In short: Microsoft 365 Copilot does not grant any new access rights, but it does make overly broad sharing in SharePoint and OneDrive, grown over years, instantly findable through a simple question in natural language. The answer is not a Copilot switch, it is governance in a fixed order: first check and contain oversharing, then set permissions and protective guardrails, and only after that activate in a controlled way. Sound Copilot governance means exactly this order.
Why oversharing is the central Copilot risk
The most common misconception ahead of a Copilot rollout is that the tool accesses data on its own authority. That is not true. Microsoft puts it unambiguously in its architecture documentation: Copilot works exclusively within a person's existing permissions and can only summarise or reference content that this person is entitled to access anyway. So the risk is not a Copilot flaw, it lies in the sharing that was already there beforehand.
The real explosive charge is the sudden findability. Files that were technically shared with many people but practically undiscoverable in the depths of SharePoint and OneDrive are now served up by Copilot at the push of a button. A data analysis by Concentric AI covering more than 550 million records concludes that around 16 per cent of an organisation's business-critical data is shared too broadly, on average around 802,000 files per company (Concentric AI Data Risk Report, 2026, a vendor report, not a neutral standard, but consistent with the problem Microsoft describes itself). The same vendor reports that Copilot accessed around 3 million confidential records per organisation in a single half-year, a figure that has not been independently confirmed but does illustrate the order of magnitude.
That the problem is real and acknowledged shows in how the people responsible have reacted. A survey of 132 IT leaders cited by Gartner found that 40 per cent of organisations delayed their Copilot rollout by three months or more because of oversharing concerns, and 57 per cent initially limited the rollout to trusted users (Gartner, 2025, reproduced via third-party sources). Microsoft has answered the same finding with countermeasures of its own, Restricted Content Discovery, SharePoint Advanced Management, Purview, and recommends a staged approach instead of an unchecked rollout.
There is a second risk dimension alongside classic oversharing: crafted content as an attack path. It is documented in the EchoLeak case (CVE-2025-32711), a zero-click vulnerability discovered by Aim Security (CVSS 9.3) in which a single crafted email could get Copilot to leak internal content from OneDrive, SharePoint and Teams to the outside without any user interaction at all. Microsoft closed the gap server-side in June 2025, and according to its own statement there was no known exploitation in the wild. The lesson stands: governance is mandatory, not optional.
The readiness checklist: clean up in this order
Microsoft summarises Copilot preparation in an official deployment blueprint and arranges it into three consecutive pillars: first fix oversharing, then set up guardrails, then meet regulatory requirements. Activation is therefore the result of a controlled process, not the mere assignment of licences. The following eight steps put that into a workable order.
- Audit permissions and oversharing. Copilot only accesses content the person in question is already allowed to see, so badly set permissions suddenly become visible. Start by getting a picture of the access situation through the SharePoint Advanced Management reports (Content Management Assessment, Data Access Governance reports such as the permissions baseline report and the EEEU report) and the risk assessments from Microsoft Purview DSPM for AI. These reports identify overshared, ownerless or sensitive sites.
- Shield high-risk sites immediately. While the clean-up is under way, sensitive sites can be kept out of Copilot on an interim basis. Restricted Content Discovery (RCD) removes individual sites from Copilot findability without changing permissions, and Purview DLP for Copilot excludes sensitive content from grounding. The alternative, Restricted SharePoint Search, is an allow list of at most 100 sites and explicitly not a security boundary, so switch it off again once the review is done.
- Actually clean up access rights. On the sites identified as sensitive you remove overly broad or anonymous access, narrow sharing links (including «Anyone» links and EEEU links) down to the necessary circle, correct broken inheritance and secure clear site ownership. Microsoft points to SharePoint Advanced Management access reviews and Restricted Access Control (RAC) for this, which hard-limits business-critical sites to a defined Entra or Microsoft 365 group. Anyone who is not in the group does not see the content in Copilot either.
- Establish sensitivity labels and DLP as guardrails. Microsoft Purview Information Protection classifies and protects sensitive content, ideally through auto-labelling and as a default label right at creation. If a label applies encryption, a person needs the EXTRACT usage right (in addition to VIEW) for Copilot to be able to use the content at all. With DLP for Copilot you can exclude labelled files and emails from grounding and keep prompts containing defined sensitive data out of responses, the central lever for banks.
- Secure identity, access and logging. Before activation, multifactor authentication for all users, reviewed Conditional Access policies and enabled unified audit logging with appropriate retention all belong in place. One important point: Copilot is not a separate, directly selectable Conditional Access app, access is controlled through the underlying Microsoft 365 services (SharePoint, Exchange and Microsoft Graph, for example). Plan your policies at service level accordingly and verify the effect against the current state of Entra.
