64% of Copilot Licensees Stopped Using It. What They Switched To Is Worse for Your Data.
The Copilot adoption crisis and the shadow AI explosion are not two separate problems. They are one compounding risk, and most organizations have no playbook for it.
MIT research shows that 95% of AI initiatives fail to deliver their intended value. Not because the technology breaks. Because the readiness layer underneath it was never built. I wrote an entire book about this pattern. I did not expect Microsoft Copilot to become the starkest example of it.
[ 01 ] The proof pointTools Don't Fail. Readiness Fails. Copilot Is the Proof.
The data is now impossible to ignore. Only 3.3% of Microsoft 365 users pay for Copilot (Windows Central / The Register, February 2026). Of those who do have licenses, 64% are not actively using the tool (Redress Compliance, 2026). When asked why they stopped, 44.2% of lapsed users cited "distrust of answers." That distrust shows up in the numbers: Recon Analytics tracked Copilot's accuracy Net Promoter Score falling from -3.5 in July 2025 to -24.1 by September 2025, based on a survey of over 150,000 respondents (Recon Analytics, U.S. AI Survey, 2025-2026). Negative. And accelerating.
This is not a rollout timing problem. It is a readiness problem, and it is spawning a second, larger problem that most IT managers have not connected yet.
[ 02 ] The compounding riskThe Adoption Crisis Meets the Shadow AI Explosion
Microsoft's response has been to double down on pricing. New Copilot Business bundles launch July 1: Business Standard with Copilot at $22 per user per month and Business Premium with Copilot at $32 per user per month. Microsoft itself appears to be hedging. As of May 28, Claude Opus is now available as a model choice inside Copilot. When the vendor starts offering a competitor's engine inside its own product, that tells you something about confidence in the original.
The employees who stopped using Copilot did not stop using AI. They moved to tools the tenant cannot see.
Shadow AI usage on corporate devices jumped from 15% to 45% in just 12 months (Verizon, Data Breach Investigations Report, 2026). ChatGPT is now found in 95% of managed environments (DKBinnovative, "AI Tool Discovery Report," 2026). Claude users are the most likely to describe AI as "essential" to their work; 68% say so, despite Claude holding only a 21% workplace footprint (PYMNTS, 2026). The most committed AI users in your organization are on the tool your tenant has the least visibility into.
That compounds quickly. The same employees who found Copilot unreliable are the ones most motivated to find alternatives. The alternatives they found operate in a governance blind spot.
[ 03 ] The boundary problemInside the Tenant vs. Outside the Tenant
Your Microsoft tenant is a boundary. Copilot lives inside it. Your Entra ID policies apply. Your data loss prevention rules apply. Your audit logs capture what happens. Copilot's answers might disappoint your users, but at least you can see what it is doing.
Claude, ChatGPT, and Gemini live outside that boundary. When an employee pastes a client proposal into ChatGPT in a browser tab, no DLP policy intercepts that data. No audit log records what was shared. No retention policy governs what the model provider does with the input. Microsoft Defender for Endpoint can see that the employee visited chat.openai.com. It cannot see what they typed into it.
[ 04 ] The financial realityThe Cost of Ignoring Both
IBM's 2025 Cost of a Data Breach Report found that shadow AI added $670,000 to the average breach cost. That is not the total breach cost. That is the premium added specifically because unauthorized AI tools were involved.
On the other side of the ledger, BCG found that 74% of companies struggle to achieve and scale value from their AI investments (Boston Consulting Group, "AI Adoption in 2024," October 2024). Copilot is no exception. You are paying for a tool most of your people do not use, while absorbing unquantified risk from the tools they actually chose.
Gartner projects $492 million in AI governance spending in 2026. Large enterprises are waking up. But for the 15-to-200-employee companies that make up the SMB market, governance budgets like that do not exist. Only 12% of SMBs have a dedicated AI strategy (Forrester, 2026). The other 88% are making do with whatever their MSP covers. Nobody has named an owner. Nobody has written a policy. The gap stays open.
[ 05 ] The structural gapThe MSP Responsibility Gap
According to Channel Insider's 2026 MSP AI Governance Readiness Survey, 94% of MSPs say they are committed to helping clients with AI governance. Only 43% can actually deliver on that commitment.
The standard MSP agreement covers the Microsoft stack: Exchange, SharePoint, Entra ID, Defender, endpoint management. It does not cover the AI layer. This is the structural gap at the center of the problem. The AI layer consists of the tools employees chose for themselves, running on corporate devices, processing corporate data. All of it falls outside the managed service agreement.
Who is responsible for governing those tools? Right now, the honest answer in most organizations is: nobody.
[ 06 ] The action planReadiness First. Policy Second. Tools Last.
Tool decisions come last in the READY Framework. Not first. Removing Copilot or banning ChatGPT are both tool decisions, and they skip the steps that make any tool decision stick.
The sequence that works starts with three questions.
What AI tools are your people actually using right now? Not what your IT policy says they should use. What they are actually using. Check browser activity in Defender for Endpoint. Ask your team directly. You will be surprised how many will tell you if you ask without judgment.
What data does each of those tools touch? For Copilot, this is straightforward; it can access whatever the user can access in Microsoft 365. For Claude, ChatGPT, and Gemini, the answer depends on what your employees are pasting, uploading, or typing into those tools. Map it.
Who in your organization owns the answer to those first two questions? If the answer is "nobody," you have found your first action item.
Once you have those answers, you have a readiness baseline. From there: readiness first, then policy, then tool decisions. Audit what is in use. Decide what is permitted and what is not. Only then evaluate whether Copilot, or any other AI tool, belongs in your stack.
Start with the readiness layer underneath the tool. Not the tool itself.
Start with readiness,
not tools.
The [AI] within REACH AI Readiness Assessment maps what your people are actually using, flags the gaps your tenant does not cover, and gives you a prioritized action plan before your next Copilot renewal.
