The mechanism
The friction was load-bearing, and it was never a control
Most enterprise file estates have a second layer of protection that nobody designed and nobody documented. Finding a document required knowing it existed, knowing roughly where it lived, and being willing to scroll. Keyword search was poor and folder names were opaque. That practical difficulty did real work. It kept a large amount of content effectively out of reach of people who were, on paper, entirely permitted to open it.
Microsoft has now written this down more plainly than any security vendor has. Its Core Infrastructure and Security Blog, published on 23 July 2026, states that the friction of manually locating and correlating documents “was never designed as a formal security control,” but that it “did create a practical limit on how quickly users could surface and act on organizational data at scale.” The same article supplies the sentence this whole subject turns on: “Copilot makes data once hidden by volume discoverable by intent.”
That is the platform vendor describing its own product removing a protection that its customers did not know they were relying on. It is worth putting in front of a board precisely because it is not a consultant’s opinion. The same post is equally careful about what does not change. Copilot “does not grant new permissions,” and is instead “a force multiplier that makes existing access faster and easier to discover, aggregate, and act on.” Both halves matter, and a page that claims an assistant breaks permissions will lose a security architect in its first paragraph.
The underlying idea is much older than generative AI, and its pedigree is useful in a room that is tired of AI-specific alarm. Saltzer and Schroeder set out the open design principle in 1975: “The mechanisms should not depend on the ignorance of potential attackers, but rather on the possession of specific, more easily protected, keys or passwords.” Content that was safe only because it was hard to find was depending on exactly that ignorance. Their least privilege principle, that “every program and every user of the system should operate using the least set of privileges necessary to complete the job,” is the actual remedy, and it is a permissions remedy rather than an AI one.
This is why the engagement is a measurement rather than a policy exercise. Nobody currently knows how much of the estate was protected by obscurity, because obscurity leaves no audit trail and appears in no report. The only way to find out is to ask, as each kind of user, and record what comes back.
Nothing in the permission model changes when you connect an assistant. What changes is how much of it one person can exercise in an afternoon.
Related evidence and next steps
- Microsoft: understanding the Microsoft 365 Copilot risk surface— Core Infrastructure and Security Blog, 23 July 2026. The friction-was-never-a-control admission and the twelve-risk model.
- Saltzer and Schroeder, The Protection of Information in Computer Systems— The 1975 primary source for open design and least privilege.
- Microsoft 365 Copilot architecture— The authoritative statement that Copilot only accesses data the signed-in user is authorized to access.




