AI Rollouts Outpace M365 Permission Checks
A Syskit study finds 76% of UK and US organizations have deployed enterprise AI, but only 43% reviewed permissions first.
Enterprise AI tools are arriving on Microsoft 365 tenants faster than the permission models underneath them are being examined. A new Syskit study, published on September 10, reports that 76% of organizations in the UK and US have deployed or piloted an enterprise AI tool such as Copilot against Microsoft 365 data — yet fewer than half checked what that data exposure actually looks like beforehand.
The gap matters because AI assistants do not create new access. They inherit it, surfacing files, sites and content that existing permissions already allow. When those permissions were never tightened, the assistant simply makes long-standing oversharing visible and searchable at machine speed.
Adoption Outruns the Permission Review
According to the State of Microsoft 365 Governance Report, only 43% of respondents confirmed they completed a thorough review of permissions and oversharing risk before deploying AI tools. The remainder said they ran only a partial review, or none at all.
The survey covers 327 IT and security decision-makers responsible for Microsoft 365 governance at US and UK organizations with 500 or more employees. It was published on September 10, with the findings reported on September 11.
Syskit's framing is blunt: AI is being deployed faster than the data foundation beneath it is being checked. That is not a subtle technical point — it means the exposure surface for a Copilot rollout is largely inherited from decisions made years earlier and rarely revisited.
The Agent Controls That Aren't There
Confidence in AI agent oversight runs well ahead of the controls meant to back it up. 91% of respondents said they are confident they can see which agents are active and what those agents can reach. Only 22% confirmed having a formal policy defining what AI agents may access.
One in ten organizations (9%) said they let an agent inherit the full permissions of whoever deployed it — meaning the agent operates with that person's entire access footprint.
The spread between perceived visibility and documented policy is the core governance problem in the report. Sight of an agent's activity is not the same as a limit on it.
Why Agents Change the Oversharing Math
Toni Frankola, CEO of Syskit, said that AI agents have removed the friction that once made accidental access to sensitive files less likely. Copilot and other AI tools can now surface content based on existing permissions, including files and sites that were shared broadly years ago and have not been reviewed since.
"What stands out in this data is that so few organizations can check what their AI can actually reach before switching it on, and fewer still plan to spend anything on finding out. Reviewing permissions is unglamorous work, but it has become the deciding factor in whether an AI rollout is safe," he added.
— Toni Frankola, CEO of Syskit
Where M365 Permissions Still Leak
Misconfigurations and permission failures across Microsoft 365 remain prevalent in most organizations, according to the report. The risk is embedded in the permission model itself: 41% of organizations leave SharePoint sites accessible to all staff without restrictions.
35% of respondents admitted former employees' files remain available to active users, and 33% said they have files shared with "Everyone." Each of these conditions is a standing invitation for an AI assistant to retrieve content its audience was never intended to include.
Ownerless Content the AI Can Still Read
Around half of respondents (47%) identify orphaned teams, groups and sites as a key governance concern. Content with no accountable owner is less likely to be reviewed, removed or secured. AI tools can reach it with the same authority as any other content.
That combination — no owner, no review cycle, full access — is what turns an ordinary permission drift into an AI-era exposure problem. Nothing needs to be newly misconfigured for the assistant to find it.
Access Reporting Falls Short of Confidence
Organizations appear more confident about their access controls than they can evidence. 83% said they know exactly who can access sensitive data at any given moment.
But only 4% could produce a complete access report for an external auditor within an hour. The majority (55%) said they would need a day or longer.
- 76% have deployed or piloted an enterprise AI tool on Microsoft 365 data
- 43% completed a thorough permissions and oversharing review before deploying
- 91% are confident they can see which AI agents are active and what they can reach
- 22% have a formal policy defining what AI agents may access
- 9% let an agent inherit the full permissions of whoever deployed it
- 41% leave SharePoint sites accessible to all staff without restrictions
- 35% say former employees' files remain available to active users
- 33% have files shared with "Everyone"
- 47% name orphaned teams, groups and sites as a key governance concern
- 83% say they know exactly who can access sensitive data at any moment
- 4% could produce a complete access report for an external auditor within an hour
- 55% would need a day or longer for such a report
- 90% have experienced or suspect a misconfiguration or over-permissioning incident in two years
- 39% confirmed one
The Incidents Already on the Record
The report also measured how often misconfiguration and over-permissioned access have already translated into incidents. 90% of organizations said they have experienced, or suspect they have experienced, a security incident linked to misconfiguration or over-permissioned access in the past two years. 39% confirmed one.
The question respondents answered was: "To what extent, if at all, has your organization experienced a security incident or data exposure event in the past 2 years attributable to M365 misconfigurations or over-permissioned access?"
That 90% figure combines confirmed events with suspicion, so it captures both organizations that know they were hit and those that believe they may have been. The 39% confirmed share is the harder floor.
What the Numbers Point To
Taken together, the findings describe a deployment pattern: AI tools are switched on across tenants where broad SharePoint access, stale former-employee files and "Everyone" shares are still routine. The assistant does not need to be compromised to expose them. It only needs to answer a question.
Syskit's report places the permission review — not model safety, not prompt injection defenses — at the center of rollout risk. That is a governance and housekeeping problem, and the survey suggests it is being skipped at scale.
For organizations weighing or already running a Copilot deployment, the practical inference is narrow and testable: the reach of the AI is the reach of the permissions already in place. Syskit's own account of the work is that it is unglamorous, but it now determines whether an AI rollout is safe or not.
Sources
- Infosecurity Magazine Original source
Continue Reading
Anthropic Researcher Exits Over AI Safety Race
A researcher says he left Anthropic over concerns it and OpenAI prioritize competitive advantage over safety in AI development.
OpenAI Board Adds AI Safety Researcher
Paul Christiano, who pioneered a key training technique, joins OpenAI's foundation board and its safety committee, citing near-term loss-of-control risk.
Anthropic logs a fourth AI misbehavior
Anthropic's alignment assessment details a January 2026 incident in which an early Claude Opus 4.6 accessed a third party's system without authorization.