Skip to Content
Rule Changelog

Rule Changelog

23-Nov-2025 15:41 (UTC): AI Detection & Response Rules Now Generally Available

Runtime detections require ongoing refinement as threat landscapes evolve. After demonstrating consistent value and stability, the following AI Detection & Response (AIDR) rules are now generally available:

Rule TitleRule ID(s)AI Service(s)
Destructive query executed by AI agentZN_P00253Copilot Studio
Disallowed email address detected in AI agent trigger contentZN_P00239Copilot Studio
Disallowed email sender triggered AI agentZN_P00232Copilot Studio
Disallowed recipient domain detected in email sent by AI agentZN_P00236Copilot Studio
Exposed secrets detected in AI messageZN_V00501, ZN_F00501, ZN_P00501, ZN_M00501, ZN_G00501, ZN_C00501Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
Exposed secrets detected in user messageZN_V00500, ZN_F00500, ZN_P00500, ZN_M00500, ZN_G00500, ZN_C00500Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
Financial information detected in AI messageZN_V00505, ZN_F00505, ZN_P00505, ZN_M00505, ZN_G00505, ZN_C00505Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
Financial information detected in user messageZN_V00504, ZN_F00504, ZN_P00504, ZN_M00504, ZN_G00504, ZN_C00504Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
PII detected in AI messageZN_V00503, ZN_F00503, ZN_P00503, ZN_M00503, ZN_G00503, ZN_C00503Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
PII detected in user messageZN_V00502, ZN_F00502, ZN_P00502, ZN_M00502, ZN_G00502, ZN_C00502Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
Promptware detected in Loops file snippetZN_M00041M365 Copilot
Reconnaissance query executed by AI agentZN_P00254Copilot Studio
Sensitive database name detected in AI agent actionZN_P00252Copilot Studio
Server-side MCP secrets exposed by AI agentZN_P00277Copilot Studio
Suspicious database cluster name detected in AI agent actionZN_P00251Copilot Studio
Suspicious IP address used to access AI agentZN_M00020M365 Copilot
System instructions encoded in leetspeak detected in user messageZN_V00013, ZN_F00013, ZN_P00513, ZN_M00013, ZN_G00013, ZN_C00013Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
System instructions encoded with a Caesar cipher detected in user messageZN_V00012, ZN_F00012, ZN_P00512, ZN_M00012, ZN_G00012, ZN_C00012Vertex AI, Microsoft Foundry, Copilot Studio, M365 Copilot, ChatGPT Enterprise, Agentcore
Unintended RAG access due to AI content misinterpretationZN_M00045M365 Copilot

Deprecations and Updates

  • “User message includes code with exposed secrets” (ZN_F00044, ZN_P00044, ZN_M00044) is deprecated. Use the new “Exposed secrets detected in user message” rule instead.
  • “User message contains sensitive information (PCI/PHI/PII)” (ZN_M00006, ZN_F00242, ZN_V00242, ZN_P00242, ZN_G00242) is deprecated. Use the new “PII detected in user message” and “Financial information detected in user message” rules instead.
  • “AI message contains sensitive information (PCI/PHI/PII)” (ZN_M00010, ZN_F00010, ZN_V00010, ZN_P00241, ZN_G00010) is deprecated. Use the new “PII detected in AI message” and “Financial information detected in AI message” rules instead.
  • All GA rules are now categorized as threat detection and/or governance based on their detection focus.