0 min read

You bought Copilot. Congratulations, you're now an AI provider.

What Article 50 actually means for a company running Microsoft 365 Copilot — internally, externally, and in the agents your staff quietly built last quarter.

What Article 50 actually means for a company running Microsoft 365 Copilot — internally, externally, and in the agents your staff quietly built last quarter.

You bought Copilot. Congratulations, you're now an AI provider.

The agent nobody registered

A few months ago, someone in HR at a large company built a small thing. It answers benefits questions. Staff ask it about parental leave and pension matching instead of emailing the HR inbox. It took her an afternoon in Agent Builder. She called it "Ask HR".

It works. Inbox volume dropped. Nobody signed anything off, because nobody thought there was anything to sign off. She used a tool Microsoft gave her, inside a platform legal had already approved.

Here is the part she does not know.

Under the EU AI Act, her company is a deployer of Microsoft 365 Copilot. Microsoft is the provider. That split is well understood and the obligations on the deployer side are light.

But "Ask HR" is not Microsoft 365 Copilot. It is a new AI system, built by her company, running under her company's name. And under Article 3, a provider is anyone who develops an AI system and puts it into service under its own name — where "putting into service" explicitly includes supply "for own use".

Internal use is not a loophole. It is squarely inside the definition.

So her company is the deployer of Copilot, and the provider of Ask HR. Different role. Heavier duties. Nobody in the building knows.

There are now over 120,000 custom Copilot agents deployed across enterprises. Most were built by people exactly like her.

You became a provider the moment someone clicked "create agent" — not when legal said you could.

First, precisely which rules apply to a Copilot estate

Before the argument, the ledger. The EU AI Act is Regulation (EU) 2024/1689, and it switches on in stages. Most of it is already law. Here is exactly which articles touch a company running Microsoft 365 Copilot, and when each one started.

Already law since 2 February 2025

  • Article 5 — prohibited practices. Eight banned categories. The one that catches Copilot estates: inferring emotions in the workplace. If any tool in your stack scores staff sentiment, that is not a transparency question, it is a prohibition question, and it has been illegal for eighteen months.
  • Article 4 — AI literacy. The duty to ensure staff using AI on your behalf are sufficiently AI-literate. Live since this date.

Already law since 2 August 2025

  • Articles 51–56 — general-purpose AI models. Microsoft and OpenAI's problem, not yours. Useful to you only as vendor documentation you can rely on.

Landing tomorrow, 2 August 2026

  • Article 50(1) — tell people they are interacting with AI. A provider duty. Yours for every agent you build.
  • Article 50(2) — mark generated content machine-readably. A provider duty. Microsoft handles this for images via Content Credentials; nobody handles it for text.
  • Article 50(3) — inform people subject to emotion recognition or biometric categorisation. A deployer duty. Yours.
  • Article 50(4) — disclose deepfakes and AI-written public-interest text. A deployer duty. Yours, and this is the one your comms team will trip.
  • Article 4 enforcement — the literacy duty becomes supervised and enforceable.
  • Article 99 — fines up to €15 million or 3% of worldwide turnover for Article 50 breaches.
  • Article 85 — any person may complain to a market surveillance authority.

Not tomorrow

  • Annex III high-risk — moved by the Digital Omnibus (in force 27 July 2026) to 2 December 2027. This is where an HR or recruitment agent eventually lands.
  • Annex I high-risk — to 2 August 2028.

One more date

  • 2 December 2026 — the Article 50(2) marking grace period ends for systems already on the market before tomorrow, and a new Article 5 prohibition on non-consensual intimate imagery and CSAM generation begins.

So for a Copilot estate the live surface is narrow and specific: Article 5 emotion inference, Article 4 literacy, and the four limbs of Article 50. Everything else is either someone else's duty or sixteen months away.

Know which article you are answering to before you build a control for it.

First, precisely which rules apply to a Copilot estate

Two hats, and the one everybody forgets

Let me make the split concrete, because everything else follows from it.

Microsoft 365 Copilot, out of the box. Microsoft built it, Microsoft placed it on the market, Microsoft is the provider. You are the deployer. Your duties are real but modest: use it within its intended purpose, keep humans in the loop, train your people, and handle the deployer-side transparency duties under Article 50(3) and 50(4).

