All Services
AI

Microsoft Copilot and Shadow AI Readiness Assessment

Evaluate Microsoft 365 permissions, identify observable unmanaged AI use, and build a prioritized governance and remediation roadmap.

Infonaligy's Copilot and Shadow AI Readiness Assessment is a focused, deliverable-driven engagement for Texas businesses that need to understand three questions: Is Microsoft 365 ready for Copilot? Which unmanaged AI tools can we observe? What governance, privacy, security, and operational gaps should we address first?

The assessment is designed primarily for organizations with 50–500 employees. It evaluates evidence available from your Microsoft 365 tenant, identities, devices, network and security tools, policies, interviews, and approved data sources.

Call 800-985-1365

Before buying more licenses or issuing a policy that cannot be enforced,

Assessment Deliverables at a Glance

Copilot Readiness Scorecard

Which departments, users, permissions, data sources, and controls are ready or need remediation?

Observable Shadow AI Inventory

Which AI tools and AI-enabled features can be identified within the agreed evidence sources?

Data and Risk Map

What business information may be entering each observed tool, and what is the likely exposure?

Governance Package

What acceptable-use rules, ownership, approval, review, and documentation should be established?

TRAIGA and TDPSA Technology Review

Which identified technology practices should legal or compliance leaders evaluate against Texas requirements?

Prioritized Remediation Roadmap

What should be approved, restricted, replaced, remediated, trained, monitored, or implemented first?

When Your Business Needs This Assessment

The engagement is useful when:

Copilot licenses exist, but adoption or business value is unclear.
Employees use ChatGPT, Claude, Gemini, transcription tools, or embedded AI without an approved process.
SharePoint, OneDrive, Teams, or guest-access permissions have grown without review.
Leaders cannot distinguish Copilot Chat from licensed work-grounded Microsoft 365 Copilot.
Sensitive-data rules do not address AI prompts, files, outputs, agents, or browser tools.
No one owns AI approvals, exceptions, incidents, or continuing review.
Cyber-insurance, client, regulatory, or board questions now include AI governance.
The organization needs evidence before choosing an AI platform or rollout sequence.

Published estimates cited in Infonaligy's current materials place SMB Copilot adoption near 12% and the observed range at 14–22 unsanctioned tools for a median 100-employee company. The current page also cites IBM's 2025 breach research for a $670,000 average additional cost when shadow AI was involved. These are market indicators, not forecasts of a specific organization's environment or losses.

Copilot Readiness Review

Microsoft 365 Copilot works within the user's existing access. That makes identity and information governance essential: Copilot does not need to bypass permissions to expose information that was already overshared.

We evaluate:

Eligible licensing, Exchange Online, Entra ID, applications, and network prerequisites.
SharePoint, OneDrive, Teams, group, guest, and link-sharing permissions.
High-risk sites, stale access, excessive membership, and broad sharing.
Sensitivity labels, retention, Data Loss Prevention, audit, and eDiscovery readiness.
Conditional Access, multifactor authentication, privileged roles, and device posture.
Department-specific workflows, training needs, adoption measures, and rollout sequence.
Copilot Chat, licensed Microsoft 365 Copilot, agents, connectors, and related governance.

Microsoft currently lists Microsoft 365 Copilot at $30 per user per month with annual payment for the referenced enterprise plan, while eligible subscriptions, bundles, and included capabilities vary. Licensing should be reviewed against the current tenant and agreement before purchase.

Observable Shadow AI Discovery

Shadow AI means employees or departments using AI tools or AI-enabled features without appropriate organizational visibility, review, approval, or governance.

Discovery may use:

Microsoft 365 audit and administration data.
Identity-provider and SaaS-access records.
DNS, proxy, secure web gateway, browser, and firewall telemetry.
Endpoint, DLP, CASB, or SSE evidence where available.
Existing application inventories and vendor contracts.
Interviews, surveys, workflow walkthroughs, and policy review.
Copilot Studio, Power Platform, agent, and connector administration data.

No assessment can guarantee discovery of every tool, personal account, prompt, file, or interaction. The report therefore identifies what is observable within the agreed scope, documents visibility limitations, and recommends how to improve continuing monitoring.

