AI does not create the permission problem; it audits it
The oversharing was always present. What changed is that finding an overshared document used to require knowing it existed, and now it requires asking a reasonable question.
An examination of why AI deployments in provider organizations pause, and what the sequencing should be instead.
Almost every healthcare AI pilot we have seen paused was paused for the same reason, and it was never the model. It was a clinician asking a reasonable question and receiving a document they were technically permitted to open and had no business reading.
This paper argues that information governance is not a parallel workstream to AI adoption but a prerequisite for it, sets out what the assessment should establish, and proposes a sequence that adds roughly six weeks to a programme and removes its most likely failure mode.
If you read nothing else, read these. The analysis that follows sets out the evidence for each.
The oversharing was always present. What changed is that finding an overshared document used to require knowing it existed, and now it requires asking a reasonable question.
In every assessment we have run, a small number of sites carry a disproportionate share of the risk. Remediating those covers most of the exposure.
Orphaned sites block remediation entirely, because nobody can approve a permission change. This is administrative work and it is usually the longest part of the programme.
An assistant reasoning across your content will reason across superseded drafts and material you should have disposed of. Retention stops being a compliance obligation and becomes an accuracy one.
Clinical work is collaborative and urgent, and the sharing model rewards speed. A consultant needs a protocol at eleven at night, so somebody shares it with everyone in the organization because that link works immediately and a permissions request does not.
Repeat that across a decade and a merged estate that has absorbed two acquisitions, and the effective permissions bear no relationship to anyone's intent.
Microsoft's own tooling reflects how common this is. SharePoint Advanced Management now reports specifically on files shared with Everyone Except External Users — the exact pattern that causes most of it — and delivers the report as a downloadable export rather than a dashboard because the row counts defeat on-screen review.
Not a list of sites. A list of content reachable by more people than the owner believes, weighted by how sensitive it is.
The distinction matters because volume is a poor proxy for risk. A site with ten thousand overshared documents that are all published policies is a lower priority than one with forty documents containing patient-identifiable material.
Discovery first, remediation second, deployment third. Organizations that reverse the first two spend the pilot period arguing about individual documents instead of learning whether the technology helps.
There is a second reason the order matters. A pilot group given access during remediation will find the unremediated content, and the finding will reach leadership as an incident rather than as a planned discovery. The same fact, arriving in a different frame, produces a paused programme instead of a funded one.
Microsoft's data security posture management for AI now surfaces which AI applications are being used and what data they reach, which makes the assessment considerably cheaper to run than it was two years ago. That is an argument for running it, not for skipping it.
Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.
Five stages. The first three belong before any licence is assigned.
Establish where sensitive content is and who can currently reach it, using governance reporting rather than assumption.
Rank by content sensitivity, not by exposure volume. Ownership gaps come first because they block everything.
Fix the highest-risk sites with owners involved. Bulk action across the estate breaks something a ward relies on.
Pilot with a clinical function, not only with IT, and with a route to report a wrong answer.
Re-baseline on a cadence. Content keeps arriving and the position drifts within a year.
The same argument lands differently across an executive team. These are the three versions worth separating.
Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.
On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.
We run the readiness assessment as a scoped, fixed-price engagement, and the findings report is yours whether or not you take the remediation work further with us — including if it tells you to delay.
An estate designed for hosting usually needs rework before it can support AI workloads safely. This paper sets out what changes and why designing for it now is cheaper.
The annual service line dispute is not an arithmetic problem. It is a participation problem, and it has a structural solution.
The question is not how long until systems are restored. It is how long the organization can deliver safe care without them.
Describe the situation in your own words.