AI is changing how organisations access information, create content and deliver results. Employees can summarise meetings, review contracts or prepare client responses in minutes. Business teams are embedding AI into SaaS platforms, while third-party agents connect applications to automate workflows and drive efficiency.
What appear to be separate technology choices often combine to create a single, interconnected exposure landscape for your data.
This distinction matters. The main AI security risk is rarely the technology itself. It is the data, permissions and governance decisions behind it.
Security leaders need to know what information an AI tool can access, which identities and permissions enable that access, which other services are involved and where the resulting data may flow next. Only then should they ask if the tool itself is secure.
Organisations do not need to pause AI adoption while waiting for perfect certainty. What matters is having enough visibility to make informed decisions about risk, control and accountability.
Approving AI tools is only the start. Business leaders need to know where their data is going, who can access it and what controls protect it across Microsoft 365, SaaS platforms and third-party services.
An AI assistant is only one part of a wider data pathway.
This pathway includes the employee making a request, the identity used to authenticate them, the permissions attached to that identity, the connected repositories, the information included in prompts and any agents, extensions or plug-ins involved. It also covers where outputs are stored, copied or shared.
This is particularly important in Microsoft 365. Microsoft explains that Copilot can use content from Microsoft Graph, such as emails, chats and documents that the user has permission to access. It only surfaces organisational data to which the individual user has at least view permission. Prompts, responses and data accessed through Microsoft Graph are not used to train the foundation large language models used by Microsoft Copilot. [Source: Data, Privacy, and Security for Microsoft Copilot | Microsoft Learn]
These safeguards are important, but they do not remove your responsibility for the underlying access model.
If a document is overshared, an outdated group still has access to a SharePoint site or sensitive information lacks clear ownership or classification, AI can make these issues more visible. It enables authorised users to find and combine information more efficiently, even if access was granted long ago.
An unexpected AI-generated result does not always mean a control has failed. More often, it shows that the access model no longer matches business intent.
Copilot readiness is about more than configuration. It must cover the state of your data estate, user and application identities, access permissions, external sharing, information protection and ownership.
Many organisations still assess AI tools in isolation. This leaves gaps between security, procurement and compliance reviews.
A more effective approach is to map AI exposure across three connected layers: Microsoft 365, AI-enabled SaaS applications and third-party or unsanctioned services. This gives a clearer view of where data moves and where controls are needed.
Microsoft 365 may contain emails, meeting information, documents, chats and other business content that employees use every day. Copilot can ground responses in organisational data from Microsoft Graph, subject to the user’s permissions. Microsoft also states that its underlying Microsoft 365 access controls and identity-based access boundaries are honoured when Copilot retrieves information. [Source: Data, Privacy, and Security for Microsoft Copilot | Microsoft Learn]
Strong information governance is essential for Copilot security.
Security leaders should understand:
Copilot does not remove the need for strong information hygiene. In fact, it makes getting that foundation right even more important.
AI adoption is not limited to dedicated assistants. Many SaaS providers are adding generative AI, automated analysis and agent-like capabilities to their platforms.
A familiar application can create a new data pathway.
The original procurement or security review may have assessed how the SaaS service stored and processed information at the time. It may not have considered later AI capabilities, the data those features can access, the models or supporting services involved or the new outputs they can generate.
When AI functionality appears inside an existing application, organisations should revisit questions such as:
Third-party risk management must keep pace with the service itself. Approval of a SaaS platform does not automatically cover every future AI feature, agent or integration.
The third layer includes consumer AI services, browser extensions, meeting assistants, coding tools, standalone agents, plug-ins and departmental trials introduced outside standard approval processes.
These tools are difficult to govern because security teams may not know they are in use. Employees may copy text, upload files or connect them to business applications without understanding how organisational data will be used or protected.
However, shadow AI should not be framed only as deliberate policy avoidance. Employees often adopt AI because they want to work more efficiently or because the organisation has not yet provided an approved option that meets their needs.
A purely restrictive response often pushes activity out of sight without addressing the underlying demand. A more sustainable approach combines discovery, clear acceptable-use policy, employee guidance, approved alternatives and controls matched to the sensitivity of the information involved. This gives organisations visibility and control while supporting secure innovation.
