Part 3 of 7 · Governance Debt
It usually happens in the first week of a pilot. Someone in finance, or legal, or the exec team types an ordinary question into Copilot — “What’s our current severance policy?”, “Summarize the acquisition terms we discussed”, “Who’s on the comp committee?” — and gets a clean, well-formatted answer, with a citation, pulled from a document they didn’t know they could open.
That is the moment the previous two posts have been building toward. You grew an estate nobody designed, you were right to be excited about AI on your own content, and then you turned it on and it worked exactly as designed — which is the problem. The severance policy was reachable the whole time. The acquisition notes were reachable the whole time. Copilot didn’t break anything. It just answered.
Nothing new was granted
Here is the part that’s genuinely hard for organizations to absorb, because it feels like the tool did something: enabling AI on your content grants no new access. Copilot answers each person using precisely what that person can already reach — every site, library, and shared inbox their identity resolves to, whether or not they’ve ever navigated there. The exposure existed yesterday. What changed today is that yesterday, using it required knowing the document existed, knowing roughly where it lived, and clicking your way to it. That friction was doing a lot of quiet work. For most of your estate’s life, obscurity was the access control.
Strip the friction away and a decade of accumulated grants all become live at once. The site shared with “Everyone except external users” in 2019 for a project that ended in 2020. The folder a since-departed employee opened to the whole org to save a support ticket. The “temporary” broad permission that outlived its reason by four years. The sharing link pasted into a Teams chat that still works because nobody ever set it to expire. None of these were decisions in any meaningful sense. They were the path of least resistance, taken thousands of times by people trying to get work done. They were harmless-ish precisely because reaching them took effort.
Reach is the whole story. The measure that matters isn’t how many files you have — it’s how many people can effectively reach a given site once you resolve group nesting, claim principals, and sharing links. That effective reach is exactly what an AI assistant inherits. A forty-file site reachable by the entire company is a bigger exposure than a hundred-thousand-file site locked to a team of six. We wrote up the mechanics of that — how effective access is computed, why the “Everyone” claim principals are the sharp edge, and why most inventory tools quietly under-count them — in a standalone piece on why Copilot’s reach is your exposure surface. This post is about the other half: what it feels like when an organization discovers it.
The realization is the event, not the exposure
The exposure was static for years. The realization arrives all at once, and it lands in a specific, recognizable sequence.
First, denial with a technical flavor: the tool must be leaking data it shouldn’t have. It isn’t. It’s honoring your permissions faithfully. Then the harder recognition: the permissions themselves are the leak, and they’ve been that way the entire time. Then the search for the culprit — who granted this? — which almost always dead-ends, because the answer is “everyone, a little at a time, over ten years, with no record.” And finally, if the organization is healthy about it, the reframe: this isn’t a security failure to pin on someone. It’s the default state of a self-service collaboration platform used the way it was designed to be used. Every tenant that adopted SharePoint, Teams, and OneDrive and let people share freely arrived here. It is the norm, not the exception, and treating it as negligence just makes it harder to fix.
That reframe matters because the alternative — hunting for a person to blame — produces exactly nothing. Nobody overshared on purpose. The grants accumulated because sharing was frictionless and cleanup was invisible and nobody’s job. The debt compounded silently, and the AI pilot was simply the first time anyone tried to spend against the account.
Microsoft is telling you the same thing
You can read the shape of this problem directly in Microsoft’s own guidance, which is worth taking as confirmation rather than sales copy. The entire premise of SharePoint Advanced Management is preventing oversharing and governing content before it becomes broadly discoverable. Microsoft’s readiness guidance for Copilot opens by telling admins to find overshared content, run data access governance reports, and adjust sharing defaults — because, in their words, sharing settings default to the most permissive option. There is a dedicated Everyone except external users report because that one claim is common and dangerous enough to warrant its own view. And Restricted Content Discovery exists specifically as a temporary control to hide sites from Copilot “while permissions and governance controls are being evaluated.” Microsoft built a pause button for exactly this realization. The pause button only exists because the realization is universal.
Where this leaves you
The uncomfortable, clarifying truth is that your oversharing surface and your AI-exposure surface are the same surface — and the day you enable AI, they become the same problem, on the same timeline, in front of the same executives. That’s not a reason to leave the value on the table. It’s a reason to look before you flip the switch: to know what “Everyone” can reach, to know which of it is sensitive, and to know that your view of it is complete rather than confidently blank where a tool couldn’t see.
The oversharing was always there. AI just made it answerable — and in doing so, made it, finally, impossible to ignore. That’s the first crack in the estate you never designed. It isn’t the only one. The next is quieter and, in its way, worse: even when access is correct, the content itself can be wrong — and AI will cite the wrong version with total confidence.