AIMicrosoft CopilotData GovernanceCyber Security

Before You Roll Out AI Tools, Fix Your Permissions

When it’s not busy going rogue and trying to take over the internet, AI can actually come with a whole host of benefits to a business, including the ability to make your information easier to find, summarise and act on. While handy, it also means that the access decisions hidden beneath your systems suddenly matter much more.

Written by Jordan StewartAI governance
AI permissions and data access governance for business
The short answer

Before rolling out any form of workplace AI, review who can access your sensitive data, remove stale and overly broad permissions, check external sharing, assign clear data owners and test the tool with a bounded pilot. You don’t need a perfect environment, but you do need to understand the environment the AI is entering.

Imagine it another way, you’ve got a vacancy at your company, and rather than an interview process, you instead walk down the street and hire the first person you encounter. Then, when they start on day one, you give them the ability to read every filing cabinet, search years' worth of email, scan everything in shared folders, and then not really check up on how they’re getting on outside of their first week on the job.

You’d probably go so far as to think anyone who did that is more than a little reckless.

Yet plenty of AI implementation projects begin pretty much in this manner. Licences are bought, a pilot group is chosen, and it’s pretty much 3, 2, 1… lift off. Only then does somebody ask why a sales user can find an old HR spreadsheet, marketing has access to the head of finance’s mailbox, and why six former suppliers still appear in a shared Team.

The AI isn’t necessarily bypassing security, so to speak. More often, it just makes an existing permissions problem visible, searchable, and much faster to exploit by accident.

AI is an access multiplier

If they’re not reviewed, the traditional permissions problems can sit quietly - and unnoticed - for years at a time. A user may technically have access to a document buried six folders deep, but just never know it exists. The thing with AI is that it changes the practical meaning of that access, as it can (and does) search, connect and summarise information that would previously have taken patience, luck and maybe several cups of coffee to uncover.

Microsoft is explicit about this in its Microsoft 365 Copilot privacy guidance: Copilot presents organisational data using the same underlying access controls as other Microsoft 365 services. That’s reassuring when your permissions are sound, but when they aren’t, it makes overshared information far easier to surface.

All of that means that simply asking, “Is the AI tool secure?” in isolation isn’t encompassing enough; you also need to know, “Is our data already shared with the right people?”

What does ‘fix your permissions’ actually mean?

Let’s not get it twisted, we’re not about to advocate for locking every file away and spending a year rebuilding SharePoint before anyone is allowed near an AI assistant. Not only is that a surefire way to annoy everyone associated with your business, but it’s also costly and, frankly, unnecessary. Instead, you should start by reducing the gap between the access people need and the access they have accumulated.

  • Teams and SharePoint sites with large, inherited membership groups
  • folders shared with “everyone” because it was convenient at the time
  • guest users whose projects ended months (or even years) ago
  • old HR, finance, legal or client documents stored in broadly accessible locations
  • service accounts, integrations or agents with more access than their task requires
  • ownerless sites and folders that nobody feels responsible for reviewing

For many organisations, that gap often appears in familiar places, such as:

AI readiness is often ordinary information governance with a new deadline.

Permissions are only one layer

To paraphrase from Shrek, a sensible AI rollout is a bit like an onion, in the sense that it’s got layers. You’ve also got to factor in identity security, data classification, retention rules, supplier review, staff guidance and have a clear view of what the tool does with prompts and outputs. Permissions sit at the centre of this AI onion, if you’ll let me continue with the analogy, because they determine what the system, user, or agent can access in the first place, and it all grows and wraps around that core.

The National Cyber Security Centre’s 2026 guidance on agentic AI makes the same practical point we’re echoing here when it comes to systems that can take actions: apply least privilege, start with tightly bounded pilots and never give an agent unrestricted access to sensitive data or critical systems.

That becomes especially important as AI moves from drafting text to reading inboxes, updating records, creating tickets or triggering workflows. Any writing assistant can produce a poor paragraph - I mean, you only have to open LinkedIn or 90% of the cold emails in your inbox, and chances are, you’ll find a handful of examples with very little effort. But an over-privileged agent can produce the same poor paragraph… and then confidently send it to a client without your intervention if you’re not careful.

A permissions-first AI implementation plan

We get it, nobody wants slow AI implementations - and we’re not saying that you should slow down, for the record. But you should make the first useful deployment small enough to understand and safe enough to learn from. Here’s our recommended plan:

01

Start with one business outcome

Choose a defined use case, a named user group and a clear data boundary. “Help the operations team summarise approved project documents” is testable. “Give everyone AI” is not.

