Part 1 sorted your Copilot agents into three tiers of inheritance. Part 2 got your environment ready to turn Copilot on. This one zooms out, because Copilot is only one room in the house.
Here’s the uncomfortable truth. Your people are not using one AI. They’re using Copilot, and the free chatbot in the browser, and the AI baked into a dozen SaaS tools you already pay for, and a few things nobody ever told you about. Governing Copilot beautifully while ignoring the rest is like bolting the front door and leaving the windows open. The data doesn’t care which opening it leaves through.
So let’s talk about all-up AI governance. Not Copilot governance. All of it.
Shadow AI refers to AI tools employees use without IT approval or oversight. These tools can expose sensitive business data, bypass security controls, and create compliance risks because they often lack governance and monitoring.
Employees often use multiple AI applications across browsers and SaaS platforms. A comprehensive AI governance strategy ensures all AI tools are managed consistently, reducing the risk of data leaks and unauthorized access.
Organizations can reduce AI risks by inventorying AI tools, implementing data loss prevention (DLP), managing app permissions, monitoring AI usage, and establishing governance policies that apply across all AI platforms.
An effective AI governance framework should define AI ownership, establish acceptable use policies, assess risk, manage data access, enforce security controls, and align with recognized standards such as the NIST AI Risk Management Framework and ISO/IEC 42001.
The first step is identifying every AI tool and application interacting with your organization’s data. Once you have visibility into AI usage, you can assess risk, prioritize governance efforts, and implement appropriate security controls.
The leak you can’t see is the one that gets you
If you think this is hypothetical, look at how people already use AI when nobody’s governing it.
One 2025 study found 81% of employees admitted to using AI tools their company never approved, and, tellingly, so did 88% of the security leaders who are supposed to stop them. When companies tried to just block the tools, 45% of workers simply found a workaround. Other research the same year found most employees pasting company data into free AI tools from personal accounts, more than half of it genuinely sensitive. Somewhere in the last two years, generative AI quietly became one of the biggest doors your data walks out of.
This is the “shadow AI” corner I called the highest-risk tier in Part 1: no identity in your environment, no consent record, no audit trail. You can’t govern what you can’t see. And it is almost never the sanctioned, well-configured Copilot that leaks. It’s the thing running in a browser tab that no one approved.
Why AI leaks differently than the old stuff
For years, data loss meant a phishing email or a misconfigured storage bucket. Predictable stuff, with a mature playbook. AI moved the leak into everyday work: a helpful paste, a convenient upload, a quick question to whatever tool is closest.
Agents raise the stakes again, because they don’t just answer, they act, and they plug into connectors that reach other systems. In one 2025 review of real-world AI incidents, generative AI showed up in roughly 70% of them, and the systems that take action on their own caused the most damaging failures. One of the most common attacks wasn’t sophisticated code at all. It was a cleverly worded prompt that talked a tool into doing something it shouldn’t.
The point isn’t to be afraid of any one tool. It’s that your AI risk is now spread across your whole environment, not parked neatly inside Copilot. So your governance has to cover the whole environment too.
You can’t govern what you can’t see, so inventory first
The first move in all-up governance isn’t a policy. It’s a flashlight.
Inventory every place AI touches your data. The Copilot and agent tiers from Part 1, yes, but also the sanctioned SaaS tools with AI features quietly switched on, and the unsanctioned shadow tools your people reached for because they were faster. Discovery tooling exists for exactly this. You are not trying to be perfect on day one. You’re trying to answer a question most leaders genuinely can’t answer today: what is actually running, and what can it reach?
Govern to the risk, not to the logo
Once you can see it, don’t try to boil the ocean. Triage, the way an ER does. Sickest first.
Score every AI tool and agent against two blunt questions.
- Data-exfiltration risk. If this thing misbehaves or gets talked into something, can it move sensitive information somewhere it shouldn’t go?
- Production-damage risk. If it misbehaves, can it break something real: a system, a record, a client-facing process?
