Using Microsoft 365 Copilot is compliant with the AI Act in the vast majority of cases. Your real duties come down to three things: disclosing AI when it is not obvious, keeping control of sensitive uses, and knowing when you stop being a mere user.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Using Microsoft 365 Copilot is compliant with the AI Act in the vast majority of cases. Your real duties come down to three things: disclosing AI when it is not obvious, keeping control of sensitive uses, and knowing when you stop being a mere user.
The question comes up in nearly every audit we run at SMEs running the Microsoft stack: "we rolled Copilot out to 40 people, are we in the clear?". The short answer is yes, provided you handle three or four specific points. The useful answer means separating what falls on Microsoft, what falls on you, and what falls on neither. If the topic is new to you, our AI Act compliance guide for SMEs sets out the general framework; this article covers only the Copilot case.
In a standard Microsoft 365 Copilot rollout, Microsoft is the provider of the AI system under Regulation (EU) 2024/1689, and your company is the deployer. That split drives everything else, because the two roles carry very different duties.
What sits with Microsoft and not with you:
What stays with you: the use. The regulation does not regulate a piece of software, it regulates purposes and roles. The same Copilot subscription may trigger nothing at all in a marketing team, and pull the company into a heavy regime if it is used to screen job applications. We set out that scoping logic in our article on who is affected by the AI Act.
Since 2 August 2026, Article 50 requires you to inform a person when they interact with an AI or view AI-generated content, unless it is obvious from the context. This is the one duty that touches almost every SME using Copilot.
Four situations are covered in practice: systems that interact directly with a natural person, synthetic content (text, image, audio, video), emotion recognition and biometric categorisation, and finally deepfakes and texts published to inform the public on matters of public interest.
Applied to Copilot, that gives:
The point most articles miss: Article 50 carves out an explicit exception where content has been through human editorial review and a person takes responsibility for publishing it. For an SME, compliance therefore runs as much through an internal review rule as through an "AI-generated" banner. Our template for an AI information notice covers the wording to use in each of these cases.
You remain a deployer as long as you use Copilot the way Microsoft designed it; you become a provider if you substantially modify a high-risk system, change its purpose so that it becomes high-risk, or place it on the market under your own brand. This is the blind spot in most Copilot rollouts we see.
The mechanism sits in Article 25. Do not over-read it: it only bites around high-risk systems. Building a declarative agent in Copilot Studio to answer internal HR questions does not make you a provider. Two configurations do deserve serious review:
The distinction is explained in detail in our article on high-risk AI systems. For now, remember that a standard Copilot rollout, internal agents included, does not tip over into it.
Article 5 has banned eight practices since 2 February 2025, and those bans apply even when you are only the deployer of an off-the-shelf tool. Two of them bear directly on uses we see emerging in Microsoft 365 shops.
Emotion recognition in the workplace is prohibited, save for medical or safety reasons. If someone floats the idea of analysing the tone of Teams messages to gauge team morale, the answer is no, and it is not negotiable. Social scoring of individuals is banned too: a dashboard ranking employees on aggregated behavioural signals falls in the same bracket.
These bans are the only ones carrying the top penalty tier, namely 35 million euros or 7 % of worldwide turnover. For an SME, the applicable cap is the lower of the two figures, which is still far beyond what a 30-person business can absorb. We have set out the full scale in our article on AI Act sanctions, and the exhaustive list in the one on prohibited AI practices.
The Digital Omnibus, in force since 27 July 2026, pushed the duties for Annex III high-risk systems back to 2 December 2027, and those for Annex I systems to 2 August 2028. The transparency strand did not move.
That nuance is poorly understood, including by firms still publishing outdated timelines. What has been postponed is the heavy machinery: risk management system, data governance, technical documentation, formalised human oversight under Article 26. What already applies: Article 5, Article 50 and the penalty regime in Chapter XII. Our full AI Act timeline walks through each deadline.
A word on Article 4 and training. The same Omnibus lightened the AI literacy duty: what weighed on companies became a non-binding incentive, with the Commission and member states taking the lead on promoting AI literacy. We would rather say so plainly than sell a fear that no longer exists, and we explain it in our article on Article 4 and AI training. That said, training Copilot users remains the single most effective way to avoid off-piste uses, and it becomes a fully fledged obligation again as soon as a high-risk system is in play.
| Topic | Who carries the duty | What you have to do |
|---|---|---|
| Technical documentation of the system | Microsoft | Keep the documentation provided, be able to produce it on inspection |
| Underlying general-purpose model | Microsoft | Nothing directly |
| Machine-readable marking of generated content | Microsoft | Check the feature is active in your tenant |
| Informing people who interact with an agent | You | Explicit notice on any agent exposed to third parties |
| Labelling published content | You | Editorial review rule or automatic labelling |
| Scope of data Copilot can reach | You | Review SharePoint and OneDrive permissions before rollout |
| Uses banned by Article 5 | You | Usage charter and control over internally built agents |
| Register of AI systems in use |
The permissions line deserves a word. Copilot surfaces what the user can already access. In an SME where SharePoint shares have piled up over five years, that means an intern may be handed a poorly partitioned salary grid. This is not an AI Act issue, it is a GDPR issue, but it is the first concrete problem we hit in the field, and it is dealt with before rollout, not after. We cover how the two texts interact in AI Act vs GDPR.
For an SME of 20 to 200 employees, a Copilot rollout can be brought into compliance in one to two working days, without a law firm. Here is the order we work in.
Do I have to declare our use of Copilot to an authority? No. There is no prior declaration for the deployer of a general-purpose AI system. Registration in the EU database applies to high-risk systems and falls mainly on providers.
Is Copilot a high-risk AI system? Not by nature. High-risk status follows from the purpose of use, not from the tool. The same Copilot stays out of scope for office work and can fall under Annex III if it is used to screen applicants or assess employees.
Do I have to tell my employees Copilot has been deployed? The AI Act does not require it directly in a standard office setup. GDPR and French employment law, however, govern informing and consulting the works council on the introduction of new technology. Check this point with your employment counsel depending on headcount.
Does an internal Copilot Studio agent change anything? As long as it stays internal and outside Annex III, you remain a deployer. Two reflexes all the same: record the agent in your mapping, and control who is allowed to create one.
What if an employee publishes Copilot output without reviewing it? If that text informs the public on a matter of public interest, the editorial control exception does not apply and labelling becomes mandatory. Which is precisely why the review rule should be written down rather than implied.
Are the duties different for a nonprofit? No. The regulation targets the activity, not the legal form. A nonprofit deploying Copilot to its staff is a deployer just like a commercial company.
Do Copilot and ChatGPT fall under the same regime? Yes in principle. The differences lie in the contract, data location and admin controls, not in how they are classified under the AI Act. Our article on the AI Act and ChatGPT covers that case in parallel.
We work on two fronts that rarely stand alone. The first is the compliance audit: inventory of uses, permissions review, drafting of the charter and transparency notices, and a mapping you can actually maintain. The second is user training, because a charter nobody has read protects nobody. GrowthPerf is Qualiopi-certified, which opens up funding through your OPCO, and both our Microsoft 365 Copilot sessions and our AI acculturation programme build the compliance strand in as standard.
If you have rolled Copilot out without addressing these points, or you are about to, the free 30-minute audit will tell you in one conversation where you actually stand. For the wider picture, go back to our AI Act compliance guide for SMEs.
| You |
| A mapping kept up to date |