Every chapter, every chart, and the full methodology in one file. One email address.
Loading form…
AI confidence ≠ control
93% are confident their governance framework is ready for AI. Yet 29% have already had it surface something it shouldn't have had access to.
say their governance workload has grown since deploying AI
of tenants run two or more AI tools, and 28% run three or more
run continuous automated monitoring of AI usage
IT leaders overwhelmingly report feeling ready for AI. The exposure data doesn't match. The teams doing more governance work report more incidents and more concern; the teams doing less report less of both. Not because they're safer. Because they're not looking.
Full Copilot deployment went from 29% to 56% between 2025 and 2026, and 93% of organizations now have it in production. Deployment isn't the interesting question anymore. What's underneath it is.
53% of respondents don't have full visibility into what their Copilot agents can access, and permissions on Microsoft 365 content don't expire on their own. The tools moved fast. The environment underneath them didn't.
Half of IT leaders (49%) are very or extremely concerned about AI reaching content nobody has reviewed. But that concern isn't evenly spread: it runs at 54% among teams with continuous monitoring and 13% among teams with none. The teams with the least visibility are the least worried about it, which is the wrong way round.
Every stat is tagged with the study it came from: the AI governance survey (n=851) or the IT operations survey (n=943). Full methodology →
This is Chapter 1 of The State of Microsoft 365, a report on how organizations run, secure, and migrate in 2026. Learn more →
The M365 Governance Index scores your environment against the 1,794 IT pros across our two studies.
Confidence is a feeling. Incidents are facts. And in 2026, they don't line up the way you'd expect them to.
This chapter is where we open up the gap between the two. What the confidence looks like when you break it down. How many incidents there actually are when you count them. How both change depending on the country you're in. And why we think the two are so important to look at together. Not because IT teams are wrong about what they've built, but because the surface they're managing keeps getting harder to see all at once at scale.
We asked 851 IT leaders how confident they are that their organization's current Microsoft 365 governance framework is sufficient to support Copilot and other AI initiatives responsibly. Half of them (51%) said "very confident," while another 42% said "somewhat confident."
We asked How confident are you that your organization's current Microsoft 365 governance framework is sufficient to support Microsoft Copilot and other AI initiatives responsibly?
93% are confident their governance framework can support Copilot — half of them 'very'. Six per cent express any doubt at all.
AI governance surveyThe next question asked whether Copilot or another AI tool has ever surfaced sensitive internal data that should not have been accessible. 29% said yes. Another 8% said they weren't sure.
We asked Has Microsoft Copilot or another AI tool surfaced sensitive internal data that should not have been accessible?
29% say yes. Another 8% cannot say whether it has: the same exposure, undetected.
AI governance surveyTwo questions, same respondents, seemingly contradictory results. One picture of readiness. One picture of what's already happened. More than a third of organizations either have a known AI exposure incident on the books or can't say whether they have. From a population that overwhelmingly reports feeling confident that they're supporting Microsoft Copilot and other AI initiatives responsibly.
Interestingly, according to IBM, 77% of C-level technology executives say that AI adoption is already outpacing governance capabilities. So this confidence may be higher in IT professionals versus IT executives.
These incidents weren't a case of AI surfacing old, outdated information that slowed end user productivity, which is also a possible outcome of not properly governing your tenant for AI. They're incidents of AI surfacing the kind of content teams are typically asked to prove they control.
No obvious pattern in what AI reached: customer records, personal data, HR, financial documents, IP. Everything sensitive was roughly equally exposed. When AI overreaches, it doesn't fail selectively across the categories teams normally treat as separately governed.
We asked What type of content was exposed? Select all that apply
Among the 29% who were burned: the records you're most accountable for.
AI governance surveyAnd it isn't a one-off. The same survey asked how confident respondents are that Copilot's access reflects current and appropriate permissions across SharePoint, Teams, and OneDrive. Again 93% said confident, 48% of them "very." Asked whether their IT team has the skills and tools to remediate AI-related governance issues if something goes wrong, that magic number held: 93% confident, 50% "very."
We asked How confident are you that Microsoft Copilot’s access reflects current and appropriate permissions across SharePoint, Teams, and OneDrive?
9Nearly as many are only somewhat confident as are very.
AI governance surveyWe asked How confident are you that your IT team has the skills and tools needed to remediate AI-related governance issues?
