AI readiness · governance, IT and Microsoft 365 · 2026
How ready is your business for AI, really?
A CISSP-led assessment of how AI reaches your data and your decisions, across three layers: the governance you can evidence, the AI already running in your IT estate, and the Microsoft 365 controls underneath it. For firms in Canada and the United States.
- Governance evidence: an approved-tool register, named owners and review of AI-assisted decisions
- AI inventory and vendor or agent risk, using the tenant, endpoint, browser and network signals available in scope; coverage gaps recorded
- Microsoft 365 controls: Purview labeling, data posture, Entra access and audit evidence, with findings mapped to NIST AI RMF and ISO/IEC 42001
Free 60-minute scoping call, then a fixed fee quoted in writing before any work starts. Delivered remotely to Canadian and US organizations. CISSP and MSc Computer Science leadership; a senior consultant aims to reply within one business day.
Twelve questions across governance, the AI running in your estate, and your Microsoft 365 controls. You see the score before we ask for an email.
Why teams book the assessment
CISSP + MSc Comp Sci
Security and AI leadership on the engagement
Since 2012
Supporting Canadian businesses
Canada and the US
Delivered remotely, governance through to tenant configuration
NIST AI RMF
Findings mapped to ISO/IEC 42001
Free, no email until you see the score
Score yourself first
Free self-check
Twelve questions about governance, your IT estate and Microsoft 365. Your answers produce a weighted score, ranked gaps and a 30/60/90-day plan.
Paid assessment
We review the records and systems named in your statement of work and record evidence gaps. A free 60-minute scoping call comes first, with the fixed fee and deliverables agreed in writing.
Tell us about your business
Three quick questions to size your report and pick the right regulatory set. Not scored.
Who it is for
Book it when AI is real on your roadmap
The assessment fits organizations with between 10 and 250 staff. Microsoft 365 is where we go deepest, and it is not the boundary. These are the four decision points where it earns its fee.
Pricing a Copilot rollout
You are budgeting licences and want the labeling and permission work costed before the seats are committed.
Shadow AI is already happening
Staff are using ChatGPT, Claude or DeepSeek on personal accounts and you have no record of what has left the tenant.
A client or insurer asked
A security questionnaire wants your AI controls in writing and may require evidence beyond a vendor self-attestation.
You operate across the border
Canadian and US obligations differ. We work from one technical control baseline and map the jurisdiction-specific requirements separately.
How it works
Three steps, and the report is yours
The scoping call is free and the fee is fixed in writing before any work begins. What you decide afterward is your call.
1. Free 60-minute scoping call
We confirm tenant size, jurisdiction, which AI tools are in play, and what your licences already cover. You get the fixed-fee quote in writing before anything starts.
2. Technical review
Read-only review across the three evidence sets fixed in the statement of work. Where a vendor, device or workflow does not expose usable evidence, we record that as a coverage gap rather than treating absence of evidence as absence of AI. Where tenant signals already exist we read them rather than surveying you. Where discovery was never switched on, the report says so and specifies what has to be enabled before useful history can be collected.
3. Report and walkthrough
A board-ready readout with the ranked findings, the remediation roadmap, a licensing recommendation and a go/no-go call. Your written quote sets the delivery schedule after scoping.
What we assess
Three layers, because AI does not respect your org chart
A policy review and a Microsoft 365 tenant scan answer different questions. Neither tells you about the AI your accounting software switched on last quarter, or who signed off the decision it made. We review three evidence sets: governance and decision records made available in scope, AI-use and integration evidence from the systems, admin portals and records named in the statement of work, and Microsoft 365 controls. We score what can be evidenced and record the coverage gaps separately.
Governance and accountability
Who approves an AI tool, what the approved-tool register contains, how exceptions are granted, and what happens when someone uses something that is not on the list. We check that the policy names a decision-maker rather than a department, because an unowned policy is not a control.
AI-assisted decisions and human review
Where AI already touches decisions about people, money or safety, and who reviews the output before it counts. This is where governance becomes testable: who reviews the output, who can override it, and what gets recorded.
Vendor and third-party AI
The AI features your existing vendors switched on inside software you already pay for, and what their terms say about your data. AI can arrive inside software you already license without a separate AI purchase, so it may never appear in a dedicated AI procurement record.
AI inventory and shadow-AI discovery
Which AI tools the in-scope tenant, endpoint, browser and network signals show your people using, licensed and unlicensed. Contractor and unmanaged-device activity is included only where an instrumented signal path can observe it, and the report records the coverage gaps separately. Microsoft Purview discovers browser activity against sites categorised as Generative AI in the Defender for Cloud Apps catalog, a published list that includes chatgpt.com, claude.ai, gemini.google.com, copilot.microsoft.com and deepseek.com. We check whether that discovery is switched on at all, and we say where uninstrumented use stays invisible.
