Microsoft Copilot doesn’t create new security problems. It finds the ones you already have and hands them to every employee who asks a question.

That’s the uncomfortable truth behind Copilot’s biggest risk: oversharing. Copilot can only see what a user could already access, but most businesses have years of file permissions, stale sharing links, and forgotten guest accounts sitting in SharePoint and Teams. Copilot doesn’t cause that mess. It just reads it out loud, instantly, to anyone who types the right prompt.

Security teams have taken notice. One 2025 industry report found Copilot accessed almost three million confidential records per organisation within six months, with 57% of organisation-wide shared data containing privileged information, rising to 70% in financial services and healthcare. In the US, Congress went as far as banning House staff from using the commercial version of Copilot over data leakage concerns. If you’re a small or mid-sized business rolling out Copilot without addressing this first, you’re not getting ahead of AI. You’re getting ahead of yourself.

The positive aspect is that the solution is straightforward. It’s the IT maintenance that many SMEs have delayed for years, and Copilot is now the motivation to address it.

Why Copilot Makes Old Problems Visible

Before Copilot, a poorly permissioned file sitting in a shared drive was a risk, but a quiet one. Someone would need to know it existed, know where to look, and take the time to search for it.

Copilot removes all three barriers. Ask it “summarise our Q3 financials” or “what’s in our redundancy planning documents” and it will search everything the logged-in user can technically reach, whether or not that access was ever supposed to be theirs. A departed employee’s old permissions, a SharePoint site shared too broadly for a one-off project, an oversized “everyone” group left over from a smaller team. Copilot surfaces all of it, instantly and in plain English.

This is why Microsoft itself frames the problem as inherited, not invented. Copilot amplifies whatever’s already wrong in a tenant, including oversharing, missing sensitivity labels, over-scoped connectors, and stale guest access.

Five Steps to Roll Out Copilot Safely

1. Run a permissions audit before you flip the switch

This is the step most businesses skip, and the one that matters most. Before any user gets Copilot access, review who can access what across SharePoint, OneDrive, and Teams. Look specifically for broad “everyone” or “all employees” sharing, external guest accounts that are no longer active, and links set to “anyone with the link.” Clean these up first. Copilot should be the last thing you turn on, not the first.

2. Apply the principle of least privilege

Each person’s access should match what their role actually requires, not what’s convenient to set up. If a user doesn’t need visibility into HR, finance, or legal documents to do their job, they shouldn’t have technical access to them, because Copilot won’t know the difference between “can see” and “should see.”

3. Use sensitivity labels and data classification

Microsoft Purview lets you classify and label content (confidential, internal, public, and so on) at the container level, so a Teams site or SharePoint library carries a default label that flows down to the files inside it. This gives Copilot, and your data loss prevention policies, a way to recognise sensitive content and restrict what it will summarise or surface.

4. Roll out in phases, not all at once

Start with a small pilot group instead of licensing your whole organisation on day one. A phased, zero-trust approach to rollout, readiness assessment, then pilot, then policy enforcement, then wider release, gives you the chance to catch permission issues and unexpected Copilot behaviour while the blast radius is still small.

5. Monitor usage and keep auditing

Copilot governance isn’t a one-time project. Use Microsoft Purview’s audit logs to track what Copilot is being asked and what it’s surfacing, and revisit permissions regularly as staff join, leave, and change roles. Microsoft is also building oversharing alerts and DLP controls directly into the Microsoft 365 admin centre, giving IT teams a single place to spot and fix exposure issues before they become incidents.

Purview does most of the heavy lifting in the steps above, but it’s worth knowing it’s not the only governance tool Microsoft is building for AI. As businesses move from just using Copilot to deploying their own AI agents, a second, newer tool comes into play: Agent 365.

Purview or Agent 365: Which Is the Right Choice for Your Business?

As Microsoft expands its AI governance tools, it’s worth being clear on where Purview stops and where a newer tool, Agent 365, picks up. They’re not the same thing, and they’re not interchangeable.

Purview governs the data. It classifies and labels content, applies DLP policies, and gives IT visibility into which files are overexposed, exactly the protections described above. This is what determines what Copilot is allowed to see and surface.

Agent 365 governs the agents themselves. Microsoft positions it as the control plane for AI agents: managing agent identities, access permissions, and lifecycle, from creation through to decommissioning. Where Purview asks “what can this agent see,” Agent 365 asks “what is this agent, who’s responsible for it, and what is it allowed to do.” Microsoft is explicit that the two tools are complementary and designed to work together, covering different layers of the same governance problem.

For most UK SMEs using the standard Copilot experience, Purview covers the majority of practical risk today, since it’s the tool controlling what Copilot can read and expose across SharePoint, OneDrive, and Teams. Agent 365 becomes more relevant once a business starts building or deploying its own AI agents, such as custom Copilot Studio agents or automated workflow agents, that need their own identities and access boundaries beyond simply answering questions over existing files. In short: start with Purview, and treat Agent 365 as the next layer to plan for as your use of AI agents grows.

Don’t Let AI Adoption Outrun Your IT Housekeeping

None of this means Copilot is too risky to use. It means Copilot should arrive after your permissions are in order, not before. For most SMEs, that’s the real barrier: not the technology, but years of accumulated sharing links, stale accounts, and “we’ll fix that later” access decisions that nobody had time to clean up.

That’s exactly the kind of groundwork Lucidica handles for clients every day, from permissions audits and Microsoft Purview configuration to phased Copilot rollouts that keep your team productive without exposing data they were never meant to see.

Want To Know What Copilot Could See in Your Organisation Right Now?

Get in touch with Lucidica for a permissions and Copilot-readiness review before you roll it out further.