93% again, this time on having the skills and tools to remediate an AI governance problem. The third near-identical confidence number in the same study.
AI governance surveyAltogether, 88% are confident that the framework is right, the permissions are right, and the team can fix what needs fixing. The paradox gets sharper when you isolate the strongest confidence group.
Confidence and exposure aren't moving in opposite directions here. They're moving in the same direction, together. Microsoft MVP Eric Overfield puts a name on the mechanism.
Confidence is overstated and incidents are understated, in opposite directions. People say they're ready because the controls exist. They under-report the exposures because nobody volunteers those. What you're looking at is the gap between having controls and checking whether they worked.

ShareGate Protect was built to close the gap Eric is talking about, then keep it closed. You can see who has access to what, where oversharing is happening, and what Copilot can actually reach. Apply automated policies to keep the environment clean as it changes, and fix issues right where you found them. No scripts, no admin-centre hopping.
See ShareGate Protect →Whatever the 29% are looking at when they answer the incident question, it isn't visible in any of the confidence questions around it.
There's a reasonable counter-explanation: maybe teams with incidents are confident because they've dealt with them: earned survivorship, new mechanisms in place, rather than a disconnect. The data doesn't support it. Respondents who reported an AI incident are nearly twice as likely to be concerned about AI accessing content that hasn't been recently reviewed for permissions:
Nearly twice as likely.
AI governance surveyThey're more than twice as likely to say governance workload has increased significantly since enabling AI:
More than twice as likely.
AI governance surveyAnd they rate their own governance maturity at roughly the same level as everyone else:
Effectively identical. An incident doesn't dent how mature a team believes it is.
AI governance surveyThat isn't a "we fixed it and feel better" profile. It's a "we know it's still possible, we're working harder, and we're still worried" profile, held at the same time as saying they're confident in their framework, their permissions, and their ability to fix things. The confidence and the concern coexist.
The averages hide something worth surfacing. Those confidence figures and the 29% exposure rate don't hold up evenly across countries.
| Country | n | Framework | Permissions | Remediation | All 3 ✓ | Incident | Unsure |
|---|---|---|---|---|---|---|---|
| United States | 219 | 96% / 61% | 94% / 62% | 95% / 62% | 49% | 37% | 9% |
| United Kingdom | 204 | 97% / 60% | 94% / 55% | 94% / 58% | 42% | 25% | 9% |
| Canada | 106 | 92% / 45% | 96% / 42% | 92% / 45% | 30% | 26% | 9% |
| France | 108 | 91% / 42% | 93% / 44% | 88% / 34% | 25% | 29% | 8% |
| Germany | 104 | 90% / 45% | 91% / 35% | 96% / 39% | 21% | 23% | 5% |
| Ireland | 54 | 89% / 30% | 89% / 31% | 91% / 43% | 24% | 20% | 13% |
| Netherlands | 56 | 86% / 38% | 86% / 32% | 89% / 39% | 20% | 30% | 5% |
| Sample avg | 851 | 93% / 51% | 93% / 48% | 93% / 50% | 35% | 29% | 8% |
No two countries match on both confidence and incidents. Four are worth examining more closely, each a distinct shape of what the paradox looks like in practice.
US respondents lead the sample on every "very confident" dimension and on the comprehensive measure: 49% "very confident on all three", 14 points above average. IT pros in the US also reported the highest exposure rate in the study. Inside that most-confident US cohort, the incident rate climbs to 43%. The strongest confidence in the sample sits in the same country as the highest exposure, and within it the two track together more tightly still.
The UK shares the confidence but not the exposure. Effectively tied with the US across all three questions, 7 points behind on the comprehensive measure, and 12 points below on incidents. Whether that reflects better controls, different reporting norms, a smaller AI footprint, or something not visible here such as stricter regulation, we can't say. What it does say is that comprehensive confidence and comprehensive exposure aren't a one-to-one match. The association appears in this sample, but our survey can't establish the cause.
Germany shows a different shape. German respondents sit mid-table on whether their framework is sufficient and their permissions appropriate, but on remediation they come out highest in the sample. Less certain the setup is right, more certain they can fix it if it isn't. Only 21% are "very confident" on all three, one of the lowest in the study, and the exposure rate is the second-lowest at 23%. Where comprehensive confidence softens, the incident count softens with it.
