Kildaris

Service 03

Your AI tools can see more than you think.

There are two versions of this problem. The assistant you deployed inherits every permission your staff already have, including years of over-broad sharing nobody noticed. And the tools you did not deploy are being fed company data through personal accounts you cannot see.

Why this comes before deployment, not after

A permission audit before you switch Copilot on costs far less than an exposure afterward. The reason is simple: Copilot does not break permissions, it obeys them. If a salary spreadsheet was shared with "everyone in the organization" in 2021 and forgotten, it was technically open the whole time. Nobody found it because nobody thought to search. Natural language search removes that accident of obscurity.

The pattern we see most. A SharePoint site created for one project, shared organization-wide for convenience, and never revisited. Multiply by five years.

What the audit covers

The audit covers six layers: where content is over-shared, what is sensitive enough to need labeling, what should be blocked from leaving, what your staff are allowed to do with AI tools in the first place, which unapproved tools are already in use, and whether the vendors behind them are covered by an agreement that protects you.

  • Permission exposure. SharePoint, OneDrive, and Teams reviewed for organization-wide links, anonymous links, and stale external guests.
  • Sensitivity labeling. Microsoft Purview labels applied to the categories that matter, with automatic labeling where the pattern is reliable.
  • Data loss prevention. Policies that stop the specific things you care about leaving, tested against real files instead of theory.
  • Acceptable-use policy. A written, readable AI policy your staff can follow, covering what may be pasted into which tools.
  • Shadow AI discovery. Which unapproved AI tools are already in use, found through DNS, browser extension inventory, and tenant telemetry.
  • Vendor review. For each AI tool you keep, whether a data processing agreement exists, where the data is held, and whether your content can be used for model training.

The tools you did not deploy

Shadow AI is now the bigger exposure at most small businesses, because it carries no agreement at all. Verizon's 2026 Data Breach Investigations Report found AI use on corporate devices tripled from 15 to 45 percent of workers in a year, that 67 percent of that use runs through non-corporate accounts, and that the average company has unapproved AI browser extensions on more than 15 percent of its users. Shadow AI now ranks as the third most common non-malicious insider action in their data loss prevention dataset.

AI use on work devices15% to 45%Change across a single reporting year
Signed in personally67%Of AI users on corporate devices
Unapproved AI extensions15%+Of users at the average company

The practical consequence is that a policy written only for Microsoft Copilot governs a minority of the AI use in your business. Governance has to cover ChatGPT, Claude, Gemini, Perplexity, and the writing and coding assistants people install for themselves, or it governs the one tool that was already the safest. Discovery comes first for that reason. A rule nobody can follow, covering tools nobody admits to using, changes nothing.

Sources. Verizon 2026 Data Breach Investigations Report. We produce the equivalent figures from your own environment during the audit, because the industry number is only useful for deciding whether to look.

What it costs

AI governance audits start at $2,000 as a fixed fee. Larger or messier tenants cost more, and we tell you which you are before starting, not after. Remediation is quoted separately once we know the size of the problem, because quoting cleanup before measuring it is guesswork dressed as a proposal.

The insurance angle worth knowing

Several major carriers added AI exclusions to standard technology errors and omissions policies during 2026. If your business is deploying AI tools, it is worth confirming in writing whether your own policy still responds. We are not insurance advisors and will not pretend to be, but we will tell you what we see, and a documented governance position helps that conversation.

Questions

Common questions

Why does Copilot need a security review before deployment?

Copilot surfaces any content a user already has permission to open. Most tenants have accumulated years of over-broad sharing that went unnoticed because nobody searched for it. Natural language search makes that content easy to find, so the permission review should happen first.

What does an AI governance audit cost?

Audits start at $2,000 as a fixed fee. Remediation is quoted separately after the audit, once the scope of cleanup is actually known.

Do we need Microsoft Purview licensing?

Sensitivity labeling and basic DLP are included in Microsoft 365 Business Premium and E3. Advanced capabilities need additional licensing, and we will tell you whether you need it before you buy it.

What is shadow AI?

Shadow AI is any AI tool your staff use without approval, typically free consumer chatbots and browser extensions. The risk is company data pasted into a service with no agreement covering it. Verizon's 2026 Data Breach Investigations Report found that 67 percent of AI use on corporate devices runs through non-corporate accounts. Discovery finds what is already in use so policy can be realistic.

Does governance cover ChatGPT and Claude, or only Microsoft Copilot?

All of them. Permission and labeling work is Microsoft-specific because that is where the content lives, but discovery, acceptable-use policy, vendor review, and data loss prevention cover ChatGPT, Claude, Gemini, Perplexity, and the writing and coding assistants staff install themselves. A policy covering only Copilot governs the smaller half of the problem.

Can you write our AI acceptable-use policy?

Yes, and it is included in the audit. It is written to be read by staff, not filed by legal, because a policy nobody reads changes no behavior.

Next step

Thirty minutes, and you will know where you stand.

No pitch deck. We look at what you are running, tell you what we would do first, and you decide whether that is worth paying for.