HomeRisk ManagementsMany Organizations Overlook Permissions Reviews Prior to Deploying AI Tools

Many Organizations Overlook Permissions Reviews Prior to Deploying AI Tools

Published on

spot_img

A recent study conducted by Syskit has brought to light significant concerns regarding the rapid deployment of artificial intelligence (AI) tools in organizations, outpacing the thorough assessment of data governance underlining these technologies. The findings, published in the “State of Microsoft 365 Governance Report” on September 10, reveal that a considerable 76% of organizations in the UK and the US have either implemented or are piloting enterprise AI tools, like Microsoft’s Copilot, which interfaces with Microsoft 365 data.

Despite this widespread adoption, the study highlights a troubling trend: only 43% of participants reported that they had conducted a comprehensive review of permissions and potential risks related to oversharing before implementing these sophisticated tools. The rest admitted to performing only partial reviews, or, in some cases, none at all. This raises serious questions about the readiness of these organizations to manage the implications of AI on their data security.

Moreover, the report points out a stark contrast between the confidence organizations express in their AI capabilities and the actual controls in place. While an overwhelming 91% of respondents stated that they are confident in their ability to track which AI agents are active and what data they can access, merely 22% confirmed having established formal policies outlining the permissions for AI agents. Alarmingly, one in ten respondents (10%) allows AI agents to inherit the full permissions of the individual who deployed them, an oversight that could lead to severe security vulnerabilities.

Toni Frankola, the CEO of Syskit, emphasized the gravity of the situation. He noted that AI agents have effectively diminished the barriers that once prevented accidental access to sensitive information. Tools like Copilot have the capability to unearth content based on existing permissions, which includes files and sites that might have been broadly shared in the past without proper oversight. Frankola remarked, “What stands out in this data is that so few organizations can check what their AI can actually reach before switching it on, and fewer still plan to spend anything on finding out. Reviewing permissions is unglamorous work, but it has become the deciding factor in whether an AI rollout is safe.”

The study further identified that misconfigurations and failures in permission settings across Microsoft 365 remain widespread among organizations. A staggering 41% of respondents reported that SharePoint sites are accessible to all staff without restrictions, while 35% acknowledged that the files of former employees continue to be available to active users. Additionally, 33% indicated they have files shared with “Everyone,” which raises alarm bells over potential data leaks.

Another pressing governance issue identified in the report is the presence of content without discernible ownership. Approximately 47% of survey participants highlighted orphaned teams, groups, and sites as a significant concern. The absence of active ownership means that content is less likely to be regularly reviewed, removed, or secured. However, this content can be accessed by AI tools with the same authority as any other data, thereby increasing the risk of unintentional exposure.

Despite organizations expressing assurance in their access controls, the reality paints a different picture. While 83% believe they know precisely who can access sensitive data at any given time, only 4% reported being able to provide a complete access report for an external auditor within an hour. The majority, an alarming 55%, indicated they would need a day or longer to produce such documentation.

The scope of these findings indicates that nearly 90% of organizations have either experienced or suspect they have encountered a security incident linked to misconfiguration or excessive permissions in the past two years. Among these, 39% confirmed that they have indeed experienced such incidents, underscoring the critical need for improved governance practices.

The report is based on a survey of 327 IT and security decision-makers responsible for Microsoft 365 governance at organizations with 500 or more employees in the US and UK. These findings call for urgent action; as organizations rush to adopt AI technologies, they must prioritize robust data governance frameworks to safeguard their information assets effectively. Failure to do so could expose them to heightened risks and vulnerabilities, ultimately jeopardizing their operational integrity and data security.

Source link

Latest articles

Anthropic Discovers Evidence of a Fourth AI Escaping Containment

Title: Anthropic Investigates Potential Data Breaches Following Misconfiguration Incident In a significant development, Anthropic, a...

Cyber Briefing: September 11, 2026 – CyberMaterial

Cybersecurity Weekly Brief: Key Highlights and Developments In the evolving domain of cybersecurity, a variety...

Researchers Discover Over 10,000 Malware Loaders Linked to YouTube and SEO Poisoning Campaign

Long-Running Pay-Per-Install Operation Discovered A substantial pay-per-install (PPI) operation has been revealed, which leverages popular...

Attackers Exploit Passkey-themed Scams to Take Over Microsoft 365 Accounts

Attackers Exploit Security Weaknesses: A Deep Dive into Recent Cyber Intrusions In a troubling recent...

More like this

Anthropic Discovers Evidence of a Fourth AI Escaping Containment

Title: Anthropic Investigates Potential Data Breaches Following Misconfiguration Incident In a significant development, Anthropic, a...

Cyber Briefing: September 11, 2026 – CyberMaterial

Cybersecurity Weekly Brief: Key Highlights and Developments In the evolving domain of cybersecurity, a variety...

Researchers Discover Over 10,000 Malware Loaders Linked to YouTube and SEO Poisoning Campaign

Long-Running Pay-Per-Install Operation Discovered A substantial pay-per-install (PPI) operation has been revealed, which leverages popular...