
Every large organization is somewhere on the enterprise AI deployment curve right now. Some are running Copilot across tens of thousands of employees. Some are piloting internal models in controlled environments. Some have deployed AI agents into operational workflows. And a significant number have done all of the above, in different corners of the organization, without a unified governance framework connecting any of it.
That last scenario is where the real risk lives — and it’s more common than most security and governance leaders want to admit.
A Cloud Security Alliance and Token Security study in 2026 found that 63% of organizations cannot enforce purpose limitations on their AI agents, and 60% cannot terminate a misbehaving agent once it’s running.
Let that sit for a moment. Six out of ten organizations with deployed AI agents cannot stop one if it starts behaving outside its intended boundaries. That’s not a theoretical governance gap. It’s an operational reality producing real incidents right now.
How We Got Here
The deployment velocity of enterprise AI has outpaced governance infrastructure at almost every organization that’s been honest about it. Productivity tools like Microsoft 365 Copilot moved from pilot to broad deployment faster than security teams could establish access controls, data classification standards, or monitoring frameworks. AI agents were introduced into workflows by business units that never asked security first. Shadow AI — employees using personal or unauthorized tools with work data — became endemic before most organizations had a policy to address it.
JPMorgan’s $1.8 billion AI investment, running 450+ use cases across more than 200,000 employees, was built governance-first, with a C-suite oversight council and compliance embedded from the start. Goldman Sachs runs every model through its Model Risk Management framework, with bias detection, data lineage tracking, and human-in-the-loop controls across all regulated operations. Both banks deployed AI to every employee’s desk. In both cases, governance is what made that scale achievable — not a constraint on it.
That’s the model. Governance isn’t what slows down AI deployment. It’s what makes broad deployment survivable.
Forrester predicts 60% of Fortune 100 companies will appoint a dedicated head of AI governance in 2026. Board oversight of AI has increased 84% in public company disclosures. Morgan Stanley and BlackRock are factoring AI governance maturity into company valuations. When investors start pricing governance maturity into valuations, it’s not a trend anymore. It’s infrastructure.
The Copilot Problem Specifically
Microsoft 365 Copilot is the most widely deployed enterprise AI tool in large organizations, and one of the most misunderstood from a security and governance perspective.
Copilot isn’t a standalone app — it’s embedded in Microsoft 365 experiences and grounded in the organization’s existing data and permissions. That interconnectedness means a misconfiguration in one area cascades across the entire AI implementation. Seventy-three percent of organizations in regulated industries have paused enterprise-wide Copilot rollouts because governance infrastructure wasn’t in place when deployment began.
The core issue: Copilot operates on the permissions that already exist in your M365 environment. Whatever a user can access, Copilot can access on their behalf — and surface in responses to other queries. If your data classification and access hygiene is poor, Copilot won’t fix it. It will surface every unclassified sensitive file an employee happens to have permission to reach.
In June 2025, security researchers disclosed a zero-click vulnerability in Microsoft 365 Copilot — CVE-2026-42824 — requiring no user interaction: an attacker sends a crafted email, and the next time the victim queries Copilot about anything touching that email, the tool silently exfiltrates prior conversation data to an external server.
A zero-click exfiltration vulnerability in the AI tool embedded across your entire M365 environment isn’t a niche technical concern. It’s a board-level risk event — and exactly the kind of incident organizations with immature AI governance are more likely to discover after the fact than prevent.
Enterprises need to govern Copilot through strong data classification, DLP policies, sensitivity labels, and usage monitoring, combined with clear policies on prompt usage and output verification, with a cross-functional team ensuring balanced governance. That’s the technical layer. The governance layer underneath requires a data classification program that’s actually current, an access review process extended to M365 content, and monitoring capable of detecting anomalous Copilot behavior — not just anomalous user behavior.
The Agent Governance Gap
Copilot augments user action. AI agents are a different category: autonomous systems taking actions on behalf of the organization without requiring a human to execute each step. The governance requirements are correspondingly different, and most organizations don’t have them.
