Copilot & AI governance

Roll out Copilot without losing control

Microsoft 365 Copilot is quick to switch on. The problem starts afterwards: it reliably finds every file a user has access to – including the ones nobody remembered were shared with everyone. That is why we start with the permissions, not with the licence.

Review first, then activate Pilot group instead of licences for all AI policy on one page Training records included

The key point

Copilot creates no new access rights. It makes the old ones visible.

Over the years, every organisation accumulates shares that nobody remembers: a folder opened up for a project, a link for “everyone in the organisation”, a group membership left over after a move to another department. As long as people had to search by hand, nobody noticed. A tool that searches the entire data estate in seconds on request changes exactly that.

Technically, Copilot respects the existing permissions – that is correct, and it is how Microsoft describes it. In practice, it means that anything shared too widely will now be found. That is not a flaw in the product; it is an audit that can no longer be put off.

That is why the order matters. If you activate first and tidy up afterwards, you are tidying up with everyone watching.

Illustration: Microsoft 365 services with mailbox, file storage and collaboration, connected through central user management.
The same permissions that organise your file storage today will determine what Copilot finds tomorrow.

Before activation

What we look at

In a small or medium-sized business, the review takes a few days and produces a list of findings ranked by urgency – useful whether or not Copilot is introduced in the end.

Sharing in SharePoint and OneDrive

Where are there links that anyone in the organisation can open? Which folders are still open even though the project ended years ago? Which libraries inherit permissions differently from what you assumed?

Groups and rights

Who is still a member of groups they should have left long ago – after changing department, after covering for a colleague, after leaving the company? Nested groups are the most common blind spot.

Confidential storage areas

Personnel files, contracts, cost calculations, medical records. These areas are excluded before anything is activated – technically, not by a notice asking people to stay away.

Data classification

Labelling confidential documents, so the restriction does not depend on each individual folder and still applies when a file is moved.

Licence planning

Who really needs Copilot? Licensing everyone is rarely the cheapest way in – and the whole workforce is rarely the group that shows the benefit first.

Pilot group

One department, four weeks, evaluated. After that, the rollout decision is based on experience rather than expectations.

Already binding: AI literacy under Article 4

Since 2 February 2025, businesses that use AI must ensure that the staff working with it have sufficient AI literacy. This applies even if a language model is only used for research and drafting texts – which means it affects practically every business in which someone has opened such a tool. Documented training is how you show that you meet the obligation.

Legal framework

What the EU AI Act requires of your business

The regulation applies in stages. For most businesses, only two rows of this table matter in practice – the first because it has applied for some time, and the last because it requires you to assess your use case.

ObligationApplies fromAffects you if …
AI literacy (Article 4)2 February 2025… AI is used in your organisation at all
Prohibited practices (Article 5)2 February 2025… AI is to be used to assess or influence people
Obligations for model providers (Article 53)2 August 2025… you publish your own models – rare for users
Labelling of AI-generated content (Article 50)2 August 2026… you publish AI-generated texts or images or run chatbots for customers
High-risk applications (Annex III)Postponement to December 2027 planned… AI has a say in decisions on job applications, creditworthiness or access to services
Information as of 11 September 2026. The postponement for high-risk applications is based on the so-called Digital Omnibus; Parliament and Council reached a political agreement in May 2026, but formal adoption was still pending on that date. Until then, the original deadlines formally continue to apply.
This is not legal advice. We set up the technology and the records; the legal assessment of your use case is a matter for your lawyer or data protection officer.

AI policy

One page that everyone reads

A rulebook that nobody opens protects nobody. Our template answers six questions on a single page – you adapt it to your organisation instead of starting from scratch.

  • Which AI tools are approved – and which are expressly not
  • What may be entered and what never may: personnel data, health data, login credentials, other people’s confidential information
  • Who checks the results before they leave the organisation
  • How AI-generated content is labelled
  • Whom to ask when in doubt – a named person, not a job title
  • How training is documented

What we do not provide
Legal advice and legal sign-off of the policy. The role of data protection officer. Commitments on how your application is classified under the EU AI Act. We work with your lawyer or data protection officer and provide what they need: inventories, logs and technical descriptions.

Frequently asked questions

Questions about Copilot and AI governance

Do we really have to train our staff?

Yes, if AI is used in your organisation. Article 4 of the EU AI Act has applied since February 2025 and requires sufficient AI literacy of the people working with it. The scope depends on how AI is used – staff who produce draft texts need less than a team that pre-screens job applications. What matters is that the training takes place and is documented.

Is Copilot worth it for us?

That depends on how well maintained your file storage is. In an organisation with clean permissions and a lot of document work, it pays off quickly. Where sharing has grown unchecked over the years, the clean-up is the bigger item – and the necessary first step. After the review, we tell you which of the two applies to you.

Can we limit Copilot to certain departments?

Yes, licences are assigned per user. The recommended route is a pilot group anyway, whose results decide the rollout – which, if in doubt, saves the larger part of the licence costs.

What about staff who use ChatGPT privately?

That is the norm, and usually the real reason to act. A ban without an alternative simply moves the use onto private devices. That is why a policy and an approved tool belong together – otherwise neither works.

Do we need an inventory of our AI systems?

An overview of which AI tools are used in your organisation, for what and with which data, makes sense in any case – for classification under the EU AI Act, for the record of processing activities under the GDPR, and simply to know what is running. We draw it up together with you; the legal assessment is made by your data protection officer.

Is our data safe with Copilot?

Processing takes place under your Microsoft 365 contract, and the existing permissions continue to apply. So the open question is rarely Microsoft – it is your own permissions. For documents that should never leave your organisation, an AI chat on your own server is the better choice.

Tidy up first, then activate

In a few days, the review shows what Copilot would otherwise find first

You get a list of findings ranked by urgency – useful whether or not Copilot is introduced in the end. And an answer to the question of whether the licence pays off for your organisation.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement