Integrating Microsoft 365 Copilot into your organization makes you responsible under the AI Act. Depending on the usage, you will need to document, supervise, and train, even if Microsoft ensures the compliance of the underlying model.
Microsoft 365 Copilot, a generative AI solution integrated into the Microsoft 365 suite, automatically brings your organization under the scope of the AI Act upon deployment.
The text distinguishes two main actors: Microsoft, as the model provider, and your company, as the deployer. The latter is responsible for ensuring that the use of Copilot complies with regulations, particularly regarding risk classification, documentation, and human oversight, even if Microsoft provides the underlying AI.
Why using Copilot triggers AI Act compliance obligations
**Article 26** of the regulation specifies that the deployer must ensure the system is used in accordance with its intended purpose. If Copilot is repurposed for HR or financial decision-making, the responsibility for compliance with these uses falls on the user organization.
Division of responsibilities between Microsoft and your company
Microsoft, as the provider of the GPAI model (GPT-4), must comply with the requirements of Articles 51 to 56 of the AI Act. However, this does not cover specific internal uses within your organization.
**Microsoft (Provider):**
- Compliance of the GPAI model (Articles 51-56)
- Publication of technical documentation and transparency reports (AI Transparency Report)
- Management of systemic risks
**Your Company (Deployer):**
- Assessment of risk level based on usage (Article 6)
- Documentation of organization-specific processes (Article 26)
- Human oversight and user training
- Transparency towards affected persons (Article 50)
Microsoft's documentation on AI Act compliance is valuable but does not replace the analysis of your own use cases.
Obligations based on Copilot usage
Regulatory requirements vary depending on the purpose of Copilot within your company.
Standard usage: productivity and general assistance
For tasks such as writing, research, or productivity assistance, Copilot is generally considered a limited risk (Article 50). Your obligations are lighter, but real:
- Inform users that they are interacting with an AI.
- Document internal uses (e.g., generating meeting minutes).
- Train employees to adopt best practices (avoiding the dissemination of sensitive data).
- Ensure that generated results do not harm third parties without adequate transparency.
High-impact usage: HR decisions, credit, health
If Copilot is involved in automated processes falling under Annex III of the AI Act (human resources, credit, health, etc.), it may be classified as high-risk. In this case, obligations are reinforced:
- Conduct a prior risk assessment (Article 9)
- Provide complete technical documentation (Article 11)
- Implement effective human oversight (Article 14)
- Ensure traceability of operations (Article 12)
- Clearly inform the persons concerned (Article 13)
> Using Copilot to screen resumes or evaluate credit applications places you in the high-risk system category, even if the model was not developed in-house.
Examples of high-risk situations with Copilot
HR management and recruitment
If Copilot is used to:
- Select or filter job applications
- Generate performance evaluations
- Propose promotions or raises
These practices fall under Annex III, point 4 and require compliance with requirements for high-risk systems.
Credit and financial analysis
Copilot used to:
- Examine loan applications
- Evaluate customer creditworthiness
- Suggest individualized pricing terms
These uses are covered by Annex III, point 5 and require reinforced compliance.
Health and insurance
Copilot used to:
- Analyze medical records
- Determine personalized insurance rates
These cases fall under Annex III, points 1 and 6 and are subject to strict requirements.
Where is your data hosted? Microsoft's guarantees
Since 2023, Microsoft has offered the EU Data Boundary option, which ensures that data processed by Copilot (documents, emails, prompts) remains within the European Union.
- Data is stored in European data centers.
- This option facilitates GDPR compliance but does not exempt you from AI Act obligations.
- Verify the activation of the EU Data Boundary in your Microsoft 365 contract.
The European AI Office notes that hosting in the EU is an important criterion, but it is not sufficient to guarantee full compliance with the AI Act.