Should you ban Copilot on Friday afternoons?

No AI on Fridays

You didn’t roll out Microsoft Copilot so your team could second-guess it. The whole pitch is speed: draft the email, summarize the meeting, answer the client in less time than it takes to write the first line yourself.

That’s exactly what worries Gartner.

Copilot’s output always looks finished

At Gartner’s Security & Risk Management Summit in Sydney in March 2026, analyst Dennis Xu half-joked that businesses should ban Copilot on Friday afternoons. His reasoning wasn’t about the tool. It was about the person using it. By the end of the week, most people are tired, and tired people stop double-checking things that look done.

Xu’s talk covered five security risks tied to Microsoft 365 Copilot. The one that led to the Friday joke was about tone, not accuracy. Copilot can produce a response that’s factually correct and still comes across as blunt or offensive, the kind of thing that’s fine in a quick message to a coworker and a real problem in an email to a client. His actual recommendation wasn’t “ban Fridays.” It was to review Copilot’s output before it goes anywhere external, and make that review a habit instead of an afterthought.

That distinction matters more than the joke does.

Here’s the part that should worry a business owner

An employee misjudging tone in a rushed email is an old risk. People have always sent messages they later regretted. What changes with Copilot is volume and speed. One employee can generate ten client-facing drafts in the time it used to take to write one, and every one of them can go out the door with nobody but the AI having “written” it.

Now put that on a Friday afternoon, when that same employee is least likely to slow down and read it twice.

This isn’t a productivity problem. It’s a reputation problem. A poorly worded email from a stressed employee is unfortunate. A poorly worded email that went out because nobody had a rule requiring a second look at AI-generated content is a process failure, and it’s the kind of thing a five-minute policy conversation prevents.

What to do about it

Banning Copilot on Fridays isn’t the answer, and Gartner wasn’t seriously proposing it. The answer is a review habit that applies every day, not just the day everyone’s running on fumes.

Set a simple rule: anything Copilot drafts that goes to a client, a vendor, or anyone outside the company gets read by a person before it’s sent. Not skimmed, read. That’s not a knock on the tool. It’s the same standard you’d hold a new hire to before they’re trusted to send email on your company’s behalf unsupervised.

Microsoft builds content filters into Copilot that catch some of this before it reaches an inbox. Turning those on is worth doing, but a filter only catches what it’s tuned to catch. It won’t replace a person deciding whether a message actually sounds like your business.

If you’re rolling Copilot out across your team, put the guideline in writing: what needs a human review before it goes out, and who owns that review. Without it, you’re relying on everyone individually deciding to slow down on a Friday afternoon. History says that doesn’t hold up.

Gartner’s joke landed because there’s a kernel of truth in it. Tired people trust polished output more than they should. But the fix isn’t picking a day to distrust Copilot. It’s building the habit of checking anything that leaves your business under your name, on a Tuesday morning as much as a Friday afternoon.

If you want help setting up simple guardrails around how your team uses Copilot, we can help you put something in place that doesn’t rely on everyone remembering to be careful at 4:30 on a Friday.

Your AI tools are making decisions you can’t explain

AI is genuinely useful. I’m not here to argue against that. Your team is using it to draft emails, summarize reports, and knock out tasks that used to take hours. That’s real value.

But here’s what’s starting to happen that most business owners haven’t thought through yet: the AI isn’t just helping. It’s acting. And in a lot of cases, nobody set clear rules for where it’s allowed to go.

What “shadow AI” actually means for your business

Shadow AI isn’t some advanced threat. It’s what you get when employees start using AI tools on their own, without IT involvement, without approval, and without any visibility into what those tools are doing or accessing. Think ChatGPT plugins connected to your email, AI agents built into project management tools, or workflow automation that touches your CRM.

Each one of those tools is operating with some level of permission inside your systems. And unless someone mapped that out deliberately, you probably don’t have a full picture of where AI is touching your data.

Microsoft’s Cyber Pulse report, published in March 2026, found that 62% of UK businesses had already deployed AI agents within their operations — up 22% year over year. More importantly, 84% of business leaders acknowledged that unauthorized or poorly governed AI agents are a serious security concern. They know the risk. The gap is visibility.

That gap matters because AI agents don’t just respond. They take action. They can access data, send communications, trigger workflows, and update records — all without a person signing off on each step.

The question you need to be able to answer

If a customer calls and says “why did I receive that email?” – can you tell them?

If a vendor asks why certain data showed up somewhere unexpected – can you trace it back?

If there’s a compliance audit – can you show which decisions involved AI and which didn’t?

These aren’t hypothetical edge cases. They’re the kinds of questions that come up in normal business operations, and they get harder to answer when AI is woven into your processes without any documentation, logging, or governance around it.

