TL;DR: Microsoft Copilot Autopilot is an always-on AI agent inside Microsoft 365 that works from a name, a role, and a goal, with its own Microsoft Entra identity, and enters private preview at the end of September 2026. INVITE’s advice: fix permissions, data labels, and agent approvals before an agent that never logs off inherits them. This guide is for CIOs, CTOs, and IT Directors at mid-market and enterprise organizations. On September 25, Microsoft rebuilt its Copilot app around three tabs: Home, Code, and Autopilot. The third needs a plan now: Copilot Autopilot doesn’t wait for a prompt, and it keeps working after its creator goes home. What Is Microsoft Copilot Autopilot? Copilot Autopilot is a persistent AI agent that runs inside your Microsoft 365 tenant, follows the channels and threads it is assigned to, and completes recurring work without being asked. Users give it a name, a role, and a goal, then @mention it in Teams, Outlook, or a document like a colleague. Microsoft previously called it Scout. Each instance gets its own identity, memory, and cloud workspace, governed through Microsoft Agent 365. Home and Code reach Microsoft’s Frontier early-access program in the coming weeks. Autopilot starts private preview at the end of September. Why Does an Always-On Agent Change the Governance Question? An always-on agent turns every existing permission problem into a live one. Copilot Chat surfaces an overshared file when someone asks the right question. Autopilot works across Teams, Outlook, and SharePoint continuously, so a finance site open to the whole company becomes something an agent can act on at 2 a.m. Satya Nadella set the standard at launch: “Everything that you observe should be governable by policy.” Policy only governs what you’ve configured. TechTimes also reports that Autopilot is built on OpenClaw, an open-source agent framework with a long public vulnerability record. Governance controls what an agent may do; it doesn’t prove the runtime is patched. Ask Microsoft directly before any agent touches regulated data. What Should IT Leaders Lock Down Before Autopilot Reaches Their Tenant? Fix oversharing first. Run a SharePoint and Teams access review. Retire company-wide permissions on sites holding HR, finance, legal, or customer data. Label sensitive data. Apply Microsoft Purview sensitivity labels and data loss prevention policies. Agent guardrails are only as good as your label coverage. Control who creates agents. Require admin approval, and use Microsoft Entra agent identities and Agent 365 to inventory every agent, its owner, and its scope. Pilot narrowly. One team, one workflow, such as project status follow-ups. Name a human owner per agent and review audit logs weekly. Define success up front. Track hours returned, task completion rate, and how often the agent escalates to a person. If you can’t measure it, you can’t defend expanding it. How Does INVITE Help Salt Lake City and Phoenix Teams Get Agent-Ready? INVITE is a Microsoft partner that has guided mid-market IT teams through Copilot deployment since its early rollout. Our AI Readiness Assessment starts where agents start: permissions, data classification, identity, and the workflows worth automating. For the groundwork, read how to deploy Microsoft Copilot without losing control of your data, then pair it with an enterprise AI strategy. Frequently Asked Questions Is Copilot Autopilot available now? Not broadly. Autopilot enters private preview at the end of September 2026 for organizations Microsoft selects. Most tenants won’t see it yet, which makes this the right window to clean up permissions and set agent policies. How is Autopilot different from Copilot Chat? Copilot Chat responds when asked. Autopilot runs persistently with its own identity, memory, and workspace, works toward an assigned goal, and keeps going while the user is offline. That shift from answering to acting is why governance comes first. What is Microsoft Agent 365? Microsoft Agent 365 is the control plane for inventorying, governing, and securing AI agent identities across a tenant. Autopilot’s permissions and audit run through it. Does Autopilot need new security controls? Mostly it needs existing controls to actually work: least-privilege access, sensitivity labels, data loss prevention, and conditional access. Then add approval before agent creation, a named owner per agent, and regular audit-log review. Is your tenant ready for agents that never log off? Book an AI readiness assessment with INVITE. We’ll review your permissions, labels, and identity controls and tell you exactly what to fix before Autopilot arrives.