Microsoft 365 Governance Incidents Rise Amid Rapid AI Adoption
Share
An estimated 77% of global organisations experienced at least one Microsoft 365 governance incident over the past year, according to research from ShareGate. The findings suggest a growing governance crisis as organisations rapidly adopt artificial intelligence (AI) tools without sufficient oversight.
Security gaps and access mismanagement
Among organisations that suffered an incident, 38% reported leaving former employees or guests with access to systems they should have lost. Additionally, 35% encountered audit or compliance gaps, while 26% experienced instances where sensitive content reached unauthorised individuals.
ShareGate attributed these failures to poor visibility, overconfidence in existing governance frameworks, and significant skills gaps regarding AI management. The research highlights a reliance on reactive measures, with 65% of respondents reporting they only learn about incidents through user complaints or quarterly audits. In contrast, only 35% of teams utilise proactive monitoring and automated alerting.
AI adoption driving new risks
The rapid deployment of AI tools has intensified these security challenges. Full Microsoft Copilot deployments doubled over the past year, increasing from 29% to 56% of organisations. Roughly 28% of these tenants now operate three or more AI tools simultaneously.
Despite high levels of confidence, 93% of respondents believed their governance frameworks were ready for AI, yet 29% had already seen sensitive internal data surfaced by Copilot or other AI tools. This data exposure indicates that existing controls may not be sufficient to prevent AI from accessing information it should not reach.
The visibility and expertise gap
Budgetary shifts are also evident, with 22% of organisations dedicating more than a fifth of their IT budget to AI. For teams that have fully deployed Copilot, this figure rises to 32%.
A lack of AI governance expertise was identified as a top-three concern for 37% of respondents. IT professionals noted that better controls for AI agents would provide the most significant relief for governance challenges, cited by 34% of those surveyed.
“Most of the tenant environments I look at aren’t broken; they just don’t know what’s happening within them,” said Richard Harbridge, principal industry advisor at ShareGate. “Teams feel confident because nothing has surfaced yet, but that doesn’t mean there’s nothing wrong.”
Harbridge noted that the gap between “no news” and “no problems” is where governance incidents often reside, and that the visibility problem compounds quickly when multiple AI tools are layered into the environment.




Leave a Reply