Why a Copilot business needs its own policy
Microsoft now calls Microsoft 365 Copilot by the name Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat, so a policy should name the tools under both names7. If your business runs on Microsoft 365, Copilot is probably already in front of your staff. Copilot Chat is pinned to the navigation bar of the Microsoft 365 apps for most eligible users by default, which includes Teams and Outlook14. That means the question is not whether your team will use AI at work, but whether they will use it on terms you have set.
A generic AI policy downloaded from the internet usually fails in two ways. It bans tools nobody uses and stays silent on the one everybody has. A Copilot policy can be specific: it can name the approved Microsoft experiences, point to the settings your administrator has chosen, and use the language your staff already see on screen, such as work mode, web search and file upload.
New Zealand has no AI-specific statute for private businesses. MBIE's Responsible AI Guidance for Businesses is voluntary3 and points businesses to existing law, such as privacy, consumer, competition, human rights and company law17. A policy is how a small business shows it has thought about those obligations before something goes wrong.
The New Zealand rules your policy has to sit inside
Your policy does not create new law, but it should translate the law you already live under into instructions a busy person can follow.
- Privacy Act 2020. The Privacy Commissioner expects organisations using AI to have senior leadership approval, to carry out a privacy impact assessment before use, to be transparent with people, and to make sure a human reviews outputs before acting on them1,2. Your policy should name your privacy officer, who every agency must appoint under section 201 of the Privacy Act 202012.
- Employment Relations Act 2000. Good faith includes giving staff information and a chance to comment before you make a decision that is likely to adversely affect their continued employment6. For a policy change, Employment New Zealand says consultation is required in some circumstances, such as where an agreement or good faith requires it, and otherwise recommends it5.
- Health and Safety at Work Act 2015. WorkSafe lists poorly managed organisational change among the psychosocial hazards a business should manage, and says controls should be reviewed before and during significant change8.
- Security. The NCSC's AI guide for small businesses names data leaks, unreliable or manipulated outputs and supply-chain weaknesses as the main risks of tools such as Copilot9.
- Public-sector clients. If you supply a government agency, read the GCDO's Responsible AI Guidance for the Public Service: GenAI. Agencies may ask suppliers to meet similar expectations on transparency, privacy and accountability4.
Before you write: four decisions to make with your administrator
A policy that does not match your tenant settings will be ignored within a month. Settle these first, then write them in.
- Which accounts. Approve Copilot Chat and Microsoft 365 Copilot signed in with a work account only. Work-account use is covered by Microsoft's Data Protection Addendum and enterprise data protection; a personal Copilot account is not10.
- Web search. Decide whether Copilot may send search queries to Bing, and for whom. Those queries are not covered by the Data Protection Addendum10,11.
- Model providers. Anthropic models are on by default for most commercial tenants outside the EU, EFTA and UK, and administrators can restrict them to named groups13. Decide whether that is acceptable for client work.
- Meeting transcription. Copilot in Teams needs transcription or recording to work after a meeting, and VoIP participants see a notice that the call is being transcribed or recorded15. Decide when staff may use it with clients.
A template outline you can adapt
Use these headings in this order. Each one has a line on what to write. Keep sentences short; this document will be read on a phone in a lunch break.
- Purpose and scope. Why the policy exists, who it covers (employees, contractors, temps) and which devices and accounts it applies to.
- Approved tools. Name Microsoft 365 Copilot Chat and Microsoft 365 Copilot with a work account. List anything else that has been approved, and say that other AI tools need written approval from the policy owner.
- Information you may and may not enter. Use three plain categories. Open: public or marketing material. Internal: business documents covered by your Microsoft 365 permissions. Restricted: health information, bank and identity details, information under legal privilege, and anything a client contract restricts. Say what each category may be used for.
- Good uses. Give five to ten examples from your own business, such as drafting replies in Outlook, summarising a Teams meeting the attendees agreed to transcribe, or checking an Excel formula.
- Not allowed. For example, making decisions about a person's employment, credit or tenancy based on Copilot output alone; pasting Restricted information into web-grounded chats; presenting AI output as professional advice without review.
- Human review and accountability. The person who sends or publishes an output owns it. Microsoft itself says generated responses are not guaranteed to be 100% factual7.
- Customers and transparency. When you will tell customers that AI helped, and how you will answer if they ask.
- Meetings and recordings. When transcription is allowed, and that participants must be told before it starts.
- Security and settings. Who administers Copilot, which settings are on, and where staff report a mistake.
- Privacy incidents. How to report a suspected privacy breach to the privacy officer straight away, so the business can decide whether to notify the Commissioner.
- Training and support. What training people get before they receive a licence, and who the internal champions are.
- Wellbeing and workload. A commitment that Copilot will not be used to monitor individual performance, and that people can raise workload concerns as roles change.
- Review. The policy owner, the review cycle, and the date of the last consultation with staff.
Writing the information categories well
The information categories do most of the work, so test them against real documents. Take five files from different teams and ask a staff member which category each falls into. If two people give different answers, the wording is too vague.
Tie the categories to tools you already own. If you use Microsoft Purview sensitivity labels, Copilot honours the usage rights of encrypted, labelled content7. Your Restricted category can then say: if a file carries the Highly Confidential label, do not upload it or paste from it. A policy that points to a visible label is easier to follow than one that asks people to judge sensitivity from memory.
Be careful with blanket bans on personal information. Most client work involves names and email addresses, and Copilot in Outlook exists to help with that mail. The Privacy Commissioner's focus is on whether the use is necessary, transparent and secure, and whether outputs are checked, not on whether a name ever reaches an AI tool2.
Consulting staff without slowing the rollout
Consultation on a policy does not have to take months. It does have to be real. Employment New Zealand says that where consultation is required, employers must allow time for it and consider the feedback before finalising the policy, and it recommends consulting even when it is not a formal requirement5. Good faith also means giving staff relevant information about proposed changes and a chance to comment before final decisions6.
A practical sequence for a small business is a draft circulated with a short explanation, a staff meeting where people can raise concerns, a set period for written comments, and a final version that notes what changed. Keep a record of the comments and your response; it is your evidence if the policy is later disputed. If staff are covered by a collective agreement, check whether it sets its own process for workplace change5.
A worked example: a Christchurch building firm
Take a generic residential building company in Christchurch with site managers, estimators and a small office team. Everyone has Copilot Chat; estimators and the office manager have Microsoft 365 Copilot licences.
The owner and the office manager, who is also the privacy officer, start with the four tenant decisions. Web search stays on, because estimators look up product data and council requirements, but the policy places client contracts and subcontractor bank details in the Restricted category. Teams transcription is allowed for internal meetings, and for client meetings only after the client agrees at the start. The approved-uses list is built from a staff workshop: drafting variation letters from site notes, summarising long specifications, turning a site diary into a weekly client update, and checking cost spreadsheets in Excel.
During consultation, two site managers ask whether Copilot will be used to judge their productivity. The final policy adds a line in the wellbeing section saying Copilot usage data will be reviewed for adoption only, not for individual performance. That one change does more for uptake than any training session.
Keeping the policy alive
Microsoft changes Copilot often. Anthropic models, for example, arrived as a default subprocessor in January 202613. Assign one person to read the Microsoft 365 message center each month and flag changes that touch the policy.
Review the whole document at least once a year, and after any privacy incident involving AI. Each review is also a chance to update the good-uses list, which is the part staff read most.
- Put the policy in the same SharePoint location as your other workplace policies, so Copilot can find it when staff ask.
- Ask new starters to read it before their licence is assigned.
- Keep a short log of exceptions approved by the policy owner.