AI Rollouts Outpacing Basic Permission Checks, Study Finds
A new State of Microsoft 365 Governance Report from security governance firm Syskit has found that while 76% of organisations in the UK and US have deployed or piloted enterprise AI tools such as Copilot, only 43% carried out a thorough review of permissions and oversharing risk beforehand. The rest ran only a partial check or none at all.
The study also found a gap between confidence and control. While 91% of respondents said they were confident they knew which AI agents were active and what they could access, only 22% had a formal policy defining what those agents were allowed to reach, and 9% let an agent inherit the full permissions of the person who deployed it. Syskit CEO Toni Frankola said AI tools have removed the friction that once limited accidental access to sensitive files, meaning old, broadly shared content can now surface without anyone noticing.
The report also highlights broader Microsoft 365 governance issues that make this riskier. It found 41% of organisations leave SharePoint sites open to all staff, 35% still give access to former employees' files, and 33% have content shared with everyone in the organisation. Nearly half flagged orphaned teams, groups and sites with no accountable owner as a major concern, since such content rarely gets reviewed or secured, yet AI tools can access it just as easily as anything else.