Tenzing logoTenzing
    Back to Insights
    AI Governance

    Six Findings from Six Months of Copilot Readiness Assessments

    7 min read
    Share:

    This week marks six months since launching Tenzing. That probably isn't a huge milestone in the grand scheme of things. It did make me stop and reflect on what we've seen over that period.

    Since April, we've been assessing a new organisation almost every week. Some were actively using Microsoft 365 Copilot. Others had Copilot with a handful of agents built in Copilot Studio. Others were much earlier in the journey and simply wanted a clearer understanding of their risks before moving forward.

    Going into those engagements, we expected to see a wide range of maturity levels. Instead, we found the same themes appearing again and again.

    At a recent event, we asked attendees a simple question:

    "Do you believe your organisation is ready for AI?"

    94% said no.

    That result closely mirrors what we've seen in practice. Most organisations understand the opportunity AI presents. Most have started taking steps towards adoption. Yet very few are confident that the foundations beneath those ambitions are strong enough.

    Over the last six months, six themes have appeared consistently enough that they are worth sharing.


    1. No organisation is 100% ready

    One of the most common misconceptions about Microsoft Copilot readiness is that organisations are either ready or they aren't. The reality is much more nuanced.

    We have yet to assess an organisation that we would describe as fully ready for Copilot. That's not because organisations are failing. Most have already invested heavily in security, governance and compliance.

    The challenge is that readiness isn't determined by a single control, policy or project. An organisation may have strong governance but limited visibility into its information estate. Another may have mature security controls but unclear ownership of AI risk. A third may be running successful Copilot pilots while still trying to understand how agents should be governed.

    Most organisations have pieces of the puzzle. Very few have assembled the complete picture.


    2. Data protection is the universal gap

    If there is one finding that has appeared in every assessment, it is data protection.

    Most organisations understand that sensitive information needs to be protected. What many struggle with is understanding where that information lives, who can access it and whether it is being protected consistently.

    These challenges existed before AI. Copilot simply makes them harder to ignore. Questions that sound straightforward often prove difficult to answer with confidence:

    • Where is our most sensitive information?
    • Who currently has access to it?
    • Are protections applied consistently?
    • Would we know if sensitive information was being exposed inappropriately?

    The organisations making the strongest progress with AI are rarely those moving the fastest. More often, they are the organisations with the clearest understanding of their information estate and a practical plan for improving it.

    For many organisations, the AI conversation quickly becomes a data protection conversation.


    3. Too much data, seen by too many

    Every readiness conversation eventually arrives at the same question:

    "What about our data?"

    It's usually asked with a wince, on the assumption that years of accumulated files and permissions are the biggest source of risk.

    They rarely are. Most organisations collaborate more sensibly than they give themselves credit for.

    What we find isn't chaos. It's concentration. The estate is broadly sound, but a small number of locations carry a disproportionate share of the risk. One recent example: a site set up for a single client, accessible to everyone in the organisation. Not the client team. Everyone, including anyone who joins tomorrow. Nobody decided that. A default was clicked years ago and quietly stayed true, invisible because finding it meant knowing it was there.

    Behind sites like that sit two habits that good collaboration quietly creates: keeping everything, and sharing widely. Both made sense at the time. AI changes the price of both.

    Keeping everything has three costs:

    • Weaker AI output. AI draws on whatever it can find. Outdated and duplicate content produces answers that are confidently wrong.
    • Paying to store liability. Data nobody uses still costs money to hold, and returns nothing.
    • Overexposure. Information kept past its retention date can turn a routine security incident into a reportable breach.

    Sharing widely carries one cost, and it's the one that matters most. AI surfaces whatever people can technically reach, not what they were meant to reach. If access is broader than intended, so are the answers.

    None of this reflects anyone doing anything wrong. And because the risk concentrates rather than spreads, the fix is focused remediation, not a rebuild. Find the handful of places where sensitive content meets wide access, and fix those first.


    4. AI policies exist. Enforcement is the challenge.

    One of the more encouraging developments we've seen is that most organisations now have an AI policy. Compared to even eighteen months ago, that represents real progress.

    The more interesting question is what happens after the policy is published. One question we ask in almost every assessment is:

    "How would you know if your AI policy wasn't being followed?"

    That question often changes the conversation. Many organisations have defined what acceptable AI use looks like. Fewer have developed the visibility, oversight and governance processes needed to understand whether those expectations are being met.

    Publishing a policy is important. But policy alone doesn't create control. The organisations making the strongest progress are connecting policy, governance, education and monitoring into a practical operating model.


    5. Few organisations have decided who owns AI risk

    Most organisations already have governance structures. Risk committees, security forums, technology boards and data governance groups are commonplace. What isn't always clear is who owns AI risk.

    We've found that a simple question often generates significant discussion:

    "Who is accountable for AI risk?"

    Security owns part of it. Risk owns part of it. Legal owns part of it. Technology owns part of it. Business leaders own part of it.

    The challenge is that AI spans all those areas simultaneously. As AI adoption increases, fragmented ownership becomes increasingly difficult to manage.

    The organisations making the strongest progress are starting to treat AI governance as an organisational challenge, not simply a technology challenge.


    6. Agents are generating more questions than answers

    Six months ago, most conversations centred on Microsoft Copilot and AI assistants. Today, more and more conversations are focused on AI agents.

    Interestingly, the questions are rarely technical. They're governance questions:

    • Who can build agents?
    • Who approves them?
    • What should they be allowed to access?
    • How should risk be assessed?
    • What oversight should exist once they're live?

    Most organisations are still developing answers to those questions. Many are still figuring out the questions to ask as the risk is still not quite understood.

    That's understandable. Agent technology is evolving quickly and governance models are still maturing.

    What feels increasingly clear is that agent governance will become one of the defining challenges of the next phase of AI adoption. The organisations that start addressing it now will be in a much stronger position than those who wait.


    What this means

    Looking back across the last six months, we've reached a relatively simple conclusion. Most organisations aren't struggling because they lack AI ambition. They're struggling because their ambitions are moving faster than the foundations needed to support them.

    The good news is that the challenges we see are remarkably consistent:

    • Data protection
    • Information visibility
    • AI governance
    • Accountability
    • Policy enforcement
    • Agent governance

    These are common problems. Which means they're solvable problems.

    The organisations making the strongest progress aren't necessarily the ones moving fastest. They're the organisations that understand where they are today, where they want to get to and what foundations they need to strengthen along the way.

    Ultimately, that's what Copilot readiness comes down to. Not perfection. Not eliminating every risk. Confidence that the right foundations are in place to support AI adoption at scale.


    Curious where you stand?

    Over the last six months, we've assessed organisations across multiple sectors and seen the same readiness challenges emerge again and again.

    If you're exploring Microsoft Copilot and want an independent view of your readiness, we're offering a complimentary AI Governance and Security Health Check, based on Tenzing's proprietary Copilot Governance Framework (CGF).

    We'll discuss your plans, walk through the most common readiness challenges we see and help you identify the areas worth prioritising next.

    No benchmark reports. No generic maturity scores. Just a practical conversation about your organisation, your ambitions and the foundations needed to support them.