# Microsoft Copilot and the AI Act: Responsibilities and Compliance for Businesses

> Integrating Microsoft 365 Copilot into your organization makes you responsible under the AI Act. Depending on the usage, you will need to document, supervise, and train, even if Microsoft ensures the compliance of the underlying model.

- Tags: AI Act Copilot Microsoft, obligations AI Act entreprise, Microsoft 365 Copilot conformité, déployeur IA AI Act, haut risque AI Act RH, Azure EU Data Boundary RGPD
- Main keyword: AI Act Copilot Microsoft

## Introduction

Microsoft 365 Copilot, a generative AI solution integrated into the Microsoft 365 suite, automatically brings your organization under the scope of the AI Act upon deployment.

The text distinguishes two main actors: Microsoft, as the model provider, and your company, as the deployer. The latter is responsible for ensuring that the use of Copilot complies with regulations, particularly regarding risk classification, documentation, and human oversight, even if Microsoft provides the underlying AI.

## Content

## Why using Copilot triggers AI Act compliance obligations

**Article 26** of the regulation specifies that the deployer must ensure the system is used in accordance with its intended purpose. If Copilot is repurposed for HR or financial decision-making, the responsibility for compliance with these uses falls on the user organization.

## Division of responsibilities between Microsoft and your company

Microsoft, as the provider of the GPAI model (GPT-4), must comply with the requirements of Articles 51 to 56 of the AI Act. However, this does not cover specific internal uses within your organization.

**Microsoft (Provider):**
- Compliance of the GPAI model (Articles 51-56)
- Publication of technical documentation and transparency reports ([AI Transparency Report](https://learn.microsoft.com/en-us/legal/cognitive-services/openai/transparency-note))
- Management of systemic risks

**Your Company (Deployer):**
- Assessment of risk level based on usage (Article 6)
- Documentation of organization-specific processes (Article 26)
- Human oversight and user training
- Transparency towards affected persons (Article 50)

Microsoft's documentation on AI Act compliance is valuable but does not replace the analysis of your own use cases.

## Obligations based on Copilot usage

Regulatory requirements vary depending on the purpose of Copilot within your company.

### Standard usage: productivity and general assistance

For tasks such as writing, research, or productivity assistance, Copilot is generally considered a limited risk (Article 50). Your obligations are lighter, but real:

- Inform users that they are interacting with an AI.
- Document internal uses (e.g., generating meeting minutes).
- Train employees to adopt best practices (avoiding the dissemination of sensitive data).
- Ensure that generated results do not harm third parties without adequate transparency.

### High-impact usage: HR decisions, credit, health

If Copilot is involved in automated processes falling under [Annex III of the AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689#d1e32-1-1) (human resources, credit, health, etc.), it may be classified as high-risk. In this case, obligations are reinforced:

- Conduct a prior risk assessment (Article 9)
- Provide complete technical documentation (Article 11)
- Implement effective human oversight (Article 14)
- Ensure traceability of operations (Article 12)
- Clearly inform the persons concerned (Article 13)

> Using Copilot to screen resumes or evaluate credit applications places you in the high-risk system category, even if the model was not developed in-house.

## Examples of high-risk situations with Copilot

### HR management and recruitment

If Copilot is used to:
- Select or filter job applications
- Generate performance evaluations
- Propose promotions or raises

These practices fall under [Annex III, point 4](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689#d1e32-63-1) and require compliance with requirements for high-risk systems.

### Credit and financial analysis

Copilot used to:
- Examine loan applications
- Evaluate customer creditworthiness
- Suggest individualized pricing terms

These uses are covered by [Annex III, point 5](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689#d1e32-64-1) and require reinforced compliance.

### Health and insurance

Copilot used to:
- Analyze medical records
- Determine personalized insurance rates

These cases fall under [Annex III, points 1 and 6](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689#d1e32-65-1) and are subject to strict requirements.

## Where is your data hosted? Microsoft's guarantees

Since 2023, Microsoft has offered the [EU Data Boundary](https://www.microsoft.com/en-us/trust-center/privacy/data-location) option, which ensures that data processed by Copilot (documents, emails, prompts) remains within the European Union.

- Data is stored in European data centers.
- This option facilitates GDPR compliance but does not exempt you from AI Act obligations.
- Verify the activation of the EU Data Boundary in your Microsoft 365 contract.

The [European AI Office](https://digital-strategy.ec.europa.eu/en/policies/ai-office) notes that hosting in the EU is an important criterion, but it is not sufficient to guarantee full compliance with the AI Act.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/copilot-microsoft-ai-act-obligations-entreprise)