Run everything through those two questions and it sorts itself into tiers, from “harmless, leave it alone” up to “high-risk, deal with it today.” Notice this works for a shadow chatbot exactly as well as it works for a custom agent. You’re governing to the risk, not to the brand name on the box.
Make the safe path the easy path
Here’s the mistake almost everyone makes first: they try to ban their way out. It doesn’t work. Remember, 45% of workers just route around the block, and now you’ve lost the visibility you had. Prohibition doesn’t kill shadow AI. It drives it underground.
The move that actually works is to give people a governed, sanctioned option that’s genuinely good, and make reaching for it easier than reaching for the risky one. Back that with a simple intake so new tools and agents are governed by default: what does it do, what does it touch, who owns it, and nothing high-risk reaches production without clearing that gate. Default-deny for the things that can hurt you. An easy front door for everything else. If getting approved is faster than sneaking around the process, people use the front door.
And put ONE name on AI risk. Not “the steering committee.” Committees are great at writing policy and terrible at holding a gate. Gates need an owner.
The plumbing that keeps you out of the headlines
Governance lives or dies on a few unglamorous controls. Get these in place across your AI, not just Copilot.
- Put DLP in front of the sensitive stuff, so a leaky prompt hits a wall instead of the open internet. Microsoft Purview does a lot of this inside your tenant already.
- Tighten connector and app-consent permissions, so tools and agents can’t quietly grant themselves more reach than any one person was ever meant to have.
- Extend your records rules to cover AI. Most organizations have legal hold, retention, and eDiscovery for email and documents, and none of it applied to AI interactions. If a regulator or opposing counsel ever asks what your AI said and did, “we weren’t keeping that” is not the answer you want.
- Know which tools are even on. Settings you assume are off often aren’t. Go check the ones that matter.
Put a framework behind it
You don’t have to invent this from scratch. The NIST AI Risk Management Framework gives you four plain jobs, govern, map, measure, and manage, and it has a profile written specifically for generative AI. ISO/IEC 42001 is the certifiable management-system standard if you need to prove it to a client or a regulator. Think of it this way: NIST tells you the what and the why, ISO gives you a certifiable how.
Here’s the gap worth closing. Recent research found only about a third of organizations have a formal AI governance framework, even though three-quarters already have some kind of AI usage policy. A policy nobody operationalizes is a document, not a control. Pick a framework, map your risks to it, and grade yourself on a maturity curve instead of pass or fail.
The bottom line
When you finally see how much ungoverned AI is running around your environment, the instinct is to slam the brakes. Don’t. That just pushes people back to the personal accounts and the browser tabs, where you have no visibility at all.
Governance isn’t the thing that lets you say no to AI. Done right, it’s the thing that lets you say yes to more of it, because you can finally see it, rank it, and trust the parts that matter. See it, tier it by risk, sanction the good and gate the risky, and extend the boring records rules to cover all of it. That’s the job. It’s not exotic. It’s discipline, applied across your whole environment instead of one product, and applied before the leak instead of after.
If you’re not sure how much AI is actually running in your environment right now, and most leaders honestly aren’t, that’s the first thing worth finding out. Tell me you want the picture, and let’s go get it.
Thanks for reading,
Chris
A few sources worth reading: UpGuard, “The State of Shadow AI” (2025); Menlo Security, “How AI is Shaping the Modern Workspace” (2025); Adversa AI, “Top AI Security Incidents, 2025 Edition”; Microsoft Purview Data Loss Prevention; NIST AI Risk Management Framework 1.0 and its Generative AI Profile; ISO/IEC 42001:2023.
Related Insights
Avoiding AI Data Leaks: Governing All of Your AI, Not Just Copilot
Part 1 sorted your Copilot agents into three tiers of...
Read MoreIs Your Microsoft 365 Environment Actually Ready for Copilot? The Governance Checklist to Run First
In the first piece, I made the case that Copilot...
Read MoreCopilot Inherits Your Security. Until It Doesn’t.
Why some Microsoft 365 Copilot agents inherit your user security,...
Read More
