Microsoft Copilot Deployments Stalled by Data Exposure Fears
A significant portion of organizations are delaying or canceling Microsoft Copilot deployments due to concerns that the AI assistant could expose confidential data, a new survey reveals.

A recent survey indicates that two-thirds of organizations have put the brakes on or completely halted the deployment of Microsoft Copilot, citing serious security concerns. The primary worry revolves around the potential for the AI-powered assistant to inadvertently expose sensitive and confidential data within enterprise environments.
CoreView's "State of Microsoft 365 Security and Governance 2026" report, released on July 21st, highlights widespread apprehension among security leaders regarding the implementation of Copilot. A key area of concern is the AI's access to confidential SharePoint data, which is often exacerbated by existing data governance challenges within organizations.
Respondents expressed confusion and anxiety regarding the specific access and permissions granted to Microsoft Copilot. These concerns are largely focused on the risk of data leakage or the unintended sharing of sensitive information through external SharePoint links, potentially exposing proprietary or private data to unauthorized parties.
Leadership appears to be the driving force behind these deployment delays. The survey found that a substantial majority of C-level executives (75%) have instructed their organizations to pause Copilot rollouts. Similarly, 60% of managers have also made the decision to delay or cancel deployments due to these security apprehensions.
"It is the most senior leaders who are pausing, because they can see exactly what AI will surface - a decade of sharing links and permissions nobody cleaned up. The risk was always there but AI has made it visible and urgent,” stated Simon Azzopardi, CEO of CoreView. This sentiment underscores how AI's capabilities are bringing previously hidden data governance issues to the forefront.
For organizations that have indeed delayed or canceled Copilot deployments, nearly three-quarters (73%) cited the risk of AI surfacing confidential internal information as the main reason. This hesitation is particularly notable for a flagship Microsoft product that has garnered significant executive attention, indicating a substantial gap between product adoption and security readiness.
CoreView suggests that many of these hesitations stem from prior negative experiences with security incidents within Microsoft 365 environments. These past breaches were often linked to the absence of fundamental security controls such as multi-factor authentication (MFA) for administrators, privileged access management (PAM), or robust configuration tamper detection.
To mitigate these risks, security experts recommend implementing stringent controls like PAM for both user and Copilot accounts to prevent unauthorized access and data exfiltration. Furthermore, a thorough examination of SharePoint application permissions and access controls is crucial to ensure that AI applications, like Copilot, or human users cannot inadvertently expose sensitive data.