The AI-Readiness Checklist: What Has to Be True Before You Turn On Copilot
Almost every company I talk to wants Copilot. Very few are ready for it. And the gap between "wants" and "ready" isn't about the AI — it's about the years of quiet mess sitting in the data underneath it.
Here's the checklist I walk clients through before we switch anything on.
1. Fix who can see what
This is the big one. Copilot doesn't get its own permissions — it borrows the user's. So anything a person can already open, Copilot can pull into an answer in seconds. In most companies, permissions have drifted for years, and people can reach files they were never meant to. Find and fix that oversharing first, or you've just built a very fast way to leak your own data.
2. Label your sensitive data
Copilot respects sensitivity labels — but only if they exist. A simple labeling scheme (four labels, not forty) tells the AI what's protected and what isn't.
3. Turn on data-loss protection
DLP rules stop labeled, sensitive content from being shared in ways it shouldn't be — including by the AI. It's the guardrail that makes labels mean something.
4. Clear out the junk
Ten years of duplicate, stale, and abandoned files aren't just clutter — they're what Copilot will happily quote. Cleanup improves both safety and answer quality.
5. Get the basics current
Licensing, identity, and the Microsoft 365 apps all need to be in a known-good state. This part is usually quick.
6. Pilot, don't blast
Roll out to a small, controlled group first. Measure. Then expand. "Turn it on for everyone" is the most expensive sentence in IT.
If you're planning a rollout this year, start with the least glamorous question in the building: who can actually see what? That's the part that saves you.
Thinking about AI for your business?
I help teams adopt AI without giving up control of their data. Let's talk about where to start.
Start a conversation →