Copilot-Ready

Information Governance in 2026

Orange stripe e1733902007923

10 things IT & Records teams must fix in Microsoft 365 (before AI exposes your weak spots)

Microsoft 365 is changing fast. With Copilot and agents becoming part of everyday work, the biggest risk for organisations isn’t “AI replacing jobs” — it’s AI surfacing information that was already overshared, mislabelled, or unmanaged.

 

Microsoft is clear that Copilot and agents pull data from Microsoft Graph and respect existing permissions, sharing settings, and policies. That sounds reassuring — but it also means any permission sprawl and messy governance you already have becomes far more visible and impactful.

 

If your organisation is serious about productivity, compliance, and audit readiness, this is the moment to modernise your IT + Records Management approach.

Trend 1: “Copilot readiness” is now a governance project (not an IT toggle)

A growing best practice is to treat Copilot rollout like a structured governance programme: audit access, restrict discovery while you clean up overshared sites, then enable at scale. Microsoft even provides “Restricted Content Discovery” to give organisations time to review and fix permissions during onboarding.

 

What to do now

  • Identify overshared sites and broken inheritance

  • Reduce “everyone except external users” type access

  • Apply lifecycle controls for sites and content before enabling AI broadly

Copilot-Ready Information Governance in 2026

Trend 2: SharePoint Premium is pushing AI-powered content management

Microsoft positioned SharePoint Premium as the future of AI-powered content management and governance — essentially accelerating automation in how content is processed, secured, and governed.

 

What to do now

  • Treat content services like a controlled system, not a dumping ground

  • Define what “high-value content” is and how it should be classified

  • Make sure governance (not just storage) is embedded into your platform

Trend 3: Retention and defensible disposal are becoming urgent again

In many organisations, retention schedules exist on paper but aren’t enforced in systems. Microsoft’s Purview guidance focuses on using retention policies and retention labels to manage retention and deletion across Microsoft 365 workloads.

 

What to do now

  • Move from policy documents to actual retention configuration

  • Align labels/policies with your file plan and legal requirements

  • Ensure disposition is auditable (who disposed what, when, and why)

Trend 4: File plans and metadata are making a comeback (for the right reasons)

When content is unstructured and inconsistently named, AI tools struggle and risk increases. Microsoft’s Purview File Plan capability supports managing retention labels from a single view and is designed to help organisations make retention more systematic.

 

What to do now

  • Simplify your file plan (avoid 500+ categories no one uses)

  • Standardise metadata that matters (owner, sensitivity, retention class)

  • Train teams on “minimum viable metadata” and enforce it

Trend 5: South Africa is still standards-driven for electronic records

For public-sector and many regulated environments, standards alignment remains critical. NARSSA states that the primary endorsed standard for electronic records in office environments is SANS (ISO) 16175-2 (structured records systems managed according to a file plan).

 

What to do now

  • Map your EDRMS/ECM system capabilities to ISO 16175-2 principles

  • Ensure your system supports structured recordkeeping requirements

  • Treat “records compliance” as an operating model, not a once-off project

The 10-point Copilot-ready governance checklist (practical and measurable)

1) Fix oversharing and permission sprawl

Copilot uses what users already have access to — so overshared content becomes a business risk.

2) Define clear information ownership

Every site/library needs an owner and a governance expectation: access reviews, metadata hygiene, and retention compliance.

3) Standardise a simple site and folder model

Reduce “random team sites” and create repeatable patterns for departments and projects.

4) Implement sensitivity and access controls for critical content

Use a consistent approach for confidential, HR, finance, legal, and executive content.

5) Turn retention schedules into system rules (Purview)

Use retention labels/policies and apply them systematically.

6) Use File Plan discipline to manage labels at scale

Treat retention like a managed catalogue, not scattered settings.

7) Ensure auditability and defensible disposal

You need evidence of controls and actions, not just “we have a policy.”

8) Set up governance for Teams + SharePoint together

Teams content (files, chats, meeting notes) quickly becomes record-relevant; governance must cover the full collaboration layer.

9) Build an operating model (IT + Records + Legal + Business)

Copilot readiness is cross-functional. IT can’t “own governance” alone.

10) Train users on “Copilot-safe behaviour”

AI makes content discoverability feel different. Users need practical rules: where to store what, how to label, and what not to overshare.

What this means for your organisation

In 2026, the strongest organisations will be those that treat information governance as productivity infrastructure. When governance is clean:

  • audits become easier

  • risks decrease

  • AI adoption becomes safer

  • and teams spend less time searching, recreating, and correcting information

Prospen Africa: Build capability in IT & Records

Prospen Africa supports organisations with training in IT and Records Management — from EDRMS fundamentals through governance, lifecycle management, and standards alignment.

Explore the IT & Records category:
https://prospen.co.za/it-and-records/