Copilot is ready. Is your data?
The pressure is familiar by now. The announcements are everywhere, the board has seen them, and somewhere on your desk is a proposal to enable Microsoft Copilot across the organisation. Perhaps the licences are already bought. The question has narrowed to how fast.
Here is the part that gets lost in the rush. Copilot is capable, and Microsoft has built a tool that works from the moment you switch it on. What decides whether it delivers is not the tool. It is the data it is pointed at.
Where that foundation was never made ready, the same pattern shows up: answers that cannot quite be trusted, adoption that never takes, and a productivity case that never arrives. Copilot readiness is a data problem, not a licensing one. The fix is well understood, and you cannot buy your way to it by adding more licences.
Copilot brings no knowledge of your business. It reads what it can reach — your files, your mailboxes, your databases — and it inherits, precisely, the permissions already in place. Where those permissions are loose, it surfaces content the reader was never meant to see. Where the data is stale or duplicated, it answers from whichever version looks relevant, in fluent prose, with a confidence the underlying data has not earned.
This is not a rare edge case, and it is not a criticism of the technology.
Microsoft says much the same thing. Its deployment blueprint for Copilot puts remediating oversharing first — ahead of guardrails, ahead of roll-out. Independent studies of enterprise generative-AI adoption reach a parallel conclusion: where returns disappoint, the cause usually lies in the conditions around the model, in how the data is governed and how well the tool is fitted to the work, rather than in the model itself.
Under Popia your organisation remains the responsible party for how personal information is accessed and used. That accountability does not transfer to a vendor, and certainly not to an AI. An assistant that can retrieve and redistribute personal information across the estate in seconds raises the obligation rather than easing it.
The instinct, faced with this, is to treat readiness as a quick tidy: clean up a few permissions, delete some old files, proceed. The opposite instinct is just as common, which is to freeze everything until the data is spotless. Neither serves you.
Copilot earns real value well before an estate is perfect, so the goal is narrower than it first appears. Govern the data each use case actually touches, before that use case goes live, and sequence the readiness to the roll-out.
That still takes deliberate work: understanding what data you hold and where it lives, modernising the platform it sits on, governing who can reach what, and cleaning the data so that what the AI retrieves is current, correct and permitted.
Microsoft has shipped stop-gaps, and the best known of them is now going away. Restricted SharePoint Search — the tenant-wide switch that held content back from Copilot while permissions were remediated — was closed to new enablement on 31 July 2026 and retires fully on 31 January 2027.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcentral.co.za — the content belongs to TechCentral.