Agents, connectors and integrations
The agents, connectors and integrations wired into your systems, each with a named owner and scoped permissions, plus any AI-generated scripts running unreviewed. Microsoft creates an Entra Agent ID for new Copilot Studio agents created after the July 2026 rollout and attaches connector permissions when the agent is published, while older agents may still run on app registrations until they are migrated. We inventory both forms.
Microsoft 365 controls and evidence
Where Microsoft 365 decides the outcome, we go deep: whether a usable Purview label set exists and whether auto-labeling carries it, Data Security Posture Management (DSPM) and the oversharing risk assessments, Entra roles and Conditional Access scoped to AI applications, and whether prompts and responses are audited, retained and searchable. This is where Microsoft 365 configuration can decide the outcome.
Where the controls differ by AI tool
Your AI controls are not the same on every tool
Microsoft Purview governs Microsoft 365 Copilot and third-party AI sites through different mechanisms, and the difference decides where your exposure sits. For third-party AI sites reached through a browser, Microsoft's own documentation lists sensitivity labels and label-free encryption as unsupported. Classification, data loss prevention, auditing and insider risk are supported, and eDiscovery of prompts and responses is limited to Edge and the four named apps described below. The controls you rely on inside Copilot are a different set from the controls available when someone opens ChatGPT in a browser tab.
Claude is the clearest example of why the tool name is not the unit of analysis. Browser activity on claude.ai runs through the supported-site path. Claude Enterprise is governed on a separate connector-based path. The Anthropic Claude connector, which Microsoft lists as in preview, uses Anthropic's Compliance API to pull activity and chat data into Purview. On that path Purview supports auditing, classification, insider risk and eDiscovery, while sensitivity labels, label-free encryption and data loss prevention are unsupported. Two deployments of the same vendor, two different control sets. Owning Purview is not the same as having this mapped, so we check which Claude path you actually use before we tell you what covers it.
The coverage narrows again further down. On the browser-based path, Microsoft restricts retention, eDiscovery and communication compliance to the Edge browser and to four named apps: ChatGPT, Microsoft's consumer Chat, Google Gemini and DeepSeek. Separate network data security integrations can capture and retain AI interactions outside that path, with their own licensing and prerequisites.
There are also prerequisites that are easy to miss during scoping. Most of the third-party AI capabilities need the Purview browser extension deployed and devices onboarded to Purview, and Microsoft documents that managing these AI interactions requires pay-as-you-go billing enabled on the tenant. Endpoint policies that warn or block a paste into an AI site need Windows or macOS devices onboarded first, and they sit behind a Purview licence tier rather than being included everywhere. Scoping confirms what your existing licences already cover, and we say so when the answer is that you own what you need already.
Canada and the United States
Nobody is going to hand you the rulebook
Neither Canada nor the United States has a single comprehensive federal AI statute. The rules that bind you still arrive through privacy, sector, state and provincial law. An inventory, a classification baseline, scoped access and logs are useful readiness evidence in both, and they do not replace the duties that apply to you specifically. During scoping we identify the regulatory and framework set proposed for the engagement, and the statement of work names the specific frameworks we will map technical findings to. Your legal counsel determines which legal duties actually apply.
Privacy law carries most of Canada's AI load
The Artificial Intelligence and Data Act (AIDA) was left unfinished when the 44th Parliament's first session ended on 6 January 2025. Canada's AI for All strategy, launched 4 June 2026, did not propose an omnibus AI statute and says the government will modernize privacy and online-safety laws instead. Obligations keep arriving through the laws that apply to your organization and your data: the Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable, Quebec's private-sector law as amended by Law 25, the Alberta and BC Personal Information Protection Acts (PIPA), and health privacy statutes such as Ontario’s Personal Health Information Protection Act (PHIPA). Bill C-36 was introduced 15 June 2026 and remains before Parliament.
State by state, already live
The states did not wait. Texas TRAIGA and Illinois HB 3773 took effect 1 January 2026. Colorado SB 26-189, signed 14 May 2026 and effective 1 January 2027, covers automated decision-making in consequential decisions and asks for more than disclosure: developer documentation, retained records, consumer notice, correction rights, and meaningful human review in specified cases. The federal framework of 20 March 2026 asks Congress to preempt state AI laws that impose undue burdens. It is a recommendation to Congress, not itself a preemption rule, so we assess the state laws that actually apply to your organization.
Voluntary, and useful anyway
AI RMF 1.0 carries no statutory mandate in either country. We use its Govern, Map, Measure and Manage functions to organise findings in a consistent shape that crosswalks to whatever framework your counterparty asks about next.
