Oversharing and AI: Why Copilot Turns a Hidden Risk into an Urgent One

Key takeaways

  • Oversharing (content accessible to far more people than intended) exists in almost every organisation, but has long been a latent
  • AI assistants like Copilot make everything a person can access instantly findable, turning latent oversharing into an active exposure.
  • Copilot doesn’t break permissions; it faithfully respects them. The problem is that those permissions are often far too broad.
  • The fix has three parts: find the oversharing, contain it during your AI rollout, and remediate it properly.
  • Addressing oversharing is the single most important preparation for a safe Copilot deployment.

A risk that was always there

In many organisations, oversharing has been quietly accumulating for years. A folder shared with “everyone” to save time. A SharePoint site left open because nobody got around to restricting it. A document link forwarded once and never revoked. A Teams channel whose membership grew far beyond those who genuinely needed access. Individually, each decision often seems harmless. Collectively, they can result in content being accessible to a much broader audience than originally intended.

None of this happens through carelessness or bad intent. It is often the natural by-product of busy people getting work done. In a small business or a non-profit, where one person may wear several hats and dedicated information governance resources are limited, the pressure to share quickly is constant. A new starter needs access to a project, so they are added to a broad group that grants far more access than the project requires. A volunteer is added to a site so they can view a document, and that access remains long after their involvement has ended. A finance file is placed in a general team area “just for this week” so a colleague can review it, then remains there for years. Each shortcut solves an immediate problem while quietly expanding access in ways that may never be revisited.

Staff turnover can add to the challenge. People change roles, projects conclude, and contractors come and go, yet the permissions they accumulate do not always follow them out the door. Over time, the gap between who can access something and who genuinely needs access can widen, often without anyone noticing.

For a long time, this was a latent risk. The sensitive salary spreadsheet might technically have been accessible to half the organisation, but in practice few people would ever encounter it because finding it required knowing it existed and having some idea of where to look. The exposure was real, but the likelihood of someone stumbling across it remained relatively low. In many cases, oversharing remained largely unnoticed because finding information still required time, effort and context.

Artificial intelligence changes that equation significantly and understanding that shift is an important part of preparing for an AI assistant rollout.

What AI changes

AI assistants such as Microsoft 365 Copilot are designed to do one thing particularly well: find and surface relevant information from across the information a user already has access to. Ask Copilot a question, and it can search documents, emails and messages across SharePoint, OneDrive, Exchange and Teams, retrieve relevant information, and present it in seconds. This is enormously valuable and, ultimately, the reason these tools exist. However, it also changes how organisations need to think about access and permissions.

One important principle sits at the heart of this:

Copilot respects existing permissions exactly.

It will not show users information they do not already have permission to access. On the surface, that sounds reassuring, and rightly so. The implication worth considering is that if a user can technically access something, even if that access was granted accidentally years ago, Copilot can now find and surface it quickly and naturally.

Two things make this shift particularly significant.

First, Copilot reduces the effort required to find information. What once depended on knowing a file existed, understanding roughly where it was stored, and searching for it manually can now begin with a simple question.

Second, it removes much of the technical barrier to discovery. Staff do not need to understand folder structures, search syntax or site hierarchies. They simply ask for information in the same way they might ask a colleague.

Risks that once sat quietly in the background become much easier to surface.

That salary spreadsheet nobody could find? A staff member asking Copilot, “What do we pay people in my team?” may now uncover it. A confidential board paper stored on an overly accessible site could appear in response to an innocent question. A redundancy discussion sitting in an email thread may be incorporated into a generated summary.

Copilot has not bypassed security controls or broken any rules. It has simply worked within the permissions it was given. AI does not create the oversharing problem; it makes existing access issues far more visible.

Why this matters for an AI rollout

This is why oversharing is the number one readiness issue for organisations adopting Copilot. Switching on a powerful AI assistant across an environment with years of unaddressed oversharing is, in effect, handing every staff member an extraordinarily efficient tool for discovering whatever they were accidentally allowed to access. For organisations handling personal, client, financial or member information (which describes most SMEs, corporates, and non-profits), the consequences range from embarrassing to seriously damaging.

Consider what is typically at stake. A professional services firm holds confidential client matters that must stay within a small team. A charity holds donor records, beneficiary details and sometimes deeply sensitive case information. Almost every organisation holds payroll data, HR files, board papers and commercial information that was only ever meant for a handful of people. If any of that has been overshared, an AI assistant can bring it to the surface for the wrong person without anyone intending harm. Beyond the immediate discomfort, there are real privacy and confidentiality obligations in play, and the trust of clients, members, donors and staff is not easily rebuilt once it is dented.

The encouraging news is that this is an entirely solvable problem, and solving it is far cheaper and less painful before a rollout than after an incident. It comes down to three steps: find it, contain it, and fix it.

Step one: Find the oversharing

You cannot address what you cannot see, so the first step is understanding where oversharing exists.

Microsoft provides tooling to help with this. SharePoint Advanced Management includes data access governance reports that highlight sites and content that may be shared too broadly, such as content shared with “everyone” or through organisation-wide links.

These reports help organisations make sense of large and often complex information environments by identifying which sites are most widely shared, where organisation-wide links are being used, and which locations may warrant further investigation.

