news

What should be included in an AI readiness assessment before deploying Microsoft Copilot or other AI models

Share

Get in touch

Book a straightforward, no-obligation discovery call with a senior member of the Cloudscape team.

Someone in your team has started pasting client emails into a free artificial intelligence (AI) chatbot to write replies faster. Someone else keeps asking when the business is getting Copilot. You can see the appeal, but a quieter question keeps coming back: where does that information go, and who could see it once AI is switched on across your files?

This guide sets out what an AI readiness assessment should include before you deploy Microsoft Copilot or any other AI model. It’s written for business owners and office managers who want to make a sound decision without becoming technical experts and works as a checklist for judging your own readiness or testing what an information technology (IT) provider proposes.

TL;DR

An AI readiness assessment should check five areas before anyone switches AI on: your goals, who can see which data, how accounts and devices are secured, your policies and legal duties, and whether staff are trained. Most of the risk sits in the access and habits an AI tool inherits from your existing setup. Skip the assessment and an AI assistant can put confidential files in front of people who were never meant to see them.

Key takeaways

  • Write down two or three business problems you want AI to solve before you buy licences.
  • Review who can open your SharePoint sites, Teams and shared folders, because Copilot can surface anything a user can already see.
  • Check that every account has an extra sign-in check and that staff use AI with their work account.
  • Agree a short AI policy listing approved tools and the information that must never go into them.
  • Start with a trained pilot group and set a date to review results before a wider roll-out.

How to use this AI readiness checklist

Work through the checklist in order, because each area shapes the next: your goals tell you which data matters, and your data tells you which security gaps to close first. If you’ve carried out an IT risk assessment before, the approach will feel familiar.

Mark each item as done, partly done or not started. Anything not started in the data or security sections should be fixed before AI reaches real users. Review the checklist at least every six months, and again whenever you add an AI tool, connect AI to another system or start handling a new type of sensitive data. AI products change quickly, so last year’s assessment is unlikely to reflect what your tools can do today.

Business goals and use cases

Specific problems you want AI to solve

Check that you can name two or three tasks where AI would save real time, such as summarising long email threads or pulling actions out of Teams meetings. Good looks like each use case having an owner and a clear sense of what better would mean, so you can tell later whether it paid off. AI advisory support can help if you want an outside view on where AI fits.

The right tool for each job

Check what each option can reach. Microsoft Learn notes that Microsoft 365 Copilot is now called Microsoft Copilot, and explains that Copilot Chat, included with eligible Microsoft 365 business plans, draws on the web, while the full Microsoft Copilot also draws on work data such as emails, files and meetings. Good looks like every use case matched to an approved tool whose data handling you understand.

Data and permissions: the core of any AI readiness assessment

Cloudscape’s view is that guardrails and readiness should come before any AI deployment, and most of that work happens here. Microsoft’s privacy documentation states that Copilot only surfaces data each user already has at least view permission for, which is only reassuring if your permissions are right.

Who can see what in SharePoint, OneDrive and Teams

Look for sites open to the whole company, links that work for anyone, old teams that still include former staff or guests, and payroll or client folders more people can open than need to. Good looks like access that follows job roles, with guests and leavers removed promptly. Microsoft recommends completing its Microsoft 365 Copilot Optimization Assessment before deployment.

Labels on sensitive files and a clear-out of old ones

Check whether sensitive documents carry sensitivity labels (tags in Microsoft 365 that mark a file as confidential and can restrict who opens it), which Microsoft says Copilot respects. Also look for old or duplicated files, because an out-of-date policy can end up in a confident-sounding answer. Good looks like labelled contracts and personal data, plus retention rules (settings that archive or delete files after a set period).

Identity, devices and security

The UK government’s Cyber Security Breaches Survey 2025/2026, published in April 2026, found that 31% of UK businesses were using, adopting or considering AI, yet only 24% of that group had cyber security practices to manage the risks. Microsoft bases its Copilot security advice on a zero-trust approach (treating every sign-in and device as untrusted until verified).

Multi-factor authentication and admin rights

Check that multi-factor authentication (an extra check when you log in, such as a code sent to your phone) covers every user, including directors. Good looks like no exceptions and admin rights limited to the few people who need them, because AI working through a compromised account can gather information far faster than a person.

Managed devices and work accounts

Check that work laptops and phones are managed through a tool such as Microsoft Intune, so lost devices can be wiped. Microsoft also advises telling staff to sign in to Copilot Chat with their work account, because protections differ by account. Good looks like company data reachable only from managed devices and work sign-ins.

