Enterprise Adoption2 min read

Most Companies Skip Access Checks Before Turning On Copilot

By , Senior AI ConsultantPublished

A new survey finds nine in ten companies have already had a security incident tied to Microsoft 365 permission mistakes, yet most are turning on AI tools like Copilot before checking who can see what.

Microsoft 365 runs the back office of most companies on earth: email, shared drives, Teams chats, and now an AI assistant called Copilot that can read across all of it. The trouble is that the access rules behind that system were never built with an AI in mind.

Over years, employees share folders, invite outside contractors as guests, change job roles, and leave. Each of those actions leaves a small trail of access that rarely gets cleaned up. A person from finance who moved to marketing three years ago might still be able to open a folder full of salary data. Nobody notices, because nobody was looking at that folder.

An AI assistant looks at everything, all the time. Turn on Copilot, and it can search across every file, chat, and email a person can technically reach, then summarize it in seconds. It does not know that a shared link was supposed to be temporary or that a permission was a mistake. It just does its job well, which is exactly the problem.

A survey of more than 300 IT and security leaders, run by the Microsoft 365 governance company Syskit, found that nine in ten had already experienced, or suspected they experienced, a security incident tied to misconfigured permissions in the past two years, and nearly four in ten confirmed one directly. Fewer than one in four had a written policy defining what an AI agent is even allowed to touch. Yet most of these same leaders said they were confident they knew exactly who had access to what, a contradiction that says more about false comfort than actual control.

This pattern shows up everywhere researchers have looked. A separate 2025 study from Concentric AI found that on average, sixteen percent of business-critical files in a typical Microsoft 365 account are overshared, adding up to hundreds of thousands of exposed files at a single company. Gartner surveyed IT leaders in 2024 and found that four in ten delayed their Copilot rollout by three months or more specifically because of oversharing concerns.

The risk is not hypothetical. Security researchers disclosed a vulnerability called EchoLeak earlier this year that let an attacker send a single crafted email, no clicking required, and quietly pull sensitive company data out through Copilot. IBM's 2025 breach report found that among companies that had an AI-related security incident, nearly all of them, ninety-seven percent, did not have proper access controls in place beforehand.

The fix is not glamorous, but it is doable. It means going through who has access to what before flipping on more AI features, not after. That cleanup often pays for itself too: reviewing old permissions tends to uncover unused software licenses and forgotten storage that companies are still paying for.

The uncomfortable truth here is that AI does not create new security holes so much as it finds every old one you forgot to patch, instantly and at scale. Companies that treat this as a one-time IT chore before a Copilot rollout will be fine. Companies that treat AI access the way they treated file sharing for the last decade, informally and by accident, are the ones that will end up explaining a leak to their board.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable