What the EU AI Act requires of organizations
Run Copilot and agents in Microsoft 365 and the EU AI Act's duties for organizations that use AI systems land on that estate:
Know which AI systems you run
Keep a live register of every Copilot deployment and agent, with owner and purpose.
AI literacy for operators
Support the AI literacy of the staff operating AI systems on your behalf.
No prohibited practices
Social scoring and untargeted facial-image scraping are banned outright.
Transparency toward people
Tell people they are dealing with AI and mark generated content machine-readably.
Who it applies to
Applies to organizations deploying AI systems in the EU, whatever their industry, with the first obligations in force since 2 February 2025.
Where the Microsoft estate breaks it
The Microsoft estate is where AI systems appear fastest and least visibly, so these duties fail quietly inside it:
Agents multiply outside any register
Any licensed user can spin up a Copilot Studio or SharePoint agent, live in no inventory.
No owner, no oversight
Agents keep answering after their builder leaves, so Art. 26 oversight has no one to attach to.
No operating evidence
Which agents run, who uses them and what they touch is scattered across per-service logs.
Copilot inherits oversharing
Agents read at the permissions the tenant grants, so every overshared site becomes AI reach.
How Rencore maps to the EU AI Act
Rencore inventories, governs and evidences the Microsoft slice of your EU AI Act scope: the AI & Agents module covers Copilot, Copilot Studio agents and SharePoint agents, while Apps, Automation and BI and Digital Workplace govern the automations, workspaces and data those agents depend on. It complements Microsoft controls such as Purview and Agent 365, never replaces them.
AI inventory, agents included
Every Copilot deployment, Copilot Studio agent and SharePoint agent in your tenant, with its owner, purpose and the data it can reach.
See how your AI is answering
Response-accuracy signals surface when Copilot or an agent drifts, so a named owner can review the behaviour and step in.

Operation monitored continuously
Policies run across agents and the data they depend on, routing violations to owners so operation is evidenced continuously.

Exportable evidence for authorities
Reports and exports, scheduled or on demand, answer audit and authority requests with evidence instead of screenshots.
Mapping at a glance
How each Rencore capability answers a specific article of the EU AI Act.
- AI inventory Art. 26
Every Copilot deployment and agent, with owner and purpose.
- Human oversight Art. 26(2)
Oversight assigned to a named, accountable person.
- Operation monitoring Art. 26(1), 26(5)
Agent operation evidenced continuously, not reconstructed.
- Exportable evidence Art. 26(12)
Answer authority requests with exports on demand.
Inventory, control and exportable evidence for your Microsoft estate.
No tool makes you EU AI Act-compliant on its own; that judgement stays with your organization and its market-surveillance authority, on the evidence.
Trusted by security, IT, and platform leaders
Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.
Frequently asked questions
Am I a deployer or a provider with Copilot and Copilot Studio?
What does our register of AI systems need to contain?
When do the obligations start?
How do the EU AI Act and GDPR stack?
Related reading
The neighboring EU regulations converge on the same Microsoft inventory. These cover the obligations next door:



