NSP Insights for NZ Businesses

What Can Your Staff See? The AI Question for NZ Businesses | NSP

Written by NSP Marketing | Sep 8, 2026, 9:47:34 PM

Copilot Isn't Creating Your Data Problem. It's Just Making It Impossible to Ignore.

 

Here's a scenario that's playing out in NZ businesses right now.

Leadership has decided to roll out Microsoft Copilot. The conversation in the meeting was about productivity - saving time on meeting notes, drafting faster, getting more value from the Microsoft 365 investment already sitting in the business. Someone ran the numbers on time saved per person per week. It looked compelling.

IT was asked to get it set up. A handful of licences were purchased. Copilot went live for a pilot group.

Within days, something unexpected happened. A staff member asked Copilot to summarise recent documents about a specific project. The summary included content from a SharePoint site she technically had access to - but had never known existed. The site contained information from a business review three years earlier. Sensitive information about performance, restructuring considerations, and commercial margins. It had been sitting there the whole time, accessible to anyone in the organisation, undiscovered simply because nobody had known where to look.

Copilot knew. Because Copilot can see everything the user can see - and it can find it in seconds.

The business hadn't created a new security problem by deploying Copilot. It had discovered one it already had.

 

AI Doesn't Need to Create a Data Problem to Expose One

Microsoft is direct about how Copilot works. In a July 2026 post on the Microsoft Community Hub, the FastTrack team put it plainly: "Microsoft 365 Copilot does not create new permissions or expose data users cannot already access. What it does do is make existing access more discoverable, bringing years of accumulated oversharing, excessive permissions, unlabeled content, unmanaged connectors, and governance gaps into sharper focus."

Read that sentence twice. Copilot doesn't give anyone access they didn't already have. It just makes using that access - finding things, connecting information, surfacing content - dramatically faster and easier.

For most businesses, that's a compelling reason to adopt it. The efficiency gains from having an AI assistant that can traverse your organisation's documents, emails, Teams conversations, and SharePoint sites are real.

But it means something else too. If your Microsoft 365 environment has data governance problems - and most environments do, after years of organic growth - Copilot doesn't create those problems. It surfaces them. At scale. For every user with a licence.

The question isn't whether AI is safe. The question is whether your data environment is ready for AI to see all of it.

 

The Information Your Business Has Forgotten About

Most NZ businesses that have been running Microsoft 365 for more than three years have an information problem they can't fully see.

It starts simply. A SharePoint site is created for a project. Documents are uploaded. The project ends. The site stays. Two years later, nobody remembers it exists - but the permissions are still there, still granting access to everyone who was involved at the time, and sometimes to everyone in the organisation.

A Teams channel is created for a specific initiative. Sensitive documents are posted in the channel - salary benchmarks, commercial proposals, M&A research, HR investigations. The team assumes the channel is private. It isn't configured that way. The content is accessible to every member of the parent team, which includes staff who joined the organisation long after the channel was relevant.

A finance manager shares a folder with a colleague. She uses the default "anyone with the link" option because it's faster. The link is still active. The colleague left the company 18 months ago.

None of these are dramatic events. Each is a small, individually reasonable decision made under time pressure in a busy organisation. Together - across years of growth, staff changes, new projects, and evolving team structures - they create what Microsoft's guidance describes as "governance debt": an accumulated layer of sharing decisions, permission settings, and access configurations that no longer reflect how the business actually intends information to flow.

Microsoft's deployment guidance notes this pattern consistently. Common oversharing scenarios include sites containing salary data, M&A documents, or customer information set to "everyone in the organisation"; inherited folder permissions that cascade access to sensitive subfolders; public Teams channels where confidential information was posted under an assumption of limited visibility; and legacy sharing links from years-old collaborations that remain active without anyone monitoring them.

Before Copilot, this governance debt was largely invisible. Employees could technically access the information, but they had to know it existed, know where to find it, and navigate SharePoint to get to it. Most of the time, they simply didn't bother.

AI removes that friction entirely.

 

When "Everyone Has Access" Becomes a Problem

To understand why this matters, it helps to understand how Copilot accesses information.

