Skip to main content
← All posts·
AI Governance

Auditing Power Platform AI Actions: Governance and Compliance for Low-Code AI in the Enterprise

Power Platform's AI Builder and Copilot Studio democratize AI but create governance blind spots. Here's how to audit, govern, and secure AI actions in Power Automate, Power Apps, and Copilot Studio.

Luca Berton13 min read

Microsoft Power Platform has become the most widespread entry point for AI in enterprises. AI Builder brings pre-built and custom AI models into Power Automate flows and Power Apps. Copilot Studio enables business users to build conversational AI agents. Power Automate's AI actions process documents, extract entities, classify content, and generate text — all without writing code.

This democratization is powerful. It's also a governance nightmare. When business users can embed AI into workflows without IT involvement, you get shadow AI at industrial scale — unaudited, ungoverned, and potentially non-compliant with the AI Act, DORA, and GDPR.

The Power Platform AI Landscape

Where AI Lives in Power Platform

  • AI Builder: Pre-built models (document processing, sentiment analysis, entity extraction, object detection) and custom models trained on business data. Embedded in Power Automate flows and Power Apps
  • Copilot Studio: Low-code platform for building conversational AI agents using GPT models with enterprise data. Deployed to Teams, websites, and custom channels
  • Power Automate AI Actions: AI-powered actions within flows — "Create text with GPT," "Extract information from documents," "Analyze sentiment." Available to any flow creator
  • Copilot in Power Apps/Automate: AI-assisted app and flow creation, plus AI-generated formulas and expressions
  • Dataverse AI features: AI-generated columns, AI insights, and intelligent matching in the data platform

Why Power Platform AI Needs Auditing

The Governance Gap

  • Invisible AI: AI Builder models embedded in flows don't appear in any centralized AI inventory. Your governance team doesn't know they exist
  • Data exposure: AI actions send data to Azure OpenAI and Cognitive Services. Business users may not understand that customer data, contracts, or financial documents are being sent to AI services
  • Decision impact: AI-driven automation can approve expenses, route customer complaints, classify risk levels, or flag compliance issues — decisions with material business impact
  • No validation: Custom AI Builder models trained by business users undergo no independent validation, bias testing, or performance monitoring
  • Regulatory blind spot: An AI Builder model classifying insurance claims is a high-risk AI system under the AI Act. If nobody knows it exists, nobody is ensuring compliance
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare

The Audit Framework

Step 1: Discovery and Inventory

First, find all AI usage in Power Platform:

Automated Discovery

  • Power Platform Admin Center: Review all environments, flows, apps, and Copilot Studio agents
  • Microsoft Purview: Data governance integration shows data flows including AI processing
  • Audit logs: Microsoft 365 unified audit log captures AI Builder model creation, training, and usage events
  • Power Platform CoE Toolkit: Microsoft's Center of Excellence toolkit provides inventory dashboards and governance automations. Deploy it if you haven't
  • DLP policy reports: Data Loss Prevention policies show which connectors (including AI connectors) are used across environments

Inventory Classification

For each discovered AI component, document:

  • Owner: Who created it? Which department?
  • Purpose: What business process does it support?
  • Data processed: What data types flow through the AI action? Personal data? Sensitive business data?
  • Decision impact: Does the AI output influence decisions about individuals, finances, or compliance?
  • AI Act classification: Based on purpose and impact, what risk tier applies?
  • Usage volume: How often does this run? How many records are processed?

Step 2: Data Flow Analysis

Map where data goes when AI actions are invoked:

  • AI Builder pre-built models: Data processed in Azure Cognitive Services within your Microsoft 365 tenant region. Confirm data residency meets your policies
  • AI Builder custom models: Training data stored in Dataverse. Model training uses Azure ML. Verify training data governance
  • GPT-powered actions: Data sent to Azure OpenAI Service. Microsoft's data processing agreement applies, but confirm: is the data used for model training? (Microsoft says no for enterprise customers, but verify your specific agreement)
  • Copilot Studio: Enterprise data accessed through connectors and knowledge sources. Responses generated by GPT with enterprise grounding. Audit which knowledge sources are connected and what data can be surfaced

Step 3: Security and Access Review

  • Environment segmentation: Are AI-enabled flows running in production environments or sandboxes? Is there environment isolation between dev/test/prod?
  • Maker permissions: Who can create AI Builder models and AI-powered flows? Is this unrestricted or role-controlled?
  • DLP policies: Are AI connectors (AI Builder, HTTP with AI endpoints) classified in DLP policies? They should be in the "Business" group, not "Non-Business"
  • Sharing and permissions: Who has access to flows and apps containing AI? Are they shared too broadly?
  • API connections: Do any flows use custom connectors to external AI services (OpenAI direct, Anthropic, etc.) bypassing Microsoft's enterprise controls?

Step 4: Compliance Assessment

For each inventoried AI component, assess against applicable regulations:

AI Act Compliance

  • Risk classification: Is this a high-risk use case under Annex III? Document classification rationale
  • Transparency: If the AI interacts with users (Copilot Studio agents), are users informed they're interacting with AI?
  • Human oversight: For decision-influencing AI, is there a human review step before the AI output takes effect?
  • Documentation: Is there any documentation beyond the flow definition? (Usually no — this is a key finding)

GDPR Compliance

  • Lawful basis: What is the lawful basis for AI processing of personal data?
  • Privacy notice: Does the privacy notice cover AI processing? Most enterprise privacy notices predate AI Builder
  • DPIA: Has a DPIA been conducted for high-risk AI processing?
  • Data subject rights: Can you respond to access and erasure requests for data processed by AI Builder?

Step 5: Governance Implementation

Immediate Actions

  • Deploy DLP policies restricting AI connectors to approved environments
  • Enable audit logging for all Power Platform AI activities
  • Implement environment strategy — default environment restricted; dedicated environments for AI workloads with appropriate controls
  • Create AI usage policy specific to Power Platform — what's allowed, what requires approval, what's prohibited

Structural Controls

  • AI review gate: Require governance review for any AI Builder custom model before production use
  • Maker training: Mandatory training for anyone creating AI-powered flows — covering data handling, bias awareness, and governance requirements
  • Monitoring dashboard: Centralized visibility into all AI Builder models, AI actions in flows, and Copilot Studio agents across the organization
  • Periodic audit cycle: Quarterly review of AI usage in Power Platform, assessing new components against governance policies

Common Audit Findings

  1. Customer data sent to AI services without DPIA: Found in 70%+ of audits. AI Builder document processing on customer contracts, invoices, or correspondence
  2. No AI disclosure to end users: Copilot Studio agents interacting with customers without AI transparency notice
  3. Overprivileged AI flows: Flows using service accounts with excessive permissions, allowing AI actions to access data beyond the intended scope
  4. Custom models without validation: AI Builder custom models trained by business users with no testing for accuracy, bias, or performance
  5. Missing from AI inventory: 100% of first-time audits discover AI usage not captured in any governance inventory
🎓 Course

Terraform for Beginners

Master Terraform to build scalable infrastructure using IaC principles.

Start on Udemy
power platform
power automate
ai builder
copilot studio
low-code
audit
governance
microsoft 365
citizen development

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →