they run as normal processes, most security or IT teams can’t monitor their risk.
Builder speed matters. The employee who installed a local coding agent made themselves incredibly more nimble and productive. Routing every task through a central enterprise platform rather than their own device kills that edge. So today builder speed vs central control is the permanent condition to design for. Telling people to stop is misguided.
Local agents already run in your environment. The question is whether you can see and constrain them wherever they act. That’s the gap Microsoft Agent 365 targets: discovery and control of agents wherever they run (local, SaaS, cloud), starting by surfacing and blocking unmanaged agents on Windows endpoints on the OpenClaw platform.
Top 3 things to know
1. The Microsoft Purview SDK puts data controls inside the app (GA). A drop-in toolkit (.NET) for data loss prevention checks and sensitivity labelling in a few lines of code, aimed at AI apps and agents built outside of Microsoft’s own AI platforms. It evaluates prompts and responses in real time and feeds activity back to Microsoft Purview.
2. Purview insights are now in the Foundry Control Plane (GA). For apps and agents on Microsoft Foundry, Purview signals surface directly: SITs detected in interactions, share of interactions involving sensitive data, spread of high-risk users. The related Purview DLP runtime controls for prompt processing in Foundry are a separate capability, in public preview. So, in one breath: insights GA, runtime DLP enforcement preview. That precision keeps a security review honest.
3. Microsoft Agent 365 is an agent control plane. It’s not an agent builder. It brings agents under the controls you already run to secure other parts of your stack like devices, data and infrastructure & networks.
Why it helps cross-team conversations: it gives identity, data-security, endpoint, and app-dev teams a shared map. Each owns a piece of the enterprise stack; runtime is the shared surface where their controls have to line up.
Agent security capabilities: what’s GA vs what’s preview
Generally available
Microsoft Agent 365 control plane · GA since 1 May 2026
Purview insights in the Foundry Control Plane · Microsoft Purview + Microsoft Foundry
DLP checks, labelling and content scanning inside custom AI apps · Microsoft Purview SDK (.NET) · GA since 1 July 2026
Windows 365 (isolated cloud PC) for Agents · Windows 365 · GA since June 1 2026
Public preview
Local-agent discovery and blocking (shadow AI, starting with OpenClaw) · Microsoft Defender + Microsoft Intune · preview since June 2026
DLP runtime controls for prompt processing · Microsoft Purview in Microsoft Foundry
Cross-cloud registry sync (AWS Bedrock, Google Cloud) · Microsoft Agent 365
Neither product nor preview
Information-flow control (label and policy-check every tool call) · Microsoft Research · research, experimental
Runtime policy enforcement, sandboxing, audit logging · microsoft/agent-governance-toolkit · MIT toolkit, not a supported control
Curated resources and references
These are the people, teams, and references I keep coming back to.
Start with the foundation
Microsoft Security team: Securing the new risk surface: local agents, claws, and open runtimes and Purview enables developers across AI apps and agents. The clearest official articulation of this shift. Read them together and mind the GA-vs-preview labels, which differ within a single post.
Microsoft Research (Zanella-Béguelin, Tople, Russinovich, Kolluri, Köpf, Costa): Information-flow control: moving toward secure, autonomous agents. The quarter’s most important conceptual read and the backbone of the deterministic argument. Explicitly research/experimental: sharpen your thinking, don’t deploy it.
Free tools for operationalising data security
Sebastian Zamorano (profesorkaz) and Nabil Senoussaoui: ClaudIA, an open-source living Microsoft 365 demo environment: synthetic users, real telemetry, and ready-made Purview/Defender/Copilot governance stories. A gift if you show an oversharing or DSPM-for-AI story rather than describe it.
Robbert Berghuis (Copilot & AI at Work): the interactive Purview map. Visualises how Purview solutions relate, which workloads each covers, and, via a deployment overlay, what to switch on first.
microsoft/agent-governance-toolkit: MIT-licensed toolkit for runtime policy enforcement, sandboxing, and audit logging (incl. Foundry Agent Service middleware). A lab for prototyping deterministic enforcement, not a supported control.
Agent-security-specific resources
Nikki Chapple & Ryan John Murphy: the AI Governance & Data Security Show. New podcast and video series on securing AI and governing data in Microsoft 365. Two epic episodes from security leaders:
Inside Purview DSPM: What’s next? With Maithili Dandige (General Manager, AI-M365 Purview Data Security) and Talhah Mir (Partner PM, Product & Engineering, Purview): what is happening behind the scenes in Microsoft Purview Data Security Posture Management (DSPM) and where the platform is heading next.
Purview Data Security Investigations Deep Dive with Christophe Fiessinger: Christophe Fiessinger, Product Manager at Microsoft, explaining how DSI helps security teams identify, investigate, and remediate data security incidents at enterprise scale.
SecurityRisksForCustomers.pdf: a side-by-side test of how Microsoft 365 Copilot, ChatGPT Enterprise, Gemini Enterprise, and Claude Enterprise behave when retrieving the same SharePoint file through connectors, across permissions, sensitivity labels, encryption, and DLP. Grab it if you need the evidence base for a connector-governance conversation with a customer or security team; tested May 2026, so treat the results as a point-in-time snapshot.