Any agent you build. Agent Builder, Copilot Studio, declarative agents grounded on your SharePoint. You developed it. You put it into service under your own name. You are the provider of that system. The provider duties under Article 50(1) and 50(2) now sit with you, not Microsoft.

This is the single most consequential thing for a Copilot-enabled organisation, and it is almost universally missed. The reason is understandable. Building an agent feels like configuration, not creation. You did not write a model. You picked some knowledge sources and typed instructions in plain English. It looks like using a product.

The Act does not care how easy it was.

One caveat worth stating plainly, because the internet is sloppy about it. Article 25 — the famous "rebranding makes you a provider" rule — sits in the high-risk chapter and is about high-risk systems. It is not the mechanism here. The mechanism here is simpler and broader: the plain definition of "provider" in Article 3(3), combined with "putting into service" in Article 3(11) covering own use. You do not need Article 25 to land in provider territory with a custom agent. The definitions get you there on their own.

The law splits duties by what you did, not by how hard it felt.

Two hats, and the one everybody forgets

Does any of this apply if we only use it internally?

This is the question every Copilot programme lead asks, and the honest answer is: yes, but less than you fear, and in a different place than you expect.

Article 50(1) applies to AI systems "intended to interact directly with natural persons". Employees are natural persons. There is no internal-use exemption anywhere in the text. So the disclosure duty travels inside your firewall.

But there is a carve-out that does a lot of work: you can skip disclosure where it would be obvious to a reasonably well-informed, observant and careful person that they are dealing with AI.

Apply that honestly and you get a clean split.

The Copilot chat pane in Teams or Word. Microsoft-branded, sitting under a button that says Copilot, in a product the company announced. Obvious. You are almost certainly fine. Write down that you reached that conclusion and why. One paragraph.

"Ask HR", embedded in a Teams channel, answering in a friendly voice. Much less obvious. A new joiner might reasonably think a person in HR is replying. This one needs a disclosure line, and you are the provider who owes it.

The fix is trivial — a greeting that says "I'm an AI assistant, and I can get things wrong. For anything binding, check with HR." That single sentence covers the legal duty and improves the tool.

Two further things bite internally, and both are more important than the disclosure question.

Article 4, AI literacy. Enforcement started on 2 August 2026. If you have rolled Copilot out to thousands of staff, you owe them training appropriate to their role. This is the most enforceable and most embarrassing gap, because the evidence is a spreadsheet you either have or you don't.

Article 50(3), emotion recognition. If any part of your stack infers sentiment or emotional state from staff — some meeting-analytics and contact-centre quality tools do — you must tell the people exposed to it. GDPR applies on top, and works councils tend to have views.

Internal deployment lowers your exposure. It does not remove your duties.

The moment output leaves the building

Everything gets sharper when Copilot-generated content crosses the boundary out of your organisation. This is where a Copilot programme turns into a compliance question.

Three crossings matter.

1. An agent that talks to customers

Build a support agent in Copilot Studio, put it on your website, and three things happen at once. You are its provider. Article 50(1) disclosure is mandatory, and the "obvious" exemption is much harder to claim when the agent has a friendly name and a human tone. And if any customer is in the EU, the output-based scope trigger is satisfied — you are in the Act's reach regardless of where your company sits.

Disclosure must land at or before the first interaction. Not in a policy page. Not after three exchanges.

2. Articles, posts and papers drafted with Copilot

This is your marketing and comms team, and it is the most common external use in practice.

Article 50(4) requires disclosure for AI-generated text published with the purpose of informing the public on matters of public interest. That qualifier is doing real work, and most people misread it in one direction or the other.

Ordinary commercial marketing — product pages, campaign copy, promotional emails — is generally not "informing the public on matters of public interest". The duty does not obviously bite.

But a great deal of corporate content is not ordinary marketing. Thought-leadership on regulation. Commentary on industry safety. Position papers. ESG and sustainability reporting. Public-health or policy content. Anything a journalist might quote. That is public-interest territory, and the duty engages.

Now the relief valve, which is generous: the duty falls away where the AI-generated text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication.

