Microsoft Purview 現可監控第三方 AI 工具(如 Anthropic Claude),並套用既有 DLP 政策來管控提示、上傳與回應中的敏感資料。[2][19] Purview 的 Data Security Investigations 新增 OCR,可辨識截圖、掃描文件與圖片中的文字,補上資料外洩調查的重要盲點。[3][46] Data Security Posture Management(DSPM)為企業提供跨 Copilot、AI 應用與代理的可觀測性與風險分析,集中監控 AI 活動。[31][35]

Create a landscape editorial hero image for this Studio Global article: How do Microsoft’s May 21, 2026 security updates expand enterprise AI governance—specifically the extension of Microsoft Purview to monitor. Article summary: Microsoft’s May 21, 2026 updates broaden AI governance in four practical ways: they extend Purview’s controls to more third-party AI activity, improve investigations of non-text data, make DSPM a more operational control. Topic tags: general, general web. Reference image context from search candidates: Reference image 1: visual subject "# Agent 365 May 2026 Update: Microsoft expands Enterprise AI governance. Microsoft continues to advance its vision for enterprise AI management with a major update to Agent 365 in" source context "Agent 365 May 2026 Update :AI Governance และ Security" Reference image 2: visual subject "# Governing AI Shadow IT with the Microsoft
企業導入 AI 的速度正在加快,但同時也帶來新的治理與安全挑戰,例如敏感資料外洩、未受控的「影子 AI」(shadow AI)工具,以及能自主運作的 AI 代理(agents)。
在 2026 年 5 月 21 日的安全更新中,Microsoft 針對這些問題推出一系列新能力,將企業 AI 治理從單純監控 Microsoft 應用,擴展到 跨 AI 工具、資料流、代理行為與執行環境的全面治理架構。
核心變化包括:
這些更新顯示,AI 治理正在從「管理應用程式」升級為「管理 AI 生態系」。
本次更新的一大重點是 Microsoft Purview 的可視性擴展到第三方 AI 應用,其中包含 Anthropic 的 Claude。安全與合規團隊現在可以在企業環境中偵測與調查 Claude 的使用情況,就像監控其他雲端應用一樣。
過去企業的 AI 治理多集中在 Microsoft 自家的服務,例如 Microsoft 365 Copilot。但實際情況是,員工往往會同時使用多種 AI 工具。
Purview 的 Network Data Security 能監控 HTTP/HTTPS 資料流並分類內容,讓企業可以將既有的 資料外洩防護(DLP)政策 套用到 AI 互動上,例如:
這意味著原本難以管控的「影子 AI 使用」開始能被納入正式治理與合規框架。
另一個重要更新是 光學文字辨識(OCR) 的加入。
Microsoft Purview 的 Data Security Investigations 現在可以辨識圖片中的文字,例如:
傳統資料安全工具多半只分析純文字內容,但實際上很多敏感資訊會透過圖片分享,例如截圖公司內部儀表板或拍攝文件。
啟用 OCR 後,Purview 能從圖片中擷取文字並套用既有保護政策,例如:
這些掃描可套用在多個 Microsoft 服務與端點,包括 Exchange、SharePoint、OneDrive、Teams 與裝置端點。
對資安調查與資料外洩事件回溯而言,這補上了一個長期存在的盲點。
Microsoft 另一個核心能力是 Data Security Posture Management(DSPM)。
DSPM 的角色是提供企業一個集中平台,持續監控整個數位環境中的敏感資料風險,包括:
DSPM for AI 進一步把監控範圍延伸到:
平台可以集中觀察 AI 活動,例如 提示互動、代理行為與資料存取模式,協助企業發現未經批准的 AI 工具或潛在資料外洩風險。
此外,DSPM 與 Microsoft Security Copilot 整合後,安全分析師可以用自然語言查詢風險與調查資料,加速事件分析流程。
隨著「agentic AI」興起,企業需要的不只是監控 AI 使用情況,而是 控制 AI 代理在哪裡運行、如何運行。
為此 Microsoft 推出 Windows 365 for Agents。這是一個專為 AI 代理設計的受管理執行環境,讓企業可以在受控平台上運行代理工作負載,並套用企業級安全與政策控制。
這項服務也與 Microsoft 的 Agent 365 架構互補。Agent 365 被定位為 AI 代理的控制平面,讓 IT 與安全團隊能在整個基礎架構中監控、管理與治理代理。
簡單來說,Microsoft 正嘗試把 AI 代理納入與 身份、端點與雲端工作負載相同的治理體系。
綜合這次更新,Microsoft 的企業 AI 治理框架大致可分為四個層次:
這代表企業 AI 治理正從單純的應用監控,轉向 完整的 AI 使用生命週期管理:
Microsoft 的 2026 年更新顯示,未來企業安全策略將不只保護資料與系統,也必須 治理整個 AI 生態系中的互動與行為。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Microsoft Purview 現可監控第三方 AI 工具(如 Anthropic Claude),並套用既有 DLP 政策來管控提示、上傳與回應中的敏感資料。[2][19]
Microsoft Purview 現可監控第三方 AI 工具(如 Anthropic Claude),並套用既有 DLP 政策來管控提示、上傳與回應中的敏感資料。[2][19] Purview 的 Data Security Investigations 新增 OCR,可辨識截圖、掃描文件與圖片中的文字,補上資料外洩調查的重要盲點。[3][46]
Data Security Posture Management(DSPM)為企業提供跨 Copilot、AI 應用與代理的可觀測性與風險分析,集中監控 AI 活動。[31][35]