Copilot Cowork Is Generally Available: Check Access and Costs Before You Enable It
A Copilot license is not a promise that every new AI experience has unlimited usage included. With Copilot Cowork becoming generally available, that is the first thing I would explain to both IT and the person paying the invoice.
Microsoft announced worldwide general availability on 16 June. Cowork is designed to carry out longer, multi-step tasks across tools and information sources. You describe the work, rather than asking for one isolated answer.
That sounds useful. It also deserves a more deliberate rollout than simply enabling another chat feature.
Separate the license from the consumption
At launch, Microsoft specifies a Microsoft 365 Copilot user subscription plus usage-based Cowork charges in Copilot Credits. Consumption depends on model use, context retrieval, tool calls and runtime. So “one prompt” is not a dependable unit for estimating the cost of every task.
The launch announcement also describes scoped spending limits, usage alerts and reporting. Cowork is off by default, with administrators deciding when to enable it and who receives access. Review those controls before inviting users.
I would avoid putting a universal cost per task in a rollout presentation. Instead, select a few tasks your organization genuinely wants to perform and measure those during a bounded pilot. Document the billing terms that actually apply to your tenant.
Pick a task with a clear finish line
My first example would be a weekly internal project briefing. Use a small, approved collection of status documents and ask Cowork to prepare a draft update for the project owner.
A useful test instruction could be:
Prepare a draft weekly update from the three project status files I provide. Separate completed work, blockers and decisions needed. Cite the source for each material statement. Mark missing information explicitly. Do not send messages, change project records or create calendar events. Return the draft for my review.
This is an example to adapt, not a guarantee that an instruction alone blocks actions. Configure the available tools and permissions to match the intended scope, and test that the agent cannot take unwanted actions through them.
Put a person next to the budget
For a small pilot, I would name a business owner, an IT owner and a spending owner. Set an initial usage boundary, agree who can approve additional consumption, and decide what happens when the boundary is reached.
During the pilot, record the task, scope of sources, output quality, corrections required and reported credit consumption. Compare similar tasks rather than treating all activity as equivalent. A cheap result that needs to be rewritten is not necessarily the better result.
Check the actual protection surface
Do not translate “enterprise security” into “every Purview feature is already available for this experience.” The launch announcement lists supported controls separately and identifies some capabilities as arriving later.
Where a planned task depends on a particular protection, verify that protection before allowing the data into the pilot. Keep this review alongside your existing DSPM for AI work.
Final thoughts
Cowork makes the conversation about AI more interesting: not just “did it answer?” but “did it finish useful work?” Start with one task, a real owner and a controlled budget. The interesting automation can follow once those basics are clear.
Keep reading
11 Sept 2026
You Can Now Build Apps with Copilot Cowork and Copilot Studio
Have an idea for an internal app? Explore app building in Copilot Cowork and Copilot Studio, with a practical starter prompt and the checks IT should make first.
1 Sept 2026
Microsoft's Responsible AI Report: What You Still Need to Govern Yourself
Microsoft's 2026 Responsible AI Transparency Report explains its own governance work. Customers still need owners, approved use cases, evaluation and monitoring.
5 Aug 2026
Copilot Domain Exclusion: What Changed and What Admins Should Check
Domain Exclusion gives admins more control over web grounding, but its rollout changed. Here is the difference between the control and disabling web search entirely.
Comments
Loading comments…