Ireland points somewhere else entirely: the lowest incident rate in the sample, and the highest "not sure" rate, four points above average. What Ireland describes isn't necessarily a safer environment. It's one where a meaningful share of respondents genuinely don't know whether an incident has already happened. Small base (n=54), so read it as directional. But the shape is distinct.
Four countries, four different stories. What links them isn't a shared pattern in how confidence and exposure relate. It's that they don't relate cleanly in any of them. Whatever confidence is tracking, it isn't a smaller exposure surface. It may be a narrower view of one.
On the M365 Governance Index's 100-point scale, the entire spread between the highest-scoring country and the lowest is 11 points. The spread between the middle half of respondents—25th percentile to 75th—is 24. Which country you're in explains far less about your AI governance than where you sit inside it. The Index scores you across cleanup, ownership, monitoring, exposure, and maturity against the 851 IT leaders in this study, in about two minutes.
This confidence and exposure paradox isn't happening in a small number of pilot environments. The AI these leaders are governing, worrying about, and being surprised by is already deployed at scale. Copilot is almost everywhere now, and in most tenants it's one of two or three AI tools IT is managing at the same time. That combination is what makes visibility the question the rest of this chapter is built around.
93% of respondents have Copilot already in production, and 98% are either deployed or actively planning to deploy within a year.
Deploying / using Copilot
Any Copilot deployment went from 82% to 93%. Full deployment nearly doubled underneath it, 29% to 56%.
Compare that to the same question a year ago: full deployment has roughly doubled, from 29% to 56%, and any deployment—pilot, partial, or full—has gone from 82% to 93%. A year ago the largest group was still piloting. Today the largest group is fully deployed.
The 2026 answer set has no "pilot" option, so 2025's pilot respondents would most likely pick "partially deployed" today.
And it isn't just Copilot. Most organizations are running more than one AI tool at once.
Two thirds of organizations use or plan two or more named AI products—two each, on average. Permissions and monitoring have to work across the whole set, not just the one with Microsoft's name on it.
IT operations surveyCopilot leads, but most run several assistants.
IT operations surveyAmong the organizations running or planning Copilot, 73% also run at least one other named AI tool. Barely a quarter of Copilot organizations are Copilot-only.
73% of Copilot organizations also run at least one other named AI tool. Barely a quarter are Copilot-only, so "what can Copilot reach" is the wrong question—the question is what any of them can reach.
IT operations survey · Among organizations using or planning Copilot.That matters for everything that follows. Permissions, monitoring, and remediation have to work across the whole set, not just the one with Microsoft's name on it. The visibility question in the next section isn't "what can Copilot reach," it's "what can any of these reach" — and for two thirds of organizations that's a question about several products at once.
Deployment is one question. What teams are actually worried about is another, and the IT operations survey put it to a different 943 respondents.
Data quality and access management still lead.
IT operations surveyData quality, relevance, and retention policies
Security and access management
Lack of internal expertise on governance for AI
Realizing the ROI of Copilot
Cost control
Ongoing governance and access management after deployment
Governing AI agents, plugins, and automations connected to Copilot
Not on the 2025 questionnaire — first year asked.
The top two are tied, and neither is about the technology. Data quality and retention is a content governance problem. Security and access management is a permissions problem. Both existed before Copilot arrived, and both decide what it can surface.
Last year those same two led the list, at 58% and 57%. They still lead, in the same order, at slightly lower intensity. That's the part worth sitting with: full Copilot deployment roughly doubled in the same twelve months, and the concern set didn't reorder. Whatever teams were worried about before they scaled, they're still worried about now. The dip in absolute levels invites two readings: normalization, familiarity reducing alarm; or the pattern this chapter keeps finding, that awareness travels with practice. As deployment broadens from early adopters to everyone, the average respondent is newer to governing AI and has looked at it less closely. Neither is comforting.
Then there's the bottom of the list, which turns out to be the most interesting entry on it. Governing AI agents, plugins, and automations ranks last as a concern, named by 19%. But the same survey asked what would have the biggest impact on improving governance and security, and the top answer, ahead of executive buy-in, automated remediation, better tenant visibility, more expertise, and more budget, was better controls for managing AI agents, plugins, and automations.
