"Copilot Ready": ready to switch on Microsoft 365 Copilot without exposing your data or stepping outside the AI Act. Behind the label sit seven precise checks. Here they are, in the order to tackle them.
1. The access inventory: who can already read what
Copilot creates no rights. It reads everything the user can already read, nothing more, nothing less. The problem lies elsewhere: in most organisations, nobody knows precisely who can read what anymore. So, first check: map the SharePoint, OneDrive and Teams shares, starting with links open to "everyone in the organisation".
2. Oversharing: the number that makes you think
Around 16% of an organisation's critical documents are accessible beyond their intended circle. Today nobody finds them because nobody looks. With Copilot, they surface in a plain chat answer. Check: an oversharing report (SharePoint Advanced Management or an external audit), then the fixes, before activation and not after.
3. Purview sensitivity labels
Without labels (Public, Internal, Confidential, Secret), Copilot treats every document the same way. With them, it respects the restrictions and leaves a trace of each use. Check: label at least HR, finance and management data, and confirm the licence actually includes Purview, which is not the case for every Microsoft 365 plan.
4. Licences and the real perimeter
Copilot M365, Copilot Studio, Power Platform: three doors into AI, often opened without management knowing. Agents built by business teams, plugged into sensitive data, outside any framework: that is "Shadow Copilot". Check: an inventory of active licences and a block on everything that is not governed.
5. The AI register and AI Act classification
Copilot is a general-purpose AI system. It must appear in the organisation's AI register, with a classification per use: drafting an email is limited risk; screening job applications is high risk (Annex III). Check: an up-to-date register, HR uses framed by a documented human validation (Article 14).
6. User training (Article 4)
AI literacy has been an obligation since February 2025. In practice, users must know when Copilot gets it wrong, how to verify an answer and when to reject a recommendation. Check: a traceable training path, with a record per person. A ten-minute video is not enough.
7. Monitoring after activation
Being ready does not stop on activation day. Check: a monthly review of Purview logs, new shares and agents created in Copilot Studio. One named owner, one short ritual, one decision a month.
In short
Copilot Ready means controlled access, labelled data, framed licences, an AI Act-compliant register, trained teams and monitoring that lasts. Most organisations get through checks 1 to 3 in two weeks. An external Copilot Readiness audit covers all seven in a week, and delivers a costed remediation plan.