M-Files warns of "Copilot liability zone" in AI governance push
M-Files, the document management vendor, has launched what it calls an AI Readiness Model, a framework designed to assess whether organisations have the information foundations needed to deploy AI securely. The announcement comes with a warning: businesses racing to adopt AI-powered assistants and automation tools may be unwittingly exposing sensitive internal data by layering those tools over years of poorly governed content.
The company argues that the core problem is not AI itself, but the state of the information on which AI operates. Outdated folder permissions, inconsistent metadata, and content that has been overshared long before AI entered the picture can all be surfaced by AI tools in ways that were never anticipated, and may never have been noticed without them.
The "Copilot liability zone"
M-Files uses the phrase "Copilot liability zone" to describe the specific risk that arises when AI is deployed on top of content governed only by folder-level permissions rather than document-level controls. In normal operations, overshared content may sit dormant. When an AI assistant begins querying that content on behalf of users, it can return information those users were technically permitted to see but were never intended to access.
Tony Grout, chief product and technology officer at M-Files, put the issue plainly: "Too many organisations still believe buying AI software makes them AI-ready. It doesn't. Businesses have an information problem; AI simply exposes the weaknesses that already exist in how information is managed."
The AI Readiness Model benchmarks maturity across five areas: strategy, metadata, governance, process automation, and AI activation. The intent is to move the assessment conversation beyond whether an organisation has deployed AI, and towards whether the information underpinning those deployments is accurate, governed, and auditable.
Market context and regulatory pressure
M-Files is not alone in making this argument. A growing number of enterprise content management and data governance vendors, including OpenText, Hyland, and a range of newer AI-native players, are positioning information governance as a prerequisite for safe AI deployment rather than an afterthought. The framing reflects a broader shift: as AI moves from pilot to production, the blast radius of a badly governed content repository expands accordingly.
From a regulatory standpoint, the stakes are material. Under the UK GDPR and its post-Brexit incarnation, unlawful disclosure of personal data, even if accidental and mediated by an AI assistant, can still trigger enforcement action. The EU AI Act introduces additional obligations for high-risk AI systems, including requirements for data governance and record-keeping that map closely onto what M-Files describes as information readiness. For regulated sectors, including financial services under DORA and healthcare under sector-specific data handling rules, the compliance exposure is correspondingly sharper.
What comes next
Grout argues that the organisations best placed to realise AI's productivity gains will be those that have invested in trusted information first: "Information readiness is becoming the foundation of AI readiness, and that's what will separate AI leaders from AI failures over the coming years."
M-Files counts more than 6,000 customers across over 100 countries and positions its platform as native to Microsoft 365, which gives the Copilot liability zone framing a directly commercial resonance: many of those customers will be evaluating or already running Microsoft 365 Copilot deployments.
The AI Readiness Model is available now, though M-Files did not disclose pricing, the number of assessments conducted to date, or any customer case studies in its release. Independent validation of the framework's benchmarks has not yet been published.