EU AI Act in Microsoft 365
The AI Act asks deployers hard questions. Your tenant holds the answers.
An organization running Copilot, Copilot Studio agents and third-party AI apps is a deployer in AI Act terms - with obligations that are concrete: human oversight by competent people, control over what data the AI is exposed to, automatically generated logs kept at least six months, transparency about what runs. 1Security answers each one from the tenant itself: the inventory, the oversight assignments, the declared restrictions with their violation lists, and a retention attestation - rolled up per agent into an evidence pack an auditor can hold.
The scenario
The obligations arrived before the tooling did.
The AI Act has been arriving in phases: prohibited practices since February 2025, general-purpose AI obligations since August 2025, and the high-risk regime now set for December 2027 after the Digital Omnibus moved the wall. That date is not a reprieve - it is the window in which every deployer stands up AI governance that actually operates.
The obligations read like a security backlog, not a legal one. Who oversees each AI system, and are they competent and authorized? What data can each system reach, and is that controlled? Are the logs kept, and for how long? A policy document answers none of it; a tenant, read properly, answers all of it.
And most of the evidence already exists in Microsoft 365 - agents with identities, audit logs, permission graphs. What is missing is the assembly: one place where the inventory, the oversight, the data controls and the logs meet per AI system, in the article-shaped form a regulator asks for. That assembly is what 1Security builds, continuously.
The walkthrough
Four obligations, answered from the tenant.
Each beat maps to an article family - and each is a screen, not a binder.
- 01
Inventory every AI system
The Agents screen holds every agent from Copilot, Copilot Studio, Azure AI Foundry, Entra Agent ID and third-party vendors - with origin, blueprint, reach and activity. Transparency starts with a complete list, and shadow agents are exactly what a registry of the registered cannot show.
- 02
Assign competent oversight
Every agent carries an owner and a sponsor, ownerless agents are their own filter, and every enforcement action routes through a human approval in a review window. That is Article 26(2) - oversight by natural persons with competence and authority - as a working screen instead of an org-chart annex.
- 03
Control the data exposure
Declare the sensitive types your AI must not touch - no-AI-access on payment cards, health data, payroll - and every agent, app and user still reaching them is a live violation with the declaration recorded. Data governance as a control with a count, not a paragraph.
- 04
Keep the logs, attest the retention
AI interaction logs are retained well past the Act's six-month floor, and the evidence pack attests it - 183 days guaranteed, with three years of history on standard licenses in practice. The pack rolls it all up per agent: article-level mapping, oversight status, restrictions, remediation trail.
What makes it work
Three parts of the platform behind the answers.
The compliance view scores the same controls against NIS2, GDPR Article 32, DORA and ISO/IEC 42001 - one set of controls, several auditors served.
AI agent inventory
Every agent across every ecosystem with owners, blueprints and reach - the population every AI Act answer starts from.
Explore the feature →AI data restriction
The data-governance control: declared restrictions with blast-radius previews, violation lists and recorded history.
Explore the feature →Audit and evidence
Three years of activity history, per-actor attribution, and exports that hold the filter state they were produced with.
Explore the feature →
FAQ
Common questions.
Are we a provider or a deployer under the AI Act?
An organization that runs Copilot, builds Copilot Studio agents for its own use, or consents third-party AI apps into its tenant is a deployer for those systems. Deployer obligations - oversight, data control, log retention, transparency - are exactly the ones this page describes. Building and selling an AI system makes you a provider, which is a different and heavier set.
Which deadlines actually matter?
The Act applies in phases: prohibited practices since February 2025, general-purpose AI obligations since August 2025, and the high-risk regime of Annex III from December 2, 2027, after the Digital Omnibus deferral. The practical reading: the oversight, logging and data-governance groundwork is already due, and the 2027 date is the window to make it operational rather than documentational.
What does an auditor actually receive?
A per-agent evidence pack: the agent, its owner and sponsor, its permissions and knowledge reach, declared restrictions with violation history, the remediation trail, and a log-retention attestation - each element mapped to the article it answers. It is exportable as a document and pullable over the read-only REST API auditors can be given directly.
Does this cover more than the AI Act?
Yes - frameworks are data, not separate products. The same controls are scored against NIS2, GDPR Article 32, DORA and ISO/IEC 42001 in the compliance view, so the restriction you declare for the AI Act answers the DORA access-control question in the same pass.
Do we need E5 or Copilot licenses for this?
No. The inventory, oversight assignments, restrictions and log retention run on the standard read-only connection and the licenses you already own. Where a specific Microsoft control needs its own license - a Copilot license for site-level content controls, for instance - the product says so on the row rather than assuming it.
Walk into the AI Act audit with the tenant on your side.
Connect read-only and the inventory, oversight gaps and data-exposure answers land the same day. The evidence pack builds itself from there.
Or answer the deployer questions from a policy binder.