Only 43% reviewed permissions before turning on the AI agent
A survey by Syskit, reported by Infosecurity Magazine, indicates that only 43% of organizations that have already put AI agents to work in Microsoft 365 environments reviewed access permissions before releasing the tool to users. Read from the other side, the number becomes more concrete: 57% activated the assistant on the same base of files, folders and mailboxes the company has accumulated over the years, without a formal check of who, or what, can read each document.
The mechanics behind this are simple, and it is precisely because they are simple that they are unsettling. An AI agent answers based on what it is authorized to read, so if the authorization is broad, the answer comes out broad as well. The study points to recurring issues in these environments such as legacy permission inheritance, folders shared "with the entire company" and former employees' accounts that remain active, and none of this requires an outside attacker to become a business problem.
It is worth taking a question to the next board meeting: if an employee asks the corporate assistant for a summary of last quarter's margins, what exactly would they be allowed to find along the way?
What this news means for decision-makers
For partners, owners and C-levels, the impact shows up first in margin, contracts and reputation, well before it shows up on any technical dashboard. Documents such as price lists, proposals under negotiation, payroll and customer data have always circulated in collaborative environments, and the difference is that the AI agent removes the friction of searching, delivering in seconds what no one would previously have found without knowing the exact folder path.
In practice, the request for "a company AI" usually comes from a business area with a legitimate urgency to gain productivity, and it tends to be approved in a short meeting focused on licensing, cost and timeline. The question of which data the assistant will be able to answer about rarely makes it onto that agenda, not out of carelessness, but because it looks like a deployment detail when it is in fact a decision about governance and compliance.
How to prepare the ground before the first question to the agent
The first move is an identity inventory, that is, a clear list of who exists in the environment, who has already left the company, which service accounts are active and what each access group can actually see. This inventory tends to reveal a great deal in a short time, because orphaned accounts and inherited groups surface easily when someone finally looks at the entire list all at once.
On top of that foundation come the managed cybersecurity capabilities that support day-to-day operations: MFA (Multi-Factor Authentication) to block the use of inherited or reactivated accounts, continuous proactive monitoring to flag access and reading volumes outside the norm, EDR (Endpoint Detection and Response) on the devices where these documents end up being downloaded, and patch management to keep the environment eligible for the latest protections offered by the platform.
Could your company explain, in an audit, what the AI agent is allowed to read?
This is the question that separates AI adoption that generates productivity from the kind that generates rework. Answering it well does not require stopping the project, it only requires flipping it into the right order: identity inventory and permission review first, then a pilot with a small group, and broad release once the access map is documented.
In practice, a managed IT model supports exactly this cycle, combining identity inventory, periodic permission review, consistently enforced MFA, continuous proactive monitoring, patch management, EDR on endpoints, a tested backup routine and team training on what is and is not worth asking a corporate assistant. The good news is that none of these capabilities are exotic or time-consuming to set up, and the internal IT team remains in charge of the strategy, gaining backup support to carry out the operational side methodically.
References
Frequently asked questions
Why review access permissions before activating an AI agent?
An AI agent answers based on the files it is authorized to read, so broad permissions produce broad answers. Reviewing access before activation prevents contracts, payroll and sales proposals from showing up for people who should never see them. According to a survey reported by Infosecurity Magazine, only 43% of organizations conducted this review before releasing AI agents in Microsoft 365 environments.
What goes into an identity inventory?
An identity inventory lists every active account in the environment, including current employees, former employees, contractors and service accounts, along with each one's access groups and what those groups are able to see. The goal is to uncover orphaned accounts, legacy permission inheritance and folders shared broadly without any need for it. It is the natural starting point of any access governance project.
Which managed IT capabilities support safer AI adoption?
The main ones are periodic permission review, identity inventory, multi-factor authentication, continuous proactive monitoring of out-of-the-norm access, EDR on endpoints, patch management and backup with tested restoration. Together, they reduce internal data exposure and generate the evidence trail that audit and compliance ask for. Team training completes the set, because it defines what makes sense to ask a corporate assistant.
If you would like to start with the access map before your next AI step, Zamak offers a Strategic IT Assessment, No Strings Attached.