← Back to blog
Microsoft 365

AI watermarks in Microsoft 365: making Copilot content identifiable via Cloud Policy

By Zarioh Digital Solutions6 min read
Share
AI watermarks in Microsoft 365: making Copilot content identifiable via Cloud Policy

Microsoft has rolled out an admin policy toggle that allows organisations to automatically watermark video and audio generated by Copilot. The setting lives in the Cloud Policy section of the Microsoft 365 Apps admin centre, is off by default, and works differently for images than for video and audio. What does it mean and what steps should you take now?

Organisations using Microsoft 365 Copilot produce AI-generated content every day: summaries, generated images, AI-narrated audio clips, and video that Clipchamp or other Copilot features have created or altered. A question increasingly raised by IT administrators and compliance teams is: how do recipients know this is AI-generated content? And how can you prove it during an audit?

Microsoft has rolled out an answer in the form of AI watermarks, a policy feature available via Cloud Policy in the Microsoft 365 Apps admin centre. Available in preview from early 2026 and now fully deployed, it gives administrators the ability to automatically label AI-generated video and audio with a recognisable marker. The details lie in the nuances: what works as an admin toggle, what does not, and which layer is always active regardless of your settings.

What are AI watermarks and why do they exist?

An AI watermark is a visible or audible label indicating that content has been generated or altered by artificial intelligence. The goal is transparency: anyone who receives the content knows it is not purely human-made. In addition to the visible or audible label, Microsoft also adds invisible metadata to every file, regardless of whether the visual watermark is on or off.

The motivation is multifold. The EU AI Act requires organisations deploying AI systems to inform users when they encounter AI-generated content. Cyber insurers and auditors are increasingly asking for demonstrable provenance of AI content. And deepfake fraud — where AI-generated audio or video is misused for scams or disinformation — is a growing risk that affects business organisations too.

What the watermark looks like: video, audio, and images

The implementation differs by content type, and that distinction is practically important for administrators. For video generated or modified by Copilot, the Copilot logo appears in the lower-right corner of the frame. The label is subtle but unmistakably visible to anyone who looks.

For AI-generated audio, a spoken sentence is added at the beginning or end of the clip, a brief statement that the audio was generated by artificial intelligence. This cannot be suppressed by the end user when the admin policy is enabled.

Images are the exception in the admin model. Watermarks on AI-generated images fall outside the admin Cloud Policy and sit in the privacy settings of the individual user. Administrators therefore cannot enforce this centrally via the admin centre. Users who use Copilot to generate images can toggle the watermark on or off themselves. This is a deliberate design choice by Microsoft, but it means images represent a governance gap that you need to address through training or policy communication.

Activating the Cloud Policy: step by step

The watermark policy for video and audio is not enabled by default. You must explicitly activate it through the Microsoft 365 Apps admin centre. Go to Customization, select Cloud Policy, and search for the policy relating to enforcing watermarks on AI-generated audio and video. Set it to Enabled and assign the policy to the user groups for which you want it applied.

The policy operates at the Microsoft 365 tenant level and applies to applications that support Copilot video generation or AI audio synthesis, including Clipchamp and the growing set of Copilot features that produce audio-driven content. New AI features Microsoft adds will automatically fall under the policy once Microsoft qualifies them for it.

For organisations that prefer a gradual approach, the Cloud Policy structure allows you to first assign the policy to a pilot group — such as the marketing or communications team that works most intensively with AI content — and then expand it after evaluation.

C2PA metadata: the invisible provenance layer

Regardless of whether the visible or audible watermark is enabled, Microsoft always adds C2PA metadata to files containing AI-generated content. C2PA stands for Coalition for Content Provenance and Authenticity, an industry standard for recording the origin of digital media, in which Adobe, Google, and other technology companies also participate.

The C2PA metadata describes who created the file, when, with which AI system, and what edits were made. This information is embedded in the file metadata and is not visible to the average user, but is readable by audit software, compliance tooling, and forensic investigation platforms. For IT teams that need to be able to trace content during an incident, this is the most robust layer.

In practice, this means that even if your organisation chooses not to enable visible watermarks, a technical trace layer is still present. That matters for audit and accountability questions, but is less relevant for the direct goal of transparency towards external recipients who do not read the metadata.

Purview and DLP: watermarks in a broader compliance context

AI watermarks do not stand alone within Microsoft 365. Microsoft Purview Data Loss Prevention now supports blocking Copilot processing on files labelled with a sensitivity label. This means: if you mark a Word document as Confidential or Internal use, Copilot can be prevented from processing that document, even if it is stored locally on the device.

The combination of watermarks and DLP creates an approach where AI-generated content is visibly labelled when it leaves the organisation, while sensitive input documents are shielded from AI processing. For compliance-sensitive sectors such as finance, healthcare, or government, this is a meaningful combination to configure.

Retention policies via Purview can also be applied to AI-generated content. If your organisation is required to retain certain AI audio files for a minimum period due to contractual or legal obligations, that can be automated via Purview labels.

What does this mean for users?

For end users, enabling the watermark policy changes very little in the day-to-day workflow. Copilot features work exactly the same; the only difference is that exported or shared video or audio carries a label. That may take some adjustment internally, but in external communications it is a deliberate signal of transparency.

It is worth informing users in advance about what watermarks are, why the organisation is enabling them, and what the implications are for content sent to customers or partners. A short internal message or an update in the IT newsletter is sufficient in most cases.

Also communicate explicitly about images: users who generate AI images are themselves responsible for enabling the watermark in their privacy settings. If your organisation wants images to be consistently labelled, translate that into a clear directive in your AI usage policy.

Three actions for IT administrators this week

First: check whether your organisation currently produces AI video or AI audio via Microsoft 365. Look at use of Clipchamp, Copilot features that generate audio-based output, and workflow automation that creates AI content. If the answer is yes, the watermark policy is directly relevant.

Second: enable the Cloud Policy for a pilot group. Choose a team that actively works with Copilot content, enable the policy, and evaluate after two weeks what questions arise internally. Most organisations encounter little resistance once users understand the purpose.

Third: add a paragraph about AI watermarks to your existing AI usage policy or Copilot guidelines. Describe what gets labelled, what does not, how C2PA metadata works, and what the organisation expects from employees who generate AI images. This closes the governance gap that images currently represent.

Want support with setting up AI governance, activating watermark features in your tenant, or building a broader Copilot governance framework? Contact Zarioh for a practical conversation about your specific situation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share