The governance ask moved to AI. The tooling mostly hasn't.
IT operations surveySame respondents. Two questions. Agents come last as a worry and first as a want. That's less contradictory than it first looks, because the two questions measure different things. Concern is largely retrospective — what has already gone wrong or is visibly straining. "What would help most" is prospective — the capability teams can see they're missing. Agents rank low on the first because for most organizations the agent layer hasn't hurt them yet. They rank first on the second because the control gap is already obvious.
Which makes this the one place in either study where teams appear to be ahead of the problem rather than behind it — and worth acting on for exactly that reason. The agent surface is the fastest-growing part of a tenant and the least governed, and the window in which this concern stays hypothetical is unlikely to stay open for long.
The AI running in a typical Microsoft 365 tenant has permissions inherited from the tenant, access to content the tenant already contains, and no built-in limit on what it can surface if the underlying permissions and content aren't clean. There's a difference between knowing AI is active in your tenant and knowing what it can touch. Just under half of IT leaders have full visibility.
Only 47% see all of it. The rest are governing an access surface they cannot fully describe.
IT operations survey53% of respondents have less than full visibility into what their agents can access, and the largest group inside that 53% is "partial". These teams aren't flying blind, but they don't have the specificity that would let them say, in front of an auditor or a legal team, this agent, in this business unit, can reach this data source, at this sensitivity level.
Copilot follows the permissions you already have. If you don't understand your permissions model, you don't know what Copilot can reach. Teams spend the rollout on licensing and training. But visibility is the part that actually prevents the surprises.

That's the challenge partial visibility creates: it doesn't scale. As tenants add agents, data sources, and sensitivity classifications, the gap between "we know agents exist" and "we know what they can each reach" widens.
And it's not just how much they can see—it's also how often they look.
Only 48% monitor AI usage continuously; the rest find out later.
AI governance survey48% run continuous automated monitoring of AI usage. Another 37% run periodic monitoring. The remaining 15% do manual spot checks, only investigate after an incident, or don't monitor at all.
Most teams monitor Copilot adoption. Far fewer monitor what it's touching. Adoption tells you whether people are using it. Only data security monitoring tells you whether that's safe.

Periodic beats spot checks, but it still only catches what's happening at the moment of the review. Between checks, things get away from you. Every partial-visibility and periodic-review respondent is running an environment where an audit question, an incident review, or a regulatory request would require an investigation to answer.
Permissions on Microsoft 365 content don't automatically expire or reset. If a document was shared with someone in 2019 and nobody has reviewed those permissions since, it's still shared with them, which means AI can read it. We asked how worried IT pros are about exactly that.
49% are very or extremely concerned. Set that beside the 93% who say their governance is ready.
AI governance surveyHalf of AI leaders are very or extremely concerned. Add "moderately concerned" and it's 79%. Only 7% aren't concerned at all. That headline doesn't tell the full story, though. Cross it against how often teams actually monitor and a pattern emerges that runs the wrong way.
| AI monitoring approach | n | Very or extremely concerned |
|---|---|---|
| Continuous automated monitoring | 408 | 54% |
| Periodic monitoring | 318 | 48% |
| Manual spot checks | 77 | 40% |
| Only investigate after incidents | 33 | 36% |
| No monitoring in place | 15 | 13% |
| Sample average | 851 | 49% |
You'd expect the teams doing the least monitoring to be the most concerned. They're the ones with the least visibility into what AI is doing. The data shows the opposite, and it's monotonic: every step away from active monitoring produces a lower concern rate. The teams with less visibility are also the teams least likely to be worried about it.
That complicates how we read the 49% headline. Half the sample is very or extremely concerned, but that concern isn't evenly distributed. It's concentrated where monitoring is more active, in the 85% running continuous or periodic monitoring. Where governance discipline is thinner, so is the worry. The teams most at risk are the ones least likely to see it. This isn't the only place in the data where awareness travels with practice.
Before AI ever reaches into content, most organizations have already done something about the content itself. We asked whether teams had run a structured content or permissions cleanup ahead of deploying or scaling AI.
Only half had done an organization-wide cleanup. Not ideal, but not unexpected.
Half ran an org-wide content and permissions cleanup first. A third did it in pockets, and one in seven has it on a list.
