Microsoft Copilot for Engineering Firms: Why the Mid-Tier Gets It Wrong (and the Top Tier Already Figured It Out)

TL;DR The top tier didn’t win at Copilot by buying more licences. Firms like Arup, Aurecon and GHD publicly run AI strategy and governance functions. They did the unglamorous data-hygiene work before switching anything on. Copilot inherits your permissions; it doesn’t fix them. If your SharePoint access has been messy since 2018, AI will faithfully surface that mess to[…]

Agentic AI is here – what it means for governance, data exposure, and intranet permissions

TL;DR Agentic AI is AI that acts, not just answers – it reads, writes, and takes steps on your behalf. Every weak permission, orphaned site, and overshared library becomes a new attack surface. The risk isn’t the AI. It’s the permissions you already have, now queried at machine speed. A single user with ‘Everyone except[…]

Getting Copilot-ready as a NDIS provider: a 6-step plan for safe rollout without exposing participant data

TL;DR Copilot doesn’t leak data. But it does reflect whatever’s already in your SharePoint. If permissions are messy, Copilot will happily surface participant records to people who shouldn’t see them. Your NDIS Code of Conduct obligations don’t pause for AI. Principle 2 (“respect the privacy of people with disability”) and the Privacy Act 1988 still apply. Copilot[…]