We get asked whether Copilot is safe to roll out more often than any other AI question. The real question is never Copilot. It is whether access control is sound enough for any AI tool to sit on top of it safely.
Copilot works inside the permissions already built into Microsoft 365. If access is well managed, it stays well managed. If it is not, Copilot does not create the risk. It just makes the existing over-permissioning visible faster.
That is one tool, reviewed. Most businesses have several others in use that nobody has reviewed at all.
The risks we see most often
Data leakage. Someone pastes a full proposal, pricing included, into an AI tool to get it rewritten. The same happens with contracts and HR data. Once it is in the tool, the business no longer controls where it sits or who can reach it.
Access that was already too broad. Copilot surfaces anything a user already has permission to see. That includes shared folders and Teams spaces nobody has audited in years. The tool did not cause the exposure. It just switched the light on.
Shadow AI. Staff using tools IT has never approved and never heard about. Not malicious. It looks like harmless productivity help from where they sit. From the business's side, there is no visibility into what data has gone in or where the output ends up.
No defined line. Ask ten staff whether a client name in a prompt is safe and you will get ten different answers. Without a policy, everyone sets their own.
How it actually happens
It is never dramatic. A manager rewrites a proposal through an AI tool and pastes the whole thing in, pricing and all. Someone uploads a spreadsheet to get help with trends. Nobody thinks twice, because nothing about it feels like a breach.
The sharper risk is when an AI tool gets connected to cloud storage or email with a scope wider than anyone checked. At that point the tool can read far more than the person granting access realised.
Data leaks do not start with a breach. They start with a small, reasonable action nobody governed.
What actually fixes it
Access first. Get it right before anything else. An AI tool sitting on top of bad permissions just moves the problem faster.
Name the approved tools. If Copilot is approved, say so. If something else is not, say that too. A policy that lists principles instead of naming tools will not get read.
Write the rule down. What must never go into a prompt. What is fine in an approved platform. When to ask IT first. One page, not ten.
Train on real examples. Not a lecture on AI risk. Show people the actual email or report they would have written, and where the line sits.
Watch for the pattern, not every keystroke. New applications appearing, broad permission grants, unusual sharing. That is what catches the problem early.
What a safer policy looks like
Four questions, answered plainly: which tools are approved, what must never go into a prompt, who signs off new tools, and what to do when unsure. It sits alongside existing access control and retention rules. It does not replace them.
We are not trying to get anyone to block AI. We are trying to get the exposure to be a choice, not an accident.