Article

4 Jul 2026

Why Your Microsoft Copilot Rollout Gets Worse the More People Use It

An MD told us his Microsoft Copilot rollout was getting worse the more people used it. Here’s what a permissions audit found, and the five-step fix for any UK SME running Copilot across Microsoft 365.

Network equipment in a server room

Here’s a phrase that’s stuck with me since a call a few weeks back. The MD of a professional services firm described his Microsoft Copilot rollout as “getting worse the more people use it,” which is an odd thing to say about a tool that’s meant to earn its keep through scale, and underneath the frustration in his voice was a quieter question about whether the technology itself was the problem or whether something else, something nobody had thought to check, was actually going on.

It was the second one. It usually is.

So we went in and audited the environment. What we found is common enough across UK SMEs running Microsoft 365 that it’s worth walking through properly, because the fix is straightforward and most businesses haven’t done it yet.

What the audit found

Three things, mainly.

Permissions set when the team was 70% smaller, never reviewed since. The folder structure and access controls had been configured two years earlier, when headcount was a fraction of what it is now. The logic made sense at the time. It hadn’t been touched since, and it no longer matched the team, the structure, or the way anyone actually worked.

Three versions of the same proposal template, none labelled, all searchable. Copilot surfaced all three whenever anyone asked it a proposal question. Nobody could say with confidence which one was live. That’s not a Copilot fault. It’s what happens when duplicate files sit in a shared drive for long enough that everyone quietly develops their own private theory about which one is current (nobody’s theory matched anyone else’s).

HR files sitting in the same folder hierarchy as marketing assets. Nobody had put them there on purpose. The structure had drifted over several years, someone had moved something somewhere convenient one afternoon, and the drift had simply never been corrected. Sensitive information was reachable by people who shouldn’t have had access to it, and Copilot, which searches across everything a user can reach, found it.

Nobody in the business, IT included, could have told you with confidence what was accessible from where.

Why this makes AI look worse than it is

Copilot searches everything it can reach, instantly, without judgement or hesitation. Give it a clean environment and that’s a genuine advantage. Give it two years of accumulated folder drift, duplicate files, and permissions nobody’s revisited since the team doubled, and that’s exactly what it will find too, at the same speed and with the same confidence.

The permissions had been drifting for years. The duplicate templates had been sitting there since before anyone mentioned the word Copilot in a board meeting. None of that was new. What changed was the speed and reach of the thing searching through it. A person looking for a file manually tends to find roughly what they’re looking for and move on, so the mess stays invisible unless someone goes looking for it deliberately. AI doesn’t work that way. It checks everything, every time, and it doesn’t get bored halfway through a folder tree.

What felt like Copilot getting worse was actually years of data hygiene catching up with the business all at once.

The governance question most rollouts skip

When a UK SME rolls out Copilot, the conversation almost always starts with features, licensing, and training. Data permissions come up rarely, if at all.

Before you extend AI access across a wider team, there’s a question worth asking first: is your data environment actually ready for a tool that can search all of it? If nobody in the room can answer confidently, that’s the place to start, not the place to skip past on the way to a bigger rollout. A permissions audit costs a fraction of what it costs to manage the fallout from something sensitive surfacing in the wrong meeting.

Fixing it: a five-step process

1. Map what’s actually accessible. Run a permissions audit with IT before anything else. Understand who has access to what across the full Microsoft 365 environment. This step usually turns up a few surprises, and it’s far better to find them this way than to have Copilot find them for you in front of a client.

2. Apply least privilege properly. People should have access to what they need for their job, and nothing beyond that. It sounds obvious. It’s rarely how permissions actually look after a few years of organic growth. Review the current state and tighten it.

3. Fix the duplicate file problem. Growing businesses accumulate duplicate templates and documents at a remarkable rate. Set a clear convention: one live version, clearly named, in one clearly signposted location. Archive everything else somewhere either inaccessible to AI search or unmistakably marked as historic.

4. Relocate anything sensitive. HR records, financial data, commercially sensitive contracts: these belong in locations with permissions that were designed on purpose, not general shared drives they drifted into years ago.

5. Build in a review cadence. Permissions aren’t a fix-it-once job. As the team grows and the structure changes, access needs revisiting. Put a six-monthly or annual review into the IT governance calendar and treat it the same way you’d treat any other compliance task.

The lesson underneath the lesson

The MD’s read on his own rollout was accurate. It was getting worse, week over week, and he could feel it happening. AI behaves like a multiplier. It accelerates whatever you hand it, clean data or messy data, and it sharpens the gap between the two faster than most businesses expect.

The businesses getting the best results from Copilot aren’t necessarily the ones with the sharpest prompting skills or the priciest licences. They’re the ones who got their data house in order before they turned the tool on, not after.

Artificia1 works with UK SMEs on AI strategy, governance, and adoption, including getting data environments ready before a Copilot rollout goes wide. Talk to us before your next one.

© All rights reserved | Artificia1 Ltd (SC846045), Registered at: First Floor 4 Earls Court, Earls Gate Business Park, Grangemouth, United Kingdom, FK3 8ZE | VAT No. 493 8647 33

© All rights reserved | Artificia1 Ltd (SC846045), Registered at: First Floor 4 Earls Court, Earls Gate Business Park, Grangemouth, United Kingdom, FK3 8ZE | VAT No. 493 8647 33