The certifiable one
Published in December 2023, ISO/IEC 42001 was the first international AI management system standard. Certification applies to the AI management system within its defined certification scope, covering policy, governance, measurement and continual improvement. This assessment contributes technical evidence toward that program rather than standing in for it.
Why it matters now
The exposure is already in the building
Bring-your-own AI is already common among people who use AI at work. Microsoft's 2024 Work Trend Index found that 78% of AI users use tools their employers did not provide, rising to 80% at small and mid-sized companies.
Microsoft and LinkedIn, 2024 Work Trend Index
78% of AI users bring their own tools
Surveyed across 31,000 knowledge workers in 31 markets, rising to 80% at small and mid-sized companies. That usage sits outside your licence count, and whether it is logged at all depends on the browser, endpoint and network controls you have actually deployed.
Read moreCBC News, 2025
DeepSeek is restricted on Canadian federal devices
Shared Services Canada restricted DeepSeek on the government mobile devices it manages, and the federal chief information officer recommended that other departments and agencies restrict it on government devices, citing the collection and retention of sensitive personal information. Reported by CBC News. Microsoft Purview lists deepseek.com among its supported AI sites, so a tenant with the required controls deployed can detect the usage and apply a data-loss policy. Retaining DeepSeek prompts and responses is documented for the Edge browser and needs a Purview collection and retention policy. The assessment tells you whether yours currently can.
Read moreMicrosoft Purview documentation, June 2026
Sensitivity labels are not a browser-AI control
For third-party AI sites reached in a browser, Microsoft lists sensitivity labels as not supported, with classification, DLP, auditing and eDiscovery supported instead. Endpoint, browser and network controls are the path that can act on labelled content headed to those tools, and each has its own prerequisites.
Read moreMicrosoft Entra Agent ID, 2026
Agents now carry their own identity
Microsoft creates an Entra Agent ID for new Copilot Studio agents created after the July 2026 rollout, attaching connector permissions when the agent is published, and Entra entitlement management can govern agent identities through access packages, which Microsoft lists as preview. Microsoft licenses that scenario through specific Agent 365 and Microsoft 365 or Entra combinations rather than one product family, so we confirm your tenant's exact entitlement during scoping. Agents created before the rollout may still run on app registrations until migrated.
Read more

CISSP-led, with graduate research in AI
Mike Pearlstein, CISSP, MSc Computer Science, Founder of Fusion Computing
Microsoft's documentation tells you what each control path can support. It does not tell you which path your staff are actually using, or how your tenant is configured today. Microsoft 365 Copilot honours the sensitivity labels already on your content. Third-party AI sites in a browser do not support sensitivity labels as an interaction control, but Endpoint DLP can still use a file's label to block an upload to one. The paths are different, not independent, and knowing which one a finding sits on is the difference between a control that fires and a control that does not. Mike's position is that the assessment exists to map the published limits onto the tenant you actually run, and to say where the coverage stops.
Frequently asked questions
An AI readiness assessment is a review of the controls that decide how AI reaches an organization's data and its decisions, scored against what can be evidenced rather than what is intended. Fusion Computing's version covers three layers: governance and accountability, including the approved-tool register and who reviews AI-assisted decisions; the AI already running in your IT estate, including vendor-enabled features, agents and shadow AI where an in-scope signal path can observe it; and the Microsoft 365 controls underneath, including Purview labeling, data security posture, Entra identity and audit evidence. It is delivered to firms in Canada and the United States, and findings map to the NIST AI Risk Management Framework and ISO/IEC 42001.
Microsoft 365 Copilot and Copilot Studio agents, plus the third-party tools your staff use in a browser: ChatGPT, Anthropic Claude, Google Gemini, DeepSeek and the wider set of AI sites Microsoft Purview publishes support for. Enterprise editions of ChatGPT and Claude also have separate connector-based coverage in Purview. Browser activity can still appear on the supported-site path, while the enterprise connector gives Purview the additional interaction data Microsoft documents for those products. Claude Enterprise in particular is governed through the Anthropic Claude connector, which Microsoft currently lists as in preview and which pulls activity and chat data into Purview from Anthropic's Compliance API.
No. This is a common misunderstanding we correct. For third-party AI sites reached in a browser, Microsoft's documentation lists sensitivity labels as not supported, while data loss prevention, data classification, auditing, insider risk management and eDiscovery are supported. Retention, eDiscovery and communication compliance narrow further still on the browser path, to the Edge browser and to ChatGPT, Microsoft's consumer Chat, Google Gemini and DeepSeek, though separate network data security integrations can cover AI interactions outside it. Claude splits across two paths: browser use of claude.ai sits on the supported-site path, while Claude Enterprise is governed through the Anthropic Claude connector, listed by Microsoft as in preview, which ingests activity and chat data into Purview and where sensitivity labels, label-free encryption and data loss prevention are all unsupported. Governing Copilot, governing a ChatGPT tab and governing Claude Enterprise are three different configurations, and the assessment maps all three.