Read that carefully, because it is the single most useful sentence in Article 50 for a Copilot-using business. You do not have to stamp "written by AI" on everything. You have to have a named human who genuinely reviewed it and owns it.

That is a governance answer, not a technology answer. And it only helps if you can prove it happened.

3. Images and synthetic media

Here you get real help from Microsoft. Images generated in Microsoft 365 Copilot and Designer carry Content Credentials — cryptographically signed provenance metadata built on the C2PA standard, the same standard the Commission's draft Code of Practice on Marking and Labelling names directly.

So for images, the machine-readable marking obligation is substantially handled upstream. Three cautions.

Do not strip it. Metadata dies easily — re-exports, crops, screenshots, and many social platforms all destroy it. Your obligation is to preserve provenance where you can, and to know where your pipeline breaks it.

Text is not marked. There is no reliable watermarking for text, from Microsoft or anyone. So for written content you cannot lean on markers. You lean on the editorial-responsibility route or you disclose.

And if an image convincingly depicts a real person or real event that did not happen, you are in deepfake territory under 50(4). Disclosure required, whatever the marketing value.

Internally you manage awareness. Externally you manage evidence.

The bigger thing sitting behind all this

Tomorrow's deadline is about transparency. The heavier regime — high-risk AI — was pushed to 2 December 2027. That is sixteen months away and it is where Copilot agents get genuinely dangerous.

Look at what organisations actually build. The most common internal agent patterns are IT help-desk deflection and HR self-service. HR self-service is one drift away from a problem.

An agent that answers "what is our parental leave policy" is fine. The same agent, extended to sift applications, rank candidates, flag performance concerns or support promotion decisions, becomes an Annex III high-risk system — employment and worker management is on the list. And because you built it, you are the provider carrying the full high-risk obligation set: risk management, data governance, technical documentation, human oversight, conformity assessment, registration.

The drift is quiet. Agents get extended by the person who owns them, in an afternoon, without a change request.

You do not have to solve this today. You do have to be able to find them in 2027. That means the register you build now has to record what each agent does, not just that it exists.

Build the inventory for the deadline after next, not the one tomorrow.

The evidence to have on file

A regulator will not ask what your policy says. They will ask what you can show. For a Copilot estate, here is the file.

1. An agent register. Every agent built in Agent Builder and Copilot Studio. For each: name, business owner, purpose, knowledge sources, internal or external audience, whether output reaches EU people, and — stated explicitly — whether you are provider or deployer for it. Nothing else on this list works without this.

2. A written role determination. One line per agent recording the provider/deployer call and the reasoning. This is the artefact that shows you understood the question at all.

3. Disclosure evidence. A screenshot of each agent's opening message showing the AI notice, dated. For the Copilot chat pane, a short note recording your reliance on the "obvious" exemption and why.

4. Publication sign-off records. For any externally published content drafted with Copilot: who reviewed it, when, and who holds editorial responsibility. A named person, not "marketing". This is what buys you the 50(4) exemption, and without the record the exemption is a story rather than a defence.

5. A content provenance policy. Confirming Content Credentials are preserved on generated images, that staff must not strip them, and documenting where your publishing pipeline breaks them.

6. Article 4 training records. Who was trained, when, on what, tailored to role. Marketing needs the labelling rules. Support needs the disclosure rules. Agent builders need to know they are creating systems, not documents.

7. Emotion and biometric assessment. A short written check on whether anything in your stack infers emotional state, and what you told people if so.

8. Microsoft's documentation. Their AI Act and transparency materials for Copilot, retained with dates. Your reliance on the upstream provider should be evidenced, not assumed.

9. Agent lifecycle and change records. When each agent was created, approved, materially changed and retired. This is what will let you spot high-risk drift before December 2027.

10. Complaint and incident records. Anything raised about AI output, and what you did about it.

One warning that applies to all of it: supplying incorrect or misleading information to a regulator is a separate offence, carrying fines up to €7.5 million or 1% of turnover. A gap in the file is recoverable. A tidied-up version of history is not.

The register is the whole programme. Everything else is a column in it.

How the governance should actually work

Three gates. Deliberately few, because governance nobody follows is worse than none.

