When One Tool Isn’t Enough: Governing AI Across Every Platform Your Firm Uses

Your firm isn’t running one AI tool. It’s running several. The firms adopting AI most safely govern the data underneath all of them, not each app one at a time.

Reading time: about 6 minutes • Topics: AI Data Governance, Microsoft Purview, Copilot, Harvey, CoCounsel, ChatGPT, Claude, Legal

At most firms, AI governance comes last, if it comes at all. The pilots ship, users are delighted, and only later does someone in the office of the general counsel ask the question that should have come first: what, exactly, can these tools see?

Note the plural. Because here’s the reality of AI in a modern law firm: it isn’t one assistant. It’s Microsoft 365 Copilot in one practice group, Harvey or CoCounsel in litigation, ChatGPT Enterprise or Claude for research and drafting, and a growing list of legal-specific tools arriving every quarter. Each one is a different door into the same sensitive data, and governing them one app at a time is a losing race.

For a law firm, the stakes aren’t academic. They’re privilege. They’re the ethical wall between two matters. They’re a client’s most sensitive files sitting in a SharePoint site that years of “just give everyone access” have quietly turned into an oversharing landmine. Point any generative-AI tool at that estate without controls, and it will do exactly what it’s designed to do: surface everything a user can technically reach, whether they should reach it or not.

Having guided a range of firms, from mid-market practices to elite AmLaw shops, through governed AI adoption, we’ve seen a clear pattern in what separates the safe rollouts from the risky ones. The safest adopters stopped chasing each AI app individually and started governing the data layer underneath all of them. Here’s what they understood.

 

The Pattern: A Multi-AI Reality Meets Legacy Access

The firms we work with aren’t deciding whether to adopt AI. They’re already running several tools at once, often without a common governance model beneath them. Leadership grasps the productivity upside immediately. What gives them pause is the risk profile of their own environment, and it looks remarkably similar from one firm to the next:

  • Multiple AI tools, one pool of sensitive data. Copilot, Harvey, CoCounsel, ChatGPT, Claude. Different apps, different vendors, all reaching into the same matters, client files, and firm financials.
  • Years of accumulated oversharing. SharePoint sites, Teams, and on-premises file shares where permissions have sprawled far beyond intent, which is exactly the surface every AI tool indexes or ingests.
  • Privileged and regulated data everywhere. Matter files, client PII, and confidential work product spread across cloud and on-prem, with inconsistent labeling.
  • Existing security investments they won’t rip out. Many firms already run a best-in-class classification platform such as Varonis, and have no intention of abandoning it to adopt AI.The temptation is to govern each AI tool inside its own console: Copilot’s controls here, another vendor’s settings there. That doesn’t scale, and it leaves gaps between the tools. The firms that get this right govern the data itself, so protection applies no matter which AI reaches for it.

 

The Insight: Govern the Data, Not Each App

The core realization is to stop treating AI governance as an app-by-app configuration problem and start treating it as a data problem. There are really two jobs: knowing what your data is, and controlling what any tool can do with it. Solve those at the data layer, and every AI tool, today’s and next year’s, inherits the same protection. The most effective architectures split those responsibilities across the platforms a firm is best positioned to run:

 

Layer Platform Responsibility
Classification &
Labeling
Varonis or equivalent Automated discovery and classification across on-prem and cloud stores.
It is the system of record for what data is sensitive.
Discovery Gaps Purview Content Explorer Classification for sources the primary tool can’t see, using the same
taxonomy with no blind spots.
Enforcement Microsoft Purview DLP and sensitivity-label controls that apply to the data itself,
including excluding sensitive content from AI indexing and processing.
Monitoring & Risk Purview (Audit, DSPM, IRM) Audit of AI-related access. Data Security Posture Management scoring,
and Insider Risk analytics for behavioral signals.

 

The rule that works: the classification platform decides what data is, Purview decides what any AI can do with it. Governing the data, rather than the individual app, is what makes the model hold as the firm’s AI stack keeps changing.

 

What About Tools Outside Microsoft?

This is the question we hear most from firms running Harvey, CoCounsel, ChatGPT Enterprise, or Claude alongside Copilot. The answer is the point of the whole approach: because the controls live on the data (classification, labeling, DLP, and access), they protect sensitive content regardless of which tool tries to consume it. Microsoft-native AI is governed most deeply, but a properly labeled, access-controlled data estate constrains what any AI tool can ingest or surface. You govern once, at the source, instead of chasing every new app’s settings.

 

The Approach: A Three-Phase Path to Governed AI

 

Phase 1. Assessment: See the Real Exposure
Before touching a single policy, map the firm’s true data-and-access reality: which repositories your AI tools can reach, where oversharing concentrates, where DLP coverage has gaps, and how classification and Purview taxonomies need to align. Run SAM and restricted-content discovery to find the sites AI reaches by default, and review audit, DSPM, and retention posture to baseline risk. The result is a clear-eyed picture of exposure, and a delineated responsibility model between tools.

 

Phase 2. Proof of Concept: Prove It Safely
Build the classification-and-enforcement model on a controlled pilot population. The classification platform drives automated labeling; those outcomes map to Purview sensitivity labels; Purview DLP enforces controls, crucially excluding the most sensitive labeled content from AI indexing entirely. Deploy every policy in simulation mode first, so you can baseline
behavior and tune thresholds before anything blocks an attorney. Governance that breaks productivity gets switched off, so validate against real workflows.

