AI & TechArtificial IntelligenceCybersecurityDigital MarketingNewswireTechnology

Microsoft Copilot Delayed Over Security Concerns

▼ Summary

– Two-thirds of organizations have delayed or cancelled Microsoft Copilot deployment due to fears it could expose confidential data.
– Security concerns stem from confusion over Copilot’s access and permissions, particularly regarding SharePoint data leakage.
– C-level executives are most likely to pause Copilot rollouts, with 75% issuing delays, compared to 60% of managers.
– 73% of those delaying cited worries that AI could surface confidential information from within the organization.
– Experts recommend applying security controls like privileged access management and auditing SharePoint permissions to mitigate risks.

A new survey reveals that two-thirds of organizations have delayed or completely abandoned deployment of Microsoft Copilot, driven by fears that the AI assistant could inadvertently expose confidential data. The findings, drawn from CoreView’s State of Microsoft 365 Security and Governance 2026 report released July 21, highlight deep-rooted security anxieties surrounding the rollout.

At the heart of the concern lies a data governance problem, particularly with SharePoint. Many organizations worry that deploying Copilot could surface sensitive information stored in SharePoint, especially given confusion over the precise access and permissions the AI tool holds. Specific risks include data leakage and SharePoint sharing links that could extend outside the organization.

The decision to pause or cancel Copilot deployment is most prevalent among C-level executives. According to the survey, three out of four executives at this level have ordered a delay across their organizations, alongside 60% of managers. “It is the most senior leaders who are pausing, because they can see exactly what AI will surface , a decade of sharing links and permissions nobody cleaned up,” said Simon Azzopardi, CEO of CoreView. “The risk was always there but AI has made it visible and urgent.”

Among organizations that have halted or scrapped a Copilot rollout, nearly three-quarters (73%) cited the fear that AI could be used to surface confidential internal information. The report noted, “For a Microsoft flagship product with enormous executive mindshare, that is a striking level of organizational hesitation.”

CoreView traces much of this hesitation back to previous security incidents involving Microsoft 365. These incidents were often linked to the absence of foundational security controls such as administrator multi-factor authentication (MFA), privileged access management (PAM), or configuration tamper detection. Cybersecurity leaders worry that the same vulnerabilities could now be exploited through Copilot.

To address these concerns, the report recommends that organizations apply security controls like PAM to both user and Copilot accounts to prevent unauthorized access and data exfiltration. Additionally, companies should thoroughly review permissions and access for SharePoint applications, ensuring that data cannot be inadvertently shared , whether by AI tools or human users.

(Source: Infosecurity Magazine)

Topics

microsoft copilot deployment 95% data exposure risks 93% data governance issues 90% c-level decision making 88% ai security concerns 87% sharepoint permissions 85% cybersecurity incidents 83% organizational hesitation 82% security controls 80% data leakage prevention 78%