Security Risks Lead Companies to Pause Microsoft Copilot Deployments
Two-thirds of organizations have delayed or canceled the implementation of Microsoft Copilot due to concerns regarding the potential exposure of sensitive data, according to the State of Microsoft 365 Security and Governance 2026 report by Coreview. Nearly three-quarters of users worry that internal artificial intelligence tools are already leaking confidential information, highlighting a significant gap between enterprise security expectations and the reality of their Microsoft 365 environments.
## Executive Hesitation and Data Exposure Risks
The reluctance to adopt AI tools increases alongside organizational seniority. According to the Coreview findings, three-quarters of executives at the board level and management have halted or postponed their Copilot rollouts. “The risk was always there, but the AI has made it visible and urgent,” said Simon Azzopardi, CEO of Coreview. He noted that organizations are often sitting on a decade of unmanaged file shares and outdated permissions, which AI tools can inadvertently surface to unauthorized users. Because Copilot operates by processing data based on a user’s existing access rights, any lack of “least-privilege” enforcement directly translates into an AI security vulnerability.
## The Gap in Microsoft 365 Security Maturity
While nearly two-thirds of organizations surveyed believe their Microsoft 365 security posture is “mature” or “advanced,” the data reveals a disconnect. Over half of these companies lack fundamental security controls, including Multi-Factor Authentication (MFA) for administrators, Privileged Access Management (PAM), or configuration drift detection. The report also highlights a specific vulnerability regarding administrative accounts. Despite their high-level access to tenant configurations and permissions, these accounts are less likely to be protected by MFA than standard user accounts, with a lower percentage of admin accounts utilizing the security measure compared to standard accounts.
## Misconceptions Regarding Data Recovery and Governance
Many organizations operate under incorrect assumptions about the native capabilities of Microsoft 365. Specifically, one-third of respondents incorrectly believe that Microsoft automatically backs up their M365 configurations, while a small portion of respondents admitted they perform no configuration backups at all. Effective governance has become increasingly difficult to manage through manual processes as environments grow. The survey found that:
* Nearly two-thirds of companies limit or delay the review of user access in SharePoint because the process is too time-consuming.
* Delegation of access reviews to individual employees fails in nearly half of organizations (46 %).
## Strategic Outlook for AI Governance
The adoption of AI tools requires a shift from manual oversight to automated, continuous transparency. To mitigate risks, organizations are increasingly looking toward tools that provide visibility at the file level rather than just the site level. Addressing these underlying infrastructure issues—specifically clearing out legacy permissions and enforcing strict access controls—is the primary prerequisite for moving from a stalled AI project to one that effectively drives productivity.
Related reading