MSAI Lab · explainer

Copilot's honest limits

Say these out loud before the seats land. Setting expectations early prevents the "we tried AI and it was mediocre" verdict that kills programmes — and none of these are reasons not to buy Copilot. They're reasons to buy it in the right order.

1

Tenant-grounded is the strength and the ceiling

Copilot answers from your SharePoint, OneDrive, Teams and email. If that estate is fragmented personal drives and five versions of the same spreadsheet, its answers will be confidently mediocre.

So: fix the estate and the same seats get dramatically better. This is why the foundations track exists.

2

It works one app at a time

It drafts in Word, recaps in Teams, analyses in Excel. It will not take a task across systems — pull data from finance, check the contract, draft the report, file it.

So: that's agent territory (Level 5 on the maturity scale), and it needs foundations Copilot doesn't build.

3

It's a drafting and retrieval engine, not a deep reasoning engine

First drafts, summaries, find-that-document: excellent. Multi-step analysis, scenario reasoning, long-contract interpretation: quality drops fast.

So: this is where frontier models — used deliberately, by a small cohort, under the same data rules — earn a place alongside Copilot.

4

It reveals your permissions; it doesn't create them

Copilot doesn't leak data. It surfaces what was already over-shared — the "Anyone" link from 2023, the confidential folder shared with Everyone. Test yourself honestly: from a standard account, ask Copilot "what documents mention salaries?" Whatever comes back that shouldn't is your work list.

So: the permission-hygiene pass isn't optional prep; it's the difference between a rollout and an incident.

5

Verification stays with the human

Confident error is a property of the technology, not a defect to wait out. The person who sends it, owns it.

So: literacy training builds the verification habit; the one-page AI policy makes it a rule your auditors can point to.

Buy Copilot in the right order: fix what it reads, train the people using it, measure what it does, and probe what a frontier model adds where Copilot stops. Sequence is the whole strategy.

The data-safety answer leadership asks for: M365 Copilot works within your tenant, respects existing permissions and sensitivity labels, and does not use your prompts or data to train the underlying models. But privacy-law compliance still depends on your configuration — permission hygiene, labels, retention, cross-border posture. Copilot inherits your permissions, so permission hygiene is a prerequisite, not a follow-up.