Try For Free
EU AI Act, Regulation (EU) 2024/1689

Prove EU AI Act control of your Microsoft 365 and AI estate

The agents multiplying in your Microsoft tenant are AI systems the EU AI Act holds you answerable for, and most of them are in no register.

A Rencore Governance compliance summary for the service Copilot: a donut chart at 75 percent, with 2,652 compliant items against 9 high, 865 medium and 0 low policy violations

Trusted by the world’s leading organizations

  • MAPAL
  • bam
  • VDL
  • Wacker
  • Grundfos
  • Amgen
  • Lufthansa
  • thyssenkrupp
  • Sunrise
  • Pattern

What the EU AI Act requires of organizations

Run Copilot and agents in Microsoft 365 and the EU AI Act's duties for organizations that use AI systems land on that estate:

Art. 26

Know which AI systems you run

Keep a live register of every Copilot deployment and agent, with owner and purpose.

Art. 4

AI literacy for operators

Support the AI literacy of the staff operating AI systems on your behalf.

Art. 5

No prohibited practices

Social scoring and untargeted facial-image scraping are banned outright.

Art. 50

Transparency toward people

Tell people they are dealing with AI and mark generated content machine-readably.

Who it applies to

Applies to organizations deploying AI systems in the EU, whatever their industry, with the first obligations in force since 2 February 2025.

Where the Microsoft estate breaks it

The Microsoft estate is where AI systems appear fastest and least visibly, so these duties fail quietly inside it:

Agents multiply outside any register

Any licensed user can spin up a Copilot Studio or SharePoint agent, live in no inventory.

No owner, no oversight

Agents keep answering after their builder leaves, so Art. 26 oversight has no one to attach to.

No operating evidence

Which agents run, who uses them and what they touch is scattered across per-service logs.

Copilot inherits oversharing

Agents read at the permissions the tenant grants, so every overshared site becomes AI reach.

How Rencore maps to the EU AI Act

Rencore inventories, governs and evidences the Microsoft slice of your EU AI Act scope: the AI & Agents module covers Copilot, Copilot Studio agents and SharePoint agents, while Apps, Automation and BI and Digital Workplace govern the automations, workspaces and data those agents depend on. It complements Microsoft controls such as Purview and Agent 365, never replaces them.

EU AI Act Art. 26

AI inventory, agents included

Every Copilot deployment, Copilot Studio agent and SharePoint agent in your tenant, with its owner, purpose and the data it can reach.

A Rencore Governance inventory tile for Copilot and agents with live counts: 37 Agent Builder agents, 37 elements, 7 capabilities, 63 knowledge sources, 6 actions and 1,255 Microsoft 365 Copilot sessions, each with its change over the period
EU AI Act Art. 26(2)

See how your AI is answering

Response-accuracy signals surface when Copilot or an agent drifts, so a named owner can review the behaviour and step in.

A Rencore Governance card tracking Microsoft 365 Copilot response accuracy over time, with the share of accurate responses and a trend chart
EU AI Act Art. 26(1), 26(5)

Operation monitored continuously

Policies run across agents and the data they depend on, routing violations to owners so operation is evidenced continuously.

Two Rencore Governance policy cards for Microsoft 365 Copilot: Copilot adoption opportunity for E3 and E5 users, medium severity, with 1,150 items checked and 821 violations found, and external website data source risk, high severity, with 26 items checked and 1 violation found, each with a three-month trend chart
EU AI Act Art. 26(12)

Exportable evidence for authorities

Reports and exports, scheduled or on demand, answer audit and authority requests with evidence instead of screenshots.

A Rencore Governance report table of M365 Copilot session counts by calendar week, CW26 to CW30 of 2026, showing 221, 618, 416, 0 and 0 sessions and a sum of 1,255

Mapping at a glance

How each Rencore capability answers a specific article of the EU AI Act.

  • AI inventory Art. 26

    Every Copilot deployment and agent, with owner and purpose.

  • Human oversight Art. 26(2)

    Oversight assigned to a named, accountable person.

  • Operation monitoring Art. 26(1), 26(5)

    Agent operation evidenced continuously, not reconstructed.

  • Exportable evidence Art. 26(12)

    Answer authority requests with exports on demand.

Inventory, control and exportable evidence for your Microsoft estate.