AI governance surveyThe interesting part shows up when you cross the cleanup data against exposure: how many respondents said AI had surfaced sensitive content it shouldn't have.
| Cleanup status | n | Had an incident | No incident | Not sure |
|---|---|---|---|---|
| Yes, organization-wide | 433 | 40% | 56% | 4% |
| Yes, limited to certain departments | 301 | 20% | 70% | 10% |
| Planned but not yet completed | 84 | 11% | 70% | 19% |
| No cleanup | 26 | 8% | 69% | 23% |
| Sample average | 851 | 29% | 63% | 8% |
On the surface this looks backwards. The teams that did the most cleanup—the ones you'd expect to have the fewest exposures—report the highest incident rate. Organization-wide cleanup produces a 40% incident rate. No cleanup produces 8%.
But the "not sure" column tells you what's actually going on. The teams that skipped cleanup entirely have a "not sure" rate nearly three times the sample average. The teams that did organization-wide cleanup have a "not sure" rate of half the average. That's the pattern. It isn't that cleanup produces incidents. It's that cleanup produces visibility. Teams that audited their content and permissions can tell you whether AI has surfaced something it shouldn't have. Teams that didn't audit are much more likely to say they simply don't know.
Which means the low incident rate in the no-cleanup group isn't a signal of safety. It's a signal of not knowing. Those aren't fewer incidents. They're incidents that haven't been detected, or ruled out, either way. The concern data said the same thing from another angle. Doing the work produces awareness. Skipping it produces the appearance of safety, plus a meaningful share of respondents who genuinely can't answer what's going on in their tenant when asked.
For the teams whose current operational state proves they take AI governance seriously — the 48% running continuous automated monitoring — we asked what first prompted the shift.
Regulation edges out the Copilot rollout itself. If you can't demonstrate what your AI is doing, you don't just have a governance problem. You have a compliance one.
AI governance survey · Respondents running continuous automated monitoring of AI usage (n=408).Regulators often require monitoring by law, so it tracks that a regulated industry would push AI governance up the list. If you can't demonstrate what your AI is doing, you don't just have a governance problem—you have a compliance problem. Microsoft MVP David Drever describes the specific moment governance becomes real:
Teams run a Copilot pilot and start finding information they never knew they had access to. That's the moment the fear arrives, and it's why my calendar is full.

Triggers explain why the work started. Ownership determines whether it continues.
Fewer than half have an owner whose policies are actually enforced consistently. For a quarter there's an owner but enforcement varies by department—a name on a page, not authority.
AI governance surveyJust under half of organizations report a clearly defined owner with formal policies and consistent enforcement. Another 26% have a defined owner, but enforcement varies across departments. 22% describe shared ownership across multiple teams with no formal governance structure, and 3% have no clearly defined ownership at all.
The middle two rows are where most of the risk sits. A named owner whose enforcement stops at the edge of their department produces exactly the pattern the exposure data shows: policy that is real in some parts of the tenant and theoretical in others. AI doesn't respect that boundary. It reaches wherever permissions allow, including into the business units where the policy was advisory. And shared ownership sounds collaborative and usually isn't — when four teams share accountability, the practical answer to "who decides whether this agent can access finance data" is often nobody, and the decision gets made by default, which is to say by whatever the permissions already allowed.
There's a capability question sitting underneath the authority question, and the other study puts a number on it: 37% of teams name lack of internal expertise on governance for AI as a top Copilot concern. Last year the same figure was 36%. A year of intensive Copilot deployment, in which full deployment roughly doubled, moved the AI governance skills gap by a single percentage point. The tooling arrived. The adoption arrived. The expertise to govern it didn't. That matters for ownership specifically, because naming an owner doesn't create capability. An owner without the skills to evaluate what an agent can reach is accountable for a decision they aren't equipped to make, which is how well-intentioned governance ends up ratifying whatever the permissions already allowed.
The pattern to watch for is a committee that advises and an admin who implements, with nobody who can say no. AI moves faster than that arrangement can respond.
The reason most organizations deploy AI is efficiency. The pitch has consistently emphasized time saved, tasks automated, work removed. But the governance side of AI is its own kind of work, and someone has to do it.
One in ten got lighter. Those are the teams worth asking what they did differently.
