Three-quarters of organizations in the United States and United Kingdom have rolled out or tested enterprise AI tools like Copilot on Microsoft 365 data, yet fewer than half completed a full permissions review beforehand, according to a new study from Syskit, a security governance firm. The company's State of Microsoft 365 Governance Report, released September 10, reveals that artificial intelligence is being implemented more quickly than the underlying data infrastructure is being audited. The disconnect between adoption speed and security preparation emerges as a central theme across the findings.
Only 43% of survey participants said they had finished a comprehensive examination of permissions and oversharing risks before turning on AI tools, according to the report. The remainder acknowledged conducting just a partial check or skipping the review entirely. Controls governing AI agents fall far behind the confidence organizations express in them: while 91% of respondents claimed they can identify which agents are running and what content those agents can access, merely 22% have established a formal policy that defines what AI agents are allowed to reach. One in 10 organizations allow an agent to assume the complete permissions of the person who deployed it. Broader permission problems across Microsoft 365 remain widespread, with 41% of companies leaving SharePoint sites open to all employees without limits, 35% admitting that files from former workers stay accessible to current staff, and 33% reporting files shared with "Everyone." Nearly half—47%—point to orphaned teams, groups, and sites with no responsible owner as a primary governance concern.
The report highlights how AI agents have eliminated barriers that previously made accidental exposure of sensitive files less probable. Copilot and similar platforms can now retrieve content based on existing permissions, including documents and sites shared broadly years earlier that have never been reviewed since, according to Syskit CEO Toni Frankola. "What stands out in this data is that so few organizations can check what their AI can actually reach before switching it on," he noted. While 83% of respondents say they know precisely who can view sensitive data at any moment, only 4% could generate a complete access report for an external auditor within one hour—the majority would require a day or more.
Organizations appear vulnerable because the permission model itself creates exposure, the report explains. Without active ownership, orphaned content is less likely to be examined, deleted, or protected, yet AI tools can retrieve it with the same authority as any other material. The challenge is compounded by legacy sharing practices: files and sites distributed widely in the past remain accessible even when business needs have changed, and AI surfaces this content instantly based on technical permissions rather than current intent. Nine in 10 organizations have either confirmed or suspect they have suffered a security incident tied to misconfiguration or excessive permissions in the past two years, with 39% confirming at least one such event. Reviewing permissions has become the determining factor in whether an AI deployment is safe, yet it remains work that few prioritize or budget for, the report concludes. The window to audit data foundations before AI adoption becomes universal is narrowing rapidly, leaving many enterprises exposed to risks they cannot yet measure. Organizations that defer permission reviews may discover their AI tools have already surfaced sensitive information to unintended audiences, turning dormant security gaps into active breaches.