Each observed tool receives a proposed disposition: approve, restrict, remediate, replace, investigate, or monitor.

Practical AI Governance for Texas Businesses

Texas organizations should distinguish statutory obligations from good governance.

TRAIGA

Identify AI systems, deployment context, prohibited-use risks, required disclosures, safeguards, testing, monitoring, and evidence relevant to the organization

TDPSA

Review applicable personal-data processing, notices, consent, processor terms, security, assessments, and consumer-rights processes

NIST AI RMF

Use a recognized structure for governing, mapping, measuring, and managing AI risk

Internal governance

Define approved tools, data rules, ownership, human review, incident escalation, monitoring, training, and exceptions

TRAIGA took effect January 1, 2026. Its requirements depend on the organization, deployment, use, and statutory provision. HB 149 required the Attorney General to publish an online complaint mechanism no later than September 1, 2026; the OAG AI complaint page is already available.

NIST AI RMF alignment is useful, but it should not be represented as a blanket legal safe harbor. Legal counsel should determine applicability and legal interpretation.

How the Assessment Works

1

Scope

Confirm users, locations, tenant, devices, evidence sources, systems, and stakeholders.

2

Collect

Review authorized configuration, permissions, logs, policies, contracts, and interviews.

3

Analyze

Evaluate Copilot prerequisites, oversharing, observed AI use, data flows, and governance gaps.

4

Prioritize

Rank findings by information sensitivity, business impact, exploitability, compliance relevance, and remediation effort.

5

Deliver

Present the scorecard, inventory, governance package, and sequenced roadmap.

6

Brief leadership

Explain decisions, ownership, cost considerations, and recommended rollout phases.

Most engagements are planned for 2–3 weeks, depending on tenant size, locations, available telemetry, and stakeholder access.

Why Businesses Choose Infonaligy

Security-first assessment

Copilot adoption is evaluated together with identity, permissions, data protection, monitoring, and incident readiness.

Microsoft 365 depth

The review connects Copilot with Entra ID, SharePoint, OneDrive, Teams, Purview, DLP, retention, and administration.

Established experience

Infonaligy has supported business technology since 2003.

Operational follow-through

Microsoft 365 consulting and management, managed security services, and AI consulting and implementation can support approved next steps.

24/7 security depth

SOC capabilities include 150+ certified security professionals and an average critical response under 14 minutes.

Trusted service

Infonaligy maintains a 5.0 Google rating with 120+ Google reviews.

Frequently Asked Questions

It evaluates licensing, identity, mailboxes, applications, permissions, information governance, security controls, use cases, training, and rollout readiness before broader Copilot deployment.
Shadow AI is the use of AI tools or AI-enabled features without appropriate organizational visibility, review, approval, or governance.
No. It identifies activity observable through agreed logs, configurations, tools, interviews, and evidence sources and documents important visibility limitations.
Microsoft 365 is required for the Copilot-readiness pillar. Shadow AI discovery and broader governance work can be adapted to another environment.
Microsoft currently lists the referenced enterprise plan at $30 per user per month, paid annually. Actual licensing depends on the subscription, bundle, agreement, and current Microsoft terms.
No. Copilot uses information the user is authorized to access. Poorly governed or overshared permissions can therefore affect what Copilot surfaces.
No. Applicability and obligations depend on the person, AI system, deployment, use, affected individuals, statutory provision, and applicable exemptions or defenses.
No. NIST alignment is valuable, but TRAIGA's liability language applies under specified circumstances. Legal counsel should interpret how it applies to the organization.
Most engagements are planned for 2–3 weeks. Tenant size, locations, evidence availability, and stakeholder access may change the schedule.
It is an Infonaligy operating principle: successful adoption depends heavily on permissions, data, policy, training, ownership, oversight, and change management—not only the AI tool.

Understand Your AI Readiness Before Scaling

Clarify Copilot readiness, expose observable shadow AI, improve governance, and give leadership a prioritized remediation and rollout roadmap.

Call 800-985-1365

Start with a complimentary assessment. Comparable strategic reviews can be valued at up to $25,000.