The problem nobody mentions in the sales demo
When Microsoft demonstrates Copilot, the demo is impressive: ask for a summary of every meeting this week, Copilot delivers. Ask for a proposal draft based on previous contracts, it delivers that too. What the demo doesn't show is what happens when your Microsoft 365 environment has never had a permissions review.
Copilot has no access of its own. It uses the signed-in user's permissions. If Sarah in finance still has access to an HR folder that should have been removed in 2021, Sarah's Copilot will include HR data in responses about project costs. If a SharePoint site from a finished project is still open to the whole company, any employee can ask Copilot to summarise those files.
That's the central risk with Copilot: it isn't a bug, it's a mirror. It reflects the exact state of your permissions.
Microsoft is progressively rolling Copilot into Microsoft 365 Business and Enterprise plans. Many organisations will gain access without having actively requested it. If you haven't prepared your environment, Copilot may already be available to your users today.
The four real risks
Copilot governance isn't bureaucracy. It's the difference between a productivity tool and an internal data leak vector. These are the four risks we see most often before implementations.
Excessive permissions: the problem you almost certainly already have
Microsoft has a name for the most common situation it encounters before Copilot deployments: structural oversharing. It happens when an environment accumulates years of permission decisions made for convenience. Someone needed access to a folder for a week, access was granted, never revoked. A project ended, the SharePoint site stayed open. An employee left, but the Teams channel they were in still exists with its original documents intact.
In organisations with more than three years of Microsoft 365 use, finding an environment without this problem is rare. And Copilot doesn't skip those files: it treats them as legitimate context for whoever is asking.
A permissions review doesn't need to be a six-month project. Start with your most critical data: contracts, financial records, HR information, intellectual property. Apply least-privilege: each user should only have access to what their current role requires.
GDPR and Copilot: what your organisation needs to check
Microsoft 365, including Copilot, operates under Microsoft's Data Processing Addendum, which is aligned with GDPR. But several points need specific attention for organisations operating under EU data protection law.
- Purpose limitation: verify that your privacy notice covers the use of AI tools in processing personal data of your data subjects
- Data residency: confirm in the Microsoft 365 Admin Center where Copilot prompt and response data is stored and for how long
- International transfers: if personal data of EU data subjects is processed outside the EEA, ensure there is an adequate transfer mechanism in place
- User training: document that employees have been instructed not to enter personal data about clients or individuals into Copilot prompts
Organisations that already have structured data protection policies under GDPR generally need targeted adjustments rather than a full overhaul to cover Copilot. Where Copilot processes personal data in automated ways, Article 35 requires a Data Protection Impact Assessment; our guide to AI DPIA requirements covers the criteria and assessment process.
What to implement before enabling Copilot
This list covers the minimum needed for a responsible deployment. The goal isn't to slow adoption: make sure the productivity Copilot delivers doesn't come with data exposure you can't trace afterwards.
What a well-run implementation looks like
A professional services firm with 120 staff that we supported through Copilot adoption found, during its permissions audit, that 34% of SharePoint sites had at least one user with access they should no longer have had. Three of those sites contained contracts with confidentiality clauses and client fee information.
Fixing the problem took three weeks. Without the audit, that data would have become part of the available context for any employee asking Copilot about client work.
After the governance project, the Copilot rollout was straightforward. Users understood what to expect, sensitive documents were labelled, and permissions reflected the reality of current roles rather than six years of unreviewed growth.
Copilot doesn't create new risks from nothing. It amplifies the risks you already had but couldn't measure.
Where to start
If you don't have a Copilot activation date yet, use that time well. A four-week readiness assessment is enough to cover permissions, data classification, and an acceptable use policy, putting you in a position to enable Copilot with confidence.
If Copilot is already active in your environment, the first step is to run an access report in the SharePoint Admin Center and see how many sites have permissions open to "Everyone" or broad groups. That number will tell you whether you have an urgent problem or a maintenance project.
Cyvra helps organisations structure AI governance before and during Microsoft Copilot adoption, covering permissions, GDPR, and acceptable use policy. Our Copilot implementation guide covers the configuration steps and rollout sequence for new deployments. If you want to talk through the current state of your environment, get in touch with our team.