Microsoft Copilot: Setup and Governance for UK Workplaces
How Microsoft Copilot for Microsoft 365 actually works, how to set it up safely in a UK organisation, and what governance it needs — covering licensing, data flows, and user training.
What Microsoft Copilot Actually Is (and Isn't)
"Microsoft Copilot" is a brand Microsoft applies to a range of AI features across its products, which can be confusing. Three distinct things are commonly called "Copilot":
- Copilot (free/consumer) — the consumer chatbot at copilot.microsoft.com. Comparable to ChatGPT in scope. Not appropriate for confidential work data because input may be retained and used.
- Microsoft 365 Copilot — the enterprise version, integrated into Word, Excel, PowerPoint, Outlook, Teams, and other Microsoft 365 apps. Licensed per user as an add-on to Microsoft 365 Business or Enterprise plans. This is the version most UK organisations mean when they say "we're rolling out Copilot."
- Copilot Studio — a tool for building custom Copilots and connecting them to organisational data. Used by IT teams and developers rather than end users.
This guide focuses on Microsoft 365 Copilot — the version that affects most UK office workers. It operates within your organisation's existing Microsoft 365 tenancy, uses your organisation's data (with permissions checks) to generate responses, and is covered by Microsoft's enterprise data processing commitments. Crucially, it does not use your prompts or your organisation's data to train Microsoft's foundation models.
Our Choosing an AI Assistant for UK Workplaces guide compares Copilot to ChatGPT Enterprise, Gemini, and Claude on data residency, GDPR posture, and approval path.
How Data Flows Through Copilot (and UK Residency)
Understanding Copilot's data flow is essential to governing it well. When a user enters a prompt in a Microsoft 365 app:
- The prompt is sent to Microsoft's Copilot service.
- Copilot pulls relevant context from the user's accessible data in Microsoft 365 — files, emails, calendars, chats — but only files the user has permission to access.
- This context, plus the prompt, is sent to a large language model (typically a model in the GPT family that Microsoft has access to).
- The model generates a response, which is returned to the user.
- The prompt and response are stored in the user's Microsoft 365 activity history (which the user can manage).
For UK organisations with their Microsoft 365 tenancy set to "UK" data residency, the data processing under steps 1–4 stays within Microsoft's UK data centres. This is a significant advantage for UK GDPR compliance and data residency requirements. Confirm your tenancy's data residency setting through the Microsoft 365 admin centre before rollout — UK residency is not the default for all tenancies.
Importantly, Microsoft's Copilot service does not use your tenancy's data, prompts, or responses to train its foundation models. This is contractually guaranteed for Microsoft 365 Copilot enterprise licences (it is not true for the free consumer version of Copilot). Get the relevant clauses from your Microsoft Customer Agreement or Volume Licensing Agreement and keep them in your AI governance file.
Licensing, Cost, and Pilot Strategy
Microsoft 365 Copilot is an add-on licence on top of an existing Microsoft 365 Business or Enterprise subscription. Pricing varies by region and contract, but at the time of writing the typical list price is around £24.70 per user per month for UK organisations — significant compared to the underlying Microsoft 365 subscription cost.
Most organisations adopt Copilot through a phased approach rather than rolling out to all users immediately:
- Pilot (50–200 users): Select a representative cross-section — typically including admin staff, knowledge workers, and managers. Measure use, value, and incidents over 6–12 weeks before committing to wider rollout.
- Targeted rollout: Extend to roles where the pilot showed clear value. Some organisations find Copilot delivers strong value in specific functions (HR, finance, communications) and lower value in others.
- Organisation-wide: Only after the targeted rollout has proven sustained value at scale.
Use the AI Vendor Due Diligence Questionnaire before signing the Microsoft 365 Copilot Schedule, and the AI Readiness Checker before pilot rollout to identify training and governance gaps.
An important governance point: do not allocate Copilot licences only to senior staff. Copilot's value is highest where it accelerates day-to-day knowledge work — typically in operational and admin roles rather than executive ones. A pilot weighted towards leadership often underestimates the tool's actual value.
Governance and User Training
Copilot raises governance considerations that don't apply to most office software. Three governance artefacts should be in place before pilot launch:
- An updated AI policy covering what Copilot is, what it can and cannot be used for, and how users should handle its output. Our Workplace AI Policy template is a starting point; for Copilot specifically, add a section on permissions and the "principle of least privilege" — Copilot can surface anything a user has access to, which makes existing permission hygiene matter more.
- An incident process for AI-related issues — hallucinations published externally, accidental disclosure, dependency on AI output for high-stakes decisions. Our AI Incident Log template gives you the structure.
- Permissions audit. Copilot accelerates the consequences of over-permissive sharing. Run a permissions audit before rollout to identify and tighten files or sites where wider access is no longer needed.
User training is essential, not optional. A 60–90 minute onboarding session covering the basics (how to write prompts, how Copilot interacts with your data, what to verify before relying on output, your AI policy) is the minimum. Our AI Training Checklist covers the structure. The How to write better prompts for work guide gives users practical prompting skills.
Plan to revisit the policy every 6 months. Microsoft is iterating Copilot rapidly, and the capabilities, limitations, and licensing structure all change frequently. A static policy will rapidly drift out of alignment with reality.