Quick summary

  • What is Copilot Wave 3? Microsoft’s latest phase of Microsoft 365 Copilot, where AI moves from assisting your team to acting on its behalf.
  • Key change: You can now build custom AI agents that follow rules and carry out tasks with little ongoing input.
  • New context layer: “Work IQ” lets Copilot understand your firm’s data and communication patterns for more relevant output.
  • On the horizon: “Copilot coworker” (in testing) can run longer, multi-step processes rather than single requests.
  • Why it matters for regulated firms: Autonomous AI creates accountability and audit questions, so you must be able to explain and defend every action it takes.
  • What to do: Approve agents deliberately, keep audit trails, define ownership, and adopt with governance before scale.

Copilot Wave 3 has arrived, and this one is different

If your firm relies on Microsoft 365 every day, you will have noticed that Copilot has not stood still. It has been quietly threading itself through Word, Excel, Outlook and the rest of the tools your people use from one hour to the next. Microsoft groups its larger updates into “waves”, releasing them in stages rather than all at once, and we have now reached the latest phase. For regulated firms in particular, Copilot Wave 3 deserves more than a passing glance, because the nature of the change is fundamentally different from what came before.

Earlier versions of Copilot were, at heart, an assistant. They drafted emails, summarised long documents and pulled together presentations. This was genuinely useful, time-saving work, yet you remained firmly in the driving seat, guiding every step. Wave 3 begins to loosen that grip. Rather than simply helping with individual tasks, Copilot is starting to take on responsibility within your workflows, and that distinction carries real weight for firms that answer to regulators, auditors and professional standards bodies.

From assistant to agent: the headline shift

The single biggest change in this wave is the ability to build your own AI agents inside Microsoft 365. In plain terms, an agent is a small, task-focused assistant that handles a specific slice of your working day. It can manage a repetitive process, follow a defined set of rules, and carry out actions without waiting for constant human prompting.

The possibilities are genuinely appealing. Imagine an agent that keeps client files organised to a consistent structure, one that supports an internal onboarding process, or one that handles the routine administration that quietly eats hours across a busy practice. For a mortgage broker, solicitor or accountancy firm, where consistency and repeatability are prized, that is an attractive proposition.

But an agent that acts on your behalf is a different governance object to a tool that merely drafts on your instruction. The moment an AI can take an action, whether that is moving a document, updating a record or sending a message, you inherit a new question: who is accountable for what it did, and can you evidence why? We explored a closely related theme in our piece on how AI agents cause governance blind spots, which is essential reading before you let any agent loose on live processes.

A more capable Copilot chat experience

Alongside agents, Copilot’s chat experience has grown noticeably more capable. You can now make changes to documents, emails, spreadsheets and presentations directly from a conversation, without hopping between screens. Ask, and Copilot acts within the file in front of you.

For fee earners and administrators under time pressure, that fluidity is welcome. Yet the same convenience blurs the line between “suggesting” and “doing”. In a regulated environment, where an amended figure in a client spreadsheet or a subtly reworded piece of advice can carry consequence, it becomes important to understand exactly what Copilot changed, when, and on whose authority. Convenience should never outpace traceability.

Work IQ: helpful context, and a data question worth asking

Wave 3 also introduces a new layer called “Work IQ”. This is Microsoft’s way of helping Copilot understand your business context more deeply. It draws on your firm’s data, communication patterns and internal content so that responses are tailored to how your team actually works, rather than serving up generic output.

In principle, that means sharper, more relevant assistance, a real benefit when your work is specialised and your language precise. But the very thing that makes Work IQ useful is also what makes it worth scrutinising: it depends on Copilot reaching into your internal information. For firms handling sensitive client data, the questions are familiar ones. Where does that data live, who can access it, and would the answers satisfy an auditor? If those questions feel uncomfortable, that discomfort is exactly the point. Our article on whether your data security is keeping pace with your business unpacks the gap between feeling secure and being demonstrably compliant.

More models under the bonnet

Microsoft is also broadening the range of underlying AI models Copilot can draw upon, incorporating technology from more than one provider. You do not need to concern yourself with the technical detail, but the practical effect is that Copilot should become more flexible and more capable over time. For a governance-minded firm, the takeaway is simply that the system is evolving beneath you, so your policies, approvals and oversight need to evolve with it rather than being set once and forgotten.