Copilot works through Microsoft Graph - the API that underpins Microsoft 365. When a user asks Copilot a question, it searches across the content that user can access: emails, Teams messages, SharePoint files, OneDrive documents, calendar entries. It finds relevant content, synthesises it, and returns a response.

It doesn't ask whether the user was supposed to have access to the content it found. It doesn't distinguish between files the user actively chose to access and files they technically had permission to access but never knew existed. As Microsoft's own guidance states: "If a user can view a document, Copilot can summarise, interpret, or reference it as contextual data. This makes unintentional access exactly as dangerous as intentional access."

That distinction matters enormously. A staff member who would never search through a SharePoint site they don't recognise will absolutely ask Copilot a question - about a project, a client, a budget, a competitor - and receive an answer that draws on content they had access to but didn't know existed.

The scenarios Microsoft has documented are instructive. A prompt like "summarise our compensation planning" can surface a salary spreadsheet from a SharePoint site configured for the whole organisation three restructures ago. An HR investigation folder with broken permission inheritance - after external counsel was given temporary access and the permissions weren't restored - surfaced workplace investigation details when a user asked Copilot about a specific employee.

These aren't theoretical edge cases. EPC Group, which has prepared more than 700 Microsoft 365 tenants for Copilot deployment, reports finding an average of 150 to 300 overshared SharePoint sites per enterprise tenant. The patterns are consistent across organisations: "Everyone except external users" groups, broken permission inheritance, anonymous sharing links, and legacy "All Employees" security groups - all of them invisible in day-to-day operations, all of them suddenly relevant when an AI assistant starts traversing the tenant.

For NZ SMEs and mid-market businesses - where lean IT teams are managing Microsoft 365 environments that have often grown organically without structured governance reviews - the permission landscape is likely to reflect years of accumulated decisions rather than intentional design.

 

Why AI Changes the Conversation About Information Access

Before AI, information security governance was often framed around what people were likely to access. The practical question was whether a staff member would actually find and read sensitive information they technically had access to.

Most of the time, they wouldn't. The friction of navigating SharePoint, knowing where to look, and having the motivation to search through content outside their immediate work kept most accidental access theoretical rather than practical.

AI removes that friction. It also removes the cognitive barrier of knowing you're accessing something you shouldn't.

A staff member who would feel uncomfortable deliberately navigating to an HR folder and reading confidential documents will ask Copilot a question about a colleague without any sense of crossing a line - and receive an answer grounded in those same documents. The intent is entirely benign. The outcome is the same.

This is what Microsoft means when it describes Copilot making data "trivially findable." The technical access was always there. What changes is the practical ability to surface it quickly, through natural language, without knowing where it's stored or even knowing it exists.

For NZ businesses, there's a specific regulatory dimension to this. Under the Privacy Act 2020, organisations have obligations around how personal information is handled and who can access it. Microsoft 365's default configurations - as OxygenIT's NZ-specific analysis noted in May 2026 - present compliance risks from the outset, with external sharing settings enabled by default across SharePoint and OneDrive that many organisations have never reviewed.

As the NZ Cyber Security Strategy 2026-2030 makes clear, AI-enabled access to personal information at unintended scale is not merely a technical misconfiguration. In a NZ regulatory context, it creates potential notifiable privacy breach obligations under the Privacy Act 2020 - where the threshold for notification is whether the breach is likely to cause serious harm to the affected individuals.

The question of what AI can see is, in part, a Privacy Act question.

 

The Questions Businesses Should Ask Before Connecting AI to Company Data

These aren't IT questions. They're leadership questions - about information, accountability, and what an organisation actually knows about its own data environment.

What sensitive information exists in our Microsoft 365 environment?

Not a general sense of what should be there. A specific, current understanding of where salary information sits, where HR records are stored, where commercial proposals and pricing documents live, where client contracts are filed, where board papers and financial projections are held. If the answer is "I'm not entirely sure," that's the starting point for any AI readiness review.

Who can currently access that information?

Not who should be able to access it based on the original intentions when folders and sites were set up. Who actually can access it today, given staff changes, role changes, project team membership, group configurations, and sharing decisions made over the last several years. These are frequently different things.