The accountability problem is subtle but real. When a person makes a decision, responsibility is clear. When an AI-assisted process contributes to that decision and you’re not sure which tool did what – ownership gets murky fast.

What to actually do about it

The starting point is an inventory. You need to know what AI tools are running in your environment, what permissions they’ve been granted, and what data they can touch. Most businesses have never done this, because the tools showed up one at a time and nobody thought to ask the question at scale.

From there, the approach Microsoft’s security team recommends is treating AI agents like any other identity, the same way you’d manage a user account. That means applying least-privilege access (the agent can only access what it actually needs), defining what actions it’s allowed to take, and logging what it does so you have an audit trail. That’s all part of what a sound cybersecurity posture looks like today.

None of that requires shutting down the AI tools your team relies on. It requires knowing they’re there and putting the same basic controls around them that you’d put around anything else that accesses your systems.

If you’re not sure where to start, that’s a conversation worth having with your IT provider. Xentric can walk through your environment and help you get a clear picture of where AI is operating and whether the controls around it are where they need to be. Reach out if you’d like to schedule a quick call.

Could you shut off your AI if you had to?

There’s a good chance AI is already doing real work inside your business. It’s drafting emails, summarizing documents, suggesting replies in your help desk, and crunching numbers in tools your team opens every day. Most of it got switched on fast, often without anyone deciding it should be.

Here’s a question almost nobody asks until it’s too late: if one of those tools did something it shouldn’t, how quickly could you stop it?

Most owners can’t answer that. Neither can the people whose job is to know.

ISACA, a professional association for IT audit and security, ran a survey of digital trust professionals in early 2026 and asked exactly this. Almost three in five (59%) said they didn’t know how fast their organization could halt an AI system during a security incident. Only about one in five (21%) said they could do it inside half an hour. These are the people who audit and secure this stuff for a living. If they’re unsure, the business owner relying on them is in worse shape.

AI isn’t one app with an off switch

When people picture AI at work, they picture someone typing into ChatGPT. That’s the small version. The bigger version is the AI baked into the software you already pay for: Microsoft 365 Copilot, your CRM, your accounting platform, your phone system, your support inbox, and increasingly the AI built into the web browsers your team uses. You didn’t install it as a project. It arrived as a feature update and started touching client data, billing, and decisions.

That’s the part that matters for a business. A consumer playing with a chatbot has nothing at stake. You have client files, regulated data, and money moving through these systems. When the AI inside one of them is wrong, it’s wrong about your business, in front of your clients, on your liability.

The problem isn’t AI. It’s that nobody’s managing it.

Think of it like a new employee who showed up without being hired. Nobody onboarded them. They have keys to the building and a login to your client files. They make decisions all day, and they don’t report to anyone. You’d never run your business that way with a person. A lot of companies are running it that way with AI.

The research backs this up. A third of organizations (33%) don’t even require staff to disclose when they’ve used AI in their work, so leadership has no clear picture of where it’s running. One in five (20%) don’t know who would be accountable if an AI tool caused harm, and only 38% point to an owner or executive. When responsibility is fuzzy, response is slow. The thing you needed to stop in ten minutes runs for an hour while people figure out whose problem it is.

Then there’s the part after the mess. Fewer than half of those surveyed were confident they could investigate and explain a serious AI incident to leadership or a regulator. That’s the call you don’t want to make to a client, an insurer, or your attorney with nothing but a shrug.

The survey that produced these numbers was tied to the EU AI Act, which is European law and doesn’t apply to a business here in the Valley. But you don’t need a European regulator to care about this. Your clients are starting to ask how you handle their data with AI. Cyber insurance applications are starting to ask too. And if your firm touches health records or California consumer data, you already have rules to answer to. The regulator changes by zip code. The exposure doesn’t.

Treat it like any other critical system

This is a governance problem, not a software problem. Governance is a heavy word for a simple idea: clear rules, real visibility, and a name attached to who’s in charge.

Three things get you most of the way there. Find out which tools in your business are using AI, including the ones that turned it on through an update. Assign an owner for each one, a real person responsible for how it’s used and what happens when it misbehaves. And confirm you can actually pause or shut each one off, and that someone knows how.

None of that slows your business down. It’s the same oversight you already apply to your network, your backups, and your financials. AI just got added to the list of things that can hurt you, and it skipped the part where you set it up properly.

So, back to the question. If an AI tool in your business went sideways this afternoon, could you find it, switch it off, and explain what happened? If you’re not sure, mapping that out is exactly the kind of work we can help you do. Get in touch and we’ll start with where AI is running in your business today.