A 2025 Gartner survey found 60% of IT leaders started a Copilot project and only 6% moved past the pilot. What separates the two is almost always the governance work done before deployment.
In this article
Gartner found 60% of IT leaders started Copilot projects in 2025, with only 6% completing a pilot and progressing further. CoreView research puts cancelled or delayed rollouts at 67%.
Copilot removes the friction that kept poorly governed data hidden, so existing permission gaps surface immediately as exposed HR records, pay details, and internal documents.
A readiness assessment applies policy-based checks across SharePoint, OneDrive, Exchange, and Teams, flagging non-expiring external share links, anonymous sharing, sites dormant for 90 to 180 days, and unlicensed accounts left open.
Governance is an ongoing discipline rather than a one-off audit, and locking down the right 20% of controls captures roughly 80% of the protection needed without stripping Copilot of its value.
If your Microsoft Copilot roll-out has stalled somewhere between ‘exciting kickoff’ and effective adoption, you’re not alone. A 2025 Gartner survey found that 60% of IT leaders had started Copilot launch projects, but only 6% managed to finish the pilot and move toward a larger deployment. This aligns with what we’ve surveyed at CoreView, with 67% of organisations having ended up cancelling or delaying their Copilot roll-outs altogether.
This is what happens when an AI adoption pilot skips some of the vital components of the readiness assessment stage. What we tend to observe is that organisations who don’t fully understand what ‘readiness’ looks like for their teams learn quickly what the sheer scope of successfully launching Copilot might involve too late.
The result? Overwhelm takes over, and your exciting strategic move forward gets parked for another quarter with no real idea how to move things forward. It’s something we’ve encountered time and again, but it’s avoidable with the right readiness assessment and a clear best-practice framework from the start.
Almost every Microsoft 365 (M365) estate has some kind of internal mandate to be using Copilot. We’re in a new AI epoch globally, and every organisation is chasing the same goal: build efficiency, cut costs, and hand more work to AI agents.
There’s a clear logic and a strong business case for bringing Copilot into the fold, but what we’re seeing here at CoreView is that execution isn’t meeting demand.
The moment teams start mapping out what Copilot needs access to, the project quickly spiders out into dozens of rabbit holes. What teams are discovering is that without proper governance over the information Copilot can reach, employees, through the Copilot AI agents, may suddenly be able to surface data they were never meant to see.
Consider the sheer volume of data sitting inside your M365 environment, including SharePoint, OneDrive, Teams, and Exchange Online. Without Copilot, you can still find information, but it takes manual searching, and sometimes, maybe, you stumble across things by accident. Copilot changes that entirely. It cuts straight through the complexity that used to slow people down and we’ve coined a phrase that captures this perfectly: the end of security by obscurity.
You can’t release the AI into your environment and try to retrofit governance afterwards because by then, it’s already too late and the proverbial horse has already bolted. Copilot adoption still needs to happen, but it has to happen in the right order with clear governance first, and Copilot second.
We’re already seeing examples of what happens when organisations get this wrong.
There are the savvy employees who get access to a powerful Copilot licence and realise how easy it is to run a query and surface information they were never meant to see, all because internal sharing policies weren’t set up properly.
Sensitive HR records are one example we hear about relatively often, with CEO bonus plans and pay details exposed through Copilot queries being another. Less common, but still concerning, examples involve staff gaining access to Copilot without the organisation’s knowledge. While preparing to release the AI, Microsoft enabled it by default and administrators had no idea it had happened. One large telco client we were working with shared that they started a new workday to find a handful of staff were already running Copilot queries with a licence nobody in the organisation had authorised or switched on.
While none of these cases resulted in extreme data leakage, there are significant risks at play. There’s an obvious compliance issue and a clear security issue around information landing in the wrong hands.
And, perhaps more discouragingly, there’s a morale issue too.
AI already creates enough anxiety for people who feel their jobs might be at risk, and Copilot is no exception. When proper governance isn’t in place, and things start to go wrong, it raises a deeper question for teams: is my personal information, the stuff I thought was secure, actually at risk?
When this happens, governance becomes a people and culture issue as much as a business one.
