There is a pattern playing out inside businesses right now that security teams are only just beginning to grapple with. A business deploys Microsoft Copilot, ChatGPT, Claude or Gemini. The IT team follows the vendor’s setup guide, enables the licence, and rolls it out to users. Within weeks, executives are summarising emails, generating first drafts, and asking questions of their data in natural language. Productivity improves. The board is pleased.
What nobody has checked is what data these AI tools can actually reach.
Because these AI tools don’t create new access, they inherit existing permissions. If a user already had access to a shared drive containing board minutes, financial forecasts, HR records, or sensitive client data, these AI tools can now potentially surface all of it in response to a simple typed question. In many Microsoft 365 environments, permissions have accumulated over years: old shared folders never cleaned up, overly broad access granted to entire departments, files that were never meant to be widely visible sitting in locations that technically anyone with a company login can reach.
The AI tool hasn’t introduced a new vulnerability in the conventional sense. It has simply made the existing one dramatically easier to exploit.
Why This Is Happening Now
The pace of AI adoption inside organisations has outstripped the pace of governance. That isn’t a criticism, it is an observation about how enterprise technology typically evolves. When email was introduced, most organisations didn’t have an email security policy until something went wrong. When staff started using smartphones for work, mobile device management came later. When cloud storage arrived, data classification lagged behind.
AI is following a similar adoption curve, but faster and with higher stakes.
The difference this time is that AI tools don’t just store or transmit data, they actively reason over it, synthesise it, and present it in response to unstructured natural language queries. The implications of overpermissioning are therefore qualitatively different. A misconfigured shared folder in a pre-AI environment might go unnoticed indefinitely. The same misconfiguration in a Copilot-enabled environment for example, can be surfaced to anyone in the organisation within seconds.
Shadow AI adds a further dimension to this problem. While IT departments are managing official deployments, staff are independently signing up for ChatGPT, Claude, Gemini, and a growing range of AI-powered productivity tools. They are pasting customer data, internal documents, and commercially sensitive material into these tools without any visibility from the organisation’s security function. In many cases they don’t know they are doing anything wrong, the tools are freely available, the interface is intuitive, and nobody told them not to.
According to research by ISACA, only 31% of organisations have some form of formal governance in place when it comes to AI. That means the majority of organisations are operating in a space where the rules haven’t been written, the risks haven’t been assessed, and the exposure hasn’t been mapped.
The Three Gaps at the Heart of the Problem
Understanding where the risk actually sits requires looking at three distinct but connected areas.
The data permissions gap. Before any AI tool can be safely deployed, the organisation needs to understand what its users can access and whether that access is appropriate. In most Microsoft 365 environments, this picture has never been properly mapped. Data has accumulated over years, access has been granted ad hoc, and the cumulative effect is a permissions landscape that nobody has a complete view of. AI tools surface this gap in a way that makes it impossible to ignore.
The governance gap. Most organisations don’t have policies that specifically address AI tool usage, data classification in the context of AI, or acceptable use boundaries for generative models. Without these policies, staff have no framework for deciding what is and isn’t appropriate and security teams have no baseline against which to measure behaviour or investigate incidents.
The visibility gap. Shadow AI is, by definition, invisible to the tools organisations use to monitor data flows. Conventional endpoint, network, and SIEM controls are designed to detect known threat patterns. They are not designed to identify when a member of staff pastes a client contract into a public AI tool. This isn’t a gap that can be closed with existing controls, it requires a different approach to monitoring and awareness.
The Questions Boards Are Starting to Ask
As AI governance has moved up the regulatory agenda, with the EU AI Act, FCA guidance on AI in financial services, and ICO attention on AI and personal data, boards and audit committees are beginning to ask questions that security and IT teams are struggling to answer.
What AI tools are currently operating within the business? What data can those tools access? Do we have a policy that governs AI usage? Have we assessed our exposure under relevant regulatory frameworks? How would we know if sensitive data had been processed by an unapproved AI tool?
For many organisations, the honest answer to most of these questions is currently “we don’t know.”
That isn’t a comfortable position to be in. It is, however, a fixable one, and the organisations that address it proactively will be in a fundamentally stronger position than those that wait for a regulatory inquiry or a data incident to force the issue.
When This Becomes Particularly Urgent
There are specific moments when the need for clarity around AI security becomes especially acute. Organisations that are actively rolling out Copilot or another enterprise AI tool are in the highest-risk window, the period between deployment and a proper security review is when exposure is greatest. The same is true when staff are using AI tools without explicit IT approval, when an insurance renewal or regulatory audit is approaching, when a board sign-off on AI investment is required, or when a new CIO, CISO, or CTO joins and needs to understand the existing landscape.
In each of these situations, operating without a clear view of AI security posture isn’t just a technical risk, it is a governance and accountability risk that sits at board level.
What a Structured Review Looks Like
So where should you start when looking at solving these problems with AI adoption in your business? At Cyberfort we encourage all businesses to undertake an AI Security Readiness review before any AI tool is fully deployed. From our experience understanding AI security exposure requires a methodical approach across four areas:
Step 1 — Scoping and Discovery. Establish the boundaries of the assessment: which AI tools are in scope, which parts of the estate will be reviewed, and which stakeholders need to be involved. This step also captures the organisation’s current understanding of its own AI usage, which is often the first point at which shadow AI usage becomes visible.
Step 2 — AI Usage and Exposure Review. Map the AI tools currently operating within the organisation, both sanctioned and unsanctioned. Assess data access permissions, identify overpermissioning in Microsoft 365 or other AI-adjacent environments, and establish a baseline picture of where sensitive data could be reached by AI tools.
Step 3 — Security and Governance Assessment. Evaluate the organisation’s current policies, controls, and monitoring capabilities against the specific requirements of an AI-enabled environment. Identify gaps in policy, monitoring, data classification, and incident response that are specific to AI risk.
Step 4 — Findings, Scorecard, and Roadmap. Produce a clear, executive-readable risk scorecard and a prioritised remediation roadmap. This gives the organisation both the board-level view and the technical detail needed to act.
What Good Looks Like
Organisations that have done this work properly typically come out of it with three things they didn’t have before.
First, a clear and accurate picture of what their AI tools can actually access, which is almost always different from what they assumed. Second, a governance framework that gives staff clarity on what is and isn’t acceptable, reducing the shadow AI risk significantly. Third, a documented security posture around AI that can be presented to insurers, regulators, boards, and enterprise customers when the question arises.
None of this requires stopping AI adoption. The goal isn’t to slow the business down, it is to make sure the speed of adoption doesn’t create a risk profile that leadership hasn’t had the opportunity to consider.
Final Thoughts
The rapid adoption of AI tools represents a shift that is structurally different from the changes that conventional security controls are designed to address. It reshapes how people work and make decisions, rather than simply introducing new technology. It draws on publicly available and organisational data as its raw material. And it has become cheap, easy, and scalable in a very short period of time.
The organisations that understand this are moving from passive awareness to active preparation: mapping their exposure, testing their people, and embedding the procedural controls that make impersonation significantly harder to execute successfully.
If this is an area where your organisation does not yet have a clear and confident answer, it is worth understanding what a structured review would tell you. The gap, once understood, is almost always more addressable than it first appears.
To start that conversation email us at [email protected] or visit cyberfortgroup.com.
