Ask the people who run Microsoft 365 whether their governance is in good shape for the AI era, and 93% say yes.
Ask those same people whether content that shouldn’t have surfaced has shown up in Copilot results, and yet 29% reported that AI tools had surfaced sensitive internal data that should not have been accessible, while another 8% were unsure whether it had happened.
That gap, overconfidence on one side, poor visibility on the other is the defining governance problem of 2026, says Richard Harbridge, Principal Industry Advisor, Microsoft 365 at ShareGate and a long-standing Microsoft MVP.
ShareGate is trusted by more than 200,000 IT pros and partners, and its annual research surveys hundreds of the people responsible for Microsoft 365.
What the data shows is a discipline in transition: governance used to be a tax. Now it’s the thing that decides whether your AI investment pays off at all.
In part one, Richard argued that migration is never really finished. Here’s the punchline: the same work that makes migrations succeed is the work that makes governance succeed too.
In part two, Richard discusses why governance should kick in the moment a migration happens, and why it has to continue or the environment will begin drifting again.
What does good governance look like now?
Richard Harbridge (RH): I’ve been using this analogy of sediment. Think of all the technology decisions you’ve made over the years, every access decision, every little call we make all the time in business. They build up like sediment. Normally you don’t have to dig through it; search does it for you. But AI has to dig through that sediment. So, when there’s stuff in there it shouldn’t be finding, that’s when you feel it.
Migrations have to deal with all that sediment too. You can’t migrate without sifting through it. That’s why I say migrations are a great test. If you’re doing a good job of understanding those layers and pulling them apart, your AI and governance journey will be much more successful. All that hard inventory and business-attribution work from the migration? Keep it. Use it as the basis for governance.
The other shift: historically, governance was policies and playbooks. Now it’s increasingly how we operate. Clean-up projects still happen, but they’re not enough anymore, because AI is generating content exponentially and agents are now requesting access themselves.
An agent is not going to spend its own tokens and goodwill telling you it doesn’t need that access anymore. If you architect it well, every access an agent gets is temporary whenever possible, and oversharing never accumulates. If you don’t, you’re compounding sprawl at machine speed.
“All those years of access decisions build up like sediment. AI has to dig through that sediment.”
Where does the overconfidence come from?
RH: I think we’ve done ourselves a disservice. We call it AI readiness, but readiness is not a finish line. What made you AI-ready last year is fundamentally different in a multi-agent world, where agents increasingly take action rather than just retrieving data like a passive assistant.
Every step in that direction demands greater governance depth. It’s not just sensitivity labels anymore; it’s proportionate coverage across all your content. Those inactive sites that didn’t matter before? Now other sites have their own agents, as agents become more interconnected and begin contributing to workflows and decisions, outdated or poorly governed information can propagate further and faster than it did through search alone.
So, you get this mix of confidence and blindness. And here’s the part I find fascinating: the people most frustrated with oversharing and permission sprawl are overwhelmingly the ones relying on native tools alone, about 50% of organizations. Fewer than 1% use purpose-built governance tooling. That number hasn’t moved in a year. The gap between the problem and the response is enormous.
“We call it AI readiness. But really, we’re never ready.”
Who is actually in charge of governance?
RH: That’s the first of two problems: accountability. Governance is treated as shared, and everyone who’s ever worked in IT knows shared accountability doesn’t work. Shared understanding is great. Shared ownership is fine. Shared accountability is not. That one’s fixable. Break it down, name who owns which outcomes.
The second problem is harder: the load. There is more governance investment than ever. Purview and information governance expertise are sexy now, and finally receiving strategic attention, and yet the total governance load keeps increasing. Because just as organizations finally catch up on resource governance, sites, content, permissions, the stuff we understand, a whole new category has landed: AI governance. How do we discover agents? How do we bring them into our ecosystem? How do we handle the shadow side of it?
Look at the numbers. Among organizations we surveyed, 77% were deploying Microsoft 365 Copilot alongside ChatGPT Enterprise at 54%, Gemini at 36%, Claude for Work at 31%. Multi-model is simply the reality of the enterprise now.
But only 47% had full visibility into what data Copilot was touching. And every connector you add loses fidelity, the visibility Microsoft can give you inside its own ecosystem largely disappears outside it. So, governance teams are being asked for visibility that, functionally, doesn’t exist yet.
