By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Cookie Policy for more information.
Icon Rounded Closed - BRIX Templates
Insights

Your Agent Estate Doubled. Your Controls Didn't.

5 minutes to read
share on
Your Agent Estate Doubled. Your Controls Didn't.

ShareGate's second annual State of Microsoft 365 2026, published September 23, 2026, found that full Microsoft 365 Copilot deployment roughly doubled year over year, moving from 29% to 56%, while 67% of organizations now run two or more AI tools inside their tenant and 28% of Copilot tenants run three or more.  Over the same period, 77% of organizations reported at least one Microsoft 365 governance incident, yet only 1% use purpose-built governance tooling, unchanged from 2025.  The gap is not a technology gap. It is an operating model gap, and it is now measurable enough to show up in a board packet.

‍

What Actually Changed in the 2026 Data?

The headline is not that Copilot grew. Everyone expected that. The headline is the asymmetry.

Deployment moved. Controls did not.

Here is what the research reports, drawn from two surveys of roughly 1,800 IT professionals and leaders across nine countries:

  • Full Copilot deployment went from 29% to 56%
  • 67% of organizations run two or more AI tools against the same content
  • 28% of Copilot tenants run three or more AI tools
  • 38% left former employees or guests with access they should have lost
  • 35% hit an audit or compliance gap
  • 26% had sensitive content reach the wrong people
  • 1% use a purpose-built governance tool, identical to last year

Read those last two lines together. A quarter of organizations had sensitive content land in front of the wrong audience, and the tooling posture behind that outcome did not move at all in twelve months.

If you want the deeper structural argument for why this happens, we wrote it up in why most Microsoft 365 Copilot deployments stall without governance.

‍

Why Is Confidence So High When Exposure Is So High?

This is the most uncomfortable finding in the report, and the one worth taking to your leadership team.

93% of IT leaders said they are confident their current Microsoft 365 governance framework is sufficient to support Copilot and other AI initiatives responsibly. Half said "very confident."

29% said Copilot or another AI tool has already surfaced sensitive internal data that should not have been accessible. Another 8% could not say either way.

That 8% matters more than people give it credit for. It is the same exposure, undetected.

The detection numbers explain the rest. 65% of teams learn about governance problems only after the fact, through quarterly audits or user complaints. Only 35% rely on proactive monitoring and automated alerting.  And 63% of organizations describe their own governance as "operationalized or better," drawn from the same respondent pool where 77% reported an incident.

Confidence is a feeling. Incidents are facts. In 2026 they point in opposite directions.

One honest caveat you should carry into any executive conversation: this is vendor-sponsored, self-reported survey data, not tenant telemetry, and ShareGate sells governance tooling.  The incident rate is also reported two ways. The 77% headline excludes a fifth category, users unable to find content, which 41% of organizations reported. Including it would push the figure to 82%.  Excluding it is the more conservative choice, and the right one, because a findability problem is a productivity cost rather than a security exposure. Use the 77% number. It is defensible.

‍

Why Does Agent Sprawl Change the Risk Math?

Oversharing is not new. What is new is that overshared content is now retrievable on request.

Copilot and agents operate inside each user's existing permissions. They do not create a new permission model. What they do is collapse the effort required to find something. Content that was technically accessible but practically buried behind three site collections and a bad search experience is now one natural-language prompt away.

That is the shift the report captures. Content that was once overshared has become a liability an AI tool can retrieve on request.

Now layer the multiplication factor. When 28% of tenants run three or more AI tools, you no longer have one retrieval surface to govern.  You have several, each with its own connectors, its own publishing path, its own owner, and in many cases its own licensing model. Our field work consistently finds the same pattern: most agents and flows accumulate in the default environment, publishing to an org catalog requires approval while sharing with individuals does not, and trial licensing creates a side door around your main control plane.

We unpacked the mechanics of how this compounds in Copilot-Ready Governance: Reduce Oversharing Risk with Purview Controls, and the before-and-after of an eight-week remediation in our Purview governance case study.

‍

Where Does Governance Actually Break?

It breaks at completion, not at neglect.

This is the most useful reframe in the entire report. A lot of teams already did the work. In the run-up to Copilot, permissions got reviewed, oversharing got audited, cleanup got funded and finished. Then the project closed, attention moved on, and the tenant kept changing every single day afterward.

Governance is the one category of IT work that degrades the moment you stop doing it, because it was never a state you arrive at. An environment that was defensible eighteen months ago is not defensible now, and nothing inside it will tell you when that changed.

The research also flags that the blocker is executive buy-in, not budget.  That is a communication problem, and it is solvable this quarter.

If ownership ambiguity is your specific failure mode, start with why Copilot and agent governance fails without an operating model.

‍

Point-in-Time Cleanup vs. Continuous Agent Governance

‍

Why Is Proving ROI Part of the Governance Problem?

Because the two failures share a root cause: you cannot measure what you cannot see.

The research found that 86% of organizations expect measurable ROI from AI within 18 months, while 51% cannot see what it costs.  Meanwhile 70% say their governance workload has grown since deploying AI.

An organization without an agent inventory cannot answer either question. It cannot tell you which agents are creating value, and it cannot tell you which ones are quietly consuming credits while serving four users. The same inventory that protects you is the inventory that justifies your spend. That is the argument that unlocks executive buy-in, and executive buy-in is the stated blocker.

Governance and value realization are the same program. Fund them as one.

Where This Leaves Us

The "we'll govern it later" window closed in 2026. Not because a vendor said so, but because the arithmetic caught up: agent estates doubled, control tooling stayed flat, and 77% of organizations have an incident to show for it.

The good news is that none of this requires a massive day-one overhaul. It requires an inventory, two or three configuration changes, and a standing cadence with named owners. Organizations that treat governance as a continuous operating practice rather than a project milestone will scale AI faster than the ones still cleaning up after each surprise.

Ready to size your agent estate and close the control gap? 2toLead helps CIOs, IT leaders, and Power Platform teams turn Copilot and agent capability into secure, measurable business value. Explore the 2toLead Insights hub or start with our SharePoint to Microsoft Purview Governance Guide (2026).

‍

Case Study Details

Similar posts

Get our perspectives on the latest developments in technology and business.
Love the way you work. Together.™
Next steps
Have a question, or just say hi. 🖐 Let's talk about your next big project.
Contact us
Mailing list
Occasionally we like to send clients and friends curated articles that have helped us improve.
Close Modal