Some of it might, and we tell you which parts before you spend anything. Microsoft documents that managing third-party AI interactions in Purview requires pay-as-you-go billing enabled on the tenant. Most of the supported browser-based capabilities also need the Purview browser extension and devices onboarded to Purview, and Microsoft names network data security and browser data security as exceptions with their own prerequisites. Endpoint policies that warn or block a paste into an AI site need onboarded Windows or macOS devices and sit behind a Purview licence tier. Part of the assessment is telling you who on your team actually needs a Copilot seat, and scoping confirms what your existing licences already cover.
Yes. The core tenant review is remote and does not change between Canada and the United States. The jurisdiction and sector mapping does. Fusion Computing is Canadian-owned and has supported businesses since 2012. The report maps the technical findings to the Canadian and US privacy, AI and sector frameworks identified during scoping, and your legal counsel confirms which duties actually apply. Hands-on and on-site services remain Canadian, across the Greater Toronto and Hamilton area and Metro Vancouver.
The 60-minute scoping call is free. The assessment itself is a fixed fee, quoted in writing after scoping, with the price set by the size of your environment and how much is in scope. Your written quote sets the delivery schedule at the same time. No work starts before you have the fee, the scope and the timing in writing.
The free scan runs Microsoft's official open-source assessment engine against your tenant and returns a branded report across seven service areas. It is automated, Copilot-focused, and genuinely free. This is the paid engagement, and it covers three layers rather than one product: the governance you can evidence, including the approved-tool register and who reviews AI-assisted decisions; the AI already running across your estate, including vendor-enabled features, agents and shadow AI; and the Microsoft 365 controls underneath, including Purview labeling, data posture, identity and audit evidence. Those findings become risk-ranked results, a remediation roadmap, a licensing recommendation and a go/no-go call. Your statement of work fixes the exact scope before anything starts. Run the scan first if you want a fast baseline, then commission this where the scan flags risk.
You do not need a full rollout, and running this before you commit seats is the whole point: it is what reduces the chance of a rollout surfacing HR files or board minutes to users whose existing permissions are already too broad. Copilot can surface content the signed-in user is authorised to access, and it does not bypass existing permissions.
One caveat we would rather state than bury. Some of the Copilot readiness work uses SharePoint Advanced Management, and Microsoft says that assigning at least one Copilot licence gives you the SharePoint Advanced Management features that support a Copilot deployment. Whether your tenant qualifies also depends on the base subscription. Microsoft's current documentation is inconsistent on Business Premium. The SharePoint Advanced Management prerequisites page does not list it, while the Copilot licensing page says Business Premium is eligible for Copilot. Copilot Business material also presents these governance features as part of the business proposition. We are not going to guess which reading applies to you. We check the actual entitlement in your tenant during scoping and tell you what you have before you buy anything.
A few features need the SharePoint Advanced Management Plan 1 add-on regardless, and other Purview capabilities carry separate licensing and deployment prerequisites of their own. Scoping confirms which licence changes, if any, are needed before we proceed. Teams that already bought licences still benefit, since the same findings decide whether to widen the rollout or fix permissions first.
DeepSeek is treated as a named risk rather than a generic one. Shared Services Canada restricted it on the government mobile devices it manages and the federal chief information officer recommended other departments and agencies do the same, citing the collection and retention of sensitive personal information. Texas banned it on government-issued devices in January 2025, and the Intelligence Authorization Act for Fiscal Year 2026, enacted 18 December 2025 as part of Public Law 119-60, directs the removal of DeepSeek from intelligence-community national security systems subject to specified exceptions. Microsoft Purview lists deepseek.com among its supported AI sites, so a tenant with the required controls deployed can detect the usage and apply a data loss policy. Retaining the prompts and responses is documented for the Edge browser and needs a Purview collection and retention policy. DeepSeek is one of only four apps in that Edge retention set, which several better-known tools are not. The assessment tells you whether your tenant can currently do any of it.
No. The report and the 30/60/90-day plan are yours to implement with your internal team or any provider you choose, and the plan is written so an internal IT lead can run it without us. An implementation engagement is available if you want help executing, and we will tell you plainly when a finding is small enough that you should just close it yourself.
Find out what your organization currently permits
Request a free 60-minute scoping call. We confirm the scope, quote a fixed fee in writing, and you decide from there. Commission the assessment and the report is yours to implement with us, with your own team, or with anyone else.