Cash isn't saying employees are acting in bad faith. He describes ordinary people using a chatbot to write an email, summarise a document or build a presentation, often without knowing what happens to the data they paste in. His fix is four steps: write an acceptable-use policy, explain it to staff, choose tools on purpose, and review the IT environment before rolling AI out more widely.
The column also promotes a free one-page policy template from his own firm, so read it as an MSP's advice with a sales pitch attached, not as neutral guidance. The core warning, though, matches what the UK's national cyber authority published last month. For Microsoft 365 shops, the most useful advice is the least exciting: fix permissions before switching on Copilot.
What the NCSC Says About Shadow AI
The timing isn't a coincidence. The NCSC blog post, published on September 7, said shadow AI was likely to persist as employees adopted new services faster than organizations could assess them and provide approved alternatives. Infosecurity Magazine reports that the agency cited Microsoft research that found 71% of UK employees had used AI tools not approved by their employer. The NCSC's own wording is vaguer and refers only to "one study." Cash's claim that AI is "probably" in use at any firm with more than a handful of staff is his opinion, not a measurement. The NCSC figure points the same way but doesn't prove it for any particular SME.
The NCSC lists three risks:
- Data exposure. Employees who give shadow AI access to company or customer data likely increase the risk of data breaches, intellectual property loss and failure to meet regulatory requirements.
- Lost visibility. Information sent to consumer AI services may be stored, retained or used to improve the service, outside the organisation's governance, unless specific privacy controls are in place.
- New attack surface. If attackers successfully exploit a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to.
The agency also argues against bans. As with shadow IT more broadly, the goal should be to reduce risk rather than assume it can be eliminated. In the agency's words, encouraging open communication about cyber security issues means employees are much less likely to turn to shadow IT services, including shadow AI. David Chismon, the NCSC's CTO for architecture, was blunter: "IT security teams should not assume they are seeing the full picture."
That matches Cash's answer to "should you block AI?", which is "probably not." On this point the MSP and the agency agree.
Section summary: The Shadow AI warning is backed by the NCSC. The 71% figure comes from survey research cited by the agency, not from an audit of UK SMEs.
Why "Just Use Copilot" Needs Some Unpacking
Cash's main Microsoft advice is that Microsoft 365 customers should see what Copilot offers inside their existing tenant before staff collect a mix of unrelated tools. That's reasonable. It also skips over several details administrators need to know.
First, the names have changed. Microsoft Learn now says Microsoft 365 Copilot has been renamed Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. Microsoft notes that some licences and experiences will keep the old names during the transition. So "Copilot" can mean several different products.
Second, there are two kinds of Copilot Chat. Microsoft's licensing documentation separates them:
| Experience | What it grounds on | Licensing |
|---|---|---|
| Web-based Copilot Chat | Internet results | Included at no extra cost with eligible Microsoft 365 subscriptions |
| Work-based chat | Content the user's Microsoft Entra work or school account can access | Requires a Microsoft Copilot licence |
Third, the data commitments apply to work accounts. Microsoft says organisational use of Copilot and Copilot Chat falls under its Products and Services Data Protection Addendum and Product Terms, with Microsoft acting as data processor. Under those terms, Microsoft says prompts, responses and data accessed through Microsoft Graph aren't used to train foundation models. Web search queries are handled differently. Microsoft says they go to Bing with user and tenant identifiers removed. Bing operates under separate data-handling terms, with Microsoft as an independent data controller for that part. Microsoft also tells customers to check the privacy statements and terms of any agents they enable.
None of this covers an employee signed into a personal account on a home laptop. That's the gap Cash describes in his second risk: devices the company doesn't manage. Picking the right tool only helps if the work actually happens in the right account.
The Permissions Audit Is the Part That Matters Most
Cash's fourth step is the one Windows and Microsoft 365 administrators should focus on. He warns against finding out that sensitive information was widely accessible only after introducing "an AI tool that can find it."
To be precise about the risk: Microsoft says Copilot respects your identity model and permissions, inherits sensitivity labels and applies retention policies. Copilot doesn't open locked doors. What it does is find every unlocked door very quickly. If a payroll spreadsheet sits in a SharePoint site shared with "Everyone except external users," nobody may have noticed for years. Ask an assistant about salaries and it may well turn up.
Microsoft's own requirements page says much the same. It describes a "secure and governed foundation" as not required but strongly recommended. It points to SharePoint Advanced Management for remediating oversharing and Microsoft Purview for sensitivity labelling and governance. Other prerequisites include a Microsoft Entra ID account and an Exchange Online mailbox for mailbox-grounded experiences.
A practical pre-Copilot checklist based on Cash's advice and Microsoft's guidance:
- Review broad sharing. Look for SharePoint sites, Teams and OneDrive links open to the whole organisation that shouldn't be.
- Remove stale accounts. Leavers' accounts and orphaned guest access are old hygiene problems that AI makes more visible.
- Label sensitive content. Purview sensitivity labels give Copilot's inherited protections something to enforce.
- Confirm device management. Check that the endpoints accessing company data are managed devices.
- Pilot first. Start with a small group before rolling out tenant-wide.
Section summary: Copilot doesn't change your permissions. It shows you what they already are. Fix oversharing first.
Writing a Policy People Will Follow
Cash's first two steps are about people rather than technology. His policy advice is to keep it short and readable: name the approved tools, list the information that must never go into an AI system, and say who to ask when unsure. He also argues that a policy buried in a staff handbook does nothing unless someone explains why it exists.
For UK organisations, the legal reasons are concrete. The ICO's position is that data protection obligations still apply when AI processes personal information. Using a chatbot isn't automatically a breach. Pasting an employee record into an unvetted consumer service, though, raises questions about lawful basis and security that a business should answer before it happens, not after.
Before drafting, ask whether staff have an approved tool that actually meets their needs. The NCSC's diagnosis is that shadow AI grows where security policies can't keep up with business needs. A policy that bans everything and offers nothing will just push the usage out of sight.
Agents Raise the Stakes
Cash notes that AI tools are moving from chat windows towards software that works with files, apps and email. The NCSC's agentic AI guidance from May recommends starting with tightly bounded, low-risk pilots and never giving an agent unrestricted access to sensitive data or critical systems. It also says named people should own an agent's access, monitoring and incident review, and the decision to shut it down. This applies to autonomous agents, not every chatbot. Any SME connecting AI to a mailbox or file share should take it seriously.
The Bottom Line
The column itself isn't new. It's practical advice from an MSP, with a template download at the end. What gives it weight is the fit with the NCSC's September warning and with Microsoft's own deployment guidance. Find out what staff are already using. Give them an approved tool in a work account. Write a short policy they'll actually read. Clean up SharePoint permissions before any AI assistant starts searching your tenant.
Has your organisation audited its sharing before turning on Copilot? Share your experience in the forum's Microsoft 365 and security discussions, especially if your audit turned up a forgotten "Everyone" link.
References
- AI is already inside your business. The question is whether you’re in control Greater Birmingham Chambers of Commerce · 2026-10-02T00:44:23
- The hidden risks of shadow AI | National Cyber Security Centre ncsc.gov.uk
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat | Microsoft Learn learn.microsoft.com