Before you point AI at SharePoint: the permissions problem

A folder icon with a magnifying glass revealing a hidden network of connected file icons behind it, representing unseen SharePoint permissions

Somewhere in your SharePoint, there is probably a folder someone can technically open but has never once clicked on. Maybe it is a stale HR share, an old finance site from a reorg three years ago, or a “temporary” link someone sent a contractor and forgot to remove. Nobody worries about it, because in practice, nobody goes looking.

An AI tool connected to that same SharePoint does not have that limit. It does not get bored, forget a folder exists, or decide a search is not worth the effort. If a person can technically see it, the AI can too, and it will read all of it in seconds if the right question gets asked.

Copilot does not create this problem. It finds it.

This applies most directly to Microsoft 365 Copilot, since that is what most businesses are connecting to their existing files first. The same logic holds for any AI tool given access to a shared drive. Copilot does not bypass your permissions. It strictly respects them. Whatever a user is allowed to see, Copilot can read, summarize, and quote back when that user asks it a question.

That sounds safe, and on paper it is. The trouble is what “allowed to see” actually adds up to inside most companies’ SharePoint after a few years of normal use. Access grants pile up. A folder gets shared broadly for one project and never gets locked back down. Someone gets added to a group for a single task and stays in it permanently. None of that gets cleaned up, because cleaning up permissions has never been anyone’s job, and nothing forced the question until now.

What “the AI has your permissions” actually means

Before Copilot, that pile of forgotten access mostly stayed theoretical. A person would have needed to know a specific folder existed, guess its name, and dig through several clicks to find it. Most people never bothered, so the exposure sat there unused.

An AI assistant removes that friction entirely. Someone asks a completely ordinary question, something like “pull together everything relevant to the Q3 planning meeting,” and the assistant searches everywhere that person has access, not just the folder they meant. If an old HR share or a finance folder happens to be in that access list, the answer can include it without the person doing anything that looks like snooping. They asked a normal question and got an answer built from files they had access to but no reason to know about.

Warning: This is not a hypothetical edge case. Independent research into live Microsoft 365 tenants backs this up. A meaningful share of business-critical data sits overshared this way, often reaching into the hundreds of thousands of exposed files at a mid-size organization before anyone looks.

Where this actually shows up

We see this pattern constantly when we look at a new client’s SharePoint for the first time, and it repeats in a few predictable shapes. A departed employee’s old files stay shared to “everyone except external users” because nobody remembered to lock them down when the person left. A project site from two years ago still has half the company on it because it was easier to add people than to manage who needed access. A sharing link someone generated for a one-time file drop never expired, and the file sitting behind it changed since then.

None of these were security incidents when they happened. They were just normal collaboration, the kind every growing business accumulates. AI does not create that mess. It just makes the mess searchable in one prompt instead of buried across a thousand folders nobody opens.

The number behind this

Concentric AI’s Data Risk Report is based on an analysis of hundreds of millions of records across real organizations. It found that roughly one in six pieces of business-critical data sits overshared, averaging somewhere around 800,000 exposed files per organization. That is not a small-company or a large-company problem specifically. It is what normal file sharing looks like after enough years without anyone reviewing it, which describes most businesses whether they have twenty employees or two thousand.

A short check before you turn this on

You do not need a full security audit to make a meaningful dent in this before connecting an AI tool to your files. We usually recommend starting with a few checks that catch most of the risk.

  • Search for SharePoint sites shared to “everyone” or “everyone except external users,” and confirm each one is meant to be that open.
  • Look for sharing links with no expiration date, especially on financial, HR, or client files.
  • Check whether departed employees’ old files and sites were locked down when they left, not just their login.
  • Confirm your HR and payroll folders are restricted to the people who actually need them, not the department they happen to sit next to.
  • Ask whoever manages your Microsoft 365 tenant whether sensitivity labels are turned on for anything that should never show up in an AI-generated summary.

Any single yes on that list, meaning a gap rather than a clean answer, is worth fixing before broader AI access gets turned on, not after.

Common questions

Does this mean Copilot is unsafe?

Not on its own. Copilot honoring your existing permissions is exactly the correct, secure design. The risk was already sitting in your SharePoint before Copilot arrived. What changes is that the risk becomes far easier to stumble into by accident, since a normal question can now surface it in a normal answer instead of requiring someone to go looking.

Do we need to fix everything before turning on any AI tool?

No, and waiting for a perfect tenant before starting is the wrong bar. Fixing the highest-risk sites first, the ones with broad sharing and sensitive content like HR, payroll, legal, and finance, covers most of the real exposure. A staged rollout that starts with a smaller pilot group while permissions get cleaned up in the background is a reasonable middle ground.

Is this only a Microsoft 365 and SharePoint problem?

Copilot is the most common way small businesses run into this today, since it is often the first AI tool connected directly to existing files. The same logic applies to any AI tool given access to a shared drive, whether that is Google Drive, a CRM, or a project management tool. Whatever the AI is allowed to see, it will find, so the permissions review matters regardless of which platform is involved.

Who is supposed to be checking this?

In most small and midsize businesses, nobody has been, because permission cleanup was never anyone’s assigned task. We think of it as belonging with IT or a managed provider going forward. Ideally it is the same person or team responsible for turning on AI features in the first place, so the access review and the rollout happen together instead of one after the other.

What about the never list from our AI policy?

The never list covers what a person actively types into an AI tool. This is a different exposure. Nobody has to paste anything for an overshared folder to surface, since the AI can find and read it on its own once it has access. Both gaps matter, and neither one covers the other.

Where to start

Pull a permissions report for your most sensitive SharePoint sites before you expand who has AI access to your files, not after. It is a smaller task than it sounds like. It is also far easier to do before an AI tool starts surfacing what is already exposed than after someone finds a document in an AI answer that should never have been reachable in the first place.

This is also exactly the kind of review our team does before turning on AI tools for a client, since it takes specific tooling to see permission sprawl clearly across a real tenant. If you want a second set of eyes on what your current setup actually exposes, we are happy to take a look. That conversation is free, and it usually turns up at least one thing worth fixing regardless of what you decide about AI.