Microsoft Purview Data Security Posture Management (DSPM) for AI complements this by highlighting where sensitive information may be exposed to AI tools specifically. Rather than viewing sharing purely through an access lens, it helps identify where confidential content intersects with AI access, allowing organisations to focus on areas that combine broad permissions with sensitive information.

Together, these capabilities help turn a vague concern into a more practical and prioritised view of what may need attention. The goal is not to remediate everything immediately, but to understand the shape and scale of the issue so that efforts can be prioritised sensibly.

Step two: Contain it during your rollout

Addressing years of accumulated access issues takes time, and most organisations do not want to delay the benefits of Copilot while that work is underway. Microsoft’s answer is Restricted Content Discovery (RCD).

RCD allows organisations to limit discovery of specific SharePoint sites so that their content does not appear in Copilot or organisation-wide search results, even where permissions would otherwise allow access. Sites covered by the policy are marked as “Restricted”, making them easier to identify and manage.

Importantly, it is designed as a temporary governance control. It provides a practical way to continue rolling out Copilot while reviewing and right-sizing access to sensitive locations.

In practice, this allows organisations to progress with their rollout while maintaining additional caution around content that has not yet been reviewed. Staff can benefit from AI across validated content, while more sensitive areas remain under assessment until permissions have been confirmed.

A common approach is to use the visibility gained in step one to identify higher-risk sites, place those locations under RCD before enabling Copilot more broadly, and then review them methodically over time.

Step three: Fix it properly

Containment creates breathing room; it is not a long-term solution. The lasting improvement comes from reviewing and right-sizing access across the environment.

  • Apply least privilege. Provide access to what people genuinely need rather than what was convenient to share. Review broad “everyone” permissions and organisation-wide links, particularly around sensitive content.
  • Review site and group membership. Examine who actually requires access to sites, channels and document libraries, paying particular attention to broad groups that may grant more access than expected.
  • Use sensitivity labels. Apply Microsoft Purview sensitivity labels to important information so that protection remains with the content wherever appropriate. A well-labelled document can retain protections even when copied, moved or shared.
  • Establish ongoing governance. Oversharing tends to develop through everyday working habits, so maintaining sensible defaults, periodic access reviews and content lifecycle processes helps reduce the likelihood of issues returning over time.

This is why many organisations choose to include a dedicated protect stage before broad AI enablement. Getting access right helps create the conditions for confident AI adoption rather than becoming a barrier to it.

A short, worked example

Consider a mid-sized non-profit preparing to roll out Copilot.

In step one, its data access governance reports reveal that a long-forgotten “Shared Resources” site was opened to everyone in the organisation years ago and still contains a folder of board minutes alongside a spreadsheet of staff salaries. The same reports also flag two project sites where organisation-wide sharing links remain active long after the projects have closed.

In step two, the organisation places those three sites under Restricted Content Discovery. Copilot is enabled across the rest of the environment, allowing staff to begin benefiting from AI in their day-to-day work, while the higher-risk sites are temporarily held back and clearly marked as Restricted.

In step three, the team works through each site in turn. The board minutes are moved to a properly secured location accessible only to board members and the executive team. The salary spreadsheet is relabelled with a confidential sensitivity label and restricted to payroll and HR staff. The outdated project links are removed, and access is reviewed and aligned to the people who still require it.

As each site is reviewed and corrected, the Restricted designation is removed, and the content becomes available to Copilot for the appropriate audience. Staff gain access to the benefits of AI early in the rollout, while potential risks are managed throughout the process and underlying access issues are addressed along the way.

Common pitfalls

A few common mistakes can make remediation efforts harder than they need to be.

The first is treating containment as the finish line. Restricted Content Discovery is designed to create breathing room while access is reviewed, but leaving sites permanently marked as Restricted can result in important governance work being deferred rather than completed.

The second is trying to fix everything at once. In most environments, it is more effective to use the available visibility and reporting tools to identify higher-risk content first and work through issues in a prioritised way.

The third is assuming the problem stays solved. Oversharing tends to develop gradually through everyday working practices, so without sensible defaults, access reviews and ongoing governance, permission issues can slowly reappear over time.

The fourth is viewing this purely as an IT responsibility. While IT teams play an important role, the people best placed to determine who should have access to a particular site, document library or team are often the people who own and use that content every day. Effective remediation usually works best as a collaboration between technology teams and business stakeholders.

A clear, practical priority

For organisations preparing to adopt Copilot or another AI assistant, reviewing oversharing and access permissions is often one of the most valuable places to start.

The first step is understanding where content may be overexposed. From there, controls such as Restricted Content Discovery can help manage risk during rollout, while longer-term remediation focuses on appropriate access controls, least-privilege access, sensitivity labels and ongoing governance.

Approached in this order, organisations can begin realising the benefits of AI while maintaining confidence in how information is accessed and protected.

The underlying access issues already exist. AI simply makes it easier for users to discover information they have permission to access. Addressing those issues before broad enablement typically leads to a smoother rollout and fewer surprises down the track.

At 365 Architechs, we help SMEs, corporates and non-profits prepare for Copilot by identifying and addressing oversharing risks, applying practical governance controls and supporting secure AI adoption from the outset.

Planning a Copilot rollout? Contact 365 Architechs for an oversharing and readiness assessment.

Author picture

Tim Timchur, Managing Director, 365 Architechs, is a qualified accountant, cybersecurity professional and governance and risk management expert.

Categories

Tags