Someone asks Copilot to summarise what is known about last year's restructuring. The answer is tidy, properly cited, and includes a passage from a set of minutes naming them and three colleagues alongside figures.
Nothing was breached. The site holding those minutes was opened to everyone in the organisation once, because something needed sharing quickly. That was in 2023 and nobody reversed it.
Copilot breaks no permissions
Establish this first, because everything else follows from it. Copilot searches with the permissions of the user asking. What you cannot open does not appear in your answer.
That sounds reassuring and it is the core of the problem. The question shifts from "can the assistant see too much" to "should this person have been able to see this already". And in most organisations that second question has been answered for years with "probably not, but it never mattered".
Unfindability was the control
This is the mechanism, and it is worth stating precisely.
A large SharePoint tenant holds tens of thousands of documents. Some fraction sits too open: a site set to "everyone in the organisation" once, a folder that came across in a migration, a sharing link that never expired.
While you had to know where something was to find it, nothing happened. Search worked on keywords and rarely returned anything useful. In practice that was a security layer: never designed, entirely effective.
An assistant works differently. It searches by meaning, so you do not need the right words. It searches everywhere at once. And it summarises, so you do not even have to open the document to learn what is in it.
What changes is not access. What changes is effort. And if effort was your only control, you did not have one.
What surfaces
The categories are strikingly consistent across organisations:
- Pay and performance documents, often as an HR system export parked somewhere "for now"
- Restructuring and redundancy material, usually in a project site nobody cleaned up
- Board and leadership team minutes
- Contracts with unusual terms the rest of the business is not meant to know about
- Personal data in attachments to old tickets and requests
What they share: they are sensitive for good reasons, and nobody deliberately opened any of them up.
What Microsoft says about it
None of this surprises the vendor. Microsoft describes remediating oversharing as the first of three pillars in its own deployment guidance, ahead of setting up guardrails and ahead of meeting AI regulatory requirements.
The recommended sequence amounts to: identify the most-used sites, run a permission state report, start access reviews on the sites that are overshared, and apply restricted access control to business-critical sites. Licences after that.
In practice it usually runs the other way round, because the licences arrived first and the cleanup is a project measured in months.
Why this is not an AI project
Perhaps the most useful conclusion is that none of this work is about AI. Permission cleanup was always necessary. It was simply never urgent.
What the assistant does is present the bill. That is unwelcome and it is also useful: there has rarely been a better week to get an access review funded than the one in which somebody stumbled into their manager's compensation letter.
The same pattern applies to any assistant searching your own sources, see what is RAG and how AI tools reach files you never uploaded.
And a second track runs alongside this project. Cleaning up permissions governs what the assistant can find inside your tenant. It says nothing about what someone pastes into a chat window from an email, a PDF, or a system that was never in SharePoint at all. Those two run in parallel, and only the first one can ever be finished.