- Clarify regulation and data hygiene. Check the tenant against AI-related requirements with Purview Compliance Manager, define retention and deletion for Copilot interactions and audit logs and provide for eDiscovery of Copilot content. Cleaning up inactive or outdated sites (site lifecycle, Microsoft 365 Archive) lowers risk and improves answer quality. Swiss requirements, FINMA circulars and the revDSG, the revised Swiss data protection act, you assess separately, they are not covered by Microsoft's guidance.
- Activate in a controlled way with a pilot group. Microsoft recommends a three-phase rollout (pilot, deploy, operate). Assign Copilot licences to a small group of early adopters first, ideally people with high existing M365 usage from across the business units. That way you spot problems early, gather feedback and build internal champions before you roll out more widely. In the official guidance, the point «protect sensitive data» deliberately comes before buying and assigning the licences.
- Measure usage and adjust. In the operating phase you measure impact and adoption through the Copilot Dashboard in Viva Insights and the Microsoft 365 usage and readiness reports in the admin centre. Keep an eye on the Purview DSPM reports and the DLP and insider risk alerts in parallel, so you continuously spot risky AI usage and can expand the rollout in a targeted way.
One qualification worth making: Restricted Content Discovery and Restricted SharePoint Search are explicitly temporary bridges that buy you time. The permanent solutions are SharePoint Advanced Management, which is incidentally included in the Copilot licence, and Microsoft Purview. The rough sequence assessment → containment → clean-up → guardrails → controlled rollout is consistently documented, only the exact position of sensitivity labels is emphasised slightly differently across individual Microsoft documents.
Switzerland and banks: revDSG, FINMA and data residency
For regulated industries in particular, the legal framework decides what is feasible. Three topics need to be kept apart: data protection law, banking supervisory requirements and the question of where the data is actually processed.
revDSG and data transfers to the USA
Anyone using Copilot with personal data has been subject to the fully revised Swiss data protection act (revDSG) since 1 September 2023: heightened transparency, the processing principles and the duty to report high-risk data security breaches to the FDPIC, Switzerland's federal data protection commissioner, as quickly as possible (Art. 24 revDSG). For data transfers to the USA, the Swiss-U.S. Data Privacy Framework has applied since 15 September 2024, permitting transfers to certified US organisations without additional measures. For recipients that are not certified, standard contractual clauses are still required.
FINMA circulars and banking secrecy
For banks, two FINMA circulars come on top. Circular 2023/1 «Operational risks and resilience, banks» (in force since 1 January 2024) sets requirements for ICT, cyber and outsourcing risks as well as for critical data and operational resilience. If a bank outsources material functions, which can include a cloud or AI service, circular 2018/3 «Outsourcing, banks and insurers» applies in addition, with binding minimum requirements on data location, exit strategy and FINMA's unrestricted rights of audit and access, safeguarded at all times. Bank client data is also subject to banking secrecy protected under criminal law (Art. 47 BankG). According to the cloud guidelines of the Swiss Bankers Association, cloud use is possible if the provider is bound in as a holder of the secret and the data is adequately protected, and a case-by-case assessment remains necessary.
Data residency and flex routing
Microsoft 365 Copilot has been covered by the data residency commitments (EU Data Boundary, Advanced Data Residency, Multi-Geo) since 1 March 2024, and Swiss tenants can use the Switzerland region (Zurich, Geneva). In November 2025 Microsoft announced that it would extend in-country processing of Copilot interactions, and Switzerland is named, with rollout during 2026. A word of caution on expectations: according to Microsoft's updated statement (as of April 2026), local inferencing for EU and EFTA countries, and therefore for Switzerland, is provided at regional level within the EU Data Boundary, not as strictly in-country processing. An assurance of «processed in Switzerland only» cannot be derived from it.
The decisive caveat for regulated users is «flex routing». Microsoft can offload the LLM inferencing of EU and EFTA tenants (Switzerland included) to the USA, Canada or Australia during load peaks. Flex routing is switched on by default for eligible tenants created after 25 March 2026 and has to be deliberately disabled in the Microsoft 365 admin centre («Do not allow flex routing») if processing inside the EU and EFTA is required. The data stays encrypted throughout and continues to be stored within the EU Data Boundary, apart from limited pseudonymised data.
What to do now
Anyone introducing Copilot is not buying a feature, they are changing the findability of their own data. The first step is therefore not the licence order but the assessment run from step 1, which shows within days how big the oversharing actually is. Everything else follows from that: short-term shielding, clean-up, guardrails, controlled activation.
This governance work is part of the real rollout cost, not of the licence price. You can read how it affects the overall picture in What Copilot really costs, and why many licences still lie idle is covered in Why Copilot licences go unused.
An honest word on who does what: this groundwork, permissions, labels, DLP, is a job for your IT and security teams, not mine. I do not sell licences and I do not configure governance. My part starts afterwards: making sure Copilot actually lands with your people, with training, a champions community and support that works in a regulated day-to-day setting. Once the technology is in place and you want to bring people along, a free intro call is the simplest first step. How I support adoption is described under Services, and specifically for banks under Copilot adoption in banks.