 

Phase 3. Optimization: Scale and Automate
With the model proven, scale enforcement across departments and data stores, automate governance actions, and tune policies to cut false positives and user friction. Integrate Purview insights with Microsoft Defender XDR for unified incident response and align to Compliance Manager and Communications Compliance for regulatory coverage. AI access expands only as controls are validated, with governance leading adoption rather than chasing it, and end-user enablement ensures attorneys understand both the power and the boundaries of the tools.

 

What Good Looks Like

Firms that adopt AI this way move forward on a governed foundation rather than a hopeful one. Governing at the data layer delivers what an app-by-app approach can’t: best-in-class classification from the tool a firm has already invested in, paired with native Microsoft enforcement and monitoring, protecting sensitive data no matter which AI tool reaches for it.

  • AI adoption without privilege exposure: sensitive content excluded from AI indexing by policy, not by hope.
  • One governance model across every AI tool: Copilot, Harvey, CoCounsel, ChatGPT, Claude and whatever comes next, all governed from the same data layer.
  • Governance that scales to agents: the same control plane that governs today’s assistants governs the AI agents coming next.

 

The Takeaway for Legal and Enterprise Leaders

If your firm is adopting AI on top of years of accumulated access, the question isn’t whether AI will find your sensitive data. It’s whether you’ll decide what it can do with that data before it does, across every tool at once. Governance is not the tax you pay for AI. It’s the foundation that lets you adopt AI, all of it, with confidence.

Wondering what your AI tools can currently see across your environment? Our AI Data Governance Readiness Assessment gives you a clear picture of your exposure across every platform, and a concrete path to a governed rollout. Talk to Canalini Consulting Group.

 

This article describes patterns and practices drawn from our AI data governance engagements; it does not reference any specific client. Canalini Consulting Group is a Microsoft Gold Partner specializing in AI data governance, Microsoft Purview, and secure adoption of Copilot and the broader legal-AI ecosystem.

Recent Posts

Social Media

Greg Gillette

Rincipal Architect, Enterprise Microsoft Solutions

Greg brings more than 25 years of enterprise Microsoft expertise to Canalini's most complex engagements, with deep mastery of Microsoft 365, identity, messaging, eDiscovery, and automation. He embodies what Canalini stands for: diligent, methodical, and relentlessly high-standard, and clients genuinely love working with him. Whether architecting a firm's identity and messaging foundation or automating the work that keeps it running, Greg is one of the architects Am Law firms trust with their hardest problems.

Natasha Romanova

Manager of Finance and Operations

Natasha owns Canalini's finance and operations function, from accounting, invoicing, and financial reporting to delivery logistics, vendor relationships, and engagement governance. A CPA candidate with an MBA in Accounting and a background in forensic accounting and financial systems, she brings the disciplined, methodical stewardship that keeps the firm running smoothly and its engagements aligned to strategy.

Michael Warren

Senior Business Development Manager

Michael leads business development at Canalini, building the relationships that bring Am Law 100 and 200 firms into the fold. Consultative by nature, he helps legal IT leaders navigate Microsoft governance, Copilot, and AI adoption, working closely with our technical team and Microsoft partners to match every firm with the right solution. He is known for turning first conversations into long-term partnerships.

Corey Tracey

Principal Engineer, End User Compute

Corey is the engineer behind Canalini's most demanding infrastructure migrations, with more than 25 years across Citrix, Azure Virtual Desktop, and the identity foundations that keep Am Law environments secure.

He specializes in the complex, high-stakes environments where reliability and security are non-negotiable. Just as often, though, it's his calm, friendly demeanor that clients remember: unflappable under pressure and genuinely easy to work with, Corey has earned a loyal following of firms who ask for him by name.

Denesh Harrilal

Principal Architect, Purview & Copilot Studio

Denesh is the technical force behind Canalini's most advanced work, architecting solutions across the full Microsoft stack: Purview and Data Governance, Copilot Studio and AI agents, Entra ID, CI/CD pipelines, M365 Security and Azure infrastructure. He sets the standard for delivery, leads the firm's most cutting-edge governance, infrastructure & security engagements, and mentors the engineering team that lets Canalini scale. When a deal needs real architectural depth, Denesh is the one Am Law clients ask for.

Michael Canalini

Founder & CEO

Michael founded Canalini in 2016 to close a gap he saw in the legal technology world: Am Law firms needed a partner who understood both the Microsoft platform and the exacting confidentiality standards of legal practice. A decade later, he has built Canalini into the Microsoft governance partner of choice for Am Law 100 and 200 firms navigating the shift to AI.

Relationships come first in everything Michael does. Clients describe him as a straight shooter who acts in good faith and stands firmly behind his brand, and that reputation has become the foundation the firm is built on. He leads client strategy and delivery across Canalini's Am Law and enterprise relationships, guiding legal leaders through Copilot, data governance, and the diligent work of protecting privileged data in a new era. For Michael, earning and keeping a firm's trust is the whole point, and it is why so many of Canalini's client relationships have lasted for years.