A security engineer configures the Microsoft Purview AI Hub and notices that some AI interactions are categorized as 'Sensitive information detected' but no policy action was taken. What is the most likely reason?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because the Microsoft Purview AI Hub provides visibility and detection of sensitive content in AI interactions, but enforcement actions require a Microsoft Purview DLP policy to be configured with appropriate rules and enforcement actions. The AI Hub itself is an observability and detection surface, not an enforcement engine.
Full explanation below image
Full Explanation
A is correct because the Microsoft Purview AI Hub provides visibility and detection of sensitive content in AI interactions, but enforcement actions require a Microsoft Purview DLP policy to be configured with appropriate rules and enforcement actions. The AI Hub itself is an observability and detection surface, not an enforcement engine. B is incorrect because encryption on sensitivity labels is a separate control for document protection and does not affect AI Hub enforcement. C is incorrect because AI Hub enforcement is controlled by DLP policies, not an Entra ID P2 license requirement. D is incorrect because DLP exemptions would prevent the detection entirely, not just the enforcement action.