Politics and regulation·July 23, 2026, 08:00
Report: Copilot exposes weak Microsoft 365 governance
AI-generated and checked against the sources listed below.
Analyst firm Info-Tech Research Group says many companies govern Microsoft 365 too loosely. When Copilot gets access to the data, the gaps become more visible.
A new report from global IT advisory firm Info-Tech Research Group points out that many organizations have weak governance of their Microsoft 365 environments. It becomes a bigger problem once the AI assistant Copilot enters the picture.
Copilot can pull information from many places in a company, such as documents in SharePoint and OneDrive and conversations in Teams. If permissions are a mess, Copilot can find and display content that an employee should not actually see.
What is the problem?
According to Info-Tech, many companies treat governance as a series of standalone settings. They lack a unified model that ties into the needs of the business. The result is uneven controls.
The report lists these typical mistakes:
- Relying on the default settings that Microsoft ships. - Unclear ownership of who is responsible. - No oversight of content and access in Teams, SharePoint and OneDrive.
John Donovan, principal research director at Info-Tech, says: "Microsoft 365 governance fails when it's treated as a series of configurations rather than a business-aligned model." In other words, governance fails when it is seen as a set of settings and not as a model that fits the business.
Copilot doesn't create the flaw, but magnifies it
The point is that Copilot does not create the gaps itself. The gaps were already there. But an AI assistant makes it easy to find sensitive material that used to sit hidden in a messy system.
What does the report recommend?
Info-Tech suggests that companies:
- set a clear direction for governance that fits business goals - map where they stand today and find the gaps - turn intentions into controls that can be enforced - make roles and decision-making responsibilities clear - embed governance in everyday work through communication and policies
The report comes with tools such as checklists, responsibility matrices and acceptable use policy templates.
What does it mean for you?
If you use Copilot at work, it is worth asking the IT department who can see which files, and whether the access rules have been reviewed. It is the company's job to clean up before the AI tool is used widely.
The report was published by an advisory firm that itself sells guidance in this area. It does not point to a specific data leak at any particular company.
Sources
Get the week's AI news in your inbox
Choose your level, topics and length. One email a week, unsubscribe at any time.
Subscribe to Promptly Newsletter