02

Map what the tool can reach

List the services, sites, folders, mailboxes, applications, connectors and plug-ins involved. Include external systems such as CRM or ticketing platforms, not just Microsoft 365.

03

Review the highest-risk information first

Prioritise HR, payroll, finance, legal, board, credentials, client-confidential material and special category personal data. Check who can access it, how that access was granted and whether it is still justified.

04

Remove stale and broad access

Close anonymous or company-wide links where they are not needed, and remove former staff/guests. Correct broken inheritance, and give each important workspace an accountable owner.

05

Strengthen identities

Permissions are only useful when the person behind the account is properly verified. Review privileged roles, MFA, Conditional Access (where appropriate), dormant accounts and service identities.

06

Set handling rules for sensitive data

Decide what users may enter into approved AI tools, what must stay out, how outputs should be checked, and where generated content may be stored. Use labels and data loss prevention controls where they fit the risk and your licensing.

07

Test the boundaries, not just the happy path

During the pilot, use test accounts representing different roles, ask known-sensitive questions and check whether the answers, source links and actions match the permissions you intended.

Keep reviewing after launch. Access changes as people join, leave and move roles. New agents and connectors expand the scope, so make access reviews, audit logs and incident handling part of normal operations rather than a one-off pre-launch tidy-up.

For Microsoft 365 environments, Microsoft’s own secure and governed data foundation guidance recommends identifying overshared, inactive and ownerless sites; applying interim protections where necessary; and then fixing access, sharing links and ownership. The exact tooling will vary by licence, but the sequence is useful for almost any organisation.

What about personal data and UK GDPR?

If an AI system processes personal data, permissions are part of a wider data protection assessment. You still need a clear purpose, an appropriate lawful basis, data minimisation, security, transparency and accountability. Depending on the risk, a data protection impact assessment may also be required.

The Information Commissioner’s Office guidance on AI security and data minimisation advises organisations to assess the security risks posed by their specific use of AI and to take a holistic view across systems, suppliers, data flows, and business processes. The ICO also notes that its AI guidance is being reviewed following changes made by the Data (Use and Access) Act, so organisations should check the latest position before relying on it for a legal decision.

In normal person speak, that means that buying an enterprise AI licence doesn’t outsource your responsibility for what information is accessible, why it is being used or how people are affected.

Three questions leaders should ask before approving rollout

If the answer to any of those is “not really”, the next step is not necessarily to abandon AI. It is to narrow the pilot until the answers become clear.

01

Can we explain what information this AI can access for each pilot user?

02

Who owns the decision to grant, review and remove that access?

03

Can we see what happened and contain it if the tool produces or takes an unexpected action?

Frequently asked questions

Does Microsoft 365 Copilot bypass existing permissions?

No. Microsoft states that Copilot uses the same underlying access controls as Microsoft 365 and only presents data that the individual user is authorised to access. The risk is that existing access may be broader than the organisation realises or intends.

Why can AI expose information that was already protected?

Often, the information was accessible rather than properly restricted. It was simply difficult to find. AI can reduce that friction by searching and summarising across the content a user can access.

Do we need to clean up every permission before starting?

No. Start with a bounded use case and the data it needs. Review that area properly, apply temporary restrictions where needed and expand only when ownership, monitoring and controls are working.

What is least privilege in an AI rollout?

Least privilege means giving a user, integration or AI agent only the access needed for its defined task, for no longer than necessary. It is especially important for agents that can take actions as well as retrieve information.

The useful outcome is confidence, not delay

Permissions and access is hardly the most glamorous topic of conversation. It’s a far cry from any clever demo, establishing an exciting efficiency, and is slightly harder to turn into a glossy slide. But ultimately, it is what lets people use AI without second-guessing every answer or worrying about what might appear next.

A good AI implementation should make information easier to use without making sensitive information easier to misuse. That starts with knowing who can access what, why they can access it and who is responsible for changing it.

Fix that foundation first, then let the AI be impressive.

Fifosys can help you assess AI readiness across Microsoft 365, permissions, identity and data governance, then shape a controlled rollout around the workflows that matter. Explore Fifosys Microsoft Copilot services or start a conversation with the team.

Jordan Stewart
Jordan StewartFifosys insights, news and practical technology guidance for UK business leaders.
Talk to Fifosys

Fix the foundation before you scale AI

Fifosys can help you assess AI readiness across Microsoft 365, permissions, identity and data governance, then shape a controlled rollout around the workflows that matter.

Next
Next

What Changed In AI This Week? OpenAI Security, Microsoft Copilot in Excel, Gemini Cost Controls and Salesforce Agents