Copilot Governance for Law Firms: Who Audits Autopilot?

Copilot governance for law firms diagram showing Copilot AI assistant and autopilot agent permissions interacting with permission boundaries to protect confidential client data, legal matters, and contracts.

I had a call last week with a managing partner who was genuinely excited about Copilot’s Autopilot rollout. New workspace, multiple models to choose from, agents that can run tasks on their own. He described it almost like hiring help. And in a way, that is exactly what it is. Which is why I stopped him before he got too far into the pitch.

If you are hiring help, someone has to check references first.

What Changed in Copilot This Month

Microsoft restructured Copilot into three areas this September: Home, Code, and Autopilot. That part is mostly cosmetic. The part that should get a general counsel’s attention is underneath it. Copilot now supports multiple models, including a newer OpenAI reasoning model alongside its existing options, so a firm can route different work to different engines depending on the task. Autopilot agents, meanwhile, run with their own identity and their own permissions rather than simply acting as an extension of whoever is logged in.

Microsoft frames this as governance progress, and honestly, it kind of is. An agent with a defined identity is easier to audit in theory than an agent quietly borrowing a partner’s credentials. Usage based billing and stronger FinOps tracking came along with the update too, which is Microsoft’s way of saying they know firms are worried about cost sprawl as much as data sprawl.

None of that answers the question a client would ask if they knew to ask it: which matters is this agent allowed to touch, and who decided that.

Why An Agent Having its Own Identity is Not the Win It Sounds Like

Here is the thing about identity. It tells you who acted. It does not tell you what they should have been allowed to act on. A paralegal has an identity too, and firms still run conflict checks and matter level access controls on top of that, because identity alone was never the control.

The American Bar Association’s practice management column has been pushing exactly this point to firms evaluating Copilot deployment, and I think it is the right instinct. Before you deploy, you map what the tool can reach, not just who it says it is when it reaches it.

 

What worries me about Autopilot specifically is scale. A person forgets to log out of a shared matter folder once in a while and it gets caught in an access review. An agent with standing permissions runs continuously, across every matter its identity has been granted access to, without the natural friction of a human getting bored or distracted or going on vacation. That is not a knock on the technology. It is just what happens when you remove the human pace from a permission structure that was designed around human pace.

An agent that never gets bored will use every permission you gave it, exactly as often as it is allowed to.

The Model Selection Problem Nobody is Pricing In

Multi model routing sounds like a convenience feature. Pick the model that fits the task, get better output, move on. For a law firm, it is also a data residency and privilege question wearing a convenience feature’s clothes.

If your firm has not set a policy for which model handles which kind of matter data, you have effectively delegated that decision to whoever configured Autopilot’s defaults, or worse, to the agent’s own task by task judgment. Sensitive work product routed to a general purpose reasoning model because it happened to be the default that week is not a hypothetical. It is what happens in the absence of a stated policy, on a long enough timeline, at any firm running multiple models without a documented routing rule.

I have sat through enough security committee meetings to know how this usually goes. Someone asks whether the firm has a policy on which AI model can see privileged material. There is a pause. Someone says they will look into it. Three months later it is still on the list.

What Copilot Governance for Law Firms Has to Mean Now

A version that survives a client audit needs three things this update just made non-negotiable.

First, a permission map for every Autopilot agent in use, reviewed on the same cadence as human access reviews, not treated as a one time setup task. Second, a written model selection policy that states plainly which categories of matter data may route to which models, with sensitive and privileged categories excluded from general purpose routing by default rather than by exception. Third, a FinOps review that doubles as a usage review, since the same usage based billing data that tells you what Copilot is costing also tells you what it is touching, if anyone bothers to read it that way.

 

None of this is exotic. It is the same discipline firms already apply to associates and contract attorneys, just extended to a tool that does not sleep and does not ask for time off.

How This Compares to the Access Problem Firms Already Know

I think the reason this update caught so many firms flat footed is that it looks new, and it really is not, not underneath. Firms have spent years building access control discipline around human users. Who can see which matter. Who gets removed when they leave. Who gets flagged when their access pattern looks wrong for their role. That discipline exists because firms learned, sometimes the hard way, that trusting a person’s job title was never enough on its own.

An Autopilot agent is not a person, but it behaves like one for access purposes now. It has an identity. It has standing permissions. It acts continuously inside systems that hold privileged material. The discipline that already exists for human access review is the right starting template. What is missing at most firms is simply extending that same discipline to a non human identity, rather than treating agent access as a separate, lighter touch category because it feels newer or more technical.

 

I would also push back gently on a framing I hear a lot, which is that agent governance requires entirely new tooling and entirely new expertise. Some of it does. Most of it does not. A firm that already runs disciplined access reviews for its people has the muscle memory to do this. The gap is usually attention, not capability. Nobody added Autopilot agents to the existing review cadence yet, because the update is new enough that it has not made it onto anyone’s checklist.

That is a fixable gap. It just has to get fixed, and soon, rather than sitting on next quarter’s list the way the model policy question usually does.

A Short List Before You Flip Anything On

Before your firm turns on Autopilot broadly, walk through this with whoever owns security and whoever owns the matters most likely to be affected:

  • Which matters, practice groups, or client categories are Autopilot agents currently permitted to access, and who approved that list
  • Is there a written model routing policy, and does it name specific model providers for specific data sensitivity tiers
  • Who reviews agent permissions, and on what schedule, separate from the initial deployment sign off
  • What does the usage based billing data show about which agents are touching which systems

 

I keep coming back to the same line whenever a client asks me whether Copilot is safe enough to deploy. Copilot’s controls are Microsoft’s door lock. A good one, increasingly. But the house still belongs to the firm, and nobody outside your walls is going to walk it room by room checking which doors got left open. For more on how Copilot governance for law firms has evolved since deployment first ramped up, and how it connects to broader Copilot readiness planning, those are good next reads before your firm’s next Autopilot rollout meeting.

Microsoft has published its own guidance on the security and governance controls available inside Copilot, which is worth reading directly rather than taking a vendor’s summary of it:  Copilot controls security and governance. The ABA has also weighed in with practical deployment guidance aimed squarely at firms in this position: What Should Law Firms Do Before Deploying Copilot.

If your firm has not run a permission level review since before this update shipped, that is the actual starting point, not another feature comparison. A Zero Trust Assessment is where I would start that conversation.

Quick Answers

  • Does Microsoft’s Autopilot permission model replace the need for firm level access reviews?
    • No. It gives an agent a defined identity to review, which is genuinely useful, but the review itself still has to happen at the firm level, on a set schedule, by someone who understands which matters carry heightened sensitivity.

 

  • Can a firm restrict which model handles privileged matter data?
    • Copilot’s multi model routing supports policy level restriction, but the policy has to be written and configured deliberately. Left on defaults, routing decisions are made by the tool rather than by the firm.

 

  • Who should own Copilot governance for law firms internally?
    • In most firms I work with, it sits jointly between IT security and the general counsel’s office, with security owning the technical permission map and the GC’s office owning which matter categories require the strictest routing and access rules.

Recent Posts

Have Any Question?

Call or email Cocha.  We can help with your cybersecurity needs!

About the Author:

Picture of Steve Combs

Steve Combs

Co-Founder & Managing Director, Cocha Technology

Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.