Chat GPT on Computer Screen

The rapid rise of artificial intelligence (AI) and embedded Copilot tools is reshaping how organisations work, accelerating productivity, automating complex tasks, and redefining workflows. But this transition is happening amid intensifying global discussions about AI governance and evolving regulatory scrutiny, from the EU AI Act to tighter privacy regimes worldwide. As businesses race to adopt AI, compliance and policy teams are sounding the alarm about a widening visibility gap that traditional controls were never designed to address.

The Compliance and Governance Challenges of AI and Copilot Adoption

One of the most significant risks AI tools introduce is a loss of visibility into data use and decision pathways. Copilots embedded in everyday platforms, such as Microsoft 365, can access and synthesise data across documents, emails, and chats to generate insights or draft content. While powerful, this capability can also unintentionally expose sensitive information or embed confidential content into outputs, raising compliance flags around data handling, retention, and auditability.

This challenge is compounded by what many in the risk community now call “Shadow AI”, the use of AI tools without explicit approval or oversight by security and compliance teams. Like the earlier era of Shadow IT, unsanctioned AI use creates blind spots where neither policy controls nor monitoring tools can see what employees are feeding into these systems or what outputs are being generated. This increases the chance of compliance violations and regulatory breaches long before the issue reaches the risk team’s radar.

Organisations that rely solely on static policies or periodic training sessions are especially vulnerable. These traditional approaches often fail to capture real behaviour in context – the very thing AI tools hinge on.

Using Behavioural Insights to Manage AI and Copilot Risk

That’s where behavioural insight matters. Tools like Redflags provide real-time visibility into how people interact with systems, allowing risk leaders to detect patterns and knowledge gaps that generic training data glosses over. By measuring genuine behaviour change over time, compliance teams can spot emerging AI-related risk trends and tailor policy responses before they escalate into blind-spot compliance issues.

For example, Redflags’ behavioural metrics can reveal whether new AI nudges, such as prompts to avoid sharing personal data with third-party Copilots, are actually reducing risky actions across the workforce. Instead of assuming compliance based on completion rates or checkbox training scores, compliance leaders can ground decisions in evidence of real organisational behaviour.

Ultimately, AI and Copilot tools are here to stay. The question for compliance teams is not if they will be used, but whether organisations have the visibility and data-informed controls to govern them responsibly. By leveraging behavioural insights alongside governance frameworks, companies can align innovation with compliance, without sacrificing one for the other.

Frequently asked questions

What compliance risks do AI and Copilot tools create?

AI and Copilot tools can create significant compliance risks when employees use them without understanding the boundaries. Common issues include pasting sensitive or personally identifiable data into AI prompts, inadvertently sharing confidential business information, and using unsanctioned tools that fall outside your organisation’s approved software policies. 

From a compliance perspective, this can put you at odds with data protection regulations such as GDPR, as well as internal data handling policies. The challenge is that these tools are intuitive and fast, so employees often use them without thinking through the implications. 

Effective security awareness training, supported by behavioural interventions, timely guidance and in-the-moment nudges, plays a key role in closing this gap. It helps employees understand what they can and cannot share, while building safer habits that keep your organisation on the right side of its compliance obligations.

Can Copilot use lead to data leakage?

Yes. Microsoft Copilot and similar AI tools can expose sensitive data when employees paste confidential information into prompts, share internal documents through unsanctioned integrations, or use personal Copilot accounts that fall outside your organisation’s security controls. 

A significant but often overlooked risk is over-permissioned access. Copilot surfaces information based on what a user can access, not what they should be accessing. If your organisation has not applied least privilege principles (ensuring employees only have access to the data they genuinely need), Copilot can inadvertently expose sensitive files, emails, or documents to people who have no business reason to see them. 

Because Copilot is embedded directly into familiar tools like Word, Outlook, and Teams, employees may not realise they are potentially sharing data beyond its intended boundaries. This makes it a particularly high-risk area for data leakage. 

Security awareness training helps employees recognise where the boundaries are and build safer habits when using AI tools in their day-to-day work. 

How should compliance leaders measure AI behaviour?

Measuring AI behaviour starts with establishing a baseline. Compliance leaders need visibility into which AI tools employees are actually using, not just the ones that are officially sanctioned. Shadow AI use is widespread and often goes untracked.
From there, useful measures include:

  • Policy awareness and training completion — are employees aware of your AI acceptable use policy, and can they demonstrate that understanding?
  • Behaviour change over time — are risky behaviours, such as pasting sensitive data into AI prompts, reducing following awareness interventions?
  • Access and permissions audits — are least privilege principles being applied consistently, reducing the risk of Copilot and similar tools surfacing data to the wrong people?
  • Incident and near-miss reporting — are employees reporting potential AI-related data handling issues, which is itself a sign of a healthy security culture?

Metrics alone do not tell the full story. The most meaningful signal is whether employee behaviour is actually changing, not just whether boxes are being ticked. That requires ongoing awareness activity, not a one-off training exercise.

How can Redflags support AI compliance?

Redflags is designed to change employee behaviour, which is exactly what AI compliance requires. Policies and acceptable use guidelines set the rules, but behavioural interventions is what turns those rules into habits. 

Redflags delivers targeted nudges that prompt employees to think carefully at the moments that matter, such as before pasting data into an AI tool or sharing documents through an unsanctioned integration. These nudges can be tailored to reflect your organisation’s specific AI policies, tools, and risk profile. 

The reporting portal gives compliance leaders visibility into engagement and behaviour change over time, supporting the kind of ongoing measurement that AI risk management demands. This moves compliance beyond one-off training tick-boxes and into a continuous cycle of awareness and improvement. 

For organisations with more complex needs, Redflags Enterprise offers the additional support of experienced security awareness practitioners who can help design and deliver a programme specifically addressing AI-related risks, including least privilege behaviours and Copilot use. Multi-language support also makes it possible to run consistent AI compliance awareness across multinational environments. 

Whether your priority is meeting baseline compliance requirements or taking a more proactive, risk-based approach, there is a Redflags package to support it.