No tool makes you EU AI Act-compliant on its own; that judgement stays with your organization and its market-surveillance authority, on the evidence.

Trusted by security, IT, and platform leaders

Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.

  • With Rencore's scalable automation solutions, organizations can not only meet current challenges but also prepare themselves for future technological advancements.
    Case Study
    Philipp Widmer Philipp Widmer Head of Platform Services Universitätsspital Basel
  • 26% vs 3%

    Organizations that govern Microsoft 365 well realize significant Copilot value 26% of the time, versus 3% for those that do not.

    Gartner, 2025 Microsoft 365 Copilot Survey
  • As we continue to expand our cloud capabilities, the foundation laid by Rencore Governance will undoubtedly play a crucial role in ensuring that each step forward is taken with confidence, security, and compliance in mind.
    Case Study
    Claude Bisdorff Claude Bisdorff Head of IT Systems Ville de Luxembourg
  • 116%

    ROI from Microsoft 365 Copilot once the program is adopted and governed, in Forrester’s Total Economic Impact study.

    Forrester Total Economic Impact
  • I currently estimate that we save around €80k per year by freeing up our IT admin team to do the work that counts.
    Case Study
    Undisclosed Undisclosed Former Lead O365 Competence Center Royal BAM
  • 71%

    of enterprises name security and governance among their top challenges to deploying Microsoft 365 Copilot.

    Gartner
  • Rencore's centralized governance tool excelled at ensuring secure data in Microsoft 365 and minimizing the risk of unauthorized access.
    Case Study
    Greg Bowles Greg Bowles IT Operations Manager Specialist Risk Group
  • 150,000+

    AI agents in use at the average Fortune 500 company by 2028. Agent sprawl is the next sprawl.

    Gartner
  • With Rencore Governance we are able to reduce manual governance activities, improve our service quality and generate valuable insights across our Microsoft service stack.
    Undisclosed Undisclosed Head of AI & Process Automation Wacker Chemie AG

Frequently asked questions

Am I a deployer or a provider with Copilot and Copilot Studio?
A deployer uses an AI system under its own authority (Art. 3(4)); a provider develops one and places it on the market under its own name (Art. 3(3)). Running Microsoft 365 Copilot as Microsoft delivers it makes you a deployer, and building an agent in Copilot Studio for internal use normally keeps you one. The role can flip: put a high-risk system into service under your own name, or substantially modify one, and Art. 25 treats you as its provider. That is why your inventory has to record who built each agent and what it does, not just that it exists.
What does our register of AI systems need to contain?
The regulation assumes a register rather than handing you a template, because every duty attaches to individual AI systems. Per system you need: what it is and where it runs, its purpose and accountable owner, its risk class against Art. 5 and Annex III, whether its output reaches people (Art. 50), the data and permissions it depends on, and its usage logs (Art. 26(6) makes deployers of high-risk systems keep automatically generated logs at least six months). Rencore builds and maintains that record for the Microsoft estate.
When do the obligations start?
In stages, and most have already started. Prohibited practices and AI literacy apply since 2 February 2025; general-purpose AI rules and penalties since 2 August 2025; Art. 50 transparency and market surveillance since 2 August 2026; the marking duty for generative systems already on the market from 2 December 2026. The high-risk regime, including the Art. 26 deployer duties, applies from 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in regulated products, dates set by Regulation (EU) 2026/1744, in force since 27 July 2026.
How do the EU AI Act and GDPR stack?
They apply in parallel to the same estate. The EU AI Act governs the AI system: its classification, transparency and oversight. GDPR governs the personal data that system processes, so a Copilot prompt over HR documents is GDPR processing whatever the AI Act says about the tool. The two connect: deployers use provider information to carry out their GDPR Art. 35 assessments (Art. 26(9)), and since the 2026 amendment a fundamental rights impact assessment under Art. 27 may cross-reference an existing DPIA. One current inventory of your AI systems and the data they reach serves both.

See your Microsoft 365 and Agent estate the way an authority will

Start with the inventory: every Copilot deployment and agent in your Microsoft tenant, with owners and the data they reach, ready to answer the questions every obligation starts from.

The Rencore Governance top issues list for the service Copilot, ranked by severity: 8 Copilot licenses assigned to disabled accounts, 1 external website data source risk, 821 Copilot adoption opportunities for E3/E5 users and 37 inactive Copilot users, each with a trend sparkline