A growing number of enterprises are rushing to deploy AI tools in Microsoft 365 without first defining what business problem they’re solving, according to a recent analysis from Petri IT Knowledgebase. The result: expensive ‘AI theater’ and risky shadow AI that can leak corporate data. IT admins need to step in with governance before the sprawl gets worse.
In the latest episode of Petri Dish, AI governance advisor Troy Norcross, founder of SERTeam, cut through the hype with a blunt message: start with the business problem, not the model or chatbot. Companies chasing AI adoption as an end in itself are producing expensive experiments rather than measurable returns. The pattern is what Norcross calls “AI theater” — separate teams deploy tools, run hackathons, or build proofs of concept primarily to demonstrate innovation. The predictable outcome is AI sprawl, shadow AI brought in by employees, and no agreed measure of whether the work improved cost, speed, quality, risk, or customer outcomes.
The real cost of skipping the business case
Norcross’s diagnosis isn’t abstract theory. It lands squarely on the desks of Windows and IT administrators every time an unsanctioned generative AI service starts receiving corporate documents. Whether it’s a browser extension scraping data, a third-party app plugged into Microsoft 365 APIs, or a custom model built without common access controls, the operational fallout is immediate. Data leaks, compliance violations, and unmonitored decision-making aren’t just boardroom talking points — they’re incidents you’ll have to clean up.
The core failure, according to Norcross, is skipping a simple sequence: define what is broken, quantify the consequence, decide what success looks like, and only then determine whether AI is the right fix. That framing can kill bad projects early. An overloaded service desk might need better knowledge management or cleaner ticket categorization before it needs a large language model assistant. Deploying an AI copilot to mask process gaps is a recipe for disaster. The key test is whether a team can state the expected operational change. “Deploy an AI assistant” is activity; “cut first-response time for password-reset tickets while maintaining resolution quality” is a measurable business outcome.
The governance vacuum: probabilistic systems, deterministic controls
Generative AI introduces a fundamental tension that legacy enterprise software never had. Most line-of-business systems behave predictably for a given transaction. AI models can generate different answers, make unsupported claims, or handle edge cases inconsistently. That doesn’t make AI unusable, but it does mean the surrounding system must carry more of the control burden.
For Microsoft-centric environments, that means pulling AI access into the existing governance estate. Entra ID groups, Microsoft Purview sensitivity labels and data-loss-prevention controls, Defender monitoring, and approved Copilot configurations become the new frontline. The model may be probabilistic; the permissions and safeguards cannot be. Without deterministic guardrails, organizations are effectively inviting employees to experiment with corporate data in ChatGPT, Google Gemini, or unvetted Copilot extensions — and that’s shadow AI at its most dangerous.
Norcross defines AI readiness as a leadership condition: executive commitment and communication, an AI-use policy, and appropriate technical infrastructure. The goal isn’t to stifle experimentation. It’s to let teams test useful ideas without turning sensitive data and compliance obligations into afterthoughts. A workable policy makes clear which tools are approved, which data may be entered into them, who can authorize new use cases, and what must happen when AI output influences customer, financial, legal, security, or employment decisions. Without those answers, shadow AI will fill the vacuum.
How we got here: AI adoption outran governance
It’s worth understanding how enterprises arrived at this juncture. Microsoft’s aggressive integration of Copilot across Microsoft 365, from Word and Excel to Teams and the Power Platform, lowered the barrier to AI-driven work in 2023 and 2024. By mid-2025, millions of users had access to Copilot features. The allure was irresistible: summarize meetings, draft documents, analyze spreadsheets with natural language prompts. But the governance frameworks lagged.
Industry surveys from Forrester and Gartner in early 2025 noted that over 60% of employees were using unapproved generative AI tools at least occasionally. The term “shadow AI” — a sibling of shadow IT — gained traction as IT teams discovered employees feeding proprietary code into public chatbots or connecting personal AI accounts to work data. Microsoft responded by adding administrative controls for Copilot, enabling tenant-wide policies in Purview, and offering AI-powered compliance solutions. Yet adoption of those controls remains patchy. Many organizations enabled Copilot before locking down the environment, and now they’re playing catch-up.
