A man reviews a digital dashboard for managing files, user permissions, and data security in an office.
Microsoft 365 Copilot is putting a spotlight on a familiar enterprise problem: confidence in data governance does not necessarily mean sensitive information is under control. ShareGate’s 2026 research found that 93% of surveyed IT leaders were confident their Microsoft 365 governance framework could support Copilot and other AI initiatives responsibly, yet 29% said Copilot or another AI tool had surfaced sensitive internal data that should not have been accessible. Another 8% were unsure whether that had happened.

That is a significant warning for administrators—but not proof that Copilot bypassed permissions. Microsoft’s documentation says its enterprise assistant surfaces organizational information that the individual user already has permission to view. The practical risk is that an AI assistant can make inappropriate existing access much easier to discover and use. A permission problem does not become harmless simply because nobody previously found the file.

A man reviews a digital dashboard for managing files, user permissions, and data security in an office. What the survey actually establishes​

ShareGate’s State of Microsoft 365 report draws on two separate studies:

  • AI governance: 851 IT leaders, surveyed through Centiment in March 2026.
  • IT operations: 943 IT professionals, surveyed through Cint in May 2026.

Together, those studies involved 1,794 respondents, but their findings should not be merged into one survey population. ShareGate wrote the questions and analyzed the responses; the panel providers handled recruiting, screening and quality control. The percentages are self-reported and unweighted, and 59% of the AI-governance sample came from technology or software organizations. These are findings about the surveyed organizations, not a measured incident rate for all Microsoft customers.

The exposure question also grouped Copilot with other AI tools. It therefore cannot establish a Copilot-only exposure rate, identify a particular vulnerability, or prove that respondents experienced a technical access-control bypass. Among respondents reporting exposure, the affected categories included customer information, internal documents, personal information, HR records, financial data and proprietary intellectual property.

The distinction matters: the evidence supports concern about AI-assisted discovery of sensitive information, not a blanket conclusion that Microsoft’s assistant defeats tenant security.

Permissions can work—and still be wrong​

Microsoft’s stated access model helps explain how apparently contradictory results can coexist. Copilot can respect a user’s permissions while retrieving information that the business never intended that user to see. Technical authorization and appropriate business access are not always the same thing.

Consider an illustrative case: an old finance folder remains accessible to a broad employee group. If an employee belongs to that group, an assistant retrieving its contents might be following the configured permissions correctly. The failure would be the excessive access, not necessarily the retrieval mechanism. That is an inference from Microsoft’s documented permission model, rather than an incident established by ShareGate’s survey.

Microsoft describes a similar issue in its own internal governance reporting. Employees sharing content with large security groups can create oversharing, allowing anyone in those groups to encounter the information through Microsoft Search or Copilot. Its explanation reinforces the need to restrict direct access—not merely make sensitive documents harder to find.

Adoption is expanding the review workload​

ShareGate reports that full Copilot deployment increased from 29% in its 2025 research to 56% in 2026, with 93% of the AI-governance respondents reporting partial or full deployment. However, the 2026 questionnaire omitted the earlier “pilot” option, and ShareGate cautions that year-to-year comparisons are directional where samples or wording differ.

Visibility remains incomplete: 53% said they lacked full visibility into what their Copilot agents could access. The workload chart also deserves careful reading: 24% reported a significant increase and 46% a moderate increase since enabling AI—not roughly seven in ten reporting a significant increase.

The broader Microsoft 365 findings are separate. ShareGate’s operations chapter reports that 77% experienced at least one governance incident during the preceding 12 months, including stale access, audit or compliance gaps, oversharing, or shadow IT and AI. That measure is neither a Copilot breach rate nor directly comparable with the AI question, which asked whether exposure had ever occurred.

Migration adds another governance pressure point​

Channel Dive’s reporting also highlights migration difficulties from ShareGate’s research:

  • 94% reported migrating data within the previous two years; only 7% said they would repeat the same approach.
  • More than eight in ten wanted identity preparation within their migration tool, while 11% reported having it.
  • Shadow IT reportedly doubled between teams running one migration and those running three.
  • More than one-third identified technical complexity as a SharePoint migration blocker.

ShareGate’s overview separately reports that compliance concerns delayed or prevented migrations for 34% of respondents, compared with 20% in its 2025 research, again subject to its year-to-year comparison caveats.

These findings describe additional operational strain; they do not establish that migration caused AI exposure. The useful planning implication is to include identity, ownership and access validation in migration work rather than treating successful data transfer as the finish line.

What Microsoft 365 administrators can do​

Microsoft’s secure-data-foundation guidance supplies a practical response beyond the survey’s warnings. Its recommended sequence is to identify high-risk content, apply interim protections, repair permissions, and establish durable guardrails. Administrators need appropriate roles and access to the relevant capabilities.

A focused review should therefore:

  1. Find the highest-risk locations. Microsoft recommends using Purview and SharePoint Advanced Management to identify sensitive, overshared, inactive or ownerless sites and files.
  2. Have owners validate access. Review excessive users and groups, broad sharing links and broken permission inheritance.
  3. Repair the underlying permissions. Remove unnecessary access, narrow sharing to approved audiences and confirm accountable ownership.
  4. Validate the result. Microsoft recommends auditing and reporting to confirm that restricted content is no longer surfaced by Copilot before removing interim protections.

These are priorities, not a universal click-by-click procedure: the applicable controls depend on the tenant and available capabilities.

Restricting discovery is not revoking access​

One especially important boundary concerns Restricted Content Discovery. Microsoft documents it as a temporary control for limiting discovery of selected SharePoint sites through organization-wide search and Copilot while permissions are reviewed. It does not change existing permissions: users with access can still reach the content directly. It also does not support OneDrive sites or affect searches originating within the site itself.

That makes it useful breathing room, not a repaired lock. Microsoft also warns that excessive use can reduce the completeness and relevance of search and AI responses. Selective containment followed by permissions remediation is more defensible than indefinitely hiding large portions of a tenant.

Continuous governance, without the sales pitch​

Channel Dive reports that ShareGate partnerships director Stacey Tozer recommends continuous monitoring, stale-access cleanup and recurring governance services. ShareGate has a commercial interest in governance products and partner services, so those recommendations should be recognized as vendor advice—not proof that a particular product prevents incidents.

Nevertheless, Microsoft’s own Zero Trust guidance supports ongoing access reviews, permissions requirements and data-protection controls. It recommends reviewing access at site and team level and using Purview classification, labeling and related policies to identify and protect sensitive content.

The central lesson is narrower—and more useful—than “Copilot is unsafe.” A written governance framework is not evidence that access is appropriate. For organizations deploying enterprise AI, the meaningful test is whether owners can explain who should reach sensitive information, administrators can enforce that decision, and subsequent checks show that the controls actually work.

 

References

  1. Microsoft Copilot reveals AI governance lapses - Channel Dive Channel Dive 2026-10-09T13:12:44.468294+00:00
  2. #1. Copilot governance: 93% confident, 29% already exposed | ShareGate sharegate.com
  3. State of Microsoft 365 2026: Governance, migration & AI risk | ShareGate sharegate.com