| Target environment | Microsoft-centric organizations on M365 E5 with Copilot for M365, Defender, and Entra as the primary security stack | Platform-agnostic — covers ChatGPT, Claude, Gemini, Copilot, and 50+ surfaces across Chrome / Edge / Firefox / Safari regardless of M365 tier |
| Coverage of direct-browser ChatGPT / Claude / Gemini use | Partial — strongest inside Edge with conditional access; Chrome / Firefox / Safari coverage depends on Defender browser-control deployment; native desktop apps thin | Full coverage on Chrome / Edge / Firefox / Safari via browser extension; native desktop apps via loopback detection; no dependency on Microsoft stack |
| Architecture | Defender + Entra + Purview pipeline; policy in Purview console; signals from Defender browser-control and SaaS-connector telemetry | Browser extension + SaaS connectors; client-side redaction; no dependency on M365 licensing |
| Pricing model | Bundled with M365 E5 — if already on E5, marginal cost is low; Purview add-ons ($8–20/user/mo) required for full AI Hub; E3 customers pay full add-on prices | Flat per-team mid-market pricing ($22–32k ACV at 1,000 emp); no M365 tier dependency |
| EU AI Act Article 26 evidence | Purview ships generic compliance templates; Article 26 indexing is customer-configured via Purview compliance portal — typical assembly 40–120 hours per quarter | Pre-indexed Article 26(1)/(2)/(4)/(5) / Article 50 / Annex IV pack; one-click export |
| ISO 42001 Annex A coverage | Purview audit logs support A.6.2.3 after customer mapping; A.4 / A.8.3 / A.9 / A.10 via customer-configured Purview policies | A.4 + A.6.2.3 + A.8.3 + A.9 + A.10 pre-indexed |
| NIST AI RMF coverage | Microsoft publishes a NIST AI RMF crosswalk whitepaper; customer-side mapping required to produce evidence per sub-category | Pre-built crosswalk to GOVERN / MAP / MEASURE / MANAGE with GenAI Profile metadata |
| Admin operator profile | Microsoft 365 Certified Compliance Admin — requires training investment; policy tuning in Purview console is powerful but deep | Compliance Officer / Head of GRC — plain-English policy editor, no Microsoft certification required |
| Time-to-first-policy on the GenAI surface | If M365 E5 + Defender + Purview baseline exists: 30–60 days. If new E5 adoption: 90–180 days | 5–10 business days |
| Coverage outside the Microsoft stack (Google Workspace, Notion, Linear) | Possible via Purview cross-platform connectors but typically secondary; the platform's center of gravity is M365 | First-class: Google Workspace, Notion, Linear, Slack, Zendesk, Salesforce, HubSpot treated equivalently to M365 |