Has any of it been shared more broadly than we intended?

SharePoint sites set to "everyone in the organisation." Teams channels with confidential documents that were posted without considering who was in the team. OneDrive files shared via "anyone with the link" links that are still active. Folders with inherited permissions that were never reviewed after temporary access was granted. Microsoft describes these as the four most common oversharing patterns - and they exist in the vast majority of M365 environments that have been in use for more than a few years.

What happens when a staff member asks AI to find information about X?

This is the most useful question to sit with. Pick a category of information your business considers sensitive - salary ranges, a commercial negotiation, an HR matter, a pending acquisition, a client's financial position. Now ask: if a staff member typed a natural language question about that topic into Copilot, what content from across the organisation's Microsoft 365 environment might inform the answer? The response to that question tells you something important about your current permissions landscape.

What AI tools are our staff already using - and with what information?

This is the shadow AI dimension. As we've covered in our series on shadow AI across NZ industries, most NZ businesses have more AI activity in their environment than leadership is aware of. Staff using ChatGPT, uploading documents to public AI tools, pasting client information into AI writing assistants. Before addressing what Microsoft Copilot can see, it's worth establishing what staff are already doing with AI tools that sit entirely outside the organisation's governed environment.

Who is actually responsible for this?

This question usually produces a silence in leadership conversations. Data governance has historically lived in IT - and in smaller NZ organisations, IT is one or two people managing a broad operational remit. The question of what information exists, where it is, who can access it, and whether that access is appropriate isn't a question those people can answer alone. It requires input from HR, Finance, Legal, Operations, and leadership.

 

This Isn't Just an IT Problem

The framing of data governance as an IT responsibility is one of the reasons it stays unresolved. IT can configure SharePoint settings. It can review sharing permissions on individual sites. It can tighten the default sharing options across the tenant.

What it can't do is decide whether the HR investigation records from 2022 should still be accessible to the people who were involved in the investigation. It can't determine whether the commercial pricing document shared with the whole sales team three years ago is still appropriate to share. It can't make a judgement about whether the strategy document accessible to every member of the leadership team Microsoft 365 group should also be accessible to every new hire who joins a leadership-level channel.

Those are business decisions. They require context that IT doesn't have. They require the people who created and are responsible for the information to make judgements about who should access it and under what circumstances.

AI readiness is a leadership conversation dressed in technical clothes. The technical work - reviewing permissions, tightening sharing settings, applying sensitivity labels - follows from the business decisions about what information should be accessible, to whom, and why. Without that upstream clarity, the technical work is incomplete at best and meaningless at worst.

When Microsoft says that oversharing "typically stems from over-permissioned data access paired with under-enforcement of internal controls," the "internal controls" they're describing are governance decisions - made or not made by people with business responsibility for information, not just technical responsibility for systems.

 

Secure AI Adoption Without Slowing Down the Business

None of this is an argument against Copilot. It's an argument for understanding your data environment before you connect AI to it.

The businesses that adopt AI most effectively aren't the ones that move fastest or the ones that move most cautiously. They're the ones that understood their information landscape before they deployed, addressed the governance gaps that AI would have surfaced anyway, and then adopted AI with confidence rather than uncertainty.

That sequence matters. An organisation that reviews its SharePoint permissions, tightens its sharing defaults, identifies and relabels sensitive content, and establishes a clear picture of who can access what before Copilot deployment is in a fundamentally different position from one that deploys first and discovers problems later. The productivity gains are the same. The risk profile is not.

The practical steps are more manageable than most organisations expect:

Understand what you have - A Microsoft 365 governance review maps the current state of your environment - where content is stored, what permissions exist, what's been shared and with whom. Microsoft provides tooling for this through SharePoint Advanced Management and Microsoft Purview. The starting point is visibility.

Address the most significant exposures first - Not every overshared file is equally sensitive. A policy document accessible to the whole organisation is different from salary data accessible to the whole organisation. Prioritisation based on the sensitivity of the content, not just the breadth of the sharing, is how you make the work manageable.

Establish defaults that reflect intention - The reason most Microsoft 365 environments accumulate sharing debt is that the path of least resistance - the default sharing settings - is often too permissive. Changing those defaults doesn't restrict what employees can do; it changes what happens automatically when they don't think about it.

