Microsoft Copilot M365 is probably the first generative AI deployed at scale in most European organisations. The Microsoft enterprise contract covers security, encryption and data residency. It does not cover the AI Act. Here are the five specific obligations that land on you.

Obligation 1. Classify Copilot in your AI register

Copilot M365 is a general-purpose AI system (GPAI in the meaning of the AI Act). It must appear in your internal register, with a risk classification for each use. Copilot in Outlook to draft an email: limited risk. Copilot in Excel to generate an HR analysis with recommendations about employees: potentially high risk (Annex III, point 4, HR).

Obligation 2. Manage functional context: one Copilot, different uses

The AI Act classifies systems by their end use, not by their technical architecture. The same Copilot M365 can be minimal risk in one context and high risk in another. Your Copilot deployment policy must reflect that granularity: permissions per group, per use case, per data sensitivity.

Obligation 3. Document the chain of responsibility

If Copilot generates a recommendation that leads to an HR decision (for example: not inviting a candidate to an interview), who is responsible? Microsoft as GPAI provider, you as deployer, or the person who validated the recommendation? The answer: essentially you, as the deployer. But you must have documented the human validation procedure (Art. 14).

Obligation 4. Turn on Purview, assuming your licence includes it

Microsoft Purview is the data governance tool that traces what Copilot reads, generates and exposes. Without Purview properly configured, you lose traceability, and therefore breach the decision-logging obligation (for high-risk cases). Yet Purview is not part of every M365 licence. Mandatory pre-check before any Copilot rollout.

Obligation 5. Train your teams on Copilot, AI Act-aware

Article 4: AI literacy has been mandatory since February 2025. For Copilot, that means training your users to: understand when Copilot hallucinates, how to verify its outputs, when to reject a recommendation, how to report abnormal behaviour. Not a 10-minute video: a documented, traceable learning path.

The typical operational risk: Shadow Copilot

Many organisations deploy Copilot for a few pilots and forget the Power Apps / Power Automate / Copilot Studio licences enabled for dozens of business users. The result: Copilot agents built without governance, plugged into sensitive data, outside the AI register. This is exactly the profile of breach that AESIA and the CNIL look for first.

The sovereignty angle: where do your prompts really go?

Microsoft announces EU residency for Copilot M365 data. But prompts sent to GPT-4 (the model underneath Copilot) transit through OpenAI under an Azure contract. If your prompts contain sensitive data (personal data, trade secrets), check the Data Processing Addendum and zero-data-retention riders. The standard version of Copilot M365 has no zero-data-retention by default.

The AI Act-compliant Copilot deployment checklist

  • Inventory of Copilot licences (M365 E3/E5/Copilot/Power Platform)
  • Use-case mapping and risk classification
  • Purview configuration + sensitivity labels
  • Entra ID scoping: who sees what through Copilot
  • Copilot literacy training, traceable register
  • Human validation procedure for high-risk uses
  • DPA renegotiated with AI Act clauses
  • Internal "Copilot use" policy signed by management

The good news: these obligations apply to all your AI systems, not just Copilot. Once this discipline is in place, you are also ready for internal agents (n8n, LangChain), HR AI SaaS, and supplier scoring modules.