Cyber Security · AI & Compliance

AI, Copilot & Cyber Essentials: what the 2026 rules mean for your AI tools

The April 2026 Cyber Essentials update (v3.3) quietly changed the game for AI. Tools like Microsoft 365 Copilot and ChatGPT are now in-scope cloud services — and where they support multi-factor authentication, it’s mandatory. Ungoverned AI can put your certification at risk. We get your AI tools in scope, secured and certified.

Free & no-obligation · we reply within one working hour

Cyber Essentials v3.3AI tools in scopeMFA mandatoryShadow-AI discovery

Quick answer

Under Cyber Essentials v3.3 (live 27 April 2026), any cloud service accessed with business credentials that stores or processes your data is in scope — and that now clearly includes AI tools such as Microsoft 365 Copilot and ChatGPT for business. Multi-factor authentication is mandatory wherever a service supports it, so ungoverned or unknown AI use can quietly put your Cyber Essentials certification at risk.

What changed

April 2026 quietly put AI in scope

Cyber Essentials is updated every year, but the v3.3 update that took effect on 27 April 2026 is the biggest in years — and it closes the loopholes that let organisations quietly leave cloud tools out of their certification. Three changes matter most for AI:

ChangeWhat it means
Cloud services can’t be excludedAny cloud or SaaS service accessed with business credentials that stores or processes your data is formally in scope. “We don’t really count that one” is no longer allowed.
MFA is mandatoryIf a cloud service supports multi-factor authentication and you haven’t enabled it, that’s an automatic fail — no second chance in that assessment.
Stricter scoping & patchingA new ‘Danzell’ question set demands a proper cloud-service inventory, and high-risk or critical updates must be applied within 14 days.

In short: the scheme now expects you to know exactly which cloud tools touch your data, and to have secured every one of them.

The connection

Why this puts AI in the spotlight

Here’s the link most people have missed: AI tools are cloud services. If your team uses Microsoft 365 Copilot, ChatGPT, Gemini, or the AI features built into your CRM — signed in with business accounts, working with company data — then under v3.3 those tools are in scope for Cyber Essentials. They need MFA, they need to appear in your inventory, and they can’t simply be left off the form.

The trouble is that AI adoption has outrun AI governance. In many organisations, staff have started using AI tools on their own initiative — “shadow AI” that leadership can’t see. Under the old rules that was a data risk. Under v3.3 it’s also a compliance risk: you can’t certify tools you don’t know you’re using.

What we do

Get your AI tools in scope, secured and certified

StepWhat it does
Discover your AI & cloud toolsWe find what’s actually in use — including shadow AI — and build the cloud-service inventory v3.3 now expects.
Enforce MFA everywhereMicrosoft Entra Conditional Access so every cloud and AI tool is protected, and nothing fails you on the MFA question.
Stop AI oversharingSensitivity labelling and data loss prevention (Microsoft Purview) so Copilot and other AI can’t surface or leak data it shouldn’t.
Set an AI usage policyClear rules on what staff can and can’t put into AI tools, so your people and your compliance stay aligned.
Get you certifiedWe prepare you for Cyber Essentials or Cyber Essentials Plus with your AI tools properly in scope — and we don’t book the audit until you’d pass.

We’re Cyber Essentials Plus certified ourselves, and AI security is one of our core services — so this is exactly the overlap we live in.

This sits where two of our services meet: Cyber Essentials certification and AI security. It also draws on our data security and Microsoft 365 security baselines work. If you’re rolling out Microsoft 365 Copilot, getting the scope and controls right first is the difference between a smooth certification and a failed one.

FAQs

Common questions

Are AI tools like Copilot and ChatGPT in scope for Cyber Essentials?
Yes. Under v3.3, any cloud service accessed with business credentials that stores or processes your data is in scope — and AI tools such as Microsoft 365 Copilot and ChatGPT for business are cloud services. If your staff use them with company accounts and data, they count.
Does Copilot need MFA for Cyber Essentials?
If the service supports multi-factor authentication — and Microsoft 365, which Copilot runs on, does — then yes, MFA must be enabled. Since April 2026, missing MFA on an in-scope cloud service is an automatic fail.
Can we exclude AI tools from our Cyber Essentials scope?
No. v3.3 formally defines cloud services and removes the ability to exclude cloud or SaaS tools that store or process your organisation’s data. If AI tools touch your data, they must be in scope.
What does shadow AI mean for our certification?
Shadow AI — staff using AI tools leadership doesn’t know about — is now a compliance blind spot as well as a data risk. You can’t certify tools you don’t know you’re using, so discovering and governing AI use is now part of getting Cyber Essentials right.
When did the Cyber Essentials v3.3 changes take effect?
The v3.3 requirements and the new Danzell question set took effect on 27 April 2026. Assessment accounts created from that date are assessed against the new rules.

Adopting AI? Get it in scope before it costs you your certification

We’ll map which AI and cloud tools you’re really using, secure them, and get you Cyber Essentials ready — with AI properly accounted for. Book a free assessment and we’ll show you where you stand.

Free and no-obligation — we typically respond within one working hour.