About
Subscribe

Copilot is ready. Is your data?

Johannesburg, 24 Aug 2026
Copilot is ready. Is your data?
Copilot is ready. Is your data?

Copilot is ready the day you switch it on. Whether it delivers depends on something Microsoft cannot ship you: a governed data estate underneath it.

Key takeaways

  • Adoption is outrunning readiness – enterprise Copilot rollouts are accelerating, but what varies from one organisation to the next is the data underneath, and that is what decides the return.
  • Copilot inherits your permissions and reflects your data – point it at an ungoverned estate and it surfaces the wrong thing, confidently and at speed.
  • Readiness is a programme, not a switch – getting there is a sequenced piece of work on the data foundation: platform, governance and permissions, done in order.
  • You cannot buy your way to it – more licences do not fix a data problem; the readiness gap is closed by governing the estate, not by widening the rollout.
  • Do the foundation first – with the data governed, Copilot delivers what it promises, on information you can actually trust.

The pressure is familiar by now. The announcements are everywhere, the board has seen them, and somewhere on your desk is a proposal to enable Microsoft Copilot across the organisation. Perhaps the licences are already bought. The question has narrowed to how fast.

Here is the part that gets lost in the rush. Copilot is genuinely capable – Microsoft has built a tool that works from the moment you switch it on.

What decides whether it delivers is not the tool. It is the data it is pointed at.

Where that foundation was never made ready, the same pattern shows up: answers that cannot quite be trusted, adoption that never takes and a productivity case that never quite arrives.

That Copilot readiness is a data problem, not a licensing one. As I argued in the companion piece, 'AI readiness is data readiness', an organisation is only as ready for AI as its data foundation is governed. The good news is that it is entirely solvable, and the fix is well understood. The catch is that you cannot buy your way to it by adding more licences.

What “not ready” actually looks like

Copilot brings no knowledge of your business. It reads what it can reach – your files, your mailboxes, your databases – and it inherits, precisely, the permissions already in place. Where those permissions are loose, it surfaces content the reader was never meant to see. Where the data is stale or duplicated, it answers from whichever version looks relevant, in fluent prose, with a confidence the underlying data has not earned.

This is not a rare edge case, and the point is not a criticism of the technology. Microsoft says much the same thing: its own deployment blueprint for Copilot puts remediating oversharing first – ahead of guardrails, ahead of rollout.

Independent studies of enterprise generative AI adoption reach a parallel conclusion: where the returns disappoint, the cause usually lies in the conditions around the model – how the data is governed, and how well the tool is fitted to the work – rather than in the model itself.

Readiness-first is not our idea. It is the vendor’s own sequence.

And in South Africa, the exposure is not only operational. Under POPIA, your organisation remains the responsible party for how personal information is accessed and used – an accountability that does not transfer to a vendor, and certainly not to an AI. An assistant that can retrieve and redistribute personal information across the estate in seconds raises that obligation rather than easing it. Here, readiness is a matter of compliance as much as performance.

Readiness is a programme, not a switch

The instinct, faced with this, is to treat readiness as a quick tidy – clean up a few permissions, delete some old files and proceed. The opposite instinct is just as common: freeze everything until the data is spotless. Neither serves you.

Copilot earns real value well before an estate is perfect, so the goal is narrower than boiling the ocean: govern the data each use case actually touches, before that use case goes live, and sequence the readiness to the rollout.

That still takes deliberate work – understanding what data you hold and where it lives, modernising the platform it sits on, governing who can reach what, and structuring and cleaning the data so that what the AI retrieves is current, correct and permitted.

Microsoft ships stop-gaps – Restricted SharePoint Search and the like – that can hide unsecured content while you catch up, but its own documentation calls them temporary, and no substitute for fixing the permissions underneath. They buy time; they do not do the work.

The sequence matters as much as the steps. Modernise the platform so the data has a sound home; optimise and govern access so that only the right people – and the right AI – can reach it; protect the estate so that what Copilot reads is current, authorised and compliant.

Done in the right order, that work compounds. Done piecemeal, it leaves exactly the gaps an AI will find first.

Readiness is a discipline, in other words – and it is one Ascent delivers as a defined programme.

How Ascent delivers

Ascent’s Data Platform Modernisation is the programme that makes an organisation ready for AI. It begins with a structured assessment of the data estate – platform, integration, governance and access – and turns what is usually a scramble into a sequenced roadmap.

That assessment is the part clients feel first: a clear view of where the estate is exposed, what to remediate and in what order, so the work is prioritised by risk and value rather than guesswork.

From there Ascent modernises the foundation itself: consolidating fragmented data, embedding governance and security into the platform rather than bolting them on afterwards, and putting in place the controls that decide what an AI is allowed to read.

Ascent builds that foundation on Microsoft Fabric. Fabric’s OneLake gives an organisation a single, governed data estate – Microsoft’s own “AI-ready data foundation” – where access, lineage and quality are set once and enforced everywhere the data is used, Copilot included. It is the difference between an AI grounded on a trustworthy source and one guessing across a sprawl nobody has curated.

And because Ascent is a Microsoft Direct CSP, the Copilot and Azure licensing can sit with the same partner that builds the foundation beneath it – one accountable relationship for the licence and the readiness, rather than a tool bought in one place and a foundation neglected in another.

Get it right and Copilot stops being a gamble – the business gets an assistant it can trust, an estate it can defend to the board and the regulator, and a head start that compounds while competitors are still cleaning up.

Modernise, optimise, protect and then switch on.

Share

Editorial contacts

Johan Lamberts
Ascent Technology
(+27) 11 745 1340
johan.lamberts@ascent.co.za