AI adoption
Building AI on Microsoft 365 without creating a new risk
Lee, Co-founder and CEO · 30 September 2026 · 6 min read
The safest place to build AI is inside the platform you already govern. Use your existing identity, permissions and data rules, and AI on Microsoft 365 adds capability without adding a new silo.
Build where you already have control
Most organisations already have identity, permissions, retention rules and audit logs set up in Microsoft 365. Building AI inside that environment means you inherit those controls rather than recreating them somewhere new.
The alternative is a standalone tool with its own accounts, its own copy of your data and its own security questions. Each of those is a new risk to assess and a new place for information to leak.
The main risks to watch
AI does not create most of the risk. It exposes the risk that was already there. A tool that searches across your files will happily surface whatever the user has permission to see, including documents that should never have been shared so widely.
- Over-shared files and sites with loose permissions
- Sensitive content with no classification or labelling
- Staff using unapproved tools with company data
- No clear record of what AI was used for, or by whom
Tidy permissions before you switch it on
Before rolling out any AI feature that reads your content, review who can access what. Fix the obvious problems: sites open to everyone, long-forgotten shares and former contractors with live access.
Apply sensitivity labels to the material that matters most. You do not need to label everything. Start with the areas where a leak would cause real harm, such as HR, legal, finance and client files.
Keep a person in the loop
Design each workflow so a named person reviews the output before it has consequences. That might be approving a drafted email, checking an extracted figure or confirming a classification. The aim is to make review quick and meaningful, not to add ceremony.
Log what the AI did and who approved it. If a question arises months later, you will be glad to have the record.
Start with one process
Choose a single process with a clear owner, build it inside the platform, and test it with a small group. Check the permissions, the logging and the failure cases. If it holds up, extend it. If it does not, you have learned that cheaply and with a contained blast radius.
