Microsoft’s documentation on Microsoft 365 Copilot is unambiguous: Copilot “can only summarize or reference content that the user is authorized to access.” It works within your existing permissions rather than around them.
Executives usually hear that as reassurance. It is not. It means that on the day you switch on an AI assistant, every permission mistake your organisation has made over the past decade becomes searchable in plain English.
The gap between having access and finding things
For years most organisations have run on a quiet assumption: that a file nobody can find is effectively a file nobody can read. A salary spreadsheet dropped into a site shared with “everyone in the organisation” in 2019 was technically open to four hundred people. In practice it sat eleven folders deep and nobody stumbled across it.
An AI assistant removes that friction entirely. It does not browse folders, it answers questions. “What is the senior team paid?” becomes a query rather than an expedition, and the answer is assembled from documents the person asking was, technically, always allowed to open.
Nothing was breached. No control failed. The permissions worked exactly as configured. That is what makes this hard to catch in an audit and easy to miss at board level.
What labelling does, and what it does not
Sensitivity labelling is the usual answer, and it is a good one. It is also frequently oversold internally.
Labels do real work. Copilot inherits the highest-priority label from the sources it draws on, so a summary built from confidential material carries that label forward. Encrypted content requires the user to hold extract and view rights before Copilot will touch it at all. Files carrying user-defined label permissions cannot be read by Copilot agents.
But labels only protect what has been labelled. In most organisations that means recent documents, in specific systems, created by people who happened to be trained. The exposure sits in everything else: a decade of unlabelled files inherited through migrations, acquisitions, departed employees and abandoned team sites.
Labelling is a control on new content. It is not a remedy for old permissions.
Where Canadian law actually sits
It is worth being clear about this, because there is a great deal of confusion. Canada does not have an AI Act. The Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued in January 2025, and has not returned in that form.
What governs AI use in Canada today is the law that already applied. PIPEDA still requires that personal information be used only for the purposes it was collected for, which becomes a live question when an assistant compiles personal data from across your systems. In Quebec, Law 25 imposes specific obligations where a decision about someone is made exclusively by automated processing.
The absence of a dedicated statute is not the absence of obligation. It means the obligation reaches you through privacy law rather than AI law, and through your customers’ contracts and security questionnaires, which are moving considerably faster than legislation. ISO/IEC 42001, the AI management system standard, is where a good deal of that demand is now settling.
Three questions worth asking before you deploy
- If we switched this on tomorrow, which document library would embarrass us first? If nobody can answer, that is the answer.
- What proportion of our files carry a sensitivity label, and who applied them?
- Who reviews permissions on sites created by people who have since left?
None of these require technical expertise to ask. All three reveal whether the groundwork exists.
The pattern we keep seeing
Organisations rarely have an AI problem. They have a decade-old file permissions problem that an AI assistant has made visible and urgent at the same time. The work is unglamorous — permission review, labelling, retention, tidying up sites nobody owns — and it is almost always cheaper before a deployment than after one.
Expert projects and consultation
Alongside our certification work, we take on advisory and project engagements: readiness reviews ahead of an AI rollout, permission and labelling assessments, and hands-on remediation where it is needed.
If you are weighing up a deployment and want an independent read on whether your data estate is ready for it, get in touch.
