Start free trial
Company News & Events

AI has outgrown the silo

AI is arriving in most organisations from several directions at once, and governance has stayed inside one of them. We are extending what Rencore governs beyond Microsoft 365. The detail comes on 1 October.

Same pattern, different technology.

For thirteen years we have watched organisations adopt Microsoft technology faster than they govern it. SharePoint, then Teams, then Power Platform, then Copilot. Every one of them arrived quicker than the plan to look after it. The result was always the same. Sprawl, oversharing, orphaned sites, unowned apps, rising risk and cost.

None of that was caused by bad decisions. It was caused by adoption outrunning the plan, every time, in almost every organisation we have worked with.

It is happening again. This time it is not one vendor.

What changed

Companies are not adding one AI. They are adding several, through different departments, at different speeds, usually without a single decision anywhere that says so.

The scale of it is now documented. In October 2023, Gartner said that by 2026 more than 80% of enterprises would be using generative AI in production. In 2023 it was under 5%. McKinsey’s 2026 survey found 56% of organisations use AI in three or more parts of the business. And no single AI provider holds more than 40% of enterprise use.

Read together, those numbers say something simple. AI is now in most of the business, it arrives from several places at once, and nobody’s governance was designed for that.

A good deal of it is not even bought. Gartner expects 40% of business applications to have AI agents built in by the end of 2026, up from under 5% in 2025. That AI turns up inside software a company already owns. Nobody chose it, so nobody is governing it.

The question has changed with it. It is no longer how do we govern our AI. It is how do we govern all of it.

Why governance stayed in the silo

Governance usually sits inside the tool. Every provider ships its own admin console, its own audit log, its own permissions model. Each works well for the thing it covers.

None of them covers the others. So every AI a company adds is one more place to govern from, one more set of rules to learn, one more export to line up against the last. The same employee exists separately in each system, and nothing joins them up.

That is structural rather than anyone’s failing. No provider can see inside another provider, and none of them has a reason to build the view that would let you compare.

You cannot govern the whole picture if you can only see one part of it.

Where we are taking Rencore

Governance cannot stay inside one ecosystem when AI does not.

So we are extending what Rencore governs beyond Microsoft 365 and into the wider AI estate. What we have built, and the order the rest of it arrives in, is what we are setting out on 1 October.

What I will say now is that this is not a side project. It is the direction of the company, and it is the first time in thirteen years we have built outside the Microsoft 365 space.

Why now

The honest answer is that we have seen where this ends.

Governance that arrives after the sprawl is a different job to governance that arrives with it. The first is a clean-up. It is measured in years and it comes out of somebody’s budget. The second is a habit, and once it is running it costs very little. We watched that difference play out across Microsoft 365 for a decade. The organisations that started early had a very different five years to the ones that started late.

AI has the same shape and it moves faster. Most companies are still early enough for this to be the second job rather than the first. That window closes quietly, without anyone announcing it.

What this does not change

This is the part to be clearest about, because it is the easiest thing to misread.

Rencore governs the Microsoft estate, and is extending to govern the AI next to it. Nothing about the Microsoft side changes.

Microsoft 365, SharePoint, Teams, Power Platform, Microsoft 365 Copilot and Copilot Studio all continue exactly as they are, with the same investment behind them. We govern more than 2.5 million users across the Microsoft estate today and we intend to govern a great many more. If you bought Rencore for Microsoft 365 governance, you have lost nothing and gained an option.

We are adding to what we do. We are not moving away from it.

What we are not claiming

Three things, said now so that nobody has to ask.

We are not first, and we are not the only vendor in AI governance. It is an established category with real competitors, several of whom we respect and some of whom we expect to work alongside.

We will not be able to govern every AI on day one, and we will not pretend otherwise on 1 October. There is a sequence. It is deliberate, and it follows where enterprise usage actually sits rather than where we would prefer to start.

And we have no customer stories yet, because the preview has not run. Once customers have used it, we will say what they found. Until then we would rather show you the roadmap than borrow somebody else’s proof.

I would rather set all of that out plainly now than have it corrected for me later.

What makes this different

Most AI governance looks at the model. Guardrails at runtime, policies on the agent, controls on the prompt. That work matters, and it governs what an AI says.

It does nothing about an over-shared site, a team nobody owns, or a permission that should have been removed two years ago. That is where the exposure actually comes from, and it is exactly what an AI reaches into the moment you switch it on.

We govern what AI can reach. Who owns something, who can get to it, where it has been shared outside the company, and how it is classified. We have been doing that work in Microsoft 365 for thirteen years. The AI estate is the same problem in a new place, and that is the work we are extending.

Runtime guardrails govern what AI says. We govern what it can reach.

If you already use Rencore

Nothing you do changes today.

What changes is the question worth asking internally. Somebody in your organisation is running AI that appears nowhere in your governance. Usually it is not one person and it is not one tool. Finding out what is actually in use, and who is accountable for it, is worth doing whether or not you ever buy another thing from us.

We have built an estate review for that conversation, and our team will walk through it with you. It takes thirty minutes and it is not a product demonstration. If it tells you that Microsoft 365 Copilot is the only AI in play, then the Microsoft governance conversation is still the right one and this announcement is early for you. We would rather say that than sell you something you do not need yet.

