Assistants built into productivity software, such as Microsoft's Copilot for Microsoft 365, search and summarize content across a user's email, files, chats and meetings. That is the feature. It is also the risk. These tools generally respect the permissions a user already has, which means they can quickly surface anything the user is technically allowed to see, including documents nobody realized were open to them.
For a law firm, where confidentiality and ethical walls matter, that makes permissions the first project, not the last.
The Core Problem: Oversharing
Over years, files accumulate in shared locations with broad access. A folder created for a one-time project is left open to "everyone." A SharePoint site is shared firm-wide for convenience. A link set to "anyone in the organization" is pasted into an email thread. Before AI, such sloppy permissions were hidden by obscurity, because nobody knew where to look. An assistant that can search everything in seconds removes the obscurity.
Consider a hypothetical: a junior staff member asks an assistant to summarize recent compensation discussions or a sensitive matter, and the tool dutifully pulls from a file that was accidentally shared widely. The assistant did nothing wrong in a technical sense. The permissions were the problem.
Before You Turn It On
1. Inventory what is shared
Use your platform's reporting to find sites, teams, libraries and files with broad access, anonymous links or external sharing. Prioritize those that hold client matters, HR, finance and partner materials.
2. Fix the permissions
- Replace "everyone" access with role or matter-based groups
- Remove inherited permissions that expose subfolders unintentionally
- Expire or delete unneeded sharing links
- Clean up guest accounts that no longer have a reason to exist
- Verify ethical walls and restricted matters are enforced at the platform level
3. Apply sensitivity labels
Classification labels can mark content as confidential and apply protections such as encryption and access restrictions. Decide on a small, practical set of labels, for example public, internal, confidential client information and restricted. Train people to use them, and consider default labeling for matter libraries.
4. Review retention
Old data that nobody needs is still searchable data. Deleting what you are not required to keep, within your retention rules, shrinks both the attack surface and the AI's reach.
5. Check licensing and configuration
Understand what the vendor says about how your data is processed, whether prompts and responses are used for model training, where data stays and what is logged. Read the current terms and admin documentation, since they change.
Pilot Before Rollout
- Pick a small group of willing users, with at least one attorney and one staff member.
- Define use cases, such as summarizing meetings, drafting routine correspondence and finding documents.
- Test what the assistant can see by asking probing questions as a standard user. If it surfaces something sensitive, fix the underlying permission.
- Gather feedback and refine policy.
- Expand gradually.
Policy and Training
Your AI policy should cover Copilot-style tools specifically:
- What the tool may be used for and what it may not
- A reminder that outputs must be reviewed before use, because the tools can be wrong
- That sensitive matters under restricted access remain restricted
- Where AI-generated notes or summaries are saved, and how they fit retention
- That lawyers remain responsible for supervision under Rules 5.1 and 5.3 and competence under Rule 1.1, themes discussed in ABA Formal Opinion 512
Monitoring
After rollout, review audit logs and usage reports. Look for unusual access patterns, and consider data loss prevention rules to prevent labeled content from being sent where it should not go.
Realistic Benefits
For many firms, the best early uses are modest: drafting emails, summarizing long threads, preparing meeting recaps and locating documents. Those save time without asking the tool to do legal analysis.
Where Counsel Cyber Helps
Counsel Cyber assesses Microsoft 365 permissions, sharing and sensitivity labeling, then helps firms pilot AI assistants with appropriate guardrails. If you are thinking about turning on an assistant, a permissions review is the right first step.