AI exposure rarely results from a single dramatic control failure. It usually develops through several ordinary weaknesses that overlap and go unaddressed.
Employees, former contractors, groups or applications may retain access that is no longer needed. AI can make the consequences of that access more visible.
Reviewing permissions is not just an administrative task. It is fundamental to being ready for AI.
Sensitive content can remain technically accessible but operationally forgotten. Broad sharing, unclear ownership and inconsistent classification make it difficult to determine which AI uses are appropriate.
Organisations cannot apply proportionate data security controls without knowing what information they hold, why it is sensitive and who should use it.
An AI service may connect to other platforms and operate through application permissions, not just an individual employee’s direct access.
Security teams need visibility into what an integration can access, which identity it uses, the actions it can perform and what happens when it is no longer needed. Without this, risk can go unnoticed.
Information can leave a governed repository through copying, uploads, browser-based tools or generated outputs. The risk is not limited to the initial prompt. The response may also contain business context that needs protection. Both inputs and outputs matter.
Effective cloud data security must consider both inputs and outputs to protect business information.
IT may own the productivity platform. Security may own data loss prevention. Procurement may approve the vendor. Legal and privacy specialists may review contractual terms. Business teams may select the use case.
Each team can complete its own task correctly, but the full data pathway may still remain unowned.
Enterprise AI governance must connect these disciplines. Otherwise, accountability stops at organisational boundaries while the data continues to move across them.
Understanding the problem is only the start. Security leaders need to decide which gaps matter most, which existing capabilities can help and how to sequence improvement.
AssureAI is CyberOne’s structured AI readiness review and roadmap service. It assesses readiness across AI usage, identity, data security, device management, governance, monitoring and attack-surface exposure. The assessment is benchmarked against the NCSC Maturity Model and mapped to the MITRE ATLAS framework for AI threats.
The service covers approved, embedded and unsanctioned AI across the organisation. It produces six connected outputs:
These outputs are brought together in a comprehensive report and a board-ready presentation.
The purpose is not to produce another generic risk catalogue. It is to give leaders a clear view of how AI is being used, where control gaps exist and which practical actions should come first. This supports informed decisions and measurable progress.
Data loss prevention is essential, but AI requires a broader view than isolated policy events. Effective security must consider users, identities, data, source applications, AI services, integrations, destinations and the reasons behind activity. This is key to protecting business information and supporting compliance.
Microsoft Purview can apply data security and compliance protections to generative AI use. Microsoft also states that Copilot honours usage rights where information is protected through Purview Information Protection, including sensitivity-label encryption. Copilot interaction data can be managed through capabilities including Content Search, retention policies and Microsoft Purview.
Not all AI use carries the same risk. Controls should match the sensitivity of the information involved. A balanced approach combines prevention, guidance, monitoring and approved alternatives.
This avoids the extremes of unrestricted adoption or blanket bans. Good governance enables safe innovation and gives leadership the visibility and control needed for high-risk activity. It turns AI from a risk into a business enabler.
Book an AssureAI evaluation: AssureAI: AI Readiness Review & Roadmap
Where is your data going? The answer is rarely a single platform or destination. Data can move through Microsoft 365, AI-enabled SaaS applications, third-party agents, browser extensions and user-led workflows within a single business process.
This does not mean organisations should retreat from AI. It means governance must follow the data wherever it moves.
The model is not the whole risk. Permissions, identities, sharing, application trust and accountability shape the exposure behind it. Data loss prevention works best when supported by wider visibility into how information is accessed and where it moves. Shadow AI is both a security concern and a sign that employees see real value in AI-enabled working. The right controls can turn this into an advantage.
The organisations best placed to benefit from AI are not those that try to remove every uncertainty before moving forward. They are those that can see where their data is going, understand why it is moving and make deliberate decisions about the controls that should accompany it. This is how to move from risk to resilience.
Governing shadow AI? Book your place on our webinar: Taking Control of AI & the Tools Nobody Approved