Microsoft Copilot has access to three million sensitive data records per organization, wide-ranging AI survey finds – here’s why it matters
- Confidential company information accounts for most data being shared across industries
- Copilot accessed millions of business records and thousands of interactions per organization
- Duplicate, stale, and orphaned records compound oversharing risks and weaken enterprise data protection
Microsoft Copilot is interacting with more sensitive data than many organizations realize, new research has warned.
Concentric AI’s 2025 Data Risk Report found Copilot accessed almost three million confidential records per organization in the first half of this year alone.
For context, that figure represents roughly 55% of all files being shared externally.
Major risks
The findings are based on aggregated data from Concentric AI customers across industries including technology, healthcare, government, and financial services.
The report noted confidential company information makes up the majority of files being shared across businesses.
On average, 57% of organization-wide shared data contained some form of privileged information. In financial services and healthcare that figure was closer to 70%.
Organizations are also leaving large amounts of data exposed.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
An average of two million critical business records per organization were shared with no restrictions, working out to about half of unrestricted data overall.
More than 400,000 records on average were shared with personal accounts, and over 60 percent of those included confidential information.
Copilot activity is adding to these worries. The report found organizations averaged more than 3,000 interactions with Copilot, during which sensitive business information could potentially be modified or exposed.
This all illustrates the risk enterprises face when securing valuable data as GenAI becomes further integrated into daily operations.
The report also pointed to broader data management problems, including duplicate, stale, and orphaned records.
Organizations in the survey sample held an average of 10 million duplicate data records and nearly seven million older than 10 years. Orphaned and inactive user data accounted for millions more.
Oversharing, excessive permissions and uncontrolled GenAI use combine to increase risk, and without stronger governance, Concentric AI says organizations could struggle to protect intellectual property, financial information and personal data.
You might also like
Confidential company information accounts for most data being shared across industries Copilot accessed millions of business records and thousands of interactions per organization Duplicate, stale, and orphaned records compound oversharing risks and weaken enterprise data protection Microsoft Copilot is interacting with more sensitive data than many organizations realize, new research…
Recent Posts
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023