Breaking
AI & MLDeveloping Story

AI Rollouts Outpace M365 Permission Checks

A Syskit study finds 76% of UK and US organizations have deployed enterprise AI, but only 43% reviewed permissions first.

··3 hours ago·5 min read
stack of papers
Photo by ron dyar on Unsplash

Enterprise AI tools are arriving on Microsoft 365 tenants faster than the permission models underneath them are being examined. A new Syskit study, published on September 10, reports that 76% of organizations in the UK and US have deployed or piloted an enterprise AI tool such as Copilot against Microsoft 365 data — yet fewer than half checked what that data exposure actually looks like beforehand.

The gap matters because AI assistants do not create new access. They inherit it, surfacing files, sites and content that existing permissions already allow. When those permissions were never tightened, the assistant simply makes long-standing oversharing visible and searchable at machine speed.

Adoption Outruns the Permission Review

According to the State of Microsoft 365 Governance Report, only 43% of respondents confirmed they completed a thorough review of permissions and oversharing risk before deploying AI tools. The remainder said they ran only a partial review, or none at all.

The survey covers 327 IT and security decision-makers responsible for Microsoft 365 governance at US and UK organizations with 500 or more employees. It was published on September 10, with the findings reported on September 11.

Syskit's framing is blunt: AI is being deployed faster than the data foundation beneath it is being checked. That is not a subtle technical point — it means the exposure surface for a Copilot rollout is largely inherited from decisions made years earlier and rarely revisited.

The Agent Controls That Aren't There

Confidence in AI agent oversight runs well ahead of the controls meant to back it up. 91% of respondents said they are confident they can see which agents are active and what those agents can reach. Only 22% confirmed having a formal policy defining what AI agents may access.

One in ten organizations (9%) said they let an agent inherit the full permissions of whoever deployed it — meaning the agent operates with that person's entire access footprint.

The spread between perceived visibility and documented policy is the core governance problem in the report. Sight of an agent's activity is not the same as a limit on it.

Why Agents Change the Oversharing Math

Toni Frankola, CEO of Syskit, said that AI agents have removed the friction that once made accidental access to sensitive files less likely. Copilot and other AI tools can now surface content based on existing permissions, including files and sites that were shared broadly years ago and have not been reviewed since.

"What stands out in this data is that so few organizations can check what their AI can actually reach before switching it on, and fewer still plan to spend anything on finding out. Reviewing permissions is unglamorous work, but it has become the deciding factor in whether an AI rollout is safe," he added.

— Toni Frankola, CEO of Syskit

Where M365 Permissions Still Leak

Misconfigurations and permission failures across Microsoft 365 remain prevalent in most organizations, according to the report. The risk is embedded in the permission model itself: 41% of organizations leave SharePoint sites accessible to all staff without restrictions.

35% of respondents admitted former employees' files remain available to active users, and 33% said they have files shared with "Everyone." Each of these conditions is a standing invitation for an AI assistant to retrieve content its audience was never intended to include.

Ownerless Content the AI Can Still Read

Around half of respondents (47%) identify orphaned teams, groups and sites as a key governance concern. Content with no accountable owner is less likely to be reviewed, removed or secured. AI tools can reach it with the same authority as any other content.

That combination — no owner, no review cycle, full access — is what turns an ordinary permission drift into an AI-era exposure problem. Nothing needs to be newly misconfigured for the assistant to find it.

Access Reporting Falls Short of Confidence

Organizations appear more confident about their access controls than they can evidence. 83% said they know exactly who can access sensitive data at any given moment.

But only 4% could produce a complete access report for an external auditor within an hour. The majority (55%) said they would need a day or longer.

  • 76% have deployed or piloted an enterprise AI tool on Microsoft 365 data
  • 43% completed a thorough permissions and oversharing review before deploying
  • 91% are confident they can see which AI agents are active and what they can reach
  • 22% have a formal policy defining what AI agents may access
  • 9% let an agent inherit the full permissions of whoever deployed it
  • 41% leave SharePoint sites accessible to all staff without restrictions
  • 35% say former employees' files remain available to active users
  • 33% have files shared with "Everyone"
  • 47% name orphaned teams, groups and sites as a key governance concern
  • 83% say they know exactly who can access sensitive data at any moment
  • 4% could produce a complete access report for an external auditor within an hour
  • 55% would need a day or longer for such a report
  • 90% have experienced or suspect a misconfiguration or over-permissioning incident in two years
  • 39% confirmed one

The Incidents Already on the Record

The report also measured how often misconfiguration and over-permissioned access have already translated into incidents. 90% of organizations said they have experienced, or suspect they have experienced, a security incident linked to misconfiguration or over-permissioned access in the past two years. 39% confirmed one.

The question respondents answered was: "To what extent, if at all, has your organization experienced a security incident or data exposure event in the past 2 years attributable to M365 misconfigurations or over-permissioned access?"

That 90% figure combines confirmed events with suspicion, so it captures both organizations that know they were hit and those that believe they may have been. The 39% confirmed share is the harder floor.

What the Numbers Point To

Taken together, the findings describe a deployment pattern: AI tools are switched on across tenants where broad SharePoint access, stale former-employee files and "Everyone" shares are still routine. The assistant does not need to be compromised to expose them. It only needs to answer a question.

Syskit's report places the permission review — not model safety, not prompt injection defenses — at the center of rollout risk. That is a governance and housekeeping problem, and the survey suggests it is being skipped at scale.

For organizations weighing or already running a Copilot deployment, the practical inference is narrow and testable: the reach of the AI is the reach of the permissions already in place. Syskit's own account of the work is that it is unglamorous, but it now determines whether an AI rollout is safe or not.

#microsoft 365#ai governance#permissions#copilot#oversharing#syskit

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories