AI Agents in Outlook and Teams: London SME Guide

AI Agents in Outlook and Teams: Who Approves, Who Pays, Who Is Liable

11 September 2026

Mailbox software changed from 2026 onwards. The AI agents in Outlook and Teams now have their own identity and work independently of oversight, using a usage-based billing model. For a London firm running on the Microsoft Teams collaboration platform, the question is no longer what the technology can do, but who signs off and what it costs next month.

AI agents in Outlook and Teams shown on a Microsoft 365 dashboard as a London SME team reviews approvals and credit costs.

Key Takeaways

  • Three distinct layers now exist: In-app Copilot assistance, Copilot Cowork Task Agents and Autopilots such as Microsoft Scout that run continuously. Each has different approvals and risk profiles.
  • Copilot Cowork reached general availability on 16th June 2026. The cloud-powered solution for multi-step processes works in Outlook and Teams and comes preloaded with 13 built-in skills.
  • Billing is no longer purely per seat. As of 1st July 2026, the usage-based Copilot Credits billing system became mandatory at the US list rate of $0.01 per credit.
  • “Copilot Actions” is an ambiguous term covering at least three separate Microsoft features. Clarify which of the three options the vendor offers.

What are AI agents in Outlook and Teams?

AI agents in Outlook and Teams are software components that conduct multi-step tasks inside Microsoft 365 rather than simply generating text on request. Unlike an assistant, a schedule or an event can trigger an agent, chain several actions together, and operate against your organisational data within permissions an administrator defines.

This distinction is important because governance requirements can differ. An assistant helps users by delivering information and recommendations, while an AI agent can act by sending messages, creating tasks or scheduling meetings.

Microsoft now separates the agent layer into recognisable tiers:

  • Copilot assistance: Copilot in Outlook, Teams, Word, and Excel suggests, composes text, and even creates summaries, with users still in charge.
  • Task agents: Including Copilot Cowork, which works across multiple steps in different applications in a cloud-hosted, secure environment, so processes can keep running without requiring the device to be turned on.
  • Autopilots: A newer category of always-on agents with their own identity, acting on a user’s behalf within the permissions and policies an administrator sets. Microsoft Scout is the first, integrated across Teams, Outlook, OneDrive and SharePoint.

For most UK SMEs, the first tier is already in use, the second is a deliberate decision, and the third is a governance project rather than a feature toggle.

Is “Copilot Actions” the same thing as an AI agent?

No. “Copilot Actions” is an umbrella term that refers to three different Microsoft features as well as a typical application. Misunderstanding their differences creates licensing problems and unmet expectations. First, identify which Microsoft product interface you mean before analysing claims about its capabilities.

The four meanings currently in circulation:

  • Microsoft 365 Copilot Actions: Introducing Ignite 2024: Automated everyday actions made easy through fill-in-the-blank prompts that you can set and forget, like your daily end-of-day action item summary.
  • Copilot Actions in Copilot Labs: An experimental consumer feature for Copilot Pro subscribers, designed to complete everyday web tasks with pause, stop, edit and take-over controls. Not a tenant-managed capability.
  • Copilot Actions on Windows 11: The agentic layer operating on local files and the desktop, governed by device policy rather than Microsoft 365 policy.
  • Lowercase “Copilot actions”: Generic usage in Microsoft documentation, for example discoverable Copilot actions in OneDrive file preview, which display ready-to-use prompts beside the Copilot button.

When a supplier claims that Copilot Actions Microsoft 365 capability is included in a quotation, ask which of the four they mean and which licence carries it.

What can an AI agent do in Outlook day to day?

Outlook’s agent features can analyse the inbox, prioritise emails, help compose emails, and support scheduling and follow-ups, demonstrating Microsoft Outlook AI integration for email and calendar workflows. Starting in 2026, Copilot Chat in Outlook will focus more on analysing data not only within one thread but across the inbox and calendar.

One realistic daily output for the professional services team would be summarising threads with decisions and owners, prioritising and categorising by priority and sender, drafting documents in the house style, and scheduling meetings on various calendars through email and calendar automation.

Mobile has caught up. Copilot in Outlook mobile provides an interactive voice experience that summarises unread email and guides the user through drafting replies, deleting, archiving, pinning and flagging without touching the screen.

Be careful when working with shared or delegated mailboxes. Permissions will be determined by the permissions in use, and a liberal permission delegated for three years will emerge during the agent’s first run.

Because the agent reads across the whole Exchange Online mailbox environment, output quality is bounded by your permissions model rather than by the model itself.

What can agentic AI do inside Microsoft Teams?

In Teams, agents capture meetings, extract action items and surface organisational knowledge in channels. Agents can be discovered and installed from the Agent Store, and agents built with the Model Context Protocol are now reachable directly inside Outlook and other Office applications alongside Teams.

The meeting layer is where most SMEs see measurable return first because the work being replaced is genuinely low value: notetaking, action capture, and post-meeting distribution.

Distribution has also become governed. Agents built in Agent Builder can be submitted for administrator review and approval before publication to the organisation’s Agent Store catalogue, where they appear under a “Built by your org” section.

What happens to meeting notes and follow-up actions afterwards?

The transcript is no longer created by the end of the interaction. The extracted actions can be directed to the Tasks module, and an integrated Tasks window brings scheduled chat interactions and agent activities under one roof, so Copilot tasks appear there as well.

That visibility is the operational objective. It becomes a liability if an agent executes tasks invisibly; it becomes an asset if the agent’s activity is recorded in a list. Consider the Tasks View to be an artefact of weekly review.

How much do AI agents in Outlook and Teams cost a UK SME?

Cost is now split into two parts, rather than one: the per-user cost for a Microsoft 365 Copilot license and usage-based Copilot Credits for agent workloads. Usage-based Copilot Credits billing is now mandatory for all workflows starting 1st July 2026, at a US list price of $0.01 per credit.

Cost componentModelPredictabilityWho controls it
Microsoft 365 base subscriptionPer user, per monthHighProcurement
Microsoft 365 Copilot licencePer user, per month, add-onHighProcurement
Copilot Credits (agent workloads)Consumption, pay-as-you-go or prepaidVariableAdministrator and end users
Copilot Studio custom agentsSeparate consumption modelVariableDevelopment owner

The budgeting risk is straightforward. Seat-based licensing produces a fixed annual figure a finance director can forecast. Consumption billing produces a figure that moves with adoption, and adoption is exactly what a successful rollout is designed to increase.

There are two ways to deal with this problem. Activate the agent capability for a specific pilot team, not the entire tenant, and negotiate a monthly credit limit.

Sterling pricing and Enterprise Agreement terms vary by contract, so validate figures against your own tenant during a Microsoft 365 Copilot rollout rather than against published list rates.

Who approves what an agent does, and how is it audited?

The approving administrator is responsible for the enabled capability, and the data controller is responsible for it. Agent policies can be configured in the Copilot Control System in the Microsoft 365 Admin centre; sensitivity labels and audit logs go through Microsoft Purview; and Microsoft Agent 365 is the control plane for governable Entra identities for agents.

Three governance layers should be documented before go-live:

  • Enablement: The agent types are turned off by default and must be manually enabled by the administrator. Identify the person who enables them and when.
  • Permission boundary: The agent cannot provide content the identity cannot access anyway.
  • Activity trail: The agent’s activity and any tasks can be checked, and internal agents undergo administrative approval before making information available to the whole organisation.

For any business operating under the jurisdiction of the FCA, SRA, or ICO, it needs to establish a policy for which forms of communication may be managed automatically, along with proof of correct configuration. Microsoft documents the technical controls in its agents admin guide, and the Information Commissioner’s Office maintains AI guidance covering the accountability expectations above.

What should a London SME check before switching agents on?

The recommended order is to conduct the permissions audit first, then scope the pilot process, and then define approvals and credit ceilings. The biggest sequencing mistake is running agents for all a tenant’s sites before conducting the SharePoint and email permissions audit.

A workable order of operations:

  • Audit access: Determine the access rights to the SharePoint site, mailbox access, and guest access. Determine what information and communication channels are accessible only to agents.
  • Pick one workflow: High transaction volume, minimal risk, trackable. Meeting minutes and internal inquiries should be enough.
  • Set thresholds: Specify situations that require human intervention, especially when third parties, obligations, and contract wording are involved.
  • Cap consumption: Set a monthly credit limit and specify who is responsible for it.

Confirm entitlements against your current Microsoft 365 subscription licensing before committing to a pilot scope, as agent capability varies by plan.

How do you know whether the agents are saving time?

Calculate edit rate, escalation rate, incident rate, and cost per outcome. You cannot rely on users’ claimed time savings as an estimate alone. Edit rate refers to the percentage of generated text edited before submission and is the truest measure of quality possible.

MetricWhat it indicatesWarning sign
Edit rateOutput quality and tone fitRising above 50%
Escalation rateTriage accuracySudden increase after a rule change
Incident countGovernance failureAny wrong-recipient or wrong-commitment event
Credits per completed taskUnit economicsCost per outcome exceeding manual cost

Establish a baseline over two weeks before enabling anything. Without a baseline, every subsequent number is an assertion, not a measurement.

Review at 30 and 90 days. If edit rate is not falling and incident count is not zero, the cause is always configuration or data hygiene rather than the model, which is where structured ongoing Office 365 support tends to pay for itself.

How Does Microsoft 365 Copilot Differ from an AI Agent?

Microsoft 365 Copilot is an AI-powered assistant that responds to user prompts within Microsoft 365 applications and generates results that users can review. An AI agent can perform complex tasks, can be triggered by scheduling or events, and can change the system state. Agents differ from Copilot in governance and billing.

Do AI agents in Outlook send emails without my approval?

This depends on the agent’s level and the specific configuration involved. Standard Copilot support in Outlook still requires human intervention. The Autopilot class of agent is self-contained and can function under the administrator’s permissions. Companies need to clearly identify the categories of communications that must go through human approval before sending out anything externally.

What are Copilot Credits and how are they billed?

Copilot Credits measure the cost of an agent load at a list rate of 1 Cent per Copilot Credit. There are pre-paid plans available. Usage-based pricing applies to all agent loads from 1st July 2026. The monthly price depends on usage, not the number of people.

Can an AI agent see emails and files a user is not permitted to see?

No. Agents act based on the rights granted to the identity they operate under. The danger lies not in agents’ ability to circumvent permissions, but in revealing information that was already overexposed and never discovered.

Are AI agents in Microsoft 365 compliant with UK GDPR?

Microsoft offers technical and contractual measures such as encryption, tenant data isolation, and logging. However, it does not assume the compliance role, which remains the data controller’s obligation. The Data Protection (Use and Access) Act 2025 altered the automated decision-making process, and the ICO Code of Practice is to be released.

How do I turn AI agents off or restrict them for certain staff?

The Copilot Control System in the Microsoft 365 admin centre manages agent categories and keeps them off by default until you enable them. An administrator can scope availability by group, limit which agents are available in the Agent Store, apply sensitivity label restrictions, and require review of internal agents.