Ex-employee logins linger at 38% of organizations, exposing files to AI

AI tools retrieve content that former employees should never have access to, and Canadian privacy law may apply

Ex-employee logins linger at 38% of organizations, exposing files to AI

Three in four organisations experienced at least one Microsoft 365 governance incident in the past year. 

That is the central finding of ShareGate's second annual State of M365 report, drawing on two surveys of nearly 1,800 IT professionals and leaders.

Some 38 percent of organizations left former employees or guests with access they should have lost. Another 35 percent hit an audit or compliance gap, and 26 percent had sensitive content reach the wrong people.

AI search meets old permissions

Full Copilot deployment roughly doubled from 29 percent to 56 percent. Ninety-three percent of organizations have Copilot in production in some form, up from 82 percent in 2025. Two-thirds run two or more AI tools on the same content. 

Because Copilot operates within users' existing permissions, stale or overly broad access becomes easier to search once an AI assistant is in place, according to an analysis citing Microsoft's documentation. 

In results ShareGate published in April from its March 2026 AI survey, 29 percent said AI tools had already surfaced sensitive internal data they should not have accessed. Eight percent of them did not know. 

Privacy obligations for Canadian employers 

For HR leaders, the findings link employee exits to legal exposure. For organizations subject to PIPEDA, a privacy breach includes unauthorized access to personal information. Breaches posing a real risk of significant harm must be reported to the Privacy Commissioner of Canada, with affected individuals notified. 

Breach records must be kept for 24 months whether or not the risk threshold is met, and deliberate failure to report can bring fines of up to $100,000. 

In Quebec, Law 25 defines a confidentiality incident to include unauthorized access to, use, or communication of personal information. 

Organizations must keep a register of such incidents and notify the Commission d'accès à l'information and the people concerned when an incident presents a risk of serious injury. Failing to report can bring penal fines of up to $25 million or 4 percent of the previous year's worldwide turnover, whichever is greater. 

Ontario, without a private-sector privacy law, requires employers with 25 or more employees to keep a written electronic monitoring policy describing any AI used to monitor staff. Since January 1, 2026, public job postings must also disclose AI use in screening, assessing, or selecting applicants. 

HR often outside AI decisions 

SHRM's 2026 research found that 52 percent of organizations do not involve HR in their overall AI strategy. Fifty-two percent of workers use unapproved AI tools, and many have shared confidential records externally, sometimes including employee data. 

In Canada, an SAP study found 56 percent of organizations say staff use unapproved AI tools at least occasionally. Meanwhile, 97 percent of 200 leaders surveyed are not fully prepared to deploy and govern agentic AI. 

Confidence runs ahead of detection 

ShareGate found 65 percent of teams learn about problems only after the fact, through quarterly audits or user complaints, while 35 percent use proactive monitoring and automated alerting. Yet 63 percent describe their governance as operationalized or better – a group drawn from the same 77 percent that reported an incident. 

Only 1 percent use a purpose-built governance tool, unchanged from 2025. Fifty-seven percent rely on built-in Microsoft tools, 38 percent on manual or internal policies, and 4 percent have none. The report attributes the incident rate to fragmented visibility, overconfidence, and an AI governance skills gap that has not closed. 

Richard Harbridge, principal industry advisor at ShareGate, said most environments he reviews are not broken but lack visibility into what is happening within them.  

"That gap between 'no news' and 'no problems' is exactly where the governance incidents live, and when you layer in multiple AI tools, the visibility problem compounds fast," he said. 

Asked what would help most, 34 percent of IT professionals named better controls for AI agents, ahead of executive buy-in (20 percent) and automated remediation (18 percent). More budget ranked last at 3 percent. 

Compliance slows migrations 

Compliance concerns led 34 percent of organizations to delay or avoid a migration in the past 12 months, up from 20 percent in 2025. Eighty-seven percent said compliance significantly or moderately affects migration decisions, up from 82 percent. 

Results are self-reported and vendor-funded, and ShareGate sells Microsoft 365 governance tooling. 

ShareGate is developed by Workleap Technologies, a Montréal-based software company. 

The IT operations survey polled 943 IT professionals in May 2026. The AI governance survey polled 851 IT leaders in March 2026, with both including Canada. Country-level results are on ShareGate's website, but the release does not include Canadian figures. 

LATEST NEWS