You can tell by the situations that come up afterward. A
Copilot agent goes live and reads files that, in principle,
nobody outside a small circle should have access to — but
technically has had access to for a long time. An agent
acts “on behalf of the organization,” but nobody clarified
beforehand who's liable when it does something wrong — the
agent identity was never settled. Sensitivity labels, the
confidentiality marking of a document as public, internal,
or confidential, have often been sitting ready in the
environment for a long time, but Copilot doesn't take them
into account yet, or gets them wrong. A misconfigured agent
reaches half the organization within hours, before anyone
notices — its blast radius, the worst-case reach, simply
wasn't bounded. And decentralized teams build their own
agents connected to external systems via MCP servers —
connections using the Model Context Protocol, through which
an agent reaches tools and data outside M365 — without any
central oversight, because nobody's watching.
On top of that, there's a question that has to be answered
independently of your own tenant: the EU Data Boundary,
Microsoft's commitment to process EU customers' data within
the EU, determines where Microsoft is allowed to process the
data at all. But it doesn't replace your own governance for
access within the tenant — one governs the location, the
other governs who sees what.