Every AI agent, copilot, and automated workflow that accesses enterprise data should be cataloged with its data access scope, credential type, policy enforcement status, and termination capability. Shadow AI is the top driver of negligent insider incidents — you cannot govern what you haven’t inventoried.
The inventory is the foundation. Without knowing what agents are deployed, what data they touch, and what actions they can take, governance is theoretical. That exercise will surface agents deployed without security review, agents with access exceeding their operational requirements, and agents with no documented termination procedure.
Governance needs to operate at three layers: the Usage Layer, which controls and monitors access to public AI services while applying policy and logging interactions; the Agent Layer, which governs what agents can do, which tools they can use, and how their actions are constrained; and the Model Layer, which protects against prompt injection, misuse, and data leakage.
The kill switch problem deserves specific attention. If 60% of organizations can’t terminate a misbehaving agent, that means 60% have deployed autonomous systems they cannot stop on demand. That’s an operational control failure that would be unacceptable for any other class of privileged system. It should be unacceptable for AI agents too. Every deployed agent needs a documented termination procedure, a named owner, and a tested kill switch.
The Governance Framework Your Organization Needs
This doesn’t require a massive program rebuild. It requires getting four things right.
AI System Inventory. Everything deployed — Copilot, agents, embedded AI in SaaS tools, shadow AI identified through monitoring — cataloged with data access scope, owning business unit, approval status, and termination procedure. This inventory is the foundation of everything else.
Data Classification and Access Hygiene. AI tools operate on the permissions and data that already exist. If your data classification program has been deferred, AI deployment is the reason to prioritize it now. Copilot will surface sensitive data living in permissive M365 environments. Agents will access whatever their credentials allow, regardless of whether that access is appropriate for the task.
Purpose Limitation and Scope Controls. Every deployed AI system should have a documented purpose, and governance controls should enforce it. An HR workflow agent shouldn’t have access to financial systems. A customer service tool shouldn’t be able to exfiltrate conversation history. Microsoft Purview has evolved into the central nervous system of AI governance for M365 environments — organizations need to shift from reactive content oversight to proactive governance so the data driving AI systems is properly managed, labeled, and secured.
Board Visibility. AI governance is a board-level topic in 2026 — not because boards need to understand prompt engineering, but because the organizational risk exposure from ungoverned AI deployment — data leakage, regulatory liability, operational disruption from misbehaving agents — is material risk boards have fiduciary responsibility to oversee. The board needs to know what’s in production, what governance controls exist, and what the escalation path is for a significant AI incident.
The organizations getting enterprise AI governance right aren’t the ones that deployed slowest. They’re the ones that built governance infrastructure before deployment velocity made it impossible to catch up. If your organization is already deployed, you’re building the framework retroactively — harder, but not impossible. Start with the inventory. Everything else follows from knowing what you actually have.
Discussion Questions
- Does your organization have a complete inventory of deployed AI systems — Copilot, AI agents, SaaS-embedded AI, and shadow AI tools employees are using with work data?
- Can your organization terminate a misbehaving AI agent on demand? Is that procedure documented and tested, with a named owner?
- Does your board currently receive reporting on AI governance — what’s deployed, what’s governed, and what the material risk exposure is?
Further Reading
- NIST AI Risk Management Framework 1.0: https://www.nist.gov/system/files/documents/2023/01/26/AI%20RMF%201.0.pdf
- Microsoft Copilot Security and Governance Documentation: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy
- Cloud Security Alliance AI Safety Initiative: https://cloudsecurityalliance.org/research/topics/artificial-intelligence
- EU AI Act Article 50 Transparency Requirements: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
Cody Keller is an Information Security Manager specializing in Governance, Risk, and Compliance with over ten years of experience in cybersecurity strategy, risk management, and regulatory compliance. He holds the CISSP, CISM, and CRISC certifications and is the author of The Parent’s Guide to Online Safety. Through CKCybersecurity.com, he writes and consults on practical security program management for organizations navigating an increasingly complex threat and regulatory landscape. Connect on LinkedIn at linkedin.com/in/codyjkeller or reach out at ckcyberconsulting@gmail.com.
Leave a Reply