Where this goes

See it all. Connect the dots. Govern it all. In that order, because it is also the order we are building in.

See it all, the inventory. Every AI user, project, session, setting and unit of spend, across every AI a company runs, in one place.

Connect the dots, the join. The same person becomes one person rather than four separate accounts in four separate systems.

Govern it all, the controls. The policies, automation and access reviews our customers already run, applied to AI as well.

Gartner has cited Rencore across nine documents published in 2026. That recognition is for work we have already done, in the estate we already govern. What it says about this announcement is that we are not arriving in this market as strangers, and that the pace of our development is going up rather than down.

Your company is using more than one AI. There is no good reason to govern only one of them. On 1 October we will show you what we have built about it.

The Multi-AI Era: the vision and the roadmap

Webinar, 1 October 2026, 16:00 CET. I will cover where Rencore is going and why. Tiina takes the product half: what we have built, what comes next, and the order it arrives in.

Register for the webinar

Sources

  1. Gartner press release, 11 October 2023. “Gartner Says More Than 80% of Enterprises Will Have Used Generative AI APIs or Deployed Generative AI-Enabled Applications by 2026.” Used here for: more than 80% of enterprises using generative AI in production by 2026, up from under 5% in 2023.
  2. McKinsey & Company, “The State of AI in 2026”. Published 25 August 2026. 1,719 respondents across 97 countries, fieldwork May to June 2026. Used here for: 56% of organisations using AI in three or more parts of the business.
  3. Menlo Ventures, “The State of Generative AI in the Enterprise”. Published November 2025. 495 US enterprise AI decision makers, surveyed 7 to 25 November 2025. Used here for: no single AI provider holding more than 40% of enterprise use. Anthropic 40%, OpenAI 27%, Google 21%, all others 12%, measured by large language model API usage.
  4. Gartner press release, 26 August 2025. “Gartner Predicts 40% of Enterprise Applications Will Feature Task-Specific AI Agents by End of 2026.” Used here for: 40% of business applications having AI agents built in by the end of 2026, up from under 5% in 2025.

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organisation and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Common questions on this

How do I find out which AI tools my organisation is actually using?
Start with the three places it shows up rather than with a survey, because the people using an unsanctioned tool are the least likely to answer one. Expense claims and corporate cards show the subscriptions bought outside procurement, identity logs show which external applications staff have signed into with their work account, and network or proxy data shows the domains being reached. The answer is usually wider than IT expects, and a good deal of it is not bought at all: it arrives switched on inside software the company already owns. Treat the result as a live inventory rather than a one-off audit, because the list changes every month.
Does Microsoft Purview or Entra already govern the AI we use outside Microsoft 365?
Partly, and it is worth being precise about where the line falls. Purview covers data classification, labelling and data loss prevention across Microsoft 365, and its reach into third-party services depends on connectors you configure. Entra governs identity and access for applications federated to it, so an AI tool signed into with a work account is visible there, while one paid for on a personal card is not. Neither builds the single inventory across providers that tells you which AI projects exist, who owns them, what they cost and what content they can reach. That cross-provider view is the gap Rencore is extending to cover, alongside the Microsoft controls rather than in place of them.
What is the difference between runtime AI guardrails and governing what AI can reach?
Runtime guardrails act on the conversation. They filter prompts, constrain what a model may answer and log what was said, which is the right control for misuse and for the tone of a response. Governing what AI can reach acts on the content underneath: who owns a site, who has permission to open it, whether it has been shared outside the company and how it is classified. An assistant with perfect guardrails will still surface an over-shared document to whoever asks, because the permission was already wrong before the AI arrived. The two are complementary, and most organisations have bought the first and not the second.
Does this change anything for existing customers governing Microsoft 365?
No. Microsoft 365, SharePoint, Teams, Power Platform, Microsoft 365 Copilot and Copilot Studio continue exactly as they are, with the same investment behind them, and Rencore governs more than 2.5 million users across the Microsoft estate today. Nothing that works now stops working, no migration is required and no existing entitlement changes. What is being added is the option to bring the AI sitting next to that estate into the same view, for organisations that turn out to need it. If Microsoft 365 Copilot is the only AI in play, the Microsoft governance conversation is still the right one.
Who should own AI governance when AI arrives through several departments?
Ownership works best split in two, because one team cannot hold both halves. A central function owns the policy, the inventory and the standard that says what good looks like, and it is usually the same group that already owns collaboration or data governance. The department that adopted the tool owns the individual object: the project, its members, its data and the decision about whether it is still needed. That split is what stops governance becoming a queue of tickets for two administrators, and it is the reason a central team trying to own every AI decision is the pattern that reliably stalls.
What happens to an AI project when the person who set it up leaves?
In most organisations, nothing, and that is the problem. The project keeps its data, its connections to company content and often its cost, while the only person who could say whether it is still needed has gone. It becomes the AI equivalent of the orphaned SharePoint site, except that it can also reach into content and answer questions about it. The fix is the same one that works for collaboration workspaces: every project carries a named owner, ownership is re-confirmed on a schedule, and a leaver triggers a decision to reassign, archive or delete rather than a silent handover to nobody.

Last updated 22 September 2026

Related articles

Rencore newsletter

Subscribe to our newsletter

Get the latest Microsoft 365 governance insights delivered to your inbox.

Loading form