Enterprise AI

What the NHS Copilot rollout reveals about enterprise AI readiness

By Richard Harbridge, Principal Industry Advisor, ShareGate

Across the public and private sectors, AI adoption continues to accelerate. In healthcare, 75% of surveyed public-sector organisations are exploring or actively working on generative AI initiatives. One of the most significant tests of AI at scale is now approaching, with NHS England announcing plans to provide Microsoft 365 Copilot to 505,000 clinicians and support staff. With more than one in four GPs already using AI tools in clinical practice, wider adoption is a logical next step. The goal is to reduce administrative burdens, improve efficiency and give staff more time to focus on patient care. 

The more difficult question, however, is readiness. Sixty-eight per cent of surveyed physicians said the NHS lacks the digital infrastructure needed to introduce AI effectively, while concerns about training, interoperability, patient safety and data privacy are already surfacing. The biggest barrier, however, remains readiness. This points to a meaningful gap between ambition and infrastructure.  

At the scale at which public-sector organisations operate, AI adoption requires governance that can keep pace with the technology being deployed and must include clear policies for data access, retention, accountability and human oversight.https://www.rcp.ac.uk/news-and-media/news-and-opinion/the-nhs-is-fundamentally-unprepared-for-ai-7-in-10-doctors-say-the-nhs-is-not-digitally-fit-to-deploy-it/ That gap is not unique to healthcare. Private-sector organisations face many of the same readiness questions, even when the regulatory context, systems and consequences differ. 

 Why existing governance frameworks need to evolve 

Traditional governance often relies on periodic reviews and slower-moving processes. Many existing frameworks were designed for more predictable systems, where changes to data access, applications and workflows happened at a pace teams could reasonably review. That made it easier to review risk, document decisions and respond as regulation evolved. Human decision-makers were also more visibly positioned at the centre of many workflows, making informed judgement calls. 

AI changes these operating conditions. AI systems can process and synthesise information at a speed and scale no human team can review interaction by interaction. At the same time, many organisations are adopting multiple tools across both operational and governance functions. The result can be an ecosystem in which similar data flows through multiple systems while outputs, actions and decisions become harder to trace consistently. 

The challenge is compounded by the nature of the modern workforce. Today, staff join, leave and move between teams, while organisations are regularly reshaped through restructuring, mergers and acquisitions. The problem of access no longer matching someone’s role or legitimate business need is not new.  Introduce AI into that environment, and existing data sprawl and oversharing become easier to discover and more consequential. 

The familiar governance mistakes  

Many governance failures begin with unaddressed blind spots that remain hidden even after deployment is underway. Organisations frequently begin AI rollouts without a clear picture of their current environment. They fail to consider what sensitive or business-critical data exists, where it lives, who owns it and who can access it.   

In large organisations, particularly public-sector bodies where data may have accumulated across decades of systems and restructures, this picture is rarely as tidy as teams assume.  Deploying AI on top of an environment that has not been properly assessed can amplify operational, regulatory and reputational risk. 

Governance is also frequently treated as a pre-launch checklist rather than a continuous operational function. Teams may invest heavily in preparation, but real-world use will inevitably surface behaviours, use cases and risks that pre-launch testing could not fully anticipate. 

Many organisations are also layering multiple specialised tools that do not communicate effectively with one another. They may deploy one platform for administrative automation, another for back-office processes and a separate solution for access governance across Microsoft 365.  Each tool may perform its individual function adequately, but together they can create fragmented oversight, duplicated effort and additional sprawl that is difficult to contain. 

 What poor governance reveals 

There is a clear disconnect between confidence and operational risk. A recent ShareGate Study found that 93% of surveyed IT and security leaders were confident their Microsoft 365 governance framework could support AI responsibly. Despite that confidence, 29% said AI tools had already surfaced sensitive information that respondents believed should not have been accessible. 

The types of data being surfaced are not abstract. They include customer information, employee records, financial data, contracts and strategic documents. In a healthcare setting, that could mean an employee receiving an answer grounded in sensitive information they were technically permitted to access but no longer had a legitimate reason to see. 

When incidents like this occur, the instinct is often to blame the tool. In Microsoft 365 Copilot, however, the more common issue is not that AI has bypassed a security boundary. Copilot respects existing permissions; the problem is that those permissions may be broader, older or less intentional than leaders realise. 

Problems arise when existing access rules were not designed with AI-assisted discovery in mind. Information that once required someone to know where to look can now be surfaced through a single prompt. 

When governance tools are fragmented and oversight is inconsistent, oversharing becomes a recurring pattern rather than an isolated incident. Remediation becomes slow and costly. The distinction that matters here lies in whether governance is reactive or proactive. Organisations that establish the right controls before deployment can reduce the likelihood and impact of data exposure, while avoiding the cost of remediating problems after trust has already been affected. 

Building the foundations first  

The NHS Copilot deployment will be one of the most significant tests of large-scale workplace AI adoption the UK has seen. Its progress will offer important lessons for both public- and private-sector organisations about what responsible deployment looks like at scale. Its outcome will depend as much on the governance surrounding the technology as on the technology itself. 

That means organisations need to move beyond surface-level readiness checks. Effective governance starts with a thorough understanding of the existing environment: what data exists, where it lives, who owns it, and who can access it.  It requires collaboration across IT, security, legal, compliance, data and operational teams, with clear accountability for the decisions each group owns. It also requires scrutiny of the tools themselves: whether the platforms work together, provide consistent oversight and reduce more complexity than they introduce.   

IT teams should ask whether they have the capacity to monitor the systems they are responsible for continuously. Organisations must also ensure that training and adoption support keep pace with deployment. Organisations must also define what information AI agents can access, which actions they can take and where human review remains necessary. 

AI adoption at scale is becoming an operational reality, and it will expose challenges that many organisations are still working to address. Effective governance is not the enemy of speed; it is what makes speed sustainable. By identifying risk earlier rather than responding after an incident, organisations give AI deployments a better chance to deliver. Teams can focus on efficiency, service improvement and better employee experiences rather than spending their time correcting governance problems that AI has made easier to see. 

The goal is not governance for its own sake. It is creating the confidence to use AI responsibly at scale. 

Related Articles

Back to top button