Build ongoing governance, not a one-time cleanup - Microsoft is explicit on this: "Reducing Copilot data exposure is not a one-time cleanup effort but a continuous governance practice." The environment will keep changing - new staff, new projects, new Teams, new sharing decisions. Governance that runs once and then stops will degrade. The businesses that maintain a clean permissions environment are the ones that treat it as an ongoing function rather than a project with a completion date.

Make AI adoption part of a broader security and governance conversation - Copilot deployment is the most compelling forcing function many NZ businesses have encountered for addressing data governance. The urgency that AI adoption creates is real - but the work it prompts needs to address the underlying environment, not just the AI-specific settings.

This is what NSP's approach to AI adoption is built around. The Secure pillar of the NSP Secure AI Accelerator specifically addresses the data environment question - Microsoft 365 permissions, configuration drift, access controls, and the governance framework that keeps them current - because enabling AI productivity without securing the data environment it operates in produces confidence without foundation. And because, as we've covered in our post on cloud drift management, the gap between how an M365 environment was originally configured and how it looks after years of organic growth is wider than most businesses expect.

 

The Conclusion That Comes From Microsoft Itself

The most important thing to understand about AI and data security isn't found in a security vendor's threat report. It's in Microsoft's own guidance for Copilot deployment.

Before you deploy Copilot, Microsoft recommends completing a data governance readiness assessment. Not because Copilot is dangerous. Because the data environment Copilot will operate in may not reflect the organisation's current intentions - and because AI will make whatever is in that environment immediately more accessible than it was before.

The biggest AI security challenge facing NZ businesses isn't the AI.

It's the question they haven't asked yet: what can our employees already see?

If you don't know the answer, that's worth finding out - before AI finds it for you.

Book an M365 security and AI readiness review with NSP →

Or call us: 0508 010 101

 

Frequently Asked Questions

Does Microsoft Copilot give employees access to data they couldn't see before?

No. Microsoft is explicit: Copilot does not create new permissions or expose data users cannot already access. It operates entirely within each user's existing Microsoft 365 permissions. What it changes is how quickly and easily users can discover and surface content they technically have access to - including content they didn't know existed.

What is SharePoint oversharing and why does it matter for AI?

Oversharing occurs when files, folders, or SharePoint sites are configured to allow access to more people than was intended - often through default settings, inherited permissions, or "anyone with the link" sharing that was never reviewed. When AI can traverse content a user has permission to access, overshared content becomes immediately discoverable through natural language prompts rather than requiring deliberate navigation.

What are the most common Microsoft 365 permission problems NZ businesses have?

Microsoft and Microsoft partners consistently identify four patterns: sites set to "everyone in the organisation" or "everyone except external users"; broken permission inheritance where site-level and file-level permissions don't align; legacy "All Employees" security groups that grant broad access; and "anyone with the link" sharing links that remain active long after the intended sharing period. All four create AI accessibility risks when Copilot is deployed.

Does Microsoft Copilot have any NZ-specific privacy implications?

Yes. Under the Privacy Act 2020, organisations have obligations around who can access personal information and how it's handled. Microsoft 365's default configurations have external sharing enabled by default, creating immediate compliance gaps. AI-enabled access to personal information at unintended scale - such as when Copilot surfaces content containing personal information that was technically accessible but not practically discovered before - creates potential notifiable privacy breach obligations under the Act.

What should a NZ business do before deploying Microsoft Copilot?

Microsoft recommends completing a data governance readiness assessment that maps what content exists, what permissions are in place, and what's been overshared. At minimum, businesses should understand where sensitive information sits in their Microsoft 365 environment, review sharing settings and address the most significant oversharing patterns, and establish ongoing governance practices rather than treating it as a one-time cleanup.

Is this a problem that only IT can solve?

No - and this is one of the most important things to understand. IT can configure permissions and change system settings. But decisions about which information should be accessible to whom require business context that IT doesn't have. Data governance requires leadership participation: people with responsibility for HR, Finance, Legal, and Operations making judgements about appropriate access, which IT can then implement and maintain.