ISSUE 14 · 7 MIN READ ·

Your AI assistant can read every file your permissions forgot about

Copilot and Gemini don't leak new data — they surface years of stale 'anyone' links and over-broad access to whoever asks. How to find oversharing.

You switch on Microsoft 365 Copilot, or Google’s Gemini, and someone in accounts asks it an ordinary question — “what are we paying people this year?” A few seconds later it hands them a tidy summary, drawn from a spreadsheet in a folder they were never meant to see. Nobody broke in. Nobody escalated a privilege. The assistant simply read what that person already had permission to open, and permission turned out to be far wider than anyone remembered granting.

This is the quiet failure, and it’s worth being precise about what went wrong. The AI didn’t leak anything. The oversharing was already there — years of “share with anyone in the company,” one-off links sent to a contractor in 2022, a drive folder set to open so a project could move quickly and never set back. All of it sat harmless for as long as nobody happened to go looking. The assistant’s only crime is that it looks instantly, on everyone’s behalf, and never gets bored.

Why it stays invisible

Permissions rot in the dark. When you share a folder “with everyone” to unblock a deadline, nothing bad happens that afternoon — or the next month, or the next year. The cost is entirely deferred, and deferred costs don’t show up on anyone’s to-do list. A human would have to know the file existed, know where it lived, and go and open it. Almost nobody ever does, so the over-broad share never announces itself.

An AI assistant collapses all three of those steps into a sentence. It has already indexed everything the asker can technically reach, so “find me the file about X” quietly traverses years of accumulated access in one go. The permission was always too loose; what changed is that loose permission is now trivially, conversationally searchable by every member of staff at once. Nothing was reconfigured, which is exactly why it feels like the tool’s fault rather than the sharing’s — and why turning the assistant off again just hides the problem instead of fixing it.

Find it yourself

You can get a sense of your own exposure in about fifteen minutes, without buying anything. The goal is to see what’s shared too widely before an assistant does it for you.

Microsoft 365 / SharePoint (admin):

  1. Sign in to the SharePoint admin centre.
  2. In the left menu, expand Reports and select Data access governance. These reports group sites by how they’re shared — the ones to care about are sites shared with “Everyone except external users” and the sites creating the most “Anyone” sharing links. One honest caveat: these reports need a SharePoint Advanced Management licence, which is included if your tenant has Microsoft 365 Copilot (Microsoft 365 E5 gets a cut-down version). They’re not part of a standard business subscription.
  3. Start at the top of those lists. A site shared with everyone that holds HR, finance, or legal material is the first thing to tighten. No licence for the reports? You can still do it site by site for free: open Active sites in the same admin centre, start with the sites holding your most sensitive material, and review who each is shared with.

Google Workspace (admin):

  1. In the Admin console, open the security investigation tool at Security → Security center → Investigation tool. This comes with the Enterprise, Education Standard and Plus, and Frontline editions — no Business edition includes it (there’s a fallback below if that’s you).
  2. Filter Drive documents by visibility — look for files set to “Anyone with the link” or shared to the whole domain.
  3. Sort for the documents opened or shared most; widely-reachable, widely-used files are where an assistant will land first.

On Business Starter or Standard, use Reporting → Reports → Apps reports → Drive instead — every edition includes it, and it shows how much is shared outside the organisation. To chase down individual files, anyone can type sharedwith:external into Drive’s own search box to list what they’ve shared outside the domain.

No admin console, or a smaller setup? Do it by feel. Pick your three most sensitive folders — payroll, contracts, anything with customer data. For each, open the sharing settings and read the access list out loud. You’re looking for three things: “anyone with the link,” access granted to the whole organisation, and named people who’ve since left or were only ever passing through. If you’d be uncomfortable with a new starter reading a folder on day one, it’s shared too widely.

The fix

The aim isn’t to lock everything down until work grinds — it’s to make broad access a deliberate choice again, not an accident that compounds.

Tighten the worst offenders first. Take the handful of sensitive, over-shared locations you found and narrow them to the people who actually need them. You won’t get through everything at once, and you don’t need to; fixing the top few removes most of the risk.

Kill the standing “anyone” links. A link set to “anyone with the link” is a permanent, forwardable key. Where you can, change the default for new shares to “specific people,” and set links to expire so temporary access stops being permanent by default.

Do a permissions pass before you widen the assistant’s reach. If you’re rolling out Copilot or Gemini, treat “review what’s overshared” as step one, not a thing you’ll get to later. The rollout is what makes the old sprawl suddenly reachable, so it’s the right moment — and the honest one — to clean it up.

Look again on a schedule. Sharing sprawls back the moment a new deadline hits. A quarterly fifteen-minute pass over the same reports keeps the list from quietly rebuilding itself.

None of this needs a security team or a new product. It needs someone to decide, once, that “who can actually read this?” is a question worth asking on purpose — and to ask it before the assistant answers it for everyone.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.