Copilot Can See Everything Your Staff Can — Here's Why That's a Problem
Here's a conversation I have a lot. A company wants to turn on an AI assistant for their whole team. I ask one question first: "Do you know exactly who can open your most sensitive folder?"
Usually there's a long pause. That pause is the whole problem.
AI borrows permissions — it doesn't set them
An AI assistant like Copilot doesn't get its own rules about what it can see. It inherits whatever the person using it can already reach. So if an employee technically has access to a file they were never meant to see, the AI can find it and drop it into an answer — instantly.
The mess was always there
In most organizations, permissions drift for years. Temporary access that never got removed. A folder shared "to everyone" for convenience. A sensitive file in a wide-open location. None of it caused a problem, because finding it took effort.
The fix isn't to avoid AI
It's to clean up access before you switch the AI on. Review who can see what, tighten the drifted permissions, protect the crown-jewel data specifically, and roll out to a pilot group first. AI didn't create the risk — it just made ignoring it dangerous.
Thinking about AI for your business?
I help teams adopt AI without giving up control of their data. Let's talk about where to start.
Start a conversation →