The control plane for data protection in Microsoft 365 is substantially more capable in August 2026 than it was twelve months ago. Microsoft documents AI observability, audit signals, data discovery, and policy actions across its security and compliance surfaces, while Microsoft Entra Agent ID documents identity, lifecycle, and access controls for agents. These are real investments in data governance infrastructure. Their scope still depends on the workload, license, configuration, and integration path.
The governance question these investments surface is not technical. It is whether organizations have built the organizational layer that gives the technical layer its meaning: the authorization decisions, the accountability assignments, the review cadences, and the drift detection that together constitute genuine data governance rather than technical configuration without organizational design. Microsoft's controls are necessary and materially improve the baseline. They do not replace the need for an accountability layer above them.
Purview and Agent 365 can tell you what Copilot and your agents are accessing. The harder document - who decided what they should access, when, and under whose authority - is yours to write.