Before rolling out Copilot, the priority is good governance, and this starts with sourcing and closing the gaps that already exist across your environment.
The core of a Copilot readiness assessment is the data side of the tenant. An M365 environment includes identity services, governance systems, and much more, but from a Copilot standpoint, the real challenge narrows down to data protection, data access, and governance. That means focusing on the platforms where information lives: SharePoint, OneDrive, Exchange, and Teams. Running an assessment means applying policy-based checks across each of these to see how the environment is performing.
We recently worked with a large public sector organisation with hundreds of SharePoint sites. Before deploying Copilot, they wanted certainty that no legacy sharing links were still open to third parties, but the problem was scale. This process involves manually checking hundreds of sites, even through the SharePoint admin console, which is enormously cumbersome. CoreView’s approach is to scan every SharePoint site for inappropriate site- or file-level permissions, tighten what needs tightening, and then put ongoing governance policies in place.
In SharePoint, this also means identifying external sharing links with no expiration, and it extends to sites with anonymous sharing enabled, creating blanket access for unknown external parties, sometimes for valid reasons, but often left on by default and never revisited. Perhaps the biggest one is SharePoint sites with no activity in 90 to 180 days. These are typically spun up for a specific project, then abandoned once it wraps, leaving an open risk point. The same logic applies to OneDrive accounts sharing files externally, and unlicensed accounts left open for employees who’ve long since left the organisation, with no governance over what happens to their information.
A readiness assessment surfaces all of this, giving you a single view of where your standard policies are holding and where they’re not. But surfacing the problems is only half the job. In large, complex estates, fixing what’s been found can mean thousands of hours, finding sites, disabling shares, and archiving information one by one.
That’s why CoreView doesn’t stop at visibility. The real value is in automating the remediation itself, so admin teams aren’t stuck spending six months manually cleaning up the data lake before Copilot can go live safely.
If you haven’t deployed governance for AI and you let it loose anyway, you’ve done it in the wrong order. Inevitably, something goes wrong, you switch it off, and you go back to the drawing board, only now you're carrying an enormous amount of risk aversion baked into your ethos.
We’ve seen this play out time and again - something terrible happens, the organisation decides AI isn't for them, and switches it off. A year later, everyone else is still using it, so they try again, but this time they lock it down to the nth degree, and it’s barely functional inside their organisation.
There’s also the financial layer to consider. Microsoft keeps repackaging its licensing, but rolling Copilot out to even a portion of your users is a genuine financial investment. Deploy it to people who aren’t using it, are afraid to use it, or don’t know how to use it properly, and you’re also looking at a financial decision that’s offering little return. At CoreView, we’re constantly meeting with organisations left disappointed with Copilot’s results, not because the technology failed them, but because their M365 estate and teams were never made ready for it in the first place.
AI is a new, evolving technology, but it’s still governed by controls. Just as you want to adopt it safely, if you wrap it in too many rules, you strip away the value it's meant to deliver. There’s no universal gold standard here, which is why every organisation that runs its own Copilot or readiness assessment will look different.
Perfect can’t be the enemy of good, but ‘good’ still starts with governance. A set of core principles that deliver basic protection won’t cost you Copilot’s effectiveness. Think of it as a minimum viable product: the classic 80/20 rule applies here. Lock down the right 20% of controls, and you’ll capture roughly 80% of the protection you need.
It’s also worth being clear that governance isn’t a one-time exercise. It’s an ongoing discipline, no matter what field you’re in, and we talk about this in terms of drift.
If you’re only auditing your data protection policies once every three years, imagine how far things will have shifted by the time that audit comes around again. New permission models get created, gaps reopen, and without a system to catch that drift and bring it back under control quickly, you’re left with governance that only exists on audit day, not governance that actually holds.
One thing we know for sure is that AI is evolving rapidly. How we use it and what it can do today isn’t going to be the same a year from now, perhaps even only a few months from now. If you’ve deployed Copilot and things are going well, that doesn’t necessarily mean you’ve future-proofed your organisation and your teams for what comes next.
While our advice is always to set up the right governance before rolling out Copilot, if you’re ready and have already deployed it without governance in place, it’s not too late.
Just like the old adage, the second best time to make the right decision is now.