Your AI Assistant Didn't Leak That File. Your Permissions Did.

/ Key takeaways
- The short answer
- Why this happens in almost every small business
- What can my AI assistant actually access?
The short answer
Your AI assistant can usually see everything the person using it can see. If your file permissions are already too broad, the AI does not create a new problem. It makes an existing one visible, and it makes it searchable.
That is the part most businesses miss. The conversation about AI security tends to focus on what the AI might do wrong. The more common issue is that the AI is working exactly as designed, on top of a permission structure nobody has reviewed in years.
Why this happens in almost every small business
Permissions grow by accident. Someone needs a file quickly, so a folder gets shared with the whole team. A contractor joins for a three-month project and gets access to a drive that made sense at the time. A departing employee's account gets disabled but their shared links stay live. A folder called “Admin” ends up visible to everyone because it was easier than working out who actually needed it.
None of this feels like a security decision when it happens. It feels like getting work done.
For years, the practical effect was limited. Nobody browses a shared drive for fun. The files were technically accessible but functionally invisible, buried three folders deep with a name nobody would search for.
An AI assistant removes that protection. It reads everything it is allowed to read, and it answers questions in plain language. Ask it about salary bands, or a client dispute, or redundancy planning, and it will find whatever it can reach and summarise it helpfully.
What can my AI assistant actually access?
For most business AI tools, the rule is simple: the assistant inherits the permissions of the person using it.
Microsoft 365 Copilot works this way. It does not bypass your access controls. It uses the signed-in user's existing permissions to search files, emails, chats and sites. Google Workspace's AI features follow a similar model.
That sounds reassuring, and in a well-organised business it is. The problem is what it means when permissions are messy. If a junior employee can technically open the HR folder, Copilot can read the HR folder on their behalf and answer questions about it.
Assistants inherit user permissions
Copilot and comparable tools search only what the signed-in person could already open. The exposure is not new access, it is old access nobody has audited.
Custom agents get their own access
An agent built to handle support tickets or process invoices is usually granted broader access than any single employee, because it works across the business. That access is granted once during setup and rarely reviewed afterwards.
Custom agents need more care than assistants.
The three questions to answer before connecting AI to anything
These apply whether you are switching on Copilot, adding a chatbot to your website, or building a custom automation.
- What can it see? Which mailboxes, folders, drives and records. Just as importantly, which ones are deliberately out of reach. If you cannot list what is excluded, nothing is excluded.
- What can it do without asking? There is a large difference between an assistant that drafts an email and one that sends it. Between one that suggests a record update and one that makes it. Decide where the line sits before it is tested.
- What happens when it is not sure? Who does it hand to, how quickly, and what does it do in the meantime. An automation with no escalation path will either guess or stall, and both create work.
The access review that should come first
Before any of the above, there is a more basic piece of work: finding out who can currently see what. This is not a technical project. For most small businesses an access review takes an afternoon, and it produces a document worth having regardless of what you decide about AI.
- Check for former employees with live access. Disabled accounts are not the same as removed access. Shared links, personal drive shares and third-party app connections often survive an offboarding.
- Find your “everyone” folders. Look for anything shared organisation-wide or set to “anyone with the link”. These are usually the largest source of unintended exposure, and they are usually years old.
- List who has admin rights. In most small businesses the honest answer is “more people than we thought”, including at least one person who no longer needs it.
- Identify the sensitive folders. HR records, payroll, contracts, client files, anything covered by a confidentiality obligation. Confirm who can reach them today rather than who should.
- Check third-party app connections. Tools connected via OAuth often hold broad, standing access to mailboxes and drives. Many were connected once for a trial and never disconnected.
- Write down what you find. The value is not just fixing what is wrong now. It is having a baseline so the next review takes an hour instead of an afternoon.
Why the order matters
Doing the access review after deploying AI means fixing problems while they are live. Doing it before means the AI launches on a structure you actually understand.
It also tends to be cheaper. Access reviews are ordinary managed IT work, done calmly, on a schedule, alongside the joiner and leaver checks that keep permissions from drifting in the first place. The same work done during an incident is not ordinary and is not calm.
There is a secondary benefit worth mentioning. A business that has done this review answers cyber insurance questionnaires, client security questions and compliance audits much faster, because the answers already exist in a document.
Permissions are the foundation, not the afterthought
The same principle sits underneath zero trust: access should be granted deliberately and reviewed on a schedule, not inherited from a decision someone made in a hurry two years ago.
AI simply makes the cost of skipping that visible sooner. A structure that was merely untidy becomes a structure that answers questions.
Where to start
If you are considering AI tools, or you already have some running, the useful first step is not choosing a product. It is finding out who can currently see what.
BPro Technologies runs access reviews as standard practice before any AI automation goes live, and as a standalone piece of work for businesses that want the picture regardless. You can see our documentation standards and permission model on our AI Automation and Cybersecurity service pages, and the decision about which tool you actually need is covered in AI vs automation.
Find out who can currently see what
A free assessment covers your existing permissions, shared links, admin rights and third-party app connections, and gives you the document to work from before any AI tool goes live.
Get Free IT Assessment/ Article map
The short answer
Why this happens in almost every small business
What can my AI assistant actually access?
The three questions to answer before connecting AI to anything
The access review that should come first
Why the order matters
Frequently Asked Questions
Can Microsoft 365 Copilot see files I do not have access to?
No. Copilot operates within your existing permissions and does not grant new access. It searches files, emails, chats and sites using the signed-in user's own rights. The risk is not that Copilot bypasses controls, it is that your existing permissions are broader than you realise, so it surfaces material that was technically reachable but practically invisible.
Does using AI mean my data trains someone else's model?
It depends on the tool and the licence. Business and enterprise tiers of major AI products generally keep data within your tenant and exclude it from model training. Free and consumer tiers often do not. Check the specific tier you are paying for rather than the product name, because the same brand can behave very differently across plans.
We are only using ChatGPT, not a connected agent. Does this apply?
Partly. If staff are pasting client information, contracts or financial data into a consumer AI tool, that is a separate exposure worth its own policy. The permission question becomes urgent once any AI tool is connected to your actual systems, because that is the point where it can reach data nobody deliberately handed it.
How often should we review access?
Twice a year is a reasonable baseline for most small businesses, plus a review whenever someone leaves or changes role. If you are deploying AI, do one immediately beforehand. Reviews are far quicker once the first baseline exists, because you are checking changes rather than rebuilding the picture from scratch.
Who should own access reviews internally?
One named person, even in a small business. Access reviews fail most often because they are everybody's responsibility and therefore nobody's. The owner does not need to be technical. They need the authority to ask why a folder is shared organisation-wide and to get an answer, and a date in the calendar.
Is fixing broad permissions expensive?
Usually not. The work is mostly investigative rather than technical: listing what exists, confirming who can reach it, and removing what nobody needs. Most of an afternoon is spent reading rather than configuring. The expensive version is the one that happens after something is exposed, under time pressure, with a client or insurer waiting.
/ Choose the next step
Move from article guidance to a practical review path.
Pick the route that best matches the issue behind the article so the next conversation starts with the right scope.
Security path
Use the assessment to review exposure first
The free assessment is the right first move when identity, endpoint protection, backup readiness, email security, or Microsoft Defender coverage needs review.
Service path
See cybersecurity coverage in practice
Review how BPro Technologies handles access hardening, endpoint protection, visibility, remediation, and evidence without using scare tactics or vague promises.
Team path
Send the current security concern
If the issue is urgent, share what changed, what tools you have, and what is already protected so the team can review the safest next step.