Microsoft 365 Copilot opens no new access path. It condenses every existing SharePoint and OneDrive permission into a prompt hit — including the broken ones. A rollout without a permissions audit and a documented flex-routing decision buys a picture of your own configuration debt.
Many mid-market rollouts do not fail on the licence. They fail the moment someone asks for contracts with bonus clauses or a list of salary agreements — and Copilot delivers. Not because the model bypasses rights. Because those rights have been too wide for years.
The mechanism is simple
Copilot stays inside the existing permission model. Whatever an account may read in SharePoint or OneDrive, that account’s Copilot may read too. Classic search listed hits. Copilot summarises them, adds context, and hands them on. That is what turns oversharing into an operational risk: organisation-wide sites, shares set to everyone, broken inheritance, and sites without sensitivity labels. Microsoft names these patterns in its own Purview documentation. Malicious intent is rarely required. Configuration debt is enough.
An early attack path (“SearchLeak”) showed the new surface after enablement. That path has been closed since the beginning of June 2026. The lesson remains: open permissions plus language-driven access create a surface that did not exist in the same way before rollout.
Flex routing: storing is not processing
Since spring 2026, flex routing applies to EU and EFTA tenants. At peak load, LLM inference for individual requests may run outside the EU Data Boundary, including the United States, Canada, and Australia. Data at rest stays largely in the EU, except for limited pseudonymised operational data. For new tenants the setting has been on by default since 25 March 2026.
A data-protection impact assessment that rests only on “everything stays in the EU Data Boundary” may rely on an assumption that no longer holds in your tenant. Flex routing can be switched off in the Microsoft 365 admin center. Inference then stays in the EU even under load. Check the setting, document the decision, and update the assessment before you approve the rollout.
AI Act: labelling, but not for every internal output
A company that uses Copilot under its own authority is a deployer. Article 50 transparency duties have applied since 2 August 2026, but not as a blanket rule for every Copilot output. They matter most for deepfakes and published AI text of public interest that has not had editorial review. Internal meeting summaries, email drafts, and in-house document analysis usually fall outside that. High-risk duties under Annex III apply only from 2 December 2027.
Setting the two up separately — Copilot governance now, a high-risk inventory in 2027 — means paying twice. The same inventory (use cases, data categories, human oversight) is already the base.
What should exist before the first licence
- Audit permissions first. Inventory organisation-wide shares and test them against real need. Purview Data Security Posture Management checks the hundred most-used SharePoint sites weekly by default. Start where usage is highest.
- Classify before the first prompt. Bind sensitivity labels for contracts, HR data, and finance files to restrictive policies that limit Copilot access to highly sensitive classes.
- Decide flex routing and write it down. On or off are both valid. Undocumented is the gap in the evidence.
- Name the roles. Who reviews AI output before reuse, who reports anomalies, who decides exceptions. Without names, every policy stays paper.
- Governance without enforcement is theatre. A policy plus e-learning, with no technical control and no record of breaches, documents only that you knew the risk. Shadow AI grows where the official path takes weeks. A fast approval path cuts workarounds more effectively than a ban alone.
Conclusion
Copilot is not a new perimeter problem. It amplifies what is already wrong in the tenant. Before the licence, oversharing, flex routing, and named owners belong in the asset, risk, and decision registers — not after the first prompt summarises the salary list.
Record the permissions audit, flex-routing decision, and named oversight in deveca GRC