What this means for you
If you manage a Microsoft 365 tenant, you’re likely facing three practical challenges right this minute:
- Unsanctioned AI services are already in use. Employees have signed up for free tiers of ChatGPT, Claude, or other generative tools, and they’re pasting corporate content into them daily. You can’t see it, but it’s happening.
- Copilot sprawl is generating unexpected costs. Microsoft 365 Copilot licenses add up quickly, and without usage analytics, you might be paying for features no one is using or, worse, for prompts that violate data-handling policies.
- Compliance gaps are widening. If your organization hasn’t mapped AI-generated content to retention schedules or hasn’t applied sensitivity labels to documents that are fed into Copilot, you’re out of step with regulations like GDPR, HIPAA, or internal data classification rules.
For power users and developers, the implications are different. You might be tasked with building custom Copilot experiences or integrating Azure OpenAI services into line-of-business apps. Without centrally defined policies and approved-model lists, your project could end up duplicating efforts or hitting a compliance wall late in development.
What to do now: a practical governance playbook
Based on Norcross’s guidance and Microsoft’s current toolset, here are concrete steps you can take this week:
1. Audit the AI landscape
Use Microsoft Defender for Cloud Apps to discover third-party AI services that are accessing your tenant. Check Entra ID sign-in logs for patterns that suggest employees are authenticating to AI platforms with work credentials. Run a survey (anonymized) to ask teams which AI tools they’re using.
2. Establish a baseline AI-use policy
Document which tools are approved, which data classifications can be used with them, and who must authorize new AI use cases. Make it short and readable. Publish it on your intranet and reference it in your employee handbook. Include concrete examples: “You can use Copilot to summarize a meeting that doesn’t contain customer PII, but you cannot paste a full customer contract into a public chatbot.”
3. Configure Copilot administrative controls
In the Microsoft 365 admin center, navigate to Settings > Org settings > Copilot. Control which users get Copilot licenses, set data handling preferences, and review the Copilot usage report. In Purview, configure communication compliance policies to flag prompts that contain sensitive info types like credit card numbers or medical terms.
4. Extend sensitivity labels to AI flows
Using Purview, ensure sensitivity labels are applied to documents and emails automatically. Copilot respects those labels when generating responses, and you can configure it to block summarization or querying of items labeled “Highly Confidential.” This is a non-negotiable step before you allow broad Copilot use.
5. Build a gated experimentation framework
Norcross advocates for innovation without recklessness. Set up a sandboxed Microsoft 365 environment where power users can test new AI integrations under defined boundaries. Use Entra ID conditional access policies to restrict data egress. Ensure that every pilot begins with a success metric that ties to a business problem.
6. Train your help desk and educate users
Your service desk will be the first to hear about AI-related issues: “Copilot gave me wrong information,” “I accidentally shared a confidential document.” Train them to handle these tickets and to spot shadow AI indicators. Run short, focused training sessions for end users that explain the risks and the approved paths.
The AI project that actually pays off
The most useful AI initiative might be modest: extracting information from a constrained document set, improving internal search, classifying low-risk requests, or assisting a defined support workflow. If it solves a named problem with a measurable baseline, it has a route to ROI. If its primary purpose is to show that the organization is “doing AI,” it’s already at risk of becoming theater. For IT admins, the win is not in chasing every shiny Copilot feature but in enforcing governance that makes genuine productivity gains sustainable — and safe.
What to watch next
Microsoft is expected to tighten Copilot governance tools further in upcoming Microsoft 365 releases. Keep an eye on Purview enhancements for AI content labeling and on the GA release of AI-powered anomaly detection in Defender. In parallel, regulatory frameworks like the EU AI Act will impose new compliance requirements starting in 2026. Organizations that have their governance house in order now will be in a far better position to adapt than those still scrambling to rein in shadow AI.