08 July 2026

Harden before broad Copilot: security that owns AI risk

Fix overshare, labels, Conditional Access, and agent permissions before you scale seats. Name who owns AI misuse risk.

security

DIGITAL SKILL WORKS LTD / 12 PANES


Broad Copilot on a soft data foundation turns search into overshare. Pane 04 Security exists so you harden before you scale. Risk needs an owner, not a slide.

Gartner’s April 2026 I&O research shows many AI initiatives stall or fail when ambition outruns preparation. Melanie Freeze notes that the 20 percent outright failure rate is largely driven by initiatives that are overly ambitious or poorly scoped. Shipping seats before labels and agent permissions is that pattern in security clothing.

Overshare hotspots

Where AI can see too much

Open sites, stale sharing links, and wide groups become prompt-reachable content. Inventory hotspots before you widen the audience.

Insight you need

List sites remediated, percent labelled content, and privileged agent counts. Those signals sit on the Security pane for a reason.

Sensitivity labels and access

Labels that machines can honour

Sensitivity labels only help if coverage is real and policies enforce them. Pair with Conditional Access so risky sessions do not get model reach.

Least privilege for makers

Makers who can publish agents need tighter defaults than consumers. Build maker tiers early.

Agent permissions

Agents are identities

Treat agents as privileged identities with scopes, owners, and review dates. Unowned agents are unowned risk.

Map to GRC

Mirror every high-privilege agent in the GRC register with purpose and risk tier. See the AI register note.

IR runbook extensions

New failure modes

Prompt injection, agent misbehaviour, and sensitive completions need playbooks. Extend existing IR rather than inventing a parallel theatre.

Standards bridges

Use NIST AI RMF MANAGE and GOVERN language as a bridge. Stay honest about what you have evidenced. ISO 27001 and related controls may already cover parts of the foundation.

Wave 0 entry

Security leads the sequence

Wave 0 starts here, then GRC, Cost and Value, Licence, Adoption. Read Wave 0 and the Start page.

Counsel stance

Guardian dial high until hotspots and IR gaps close. Pathfinder stays fenced. Chair refuses seat expansion that skips this work, as in the worked Counsel example.

FAQ

Can we label while rolling out seats?

You can label in parallel for low-risk cohorts. Do not open high-sensitivity estates until coverage holds.

Is this only Microsoft?

No. The same order applies to any assistant or agent that can retrieve organisational content.

Who owns Security for AI?

CISO-accountable owner, with business owners for data domains. GRC mirrors accountability.

How does this prove value?

It prevents value destruction. Pair with value realisation so spend still faces a frozen case.

What about McKinsey’s adoption numbers?

Widespread use without control still fails the EBIT test McKinsey reports in State of AI 2025. Hardening is how you scale without multiplying blast radius.

What do packages deliver in week 1?

Hotspot list, owner map, and IR gap list. See offerings. DIGITAL SKILL WORKS LTD / 12 PANES

Back to blog