Jessica Entwistle
September 14 2026
A study by Syskit, reported by Infosecurity Magazine, has found that only 43% of organisations deploying AI agents in Microsoft 365 environments completed a permissions review beforehand. The research highlights a significant governance gap: AI tools such as Microsoft Copilot operate with the same permissions as the users who deploy them, meaning they can access, summarise and act on any data those users can see. Without a permissions review, organisations risk AI tools inadvertently exposing sensitive information, creating compliance issues or amplifying existing over-permissioned access across SharePoint, OneDrive and Teams. The study suggests that many organisations are treating AI deployment as a technical rollout rather than a governance and data protection challenge.
For UK organisations, this is a practical governance challenge. Many businesses have accumulated years of loosely managed permissions across Microsoft 365, with users retaining access to files, sites and channels long after they needed them. When AI tools are introduced into this environment, they inherit those permissions and can surface information that users may not have actively accessed in years but still technically have rights to view. This creates both a data protection risk and a potential compliance issue, particularly for organisations handling sensitive personal data, financial records or legally privileged material under UK GDPR, sector-specific regulations or contractual obligations. The operational lesson here is that AI deployment should not be treated as a purely technical rollout; it requires a clear understanding of what data the AI can access and whether that access is appropriate. For organisations in regulated sectors such as legal, healthcare or financial services, the risk is amplified: AI tools could inadvertently expose client data, patient records or confidential financial information to users who should not have access to it. This is not a hypothetical concern; it is a foreseeable consequence of deploying AI tools in environments where permissions have not been actively managed.
Organisations deploying or planning to deploy AI tools in Microsoft 365 should conduct a permissions audit before rollout, not after. This means reviewing who has access to what across SharePoint, OneDrive and Teams, removing unnecessary permissions and ensuring that AI tools are deployed in a way that reflects the principle of least privilege. Consider whether sensitive data is appropriately classified and whether access controls are configured to prevent AI tools from surfacing information to users who should not see it. For organisations that have already deployed AI tools, this is a prompt to conduct a retrospective review and address any over-permissioned access that may have been inherited. It is also an opportunity to clarify who is responsible for permissions governance across collaboration platforms and to ensure that accountability for this area is clearly assigned and understood. Finally, consider whether your AI deployment process includes a governance checkpoint that requires permissions to be reviewed and approved before AI tools are enabled for users or groups.
Source: Infosecurity Magazine