on the record · Aug 2026

Copilot is licensed. That doesn't mean it's governed.

A Copilot licence is a buying decision, not a governance one. The gap between having Copilot and proving what it touched is where the risk lives.

Aug 20264 min readBy gopal joshi, Founder, Stringify AI

A license is not a governance decision#

Someone in your company bought Copilot and turned it on. That was a buying decision. It is not the same as a governance decision, and the gap between the two is where the risk hides.

A license answers one question: can people use this? Governance answers harder ones. Who is allowed to use it? On what data? What gets recorded? And if someone asks "why did it do that?" — can you show them? None of that comes switched on with the license. You bought the tool. You did not buy the proof.

The problem is usually boring, not dramatic#

Most AI mistakes inside companies are not hacks. They are people using the tool the wrong way. Someone pastes a client contract into a model to get a summary. A Copilot workflow reads a field it should not. No attacker. No headline. Just normal software doing normal things that no one can prove afterward.

Watch the work before you trust it#

So "we have Copilot" and "we can prove what Copilot did" are two different sentences. Closing that gap is not a setting you switch on. It is a habit: watch the work before you trust it.

That is what an Inspector does in Watch mode. It sits next to the AI already running in your work and records what it does — on your own systems — before it is allowed to act on its own. You don't govern Copilot by trusting the switch that turned it on. You govern it by being able to show what it did.

The three questions a licence does not answer#

Most organisations discover the gap in the same order, and usually in a meeting where somebody senior asks a reasonable question.

Who is allowed to use it, on what? A licence is assigned to a person. The permission that matters is the one attached to the data they can already reach — because that is what the assistant inherits the moment it is switched on. A person who could technically open a folder but never did now has a tool that opens it instantly and summarises it.

What gets recorded? Not "is there a log" — every product has logs. The question is whether the record answers the thing you will actually be asked: which documents informed this output, and would you be able to show that in six months.

What happens when it is wrong? Assistants are most useful on work nobody wants to do, which is often work nobody wants to check either. That combination is where a wrong answer travels furthest before anyone notices.

Why governance lags the licence by design#

None of this is a criticism of the tool. A licence is a commercial arrangement, sold on a subscription cycle, decided by whoever owns that budget. Governance is a slow, cross-functional argument involving legal, security and whoever owns the data. The two run at completely different speeds, and the fast one always ships first.

That is fine, as long as somebody notices the gap has opened. What goes wrong is when the licence is mistaken for the decision — when "we have Copilot" is treated as an answer to "how are we governing AI", which it never was.

What to do about it this quarter#

Do not start with a policy. Start with one workflow where the assistant is already used daily, and find out what it reads. That takes a week, needs no procurement, and reliably produces at least one surprise.

Then ask who would catch a wrong answer in that workflow, and how long it would take. If you can name the person and the moment, you have a system worth extending. If you cannot, you have found the thing to fix — and it is not the model.

Watch mode does the first part without touching anything. It sits beside the AI already running in your work and records what it does. You end the six weeks with a description of the workflow, which is the one thing policy cannot be written without.

The sentence to listen for#

In most organisations the gap announces itself in one phrase, usually said reassuringly: "it only sees what the user can already see."

That is true, and it is the problem. Permissions accumulated over a decade on the assumption that access is bounded by effort — that nobody would actually read four thousand documents in a folder they technically have rights to. An assistant removes the effort, and the assumption goes with it.

So the honest version of that sentence is longer. It only sees what the user can already see, instantly, in bulk, summarised, and without leaving a trace anyone would recognise as reading.

← On the record

On the record

The license was the easy part. The proof is the work.
gopal joshi
Founder, Stringify AI
See what an Inspector catches in Watch mode →
gopal joshi, Founder of Stringify AI