You do not preserve authority by knowing every AI feature before your team does. You preserve it by deciding which work may change, what evidence counts, who remains accountable and when an experiment must stop.
That is the manager’s job. The prompt belongs to the person using the tool. The decision boundary belongs to you.
Start with the work, not the fear
The original version of this article claimed that AI-aware managers would accelerate their careers and included neat success stories with no verifiable evidence. Those claims have been removed.
Current research supports a more measured position. The International Labour Organization’s 2025 task-level analysis found that generative AI exposure is widespread, but concluded that transformation is more likely than wholesale job replacement because most exposed occupations still require human input. That is a population-level assessment, not a prediction about your role, employer or promotion prospects. Read the ILO research brief.
So ask a smaller and more useful question:
Which parts of our work can AI assist, and what must remain a human decision?
A five-part management loop
1. Choose one workflow and name its owner
“Use more AI” is not an operating instruction.
Choose a real workflow such as preparing a weekly project update, summarising non-confidential meeting notes or drafting a first response to a common internal question. Name the person who owns the outcome even when AI contributes.
Write down:
- the input;
- the expected output;
- the decision or action the output informs;
- the named human owner;
- uses that are out of scope.
This is an application of the Map function in the US National Institute of Standards and Technology’s AI Risk Management Framework. NIST recommends defining the intended context, users, impacts and limits before judging an AI system. The framework is voluntary, and NIST is revising version 1.0, so use it as a structure rather than a compliance badge. See the NIST AI RMF Core.
2. Set the data boundary before anyone experiments
Decide which information may enter the tool:
- public or synthetic content;
- ordinary internal material;
- confidential commercial information;
- personal data;
- special-category or regulated data;
- credentials, secrets and security information.
Do not leave that decision to whoever finds a browser tab first.
For Microsoft Copilot, Microsoft states that prompts, responses and organisational data accessed through Microsoft Graph are not used to train foundation models. It also states that Copilot works within the signed-in user’s existing permissions. That does not make an untidy permission model safe. It means overshared SharePoint, OneDrive, Teams or email content can become easier for an already-authorised person to find.
Microsoft therefore tells administrators to assess oversharing, review access controls, use appropriate audit and information-protection controls, and pilot before wider deployment. Read Microsoft’s Copilot privacy documentation and setup guidance.
If the experiment uses another AI service, verify that service’s current contract, retention, model-improvement settings, regions and administrator controls separately. Microsoft’s terms do not travel with data copied elsewhere.
3. Define acceptance tests before comparing outputs
A polished paragraph is not proof that a workflow improved.
Create a small test set containing ordinary cases, awkward cases and known failure cases. For each one, record:
- the correct source material;
- the expected result;
- errors that would make the result unusable;
- who checks it;
- what happens when the check fails.
For a project update, acceptance might mean every status statement traces back to an approved project record, dates are preserved, uncertainties are labelled and no action is assigned to the wrong person.
That is more useful than asking whether the output “looks good”.
4. Run a controlled pilot
Use approved accounts, approved data and a deliberately narrow group. Make sure IT, security, privacy, legal or employee representatives are involved where the risk and local rules require them.
Microsoft’s current deployment guidance describes a pilot, deploy and operate sequence. It also notes that Microsoft Copilot requires eligible licensing, while some security, governance and analytics features can require additional licences. Check the tenant and current Microsoft Copilot licensing documentation before promising a capability or budget.
During the pilot, keep a simple decision record:
| Record | What to capture |
|---|---|
| Workflow | The exact task and boundary tested |
| Tool context | Product, account type, model or feature where visible |
| Data class | The highest sensitivity allowed |
| Human control | Reviewer and approval point |
| Quality | Passed and failed acceptance cases |
| Operational cost | Licences, metered use and human review effort |
| Incidents | Incorrect output, disclosure, bias, security concern or workflow failure |
| Decision | Expand, change, pause or stop |
Do not quietly change the test when the tool performs badly. A failed case is evidence.
5. Decide with evidence, then keep watching
The end of a pilot is a decision point, not a launch ceremony.
Possible decisions include:
- adopt the workflow with the tested controls;
- narrow it to lower-risk inputs;
- revise the process and run another test;
- choose another tool;
- stop because the review cost or risk outweighs the benefit.
If you expand, assign an operational owner and a review date. Models, product features, licences, data and business processes change. Yesterday’s test result is not permanent assurance.
Microsoft’s Copilot Control System groups its guidance around security and governance, management controls, and measurement and reporting. Those areas are useful prompts for an operating review, but product telemetry alone cannot prove business value. See the Copilot Control System overview.
What to measure
Measure the workflow against its old baseline, not against an AI adoption target invented for a slide.
Useful measures might include:
- correction rate;
- unsupported statements found during review;
- cases escalated to a human;
- elapsed work time measured consistently before and during the pilot;
- rework caused downstream;
- security or privacy incidents;
- user and reviewer confidence, captured separately.
These measures prove only what happened in the observed workflow and period. They do not prove that AI made every team member more productive, caused revenue growth or improved someone’s career.
Do not turn adoption data into secret worker scoring
Usage telemetry can help an organisation see whether a licensed product is being used. It is a poor substitute for judging the quality of a person’s work.
In the UK, the Information Commissioner’s Office says worker monitoring must be lawful, fair and transparent, and that organisations should assess necessity and proportionality. Its guidance is currently under review following legislative changes, so check the latest version and obtain appropriate advice before designing monitoring or automated employment decisions. See the ICO guidance on monitoring workers.
Tell people what is measured, why, who sees it and how it affects them. Do not use prompt counts as a proxy for judgement, effort or value.
Facts, interpretation and forecast
Keep these separate when you speak to your team:
- Fact: Microsoft documents specific permission, privacy, licensing and administration behaviour for its Copilot products.
- Fact: Your pilot produced a recorded set of passes, failures, costs and incidents.
- Inference: The workflow may be suitable for a broader group if the same controls and conditions hold.
- Forecast: Future product capability, staffing need or career impact remains uncertain.
- Opinion: A manager who admits uncertainty while setting a clear test is showing stronger leadership than one who pretends certainty.
Only the first two belong in a claim that something has been proved.
The authority worth keeping
Your team does not need you to win a prompt competition.
They need you to make the awkward calls:
- Which problem is worth solving?
- Whose data is involved?
- Who can approve the risk?
- What must a human verify?
- What evidence would change the decision?
- Who owns the result when the AI is wrong?
That is not surrendering authority to AI. It is using managerial authority properly.
If you are responsible for a Microsoft Copilot pilot, bring one proposed workflow, its data boundary and its acceptance test to the Microsoft Copilot Adopters Space.
Sources
- Generative AI and jobs: a 2025 update, International Labour Organization
- AI Risk Management Framework Core, NIST
- Data, privacy and security for Microsoft Copilot, Microsoft Learn
- Set up Microsoft Copilot and assign licences, Microsoft Learn
- Microsoft Copilot licensing, Microsoft Learn
- Copilot Control System overview, Microsoft Learn
- Data protection and monitoring workers, Information Commissioner’s Office
