Skip to main content
Back to InsightsBuild

Preparing your environment for AI

By Slink Editorial

Microsoft Copilot and similar AI productivity tools promise to accelerate how knowledge workers operate — drafting communications, summarising meetings, finding information, automating routine tasks. The promise is real. So is the risk of enabling these tools in an environment that isn't ready for them. AI tools don't improve a broken environment. They amplify it.

The amplification problem

AI tools that surface information do so by traversing what the user has access to. In a well-governed environment, that means appropriate content is surfaced appropriately. In an environment where access controls are loose — where staff have broader permissions than their role requires, where sensitive documents are in shared locations without access restrictions, where former employees still have active accounts — the AI surfaces that content too, to anyone who has access to the AI tool.

The most commonly cited risk when organisations enable Microsoft 365 Copilot is that staff discover content they weren't intended to access — salary data in an HR folder that was shared too broadly, confidential client information in a project site that everyone could see but nobody thought to check, strategic documents from the executive team in a location that was assumed to be private. Copilot's search is comprehensive and fast. It finds what's there.

Identity and access: the starting point

Before enabling any AI tool that traverses your data, review your access control model. Start with your identity provider — typically Microsoft Entra ID or Google Workspace — and audit group memberships and permission assignments. Are permissions granted at the individual level, creating a maintenance burden as people change roles? Are there broad groups with access to sensitive content that were created for convenience rather than necessity? Are former employees' accounts deactivated and their access removed?

The principle of least privilege — giving each user access to exactly what their role requires and nothing more — is the correct baseline for an AI-ready environment. It's also, separately, the correct baseline for security. Preparing for AI is an opportunity to get this right if it hasn't been done already.

Data classification and location

AI tools surface data based on where it lives and who can access it. If sensitive data is stored in locations that aren't restricted appropriately, that sensitivity is invisible to the AI. The tool will surface the data to anyone it's relevant to, because it has no way to know that the data was intended to be restricted.

A data classification exercise — identifying where sensitive data lives, what category it falls into, and whether the access controls on its location are appropriate — is a prerequisite for safe AI enablement. Microsoft Purview provides labelling and classification capabilities within the Microsoft 365 ecosystem. The exercise of labelling also forces the discovery work: you can't classify what you haven't found.

Device compliance

AI productivity tools typically run on managed devices. Before enabling Copilot, confirm that your device management policy is in place and enforced — that devices accessing Microsoft 365 or Google Workspace are enrolled in your MDM solution, that encryption is enabled, that OS versions are current, and that conditional access policies prevent access from unmanaged or non-compliant devices.

This isn't new guidance — it's the standard baseline for a well-managed Microsoft 365 or Google Workspace deployment. AI tools make it more consequential, because the surface area of what a compromised device can access expands when AI is traversing content on the user's behalf.

Starting the right way

The businesses that get the most from AI productivity tools are those that take the preparation seriously rather than treating it as a compliance checkbox. The preparation work — tightening access controls, classifying data, enforcing device compliance — improves the environment regardless of whether AI is then enabled. The AI deployment is then lower risk and higher value, because it's working with a well-governed foundation rather than amplifying the gaps in one that isn't.

Ready to move forward?