Policy, governance and legal duties

Microsoft research carried out by Censuswide in October 2025 found that 71% of UK employees had used unapproved consumer AI tools at work, and 51% did so every week. In 2026 the National Cyber Security Centre (NCSC) advised reducing this risk by understanding why people use such tools and offering secure alternatives.

An AI acceptable use policy and approved tools list

Good looks like a short, plain-English policy that everyone has read, listing approved tools, what can’t be entered into them and who to ask about new ones. In Cloudscape’s experience, when staff try to connect an outside AI tool to a properly configured Microsoft 365 environment, it’s blocked by design, which turns a quiet workaround into a conversation about whether the tool is safe.

Data protection checks and sector rules

The Information Commissioner’s Office (ICO) guidance on AI and data protection says that in the vast majority of cases, using AI will require a data protection impact assessment (DPIA), a documented review of risks to people’s personal data, although the ICO notes this guidance is under review. Also check what regulators and client contracts say about third-party tools, including what FCA-regulated firms need if you’re regulated by the Financial Conduct Authority (FCA). Good looks like a DPIA signed off before roll-out.

People, pilots and roll-out

Training staff to check AI answers

Check that training covers how to check what AI produces. The NCSC warns that AI can present incorrect statements as facts, and Microsoft says Copilot’s responses aren’t guaranteed to be 100% factual. Good looks like a firm rule that a person reviews anything AI drafts before it reaches a client.

A small pilot with a review date

Check who goes first, for how long and how you’ll decide whether to expand. Microsoft says the right Copilot licence depends on your existing subscriptions, so tidy your Microsoft 365 licensing before buying more. Good looks like a pilot group from several teams, a fixed trial period and measures tied to your original use cases.

Your AI readiness checklist at a glance

Print this table and mark each item as done, partly done or not started to see where your gaps are.

Item How to check it What good looks like
Business problems defined Ask each team lead for their two most time-consuming tasks Two or three use cases, each with an owner
Right tool for each job Compare what each tool can access and store Every use case matched to an approved tool
SharePoint, OneDrive and Teams access Review company-wide sites, open links and guests Access follows job roles
Sensitive files labelled Spot-check board papers, contracts and personnel files Confidential files labelled and restricted
Old and duplicate data Look for files nobody has opened in years Retention rules in place
Multi-factor authentication Check the admin centre for accounts without it Every user, no exceptions
Devices and work accounts List every device that reaches company data Managed devices and work sign-ins only
AI acceptable use policy Ask three staff where to find it Short, read by all, approved tools listed
DPIA and sector rules Review contracts and regulator guidance DPIA done or exemption recorded
Pilot, training and review Confirm pilot names, dates and measures Trained group with a set review date

How long does an AI readiness assessment take for a small business?

It depends mainly on how many users and SharePoint sites you have, how tidy your permissions are and how many AI use cases you want to test. A business with well-organised files and a handful of clear goals will move through the checklist far faster than one with years of informal sharing.

The review itself is usually the quicker part. Fixing what it finds, such as reworking access on old sites or labelling sensitive files, takes longer, so plan them as two stages and don’t switch licences on until sensitive data is sorted.

Does a small business need an AI readiness assessment if staff only use free AI tools?

Yes, arguably more so, because free consumer tools sit outside the controls, you’d normally rely on. The NCSC notes that information put into consumer AI services may be stored, retained or used to improve the service unless specific privacy controls are in place.

The same 2025 Microsoft research found that 28% of UK employees used unapproved tools because their company didn’t provide a work-approved option. Here, the assessment focuses less on permissions and more on policy, training and choosing an approved alternative for the tasks people already do.

Getting your business ready for AI the safe way

Being ready for AI means clear goals, permissions that match who should see what, secure accounts and devices, a policy staff understand and a trained pilot group with a review date. None of it needs new technology first, and most of it strengthens your security whether you go on to deploy AI.

Cloudscape has more than 25 years of experience supporting London businesses, manages over 130 Microsoft 365 environments, and is a Microsoft Partner with Cyber Essentials accreditation. Talk to Cloudscape about AI readiness for a second opinion on where your business stands before AI goes live.

Related news

IT Support

How Much Does Managed IT Support Cost for a 25–50 Person Financial Services Firm in London?

IT Support

Is 24/7 IT Support Necessary for Financial Services Firms, or Is It Overkill?

IT Support

What IT Support Does an FCA-Regulated Financial Services Firm Actually Need to Stay Compliant?

Contact us

Ready to simplify your IT? Book a free discovery call

We’ll review your setup, highlight quick wins, and answer your questions.

Secret Link