There’s a common misconception circulating a lot right now: that deploying AI in a company is risky because AI has access to sensitive data.
There’s a common misconception circulating a lot right now: that deploying AI in a company is risky because AI has access to sensitive data. That’s the wrong way to frame the issue. As Stéphane Perrenoud, a U-consultant at UDITIS, puts it: “Copilot doesn’t create new risks; it reveals the ones that already exist.”
In other words: It’s not AI that exposes your data. It’s what you haven’t done yet that exposes it.
AI as a revealer
Copilot respects the existing permissions in your Microsoft 365 environment. It sees only what the user who queries it is authorized to see. If an employee in accounting can access HR data that they shouldn’t be viewing, Copilot will grant them access to that same data. This isn’t an AI bug. It reflects improperly configured access rights.
This is precisely why the question isn’t “Should I be afraid of AI?” but “Is my environment ready for it?”
What “getting organized” means in practice
Before enabling anything, there are a few fundamental questions a company must be able to answer. Where is my data located—in SharePoint, Teams, OneDrive, or email? Who has access to it, and is that access still justified? Are the documents classified—that is, labeled as public, internal, confidential, or sensitive?
This process of mapping and classifying data is not new. It should exist independently of AI. But the arrival of Copilot makes it a concrete priority, because a document that is misclassified or accessible to too many people will be processed by AI exactly as it is processed today: without any filters.
Microsoft Purview, the governance tool integrated into the Microsoft ecosystem, allows you to manage this classification, enforce data loss prevention (DLP) policies, and ensure that AI only accesses what it needs to. DLP policies are enforced before any response is generated by Copilot.
Three levels of copilot, three levels of requirements
Microsoft’s Copilot ecosystem is not monolithic. There are several levels, each tailored to different use cases.
- Copilot Chat is the basic assistant, included in existing M365 and Office 365 licenses. It allows you to search, write, and summarize, but it primarily operates on public data, without a direct connection to your corporate files.
- Copilot for Microsoft 365, available for approximately 17 francs per month per user, goes much further: it’s integrated directly into Word, Excel, Outlook, and Teams. It can summarize a Teams meeting, analyze a document, and draft an email based on internal context. This is where data governance becomes critical, because this is where AI truly begins to work with your information.
- Copilot Studio, meanwhile, allows you to create specialized agents connected to your systems, your CRM, your ERP, and your internal knowledge bases.
UDITIS’s role in this process
Preparing a Microsoft 365 environment to support AI is a multifaceted task that involves: inventorying and mapping existing data, reviewing access rights based on the principle of least privilege, implementing classification and protection policies, securing identities with multi-factor authentication, and finally, raising awareness among teams about what AI can and cannot do.
UDITIS supports its clients at each of these stages, prior to the deployment of Copilot, to ensure that enabling AI delivers value rather than highlighting what should have been done long ago.
The rest of this series
This article sets the stage. The following articles will delve into specific use cases: what Copilot Chat and Copilot for Microsoft 365 can actually do on a day-to-day basis, how AI agents work and integrate into an existing information system, and finally, what Copilot Cowork represents, Microsoft’s next step toward truly agent-based AI, capable not only of assisting but also of taking action.