Gate 1 — Build

Control who can create agents at all. In practice this is not the blunt Microsoft 365 admin toggle, which couples creating and using and will strip your staff of Copilot features you wanted to keep. The clean separation lives in Power Platform — an environment with a security group, and the create/update-agent security role granted only to an approved builder group, with environment routing so Agent Builder agents land where you can see them.

Everyone keeps their licence and full use of Copilot. Only an approved group can build. That is the split most organisations actually want, and it is the one that survives an audit.

Registration happens here, at creation, not in a later sweep.

Gate 2 — Publish

Control what leaves the building. Any Copilot-drafted content going to an external audience needs a named human reviewer who takes editorial responsibility, and a record of it. Any agent facing customers needs a disclosure line and a screenshot on file before launch.

Sharing controls matter here too. For Agent Builder agents, the Microsoft 365 admin sharing control governs who may share — and it is an allow-list, so if you want to restrict a few people you point it at a group containing everyone who may share.

Gate 3 — Review

Quarterly, walk the register and ask one question per agent: has what this does changed? You are hunting for drift toward employment, credit, education or essential-services decisions — the Annex III categories that turn a helpful agent into a high-risk system in December 2027.

A simple status per agent works well. Green, running as registered. Amber, changed or unclear, needs a look. Red, now touching decisions about people, or reaching an audience it was not built for — stop and reassess.

Underneath all three gates, the unglamorous controls still carry most of the actual risk: sensitivity labels, SharePoint access hygiene, and DLP. Copilot does not create an oversharing problem. It makes an existing one visible and fast. If your permissions are wrong, an agent will surface that at conversational speed, and no amount of Article 50 disclosure will help.

Three gates, one register, and a quarterly hour. That is the whole programme.

How the governance should actually work

What to do this week

If you run a Copilot estate and you want to be honest by Friday:

  1. Export the list of agents in your tenant. Most organisations are surprised by the number and by who built them.
  2. Split it into internal and external. External is where you start.
  3. Add a disclosure line to every agent that talks to anyone, starting with customer-facing ones. Screenshot each. File it.
  4. Write one page on the Copilot chat pane and why you consider AI use obvious there.
  5. Add a reviewer field to your content publishing process, and start recording who signed off. Today's content, not last year's.
  6. Book the AI literacy session. Record attendance.

That is a week of work and it covers the realistic first complaint.

The honest summary

If you have deployed Copilot and changed nothing else, you are a deployer with modest duties, and tomorrow is mostly a documentation exercise.

If your people have built agents — and after 120,000 of them across enterprises, they almost certainly have — you are a provider of systems you did not know you owned, with duties nobody has assigned to anyone.

Internally, the exposure is real but manageable, and mostly about training and honesty. Externally, it sharpens fast: disclosure on agents, editorial responsibility on published content, provenance on images.

And the thing to actually worry about is not tomorrow. It is the HR agent that quietly learns to rank people, sixteen months from now, in an organisation that never wrote down that it existed.

The risk was never the tool you bought. It is the hundred small ones your people built with it.

Who owes what

Situation Your role Key duty
Copilot chat in Word, Teams, Outlook Deployer AI literacy; disclosure likely obvious
Agent you built, internal audience Provider Disclosure at first interaction; register it
Agent you built, customer-facing Provider Disclosure mandatory; EU scope triggered
Copilot-drafted marketing copy Deployer Usually no 50(4) duty — not public interest
Copilot-drafted thought leadership or policy content Deployer Disclose, or evidence named editorial responsibility
Copilot-generated images published externally Deployer Preserve Content Credentials; label deepfakes
Emotion or sentiment analysis on staff or customers Deployer Inform the people exposed (50(3)) + GDPR
Agent touching hiring, performance or promotion Provider Not yet — but high-risk from 2 Dec 2027

General explainer, not legal advice. Roles under the Act are fact-specific, and a determination for one agent does not carry to another. Take advice on your actual estate.

On You bought Copilot. Congratulations, you're now an AI provider. · 0 comments
Comments are moderated

No comments yet — be the first to add to the discussion. Comments appear after they’re reviewed.

Comments are read before they appear.

Enjoyed this article?

Want more insights?

Subscribe to get the latest articles delivered straight to your inbox.