JJC SystemsBook a Consultation
Microsoft Purview · Healthcare

Information governance as an AI prerequisite

An examination of why AI deployments in provider organizations pause, and what the sequencing should be instead.

PublishedJuly 19, 2026
Length16 pages · 17 min read
SectorHealthcare
PlatformMicrosoft Purview
Service areaManaged IT & Security
Abstract

Information governance as an AI prerequisite

Summary

Almost every healthcare AI pilot we have seen paused was paused for the same reason, and it was never the model. It was a clinician asking a reasonable question and receiving a document they were technically permitted to open and had no business reading.

This paper argues that information governance is not a parallel workstream to AI adoption but a prerequisite for it, sets out what the assessment should establish, and proposes a sequence that adds roughly six weeks to a programme and removes its most likely failure mode.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

AI does not create the permission problem; it audits it

The oversharing was always present. What changed is that finding an overshared document used to require knowing it existed, and now it requires asking a reasonable question.

02

Exposure concentrates, which makes remediation tractable

In every assessment we have run, a small number of sites carry a disproportionate share of the risk. Remediating those covers most of the exposure.

03

Site ownership is the binding constraint, not technology

Orphaned sites block remediation entirely, because nobody can approve a permission change. This is administrative work and it is usually the longest part of the programme.

04

Retention is a governance control that AI makes urgent

An assistant reasoning across your content will reason across superseded drafts and material you should have disposed of. Retention stops being a compliance obligation and becomes an accuracy one.

Analysis

The argument in full

Why healthcare estates overshare

Clinical work is collaborative and urgent, and the sharing model rewards speed. A consultant needs a protocol at eleven at night, so somebody shares it with everyone in the organization because that link works immediately and a permissions request does not.

Repeat that across a decade and a merged estate that has absorbed two acquisitions, and the effective permissions bear no relationship to anyone's intent.

Microsoft's own tooling reflects how common this is. SharePoint Advanced Management now reports specifically on files shared with Everyone Except External Users — the exact pattern that causes most of it — and delivers the report as a downloadable export rather than a dashboard because the row counts defeat on-screen review.

What the assessment should establish

Not a list of sites. A list of content reachable by more people than the owner believes, weighted by how sensitive it is.

The distinction matters because volume is a poor proxy for risk. A site with ten thousand overshared documents that are all published policies is a lower priority than one with forty documents containing patient-identifiable material.

  • Broad-access sharing links on libraries containing patient-identifiable data
  • Permission inheritance broken years ago and never reviewed since
  • Sites with no active owner, where nobody can approve a change
  • Content with no sensitivity label, in libraries where labelling was assumed automatic
  • Guest and external access that outlived the project justifying it

The sequence, and why reversing it fails

Discovery first, remediation second, deployment third. Organizations that reverse the first two spend the pilot period arguing about individual documents instead of learning whether the technology helps.

There is a second reason the order matters. A pilot group given access during remediation will find the unremediated content, and the finding will reach leadership as an incident rather than as a planned discovery. The same fact, arriving in a different frame, produces a paused programme instead of a funded one.

Microsoft's data security posture management for AI now surfaces which AI applications are being used and what data they reach, which makes the assessment considerably cheaper to run than it was two years ago. That is an argument for running it, not for skipping it.

Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

The readiness sequence

Five stages. The first three belong before any licence is assigned.

1

Discover

Establish where sensitive content is and who can currently reach it, using governance reporting rather than assumption.

2

Prioritise

Rank by content sensitivity, not by exposure volume. Ownership gaps come first because they block everything.

3

Remediate

Fix the highest-risk sites with owners involved. Bulk action across the estate breaks something a ward relies on.

4

Deploy

Pilot with a clinical function, not only with IT, and with a route to report a wrong answer.

5

Sustain

Re-baseline on a cadence. Content keeps arriving and the position drifts within a year.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the CIO

For the Chief Medical Officer

For the Privacy Officer

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
Microsoft Purview data security posture management for AI
02
SharePoint Advanced Management
03
Sensitivity labels in Microsoft Purview
04
Retention policies and retention labels
05
Microsoft 365 Copilot data protection and security

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

We run the readiness assessment as a scoped, fixed-price engagement, and the findings report is yours whether or not you take the remediation work further with us — including if it tells you to delay.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

azure
healthcare16 pages

Building for AI on regulated infrastructure

An estate designed for hosting usually needs rework before it can support AI workloads safely. This paper sets out what changes and why designing for it now is cheaper.

May 17, 2026 · 16 pages · 17 min readRead
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.