On the horizon: “Copilot coworker”

Looking a little further ahead, there is one feature worth watching closely. Microsoft is currently testing something called “Copilot coworker”, which extends the agent idea considerably. Instead of responding to a single request, a coworker can carry out longer, multi-step processes and run with them. You could hand over something more involved and let it work through the sequence on its own.

The productivity case writes itself. The governance case is more demanding. A multi-step, semi-autonomous process is precisely the kind of activity that can drift out of sight if nobody has designed in checkpoints. The right response is not to shy away, but to prepare, and preparation begins with a question every board should be able to answer confidently: if an AI process did something it should not, could you intervene quickly and explain what happened? We tackled that scenario directly in our post on how you would stop AI in an emergency, and it is a useful stress test for any firm considering more autonomous tools.

The controls Microsoft is adding, and why they matter

Encouragingly, Microsoft recognises that greater capability demands greater control. To support this wave, it is introducing tools to help businesses manage agents properly: visibility over what agents are doing, insight into how they are being used, and clarity on how they fit within your wider systems. This matters, because as Copilot becomes more powerful, it needs to be governed rather than merely enabled.

For a regulated firm, that management layer is not optional housekeeping. It is the foundation of a defensible position. Think of it in the same terms as any other operational risk: identify what could go wrong, put controls in place, monitor them, and keep evidence. Applied to Copilot, that means knowing which agents exist, who approved each one, what data they touch, and what actions they are permitted to take.

A practical governance checklist for regulated firms

Before you embrace agents and the wider Wave 3 capabilities, a short, disciplined checklist will keep you on solid ground:

  • Approve deliberately. Treat the creation of any agent as a decision that requires sign-off, not something individuals can spin up unnoticed.
  • Define ownership. Every agent should have a named owner accountable for its behaviour and its output.
  • Scope tightly. Limit each agent to the specific task, data and permissions it genuinely needs, and no more.
  • Keep an audit trail. Ensure you can reconstruct what an agent did, when and why, to a standard that would satisfy a regulator.
  • Plan the “stop”. Know in advance how you would pause or disable an agent, and who has the authority to do so.
  • Review regularly. Revisit which agents are live, whether they are still needed, and whether their permissions remain appropriate.

None of this is designed to slow you down. It is designed to let you adopt genuinely useful technology with confidence, knowing that client trust and compliance obligations are protected rather than quietly eroded.

The bottom line for professional firms

Copilot Wave 3 is a meaningful step forward. The move from an assistant that helps to an agent that acts opens up real efficiency, and features like Work IQ promise support that is genuinely tailored to how your firm works. For regulated businesses, the opportunity is real, but so is the responsibility. The firms that benefit most will be those that pair enthusiasm with oversight, adopting these capabilities inside a clear governance framework rather than bolting controls on after the fact.

If you would like help understanding how to introduce Copilot Wave 3 safely and effectively, with the accountability, audit readiness and control your obligations demand, get in touch with the team at Absolutely PC. We will help you turn a powerful new capability into a well-governed advantage.

What next?

One of my passions is helping businesses to succeed and if I can help you save some money as well – even better. You can fill out our contact form, phone us or click on the appointment button below and let’s start a conversation to see if I can help your business. Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.
Cyber Security
A professional reviewing a cyber security incident response plan on screen, representing governance and ransomware resilience in a regulated firm.

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

Cyber Security
A close-up of a CAPTCHA-style "prove you're not a robot" verification prompt on a computer screen, illustrating the fake CAPTCHA scam targeting professional firms.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to "prove you're human" by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here's how the trap works, and how to protect your team.

AI
Rows of identical humanoid robots beside a December wall calendar with a Friday date pinned, illustrating the question of whether regulated firms should pause AI use on Fridays.

Should Your Firm Hit Pause on AI Every Friday Afternoon?

By the close of the working week, even careful professional teams are stretched thin, and that is exactly when AI-generated work slips through unchecked. The output looks board-ready, so a tired reviewer approves it without a second read. For regulated firms, that quiet moment of over-trust is a genuine compliance risk. So should you pause AI on Friday afternoons?

Cyber Security
A laptop screen displaying a Windows 11 update prompt, illustrating the risk of a convincing fake update targeting regulated professional firms.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.