“Shared understanding is great. Shared ownership is fine. Shared accountability is not.”
Agents, skills, is this a whole new attack surface?
RH: On the surface, SharePoint Skills look like a governance freebie, they look relatively contained. They inherit permissions, they can’t reach outside the SharePoint environment, they run on behalf of the user in the moment. Simple checkmark, right?
Dig deeper. First, skills multiply, just like sites did. Two redundant skills, both shared, and your agent has to make a judgment call about which to use. We’re going to have to consolidate skills the way we consolidate systems.
Second, and more interesting: most people have edit rights to each other’s skills, because they live in SharePoint and, as we’ve established, everyone overshares.
Consider a plausible abuse scenario: someone with edit rights changes a widely used vendor-evaluation skill so that it subtly favours one vendor. Even if the line is removed later, detecting the change, understanding its intent, and identifying every affected decision could be difficult. Yet detecting exactly that is our responsibility.
The point is not that this is already widespread. It is that reusable instructions are becoming governed business artifacts, and they need controls appropriate to that role.
I’m not fear-mongering. The point is that capability always outruns visibility, and the dangerous gaps are the ones you don’t know exist. A mature governance response sees a new capability and asks: are we instrumenting visibility so we’d know if this were ever abused? An immature one sees a checkmark that permissions are inherited.
Most IT teams are already overwhelmed. Where should they start?
RH: Take what you understand and solve that first. The vast majority of effort right now should go on the unglamorous questions: What’s inactive? What’s overshared? Where does highly sensitive content live?
You can detect that with Purview even on E3, before you get anywhere near E5 auto-labeling. Does it exist, where does it exist, where are the hot spots? Any organization can get that data, and once you have visibility, you can act.
And let go of the anxiety that everyone else is miles ahead.
Microsoft talks about “frontier organizations” a lot; the genuinely advanced organizations are still a minority, and the definition of “frontier” varies considerably.
Most organizations aren’t behind.
What’s actually happening in most enterprises is simpler: “we’ve been putting off that migration for years, we’ve been not cleaning up for years, and now we have to.” That’s comforting, in a way because it’s work we understand.
Solve the problems you understand today, and when the frontier problems arrive, you’ll be in position for them.
The near-term prize isn’t replacement, either. We are still, in 2026, in the collaboration phase of AI. The benefit is where you work with it.
For many enterprises, the near-term value still comes from augmentation and collaboration. AI may draft the email, summarize the meeting, or propose the next action, but people still provide context, judgment, and accountability.
IT’s job is to be proactive in reducing friction and building confidence inside that collaboration, safely scaled, not to bet the main revenue lines on moonshots.
“Most organizations aren’t behind. Solve the things you understand today, and you’ll be ready for the frontier when it arrives.”
Is there any good news in your data?
RH: Genuinely, yes. 78% of IT leaders now say governance activity directly affects their confidence in AI investment. That’s the shift: governance used to be positioned as a tax, and now, especially at the C-level, it’s understood as the enabler.
I’d go further. Access to strong models is becoming less differentiating. What remains distinctive is how your organization combines its people, processes, governed data, and institutional knowledge.
The model may be shared. Your people, processes, and governed data are not.
SharePoint Skills are fascinating for exactly this reason: they offer an early example of how parts of an organization’s process knowledge can become reusable digital artifacts rather than remaining buried in documents or individual experience.
The organization that understands, cleans, and curates that has a real advantage over a competitor in the same field with the same models.
So how you operate, organize, and optimize what you already manage, that’s increasingly what governance is. And for the people doing it, it’s one of the best career bets in IT right now.
“Governance used to be a tax. Now it’s the enabler and your data is the competitive advantage.”
Richard Harbridge is Principal Industry Advisor, Microsoft 365 at ShareGate and a long-standing Microsoft MVP. He built and sold consulting businesses in the US and Canada, worked with partner executives at Microsoft, and now leads CIO think tanks and ShareGate’s annual Microsoft 365 research.
Not sure whether your Microsoft 365 estate is Copilot-confident or just Copilot-hopeful? Cloudwell can help you find out.
Other useful Cloudwell blogs on governance:
https://cloudwell.io/copilot-5-sharepoint-governance-fixes-to-make/
https://cloudwell.io/susan-hanley-on-sharepoint-knowledge-management/