Shield Connectors

Microsoft 365 Copilot Connector

Microsoft 365 Copilot | Connector

Shield’s native connector for Microsoft 365 Copilot flows employee AI interactions directly into your existing compliance platform — no new tools, no new portals, no new process steps.

What Is the Shield Connector for Microsoft 365 Copilot?R

Microsoft 365 Copilot is being adopted at speed across the financial services industry, embedding AI assistance directly into the tools employees use every day — Outlook, Teams, Word, Excel, and more. For regulated firms, that adoption creates an immediate and largely unresolved compliance challenge: every prompt an employee submits to Copilot, and every response Copilot generates, is potentially a regulated communication that must be captured, retained, and made available for supervision and investigation.

Regulators have been unambiguous that the channel of communication does not change the nature of the obligation. If an employee uses Copilot to draft client communications, summarise trade-related discussions, analyse position data, or generate market commentary, those interactions are in scope. Firms that cannot demonstrate capture and oversight of AI-assisted communications face the same recordkeeping and supervision exposure they would for any other unarchived channel.

Shield’s native connector for Microsoft 365 Copilot captures every employee prompt and AI response, flowing them directly into Shield’s existing archive, search, case management, surveillance, and export workflows. Copilot interactions are processed end-to-end in under 24 hours, with rich metadata preserved for audit and investigation — fulfilling regulatory requirements for AI-assisted communications without adding new tools, portals, or process steps.

Copilot is not a productivity tool that sits outside the compliance perimeter. It is an AI layer embedded inside every regulated communication channel your firm already uses — and it requires the same capture, retention, and oversight discipline as those channels.

Why Microsoft 365 Copilot Compliance Is Complex

Microsoft 365 Copilot presents compliance challenges that are structurally different from those posed by conventional communication channels, and that existing archiving approaches were not designed to address.

AI-generated content is not self-evidently a communication. Conventional surveillance tools are built to detect risk in human-to-human communications. Copilot introduces a third party — the AI — into the communication chain. A prompt submitted by a trader, a summary generated by Copilot from a confidential document, or a draft email produced by Copilot at an employee’s instruction all carry compliance risk, but none of them fit neatly into the message-capture workflows designed for email or chat.

Context is essential and easily lost. A Copilot response only carries meaning in relation to the prompt that generated it, the underlying documents or data Copilot accessed, and the broader conversation or workflow in which it appeared. Capturing the response in isolation — without the prompt, the metadata, and the application context — produces a compliance record that is incomplete, unsearchable, and indefensible under examination.

The regulatory framework is still developing — but the obligation is not. Regulators including the SEC, FINRA, FCA, and ESMA have each signalled that AI-assisted communications are subject to existing recordkeeping and supervision rules, even in the absence of AI-specific guidance. Firms cannot wait for bespoke AI regulation to implement capture. The obligation exists now, under existing frameworks, and the absence of a compliant archiving solution is already an exposure.

Key Features of the Shield Microsoft 365 Copilot Connector

Complete Prompt and Response Capture. Shield captures every Microsoft 365 Copilot interaction — employee prompts, AI-generated responses, and any content Copilot surfaces, summarises, or drafts from underlying documents and data. Capture is comprehensive across the full suite of Copilot-enabled Microsoft 365 applications, including Outlook, Teams, Word, Excel, and PowerPoint. No interaction is dropped, truncated, or captured without its corresponding context.

Rich Metadata Preservation. Shield retains and enriches the full metadata layer associated with each Copilot interaction — including user identifiers, application context, session identifiers, timestamps, the underlying documents or data sources Copilot accessed, and the workflow in which the interaction occurred. This metadata is preserved in its original form, made fully searchable, and stored as part of the immutable compliance record, ensuring that audit and investigation workflows have the full context required to assess each interaction accurately.

End-to-End Processing in Under 24 Hours. Copilot interactions captured by Shield are processed, enriched, and made available within the compliance platform in under 24 hours from the point of capture — ensuring that supervision, surveillance, and investigation workflows operate on near-real-time data, and that the compliance record does not lag behind operational activity.

Immutable, Audit-Ready Archive. All Copilot interaction data captured by Shield is stored in a tamper-evident, WORM-compliant archive with a complete audit trail of every access and action taken on the record. Data is indexed for rapid search and retrieval, supporting regulatory examination responses, eDiscovery requests, and internal investigations. Retention periods are fully configurable to meet jurisdiction-specific requirements across applicable regulatory frameworks.

Native Integration with Existing Shield Workflows. Copilot interaction data flows directly into Shield’s existing archive, search, case management, surveillance, and export workflows — the same workflows compliance teams already use for email, chat, voice, and trade communications. There are no new tools to learn, no new portals to access, and no new process steps to manage. Copilot compliance is handled within the platform your team already operates.

