Skip to main content
CybersecurityPrivacy & Surveillance

Security Fears Stall Microsoft Copilot Rollouts

Blurred Microsoft Copilot interface on a computer screen in a corporate setting.

Two-thirds of organizations have delayed or cancelled deployment of Microsoft Copilot over fears that the AI assistant could expose confidential data, a CoreView survey released 21 July shows.

Scale of hesitation: Two-thirds of organizations pause or cancel Copilot rollouts

CoreView’s State of Microsoft 365 Security and Governance 2026 report found that roughly 66% of surveyed organizations have either delayed or cancelled plans to deploy Microsoft Copilot. The report frames this as a widespread, program-level hesitation tied to concerns that Copilot might surface confidential information from corporate systems — most notably SharePoint.

C-level and managers driving the pauses

The decision to slow or stop Copilot deployments is coming from the top. According to the survey, three quarters of C-level executives have issued instructions to delay a Copilot rollout across their organizations, and 60% of managers have done the same. “It is the most senior leaders who are pausing, because they can see exactly what AI will surface - a decade of sharing links and permissions nobody cleaned up. The risk was always there but AI has made it visible and urgent,” said Simon Azzopardi, CEO of CoreView.

SharePoint access and permissions at the heart of the concern

Respondents singled out SharePoint as a primary worry. The report says confusion remains around the access and permissions Microsoft Copilot has, with specific anxieties about data leakage and SharePoint sharing links being exposed outside the organization. CoreView connects these worries to a broader data governance problem: years of accumulated sharing links and permissions that can be surfaced by AI if not properly controlled.

Past Microsoft 365 incidents and missing foundational controls

CoreView links much of the present hesitation to organizations’ experiences with security incidents involving Microsoft 365. The report attributes those incidents to the absence of at least one foundational security control — examples named include administrator multi-factor authentication (MFA), privileged access management (PAM), or configuration tamper detection. Cybersecurity leaders surveyed expressed concern that the same gaps that produced incidents in Microsoft 365 could also produce incidents involving Microsoft Copilot.

To address those risks, the report recommends applying controls such as PAM to both user accounts and Copilot accounts to prevent unauthorized access and data exfiltration. It also advises organizations to examine permissions and access of SharePoint applications “to ensure that this access cannot be invertedly shared in a way that puts the data at risk, either by AI applications or human users.”

How technologists, procurement leaders, and executives are responding

  • Technologists and security teams: the report implies a focus on closing specific control gaps — implementing administrator MFA, applying PAM, and activating configuration tamper detection — and reviewing SharePoint permissions to limit what Copilot or any account can surface.
  • Procurement and deployment leaders: with three quarters of C-levels and 60% of managers pausing rollouts, procurement decisions and deployment timelines are being reevaluated, prioritizing proofs of governance and control before wider adoption of Copilot.
  • Executives: senior leaders are taking visible, directive action to delay deployments until they can see clearer assurances that long-standing sharing and permission configurations will not be exposed by AI.

The CoreView report characterizes the reaction as a striking level of organizational hesitation for “a Microsoft flagship product with enormous executive mindshare.” For many organizations, that hesitation can be traced back to concrete, remediable gaps: missing MFA, absent PAM, or insufficient tamper detection. Whether those fixes will be implemented rapidly enough to convert executive caution into renewed adoption is the immediate question left on organizations’ deployment calendars.

https://www.infosecurity-magazine.com/news/microsoft-copilot-delayed-over/