Dive Brief:
- Microsoft Copilot is undermining data governance even in organizations that are confident in their AI safety policies, according to a report published by ShareGate. The software vendor surveyed nearly 1,800 IT operations and governance professionals.
- More than 9 in 10 respondents said they had a robust governance framework, yet 29% reported incidents in which AI tools accessed sensitive data. The disconnect comes amid rapid Copilot adoption, with 56% of organizations reporting full deployment of the Microsoft assistant, up from 29% in 2025.
- Governance lapses are a recurring revenue opportunity for partners, according to Stacey Tozer, director of global partnerships at ShareGate. "A lot of clients don't realize they need help until something breaks,” Tozer said in an email. “AI makes that gap much harder to ignore. Copilot is already in production at 93% of the organizations we surveyed, and it will happily surface the overshared files and old access nobody has looked at in years.”
Dive Insight:
Half of IT leaders are very or extremely concerned that AI will reach content nobody has reviewed, according to the report. Respondents who reported documented AI exposure incidents involving Microsoft Copilot or other agentic tools said the breaches have included customer data, internal documents, HR and financial data and IP.
More than three-quarters of organizations experienced governance incidents in the past 12 months related to their Microsoft 365 environment, including stale access, audit and compliance gaps, oversharing and shadow IT/AI within Microsoft 365 tenants.
Migration from on-premises to cloud and tenant-to-tenant also presents significant challenges for IT professionals — 94% of organizations have migrated data in the last two years, but only 7% said they would do it the same way again.
More than 8 in 10 respondents said they want identity preparation handled inside their migration tool, but only 11% have it. Shadow IT doubles between teams running one migration and teams running three, according to the report. And over one-third of respondents said technical complexity — not budget — is blocking their SharePoint migration.
Compliance is essential for organizations implementing migrations, but many say they’re not compliant enough. Partners can help. “A third of organizations delayed or skipped a migration last year because of compliance concerns, up from 20% the year before,” Tozer said. “When a partner builds compliance readiness or adds governance to the plan, that work moves forward and usually leads to the next project.”
The governance work has only increased for IT professionals, with 71% reporting their governance workload has gone up significantly since enabling AI. Partners can help organizations secure increasingly complex Microsoft 365 environments by treating security as a continuous project, Tozer said.
“Governance can't be a one-time cleanup project,” she said. “The partners I talk to who are doing well are turning it into an ongoing service. They help their clients know who has access to what before Copilot does.”
Tozer recommends boosting visibility by setting up continuous monitoring to catch issues before they become incidents, rather than after quarterly audits or user complaints. She also said fixing Copilot permissions and stale Microsoft 365 access is some of the most valuable work a partner can do.
The recommendations extend beyond Copilot and Microsoft. Tozer said two-thirds of organizations are using two or more AI tools for the same content.
“Every one of them is another way for overshared data to surface, so partners need to help clients set access rules that hold up no matter which tool is asking,” she said. “None of this is a one-time fix. People leave, permissions drift and clients keep adding new AI tools. The partners who turn monitoring, cleanup and access control into a repeatable service are the ones who keep their clients secure and grow their practice at the same time.