AI Surveillance Models for Copilot Interactions. Shield applies AI surveillance models to Copilot prompt-and-response pairs, identifying interactions that carry compliance risk — including the use of Copilot to draft communications that reference MNPI, summarise restricted information, generate market commentary, or produce client-facing content that requires supervision. Models are fully customisable to reflect a firm’s specific risk appetite, restricted content categories, and internal policy requirements.

Data Governance and Chain of Custody. Shield’s Copilot connector preserves a complete, verifiable chain of custody from the point of capture through to archiving and retrieval. Every stage of data handling is logged, auditable, and reportable — giving compliance officers and legal teams the confidence that Copilot records are admissible, complete, and have not been altered or tampered with at any point in their lifecycle.

Regulatory Coverage

Microsoft 365 Copilot interactions are subject to existing recordkeeping, supervision, and surveillance obligations under financial services regulations globally. Regulators have confirmed that the use of AI tools does not create an exemption from those obligations. The Shield Copilot connector supports compliance with:

SEC Rules 17a-3 and 17a-4 — requiring broker-dealers to capture, preserve, and produce records of all communications related to their business, including AI-assisted communications, stored in WORM-compliant format with an audit trail, for a minimum of six years.

FINRA Rules 4511 and 3110 — requiring member firms to archive all communications relating to their business as such, with written supervisory procedures and supervision requirements in place — including for AI-assisted drafting, summarisation, and analysis tools used in connection with regulated activity.

MiFID II Article 16(7) and Market Abuse Regulation (MAR) — requiring investment firms to record and retain electronic communications related to orders and transactions for a minimum of five years, with trade reconstruction capability within three days, and to monitor communications for indicators of market abuse — obligations that extend to AI-generated content used in connection with trading and investment activity.

CFTC Regulation 1.35 and 17 CFR § 23.202 — requiring swap dealers, major swap participants, and futures commission merchants to retain records of all communications relating to commodity interests and swap transactions, including those generated or assisted by AI tools, as part of a complete audit trail.

FCA Rules (SYSC 10A and MAR) — requiring FCA-regulated firms to record and retain relevant electronic communications for a minimum of five years and to implement effective surveillance arrangements — obligations that the FCA has confirmed apply to AI-assisted communications used in connection with regulated activity.

GDPR and applicable data privacy regulations — Shield’s architecture supports data residency requirements and privacy-compliant data handling across jurisdictions, ensuring that the capture and retention of Copilot interaction data meets GDPR obligations alongside financial services recordkeeping requirements.

Other Related Connectors

Shield’s connector portfolio spans the full range of eComms channels, collaboration tools, and trading platforms used across regulated financial institutions. All connectors feed into a single unified compliance platform — so Copilot interaction data is always reviewed in the context of every other channel your workforce uses.

Frequently Asked Questions

Does Microsoft 365 provide native compliance archiving for Copilot interactions? Microsoft 365 includes some retention capability for Copilot interactions through Purview, but this is not purpose-built for the surveillance, supervision, and AI-powered misconduct detection required under financial services regulations. Firms regulated by the SEC, FINRA, CFTC, FCA, or MiFID II require a dedicated compliance solution — such as Shield — to meet the full scope of their recordkeeping, monitoring, and supervision obligations for Copilot interactions.

What data does Shield capture from Microsoft 365 Copilot? Shield captures every employee prompt submitted to Copilot and every AI-generated response, together with the full metadata layer — including user identifiers, application context, session identifiers, timestamps, and the underlying documents or data sources Copilot accessed. Data is ingested directly from Microsoft 365 to preserve chain of custody and ensure the integrity of the compliance record from the point of capture.

How quickly are Copilot interactions available in Shield for supervision and surveillance? Copilot interactions are processed end-to-end within Shield in under 24 hours from the point of capture, ensuring that supervision, surveillance, and investigation workflows operate on near-real-time data and that the compliance record does not lag behind operational activity.

Do Copilot interactions need to be supervised differently from other communication channels? Copilot interactions require the same capture, retention, and supervision discipline as any other regulated communication channel — but they also present unique surveillance considerations given the AI-generated nature of the content. Shield’s surveillance models are applied to prompt-and-response pairs rather than individual messages, preserving the context required to assess whether an interaction carries genuine compliance risk.

Which regulations does the Shield Copilot connector help firms comply with? The Shield Copilot connector supports compliance with SEC Rules 17a-3 and 17a-4, FINRA Rules 4511 and 3110, MiFID II, Market Abuse Regulation (MAR), CFTC Regulation 1.35 and 17 CFR § 23.202, FCA SYSC 10A, and applicable data privacy regulations including GDPR.

How quickly can the Shield Copilot connector be deployed? Shield’s native Copilot connector is designed for rapid deployment within existing Microsoft 365 environments. It can be configured and activated without extensive IT involvement, and Shield’s onboarding team supports firms through the full deployment and validation process to ensure Copilot interactions are captured completely and accurately from day one.