Microsoft has been auto-installing the Copilot app across Irish organisations this summer. For most, AI arrived on the desktop before the policy did — and that ordering is the problem.
Something changed on Irish desktops between mid-June and mid-July, and most organisations did not decide it. Microsoft resumed automatically installing the Microsoft 365 Copilot app on eligible Windows devices running commercial Microsoft 365 desktop apps, unless an administrator had opted out through the Microsoft 365 Apps admin centre. The signal is unambiguous: Microsoft now treats Copilot as a default layer of the Microsoft 365 experience, not an optional assistant you choose to switch on.
For a large number of Irish organisations, that means AI arrived on the desktop before the policy did. And the ordering is the whole problem.
The governance gap this opens
For two years the governance conversation has been framed as a decision an organisation gets to make: should we adopt Copilot, and if so, under what controls? Auto-install quietly removes the "if". The tool is present, visible in the app tray, and available to staff who never attended a rollout session and never read a usage policy — because in many cases no usage policy exists yet.
This is not a hypothetical risk. The consistent finding across enterprise deployments is that data governance is the single biggest roadblock to Copilot adoption, precisely because the tool inherits the permissions of the person using it. Copilot can surface anything an employee already has access to, and in most organisations employees have access to far more than anyone has audited — the half-forgotten SharePoint site, the finance folder shared too broadly three restructures ago, the HR documents that were never properly locked down. The app does not create the oversharing. It makes it queryable in natural language, which is a different order of exposure.
When a tool with that reach installs itself by default, the absence of a policy is no longer a neutral state. It is an active governance failure, because the controls that should have preceded the tool are now running behind it.
Why the timing is unusually poor
This would matter in any month. It matters more in this one, because the auto-install wave lands days before the EU AI Act's Article 50 transparency obligations begin to apply in Ireland on 2 August 2026. Article 50 governs how organisations disclose AI-generated and AI-assisted content and interactions. An organisation that does not know which staff are using Copilot, for what, and on which documents, is not in a position to make the disclosures the regulation now expects — because it cannot see its own usage.
The Irish enforcement model sharpens this further. As we have written in which regulator actually supervises your AI in Ireland, the body assessing your AI is usually your existing sector regulator, not a generalist newcomer. The Central Bank, the Data Protection Commission and others already hold a supervisory history with you and already have a view of where you cut corners. "Microsoft installed it automatically" is not an answer any of them will find persuasive. Deployer obligations under the Act sit with the organisation, not the vendor pushing the update.
What to actually do about it
The instinct is to reach for a policy document. That is the second step, not the first. A policy written without knowing what is already happening in the tenant is a guess, and guesses in this area tend to be either so restrictive that staff route around them or so permissive that they authorise the exposure they were meant to prevent.
The first step is to look. Pull the tenant's Copilot usage data and establish who has the app, who is actively using it, and against what content. Run a permissions review on the repositories Copilot can reach, because that map — not the app itself — defines your real exposure surface. Only then does a policy have something to govern: it can name the workflows that are encouraged, the data that is off-limits, and the disclosure practice that Article 50 now requires, all grounded in what the organisation is actually doing rather than what it imagines it is doing.
There is a strategic point buried in this that is easy to miss in the rush to control it. Auto-install has handed most organisations a live, tenant-wide picture of where AI genuinely earns its place and where it sits idle — the same diagnostic signal we described in the question to ask before renewing Copilot. Governing the default deployment well and reading the usage data it generates are the same piece of work. Done together, the compliance task and the value task stop competing for attention and start funding each other.
Turn the default into a decision
Copilot being on by default does not have to mean it is ungoverned by default. But closing the gap requires deliberate work in a narrow window, before the Article 50 date makes the absence of visibility a compliance question rather than an operational one.
If Copilot has appeared across your organisation ahead of any policy to govern it, this is exactly the situation our Copilot Adoption Diagnostic is built for — a fixed-fee, vendor-neutral read of what is actually running in your tenant, with a governance and disclosure plan attached. We are not a Microsoft partner and we do not resell licences, which is precisely what makes the assessment worth having. Book a diagnostic conversation, and turn a default you did not choose into a decision you did.