Platform / AI Governance & Shadow AI Control

AI Governance & Shadow AI Control

Decide what AI can see.

XQ keeps sensitive data away from unauthorized AI tools and governs what approved models and agents can ingest. Because policy is enforced on the data itself, the same rules apply to Copilot, internal LLMs and AI agents — and AI-generated outputs are protected automatically.

Built for CISOs approving Copilot and enterprise AI · Teams building RAG pipelines on sensitive data · Organizations worried about data pasted into public AI tools

At a glance

BlocksUnauthorized AI tools (shadow AI)

GovernsWhat LLMs and agents can ingest

ProtectsAI-generated outputs

ModelsLLM-agnostic

Works with Microsoft Copilot · Microsoft Purview · RAG pipelines · Internal LLMs · AI agents

Shadow AI sees ciphertext

Unapproved tools can’t obtain keys, so protected data stays unreadable to them.

AI respects entitlements

Models and agents retrieve only what each user is authorized to see.

Outputs stay governed

Content generated from sensitive data inherits protection automatically.

The shadow AI problem

Employees paste contracts into public chatbots, connect AI assistants to shared drives, and build agents that read across systems. Network controls and app allow-lists can’t keep up, and once data reaches a model it’s out of your control. XQ governs the data, so it doesn’t matter which tool asks for it.

How XQ governs AI

  • Classify first. AI-powered classification labels sensitive data so policy knows what to protect.
  • Decrypt only for approved use. Data-level policy releases keys only to authorized users, applications and models.
  • Agentic DLP. Policies follow AI workflows and agents, blocking sensitive data from being sent where it shouldn’t go.
  • Protect the output. AI-generated content derived from protected data is protected in turn.

See how XQ would govern AI on your data.

Works with the AI you approve

Data-level policies plug into Copilot and RAG pipelines, so AI retrieves only the documents and chunks each user is authorized to see — before any context reaches the model. XQ is LLM-agnostic, so the same controls apply as your AI stack changes.

From capability to program

For the full enterprise AI governance story, including shadow AI, Copilot rollouts and AI regulation, see Enterprise AI Governance and Zero Trust AI.

Related resources and articles

AI governance and shadow AI, answered directly.

How does XQ stop data from reaching unauthorized AI tools?

Protected data stays encrypted, and only authorized users and applications can obtain the keys to read it. An unapproved AI tool that receives protected data gets ciphertext.

Does XQ work with Microsoft Copilot?

Yes. XQ’s data-level policy means Copilot and other assistants retrieve only what the individual user is entitled to see, and XQ syncs with Microsoft Purview labels.

How does XQ govern RAG pipelines?

Data-level policy is applied at retrieval, so a RAG pipeline returns only the documents and chunks the requesting user is authorized to see — before any context reaches the model.

Are AI-generated outputs protected?

Yes. Content an AI model generates from protected data is protected in turn, so summaries and answers inherit the governance of their source data.

Is XQ tied to a particular AI model?

No. XQ is LLM-agnostic: controls apply to the data, so they work with public models, internal LLMs and AI agents alike.

What is agentic DLP?

Data loss prevention that follows AI agents and automated workflows, enforcing the same data policy on what an agent can read, combine and send.

Let AI in. Keep control of your data.

See how XQ governs what models and agents can see.