Two-thirds of firms delay Copilot over SharePoint risks
Thu, 23rd Jul 2026 (Today)
Two-thirds of enterprises have delayed or cancelled Microsoft Copilot deployments, according to CoreView, which based the finding on a survey of 279 Microsoft 365 decision-makers.
The research found that 66% of organisations had paused or stopped rollout plans over concerns that artificial intelligence tools could expose confidential SharePoint data. It also found that 73% were worried AI was already surfacing sensitive information inside their organisations.
Concerns were stronger among senior executives than mid-level managers. The survey found that 75% of C-level executives and vice presidents had delayed or cancelled Copilot deployments, compared with 60% of managers.
The gap suggests organisations view risk differently, particularly in legal, compliance, finance and human resources, where broad access to internal documents can create governance problems if permissions have not been tightened.
Security gaps
CoreView's findings also suggest many organisations rate their Microsoft 365 security more highly than their controls warrant. Nearly two-thirds, or 62%, described their security posture as established or advanced, yet 54% of that group were still missing at least one basic control, such as administrator multi-factor authentication, privileged access management or configuration tamper detection.
The survey highlighted another weakness in administrator account protection. Administrator accounts, which can change permissions and access controls across Microsoft 365 environments, were less likely than standard user accounts to have fully enforced multi-factor authentication: 55% versus 62%.
One in five organisations said multi-factor authentication was enforced more weakly on administrator accounts than on ordinary employee accounts. That matters because administrator settings determine which files, sites and records AI assistants can retrieve.
Backup confusion
The report also found confusion over configuration backup responsibilities. More than one-third of respondents, or 37%, believed Microsoft automatically backs up Microsoft 365 configurations, while 11% said their organisations had no configuration backup at all.
Without a reliable record of permissions, sharing settings and access controls, organisations may struggle to understand what information internal AI tools can reach. In large Microsoft 365 estates, configuration drift can leave old sharing links, inherited access rights and outdated policies in place.
SharePoint emerged as a particular source of concern. Organisations delaying Copilot were more than three times as likely to be highly concerned about anonymous SharePoint links as those that had already deployed the tool: 48% expressed high concern, compared with 14% of adopters.
Access reviews
User access reviews also appear to be a weak point. Nearly two-thirds of organisations, or 63%, said they defer or limit access reviews because the process is too time-consuming, while 46% said they struggle to get employees to complete them.
As Microsoft 365 environments expand across departments and geographies, manual reviews become harder to manage. That can leave businesses with more users holding access they no longer need, increasing the chance that AI tools expose information more widely than intended.
The survey drew on responses from IT, security and infrastructure decision-makers at organisations using Microsoft 365. Most respondents were in North America, with additional representation from the UK, Australia and continental Europe. The industry mix included technology, healthcare, finance, manufacturing and public sector education organisations.
Simon Azzopardi, chief executive officer of CoreView, said: "Two-thirds of enterprises have delayed or cancelled Copilot. It is the most senior leaders who are pausing, because they can see exactly what AI will surface - a decade of sharing links and permissions nobody cleaned up. The risk was always there but AI has made it visible and urgent. We built CoreView Control for SharePoint for precisely this moment - continuous file-level visibility and remediation, below the site level where Microsoft's native controls stop by design. When you fix the SharePoint estate, Copilot stops being a board-level risk and becomes a productivity decision."