A project lead asks her assistant for an overview of open items with a client. Back comes a tidy list containing two lines from an email thread she was never copied on, and a reference to a document in a team site she joined briefly two years ago.
She uploaded nothing. She shared nothing. She asked one question.
The model is not waiting for a file
Most people picture AI data exposure as a single action: you paste something or you drag something in. That is the mental model from the early chatbot era, when an assistant knew only what you handed it.
Once an assistant is attached to your work account, that picture stops holding. It has access to sources: your mailbox, your calendar, your documents, shared folders, your chat history. Exactly which ones depends on the permissions approved when the integration was set up, which is usually a consent screen somebody clicked through.
So there is no sharing moment. The question "what did I share" no longer has an answer, because the answer is: everything I can reach.
It searches with your permissions
This is the part people find reassuring right up until they think it through.
The assistant breaks no rules. It sees nothing you would not see yourself given an hour of searching. That is precisely why it goes wrong: it does that hour in two seconds, and it does not need to know the right search term.
What surfaces is wherever your permissions run wider than anyone intended:
- Sharing links that never expire. Somebody shared a folder four years ago with "anyone with the link". The link still works and you were once sent it.
- Old project memberships. You joined a team site for one question and were never removed.
- Shared mailboxes. What sits in the team inbox belongs to the team, including what landed there by mistake.
- Permissions inherited from a migration. Moving between systems, access is routinely widened so that "nobody loses access to their work", and then never narrowed again.
Microsoft 365 shows this most clearly, because so much lives in SharePoint and the integration is deep by default. See what happens when Copilot can reach SharePoint. The pattern is not vendor-specific: it holds for any assistant searching first-party sources.
Why search-and-summarise is not just search
The tempting objection is that this was always possible, so nothing is new.
Technically true. Practically wrong, for three reasons.
Search works on words. You have to know what something is called. An assistant searches on meaning, so "what was going on with that restructuring" finds the document whatever its filename.
Search returns a list. You still have to open, read and judge. That is enough friction to make people give up. An assistant summarises, delivering the content without the threshold.
And search looks inside one system. An assistant combines mail, documents and chat into one answer, exposing connections that existed in no single system on its own.
Constrain, then remediate
Two tracks worth keeping separate, because they have different owners.
Constrain the integration. Which sources may the assistant touch? Most enterprise assistants make this configurable per source, and starting narrow and widening beats the reverse.
Remediate the permissions. This is the real work and it is not about AI. Expiring sharing links, periodic access reviews, revoking guest accounts, and working through the sites set to "everyone in the organisation". It was always necessary; it has now become measurable.
What becomes obvious after doing this for a while: the assistant is rarely the cause of anything. It is the first party to systematically exercise permissions that were too broad for years. That makes it less of a risk than a detection mechanism, and it explains why the cleanup that should have happened long ago suddenly has a budget.