AI governance surveyWhy the increase? Microsoft MVP Drew Madelung has a theory:
The rate of change has become unattainable for M365 admins. The people who used to organize SharePoint are also now sitting on an AI steering committee and they may not even know much about AI yet.

83 respondents said governance workload went down after they enabled AI. A small group, and worth being careful with. Three habits are more common among them than across the study, though not by enough to call any one of them the reason. The row that actually separates them is the last one.
| Workload decreased | Sample average | |
|---|---|---|
| Run continuous automated monitoring | 58% | 48% |
| Have a clearly defined owner with consistent enforcement | 55% | 48% |
| Have done organization-wide or departmental content cleanup | 89% | 86% |
| Reported an AI exposure incident | 16% | 29% |
| Describe their governance as operationalized or better | 77% | 63% |
Continuous monitoring means the surveillance is running whether or not anyone’s actively checking. Defined ownership means the accountability question is answered before an issue lands. Both are more common here, and neither gap is large enough to carry an explanation on its own. The cleanup gap is smaller still, close enough to the study average to be noise.
The incident row is the one to read carefully, because it's the easiest to misread. This group does report AI exposure well below the sample. But an exposure incident is itself governance work: among teams who had one, 88% say their workload went up. A group defined by workload going down was always going to contain fewer of them. That row describes what being in this group means, not what the habits above bought.
What does hold up is the last row. Three quarters of this group describe their governance as operationalized or better, against 63% of the study, and that gap is the one still standing when you account for all three habits at once. It isn’t a checklist. Most of this group is missing at least one of the three. It’s whether the whole thing runs as an operation.
Compare your environment against the 851 IT leaders in the AI-governance study, filtered by your region, size, and industry, for a peer-ranked score on cleanup, ownership, monitoring, exposure, and maturity, plus the dimensions where the gap between you and the teams whose workload got lighter is widest.
That's the operating model. Not "deploy AI and hope." Not "deploy AI and add headcount." Deploy AI into an environment where monitoring and ownership are handled and defined, and the tools start giving back time instead of taking it.
In this study, 8% of leaders couldn’t say whether AI had surfaced something it shouldn’t have. Among the teams who hadn’t finished a content cleanup, that figure was 20%, three times the rate among teams who had. “Not sure” is the most actionable answer in the whole dataset, because it’s the one you can resolve without a project.
Pull a list of every AI agent and Copilot deployment currently active. For each one, note what data sources it connects to and who approved it. Flag anything unowned, unknown, or connected to sensitive sources. You're not remediating yet. You're establishing whether you can answer the question at all. Most teams find the exercise takes an afternoon and changes the conversation, because "we have full visibility" and "we can produce the list" turn out to be different claims.
These two go together: monitoring without ownership generates alerts nobody acts on, and ownership without monitoring is accountability for something you can't see.
On monitoring: 48% run continuous automated monitoring today. If you're in the 37% doing periodic reviews, you don't need to jump straight to full coverage. Start with the signals that change fastest: new agents appearing, changes to what an existing agent can reach, and sensitivity-label changes on content in scope for AI.
On ownership: if you already have a defined owner with consistent enforcement, this quarter's work is coverage. If you're in the 26% where enforcement varies, or the 22% with shared ownership, the work is naming one person with the authority to say no.
The cleanup data makes a specific argument: organization-wide cleanup didn't produce fewer reported incidents, it produced fewer unknowns. The teams that had done the work could answer the question. The teams that hadn't were three times more likely to say they didn't know.
That's the target state. Not "no incidents," which no environment can promise. An environment where you would know. Concretely: content and permissions cleaned at tenant scale, workspace lifecycle automated, continuous monitoring across every AI tool, and a defined owner who can evidence all of it to an auditor.
The 10% whose governance workload went down after deploying AI are the proof this is achievable. Not as a checklist: most of them are missing at least one of the three habits this chapter walked through, and the survey never asked what order anyone did things in. What three quarters of them share is a posture.
They described their governance as operationalized or better, against 63% of the study. That's the difference that holds up once the individual habits are accounted for. Then re-measure, and treat the result as the evidence, rather than the confidence, that the first part of this chapter was about.
Built for exactly this: tenant-scale visibility into permissions and sharing, automated policies that keep the environment clean, in-context remediation, and impact metrics you can hand to an auditor or a CFO. See it, fix it, keep it that way.
Discover Protect →