12.1 Copilot: what it can and cannot do
Checked against Microsoft's Copilot for Microsoft 365 documentation, August 2026
What you'll be able to do
Use Copilot where it genuinely helps, and check it where it does not. You will know what it can see, where it is reliable, where it invents, and what your organisation can see about your use of it.
Before you start
Copilot in Microsoft 365 needs its own paid licence on top of a work or school plan. It is the last of Getting Your Footing's five paid features. If you have no licence, this lesson still pays, because the judgement transfers to every AI assistant you will meet.
The work
- Same either way: know what it sees, because that explains both its power and its risk. Copilot in Microsoft 365 works over your own context: the open document, your mail and calendar, and the files shared with you across the organisation. "Summarise the thread with the vendor" works because it can read that thread. The other side of that is the same sentence: it can bring up anything you have access to. That is why organisations spend months on permissions before switching it on.
- Same either way: learn where it is reliable, which is the heart of this lesson. It is strong when the source is in front of it. Summarising a document or a thread it can read. Rewriting text you gave it. Drafting from your outline. Changing the shape of something that already exists. It is weak when it must supply the facts itself. Figures, references, names and dates from nowhere come out fluent, confident and invented, because producing believable language is what the underlying model does. Fluent is not accurate, and confident is not evidence.
- Same either way: make the checking habit absolute. Never send out a number, name, date or reference that you did not check against the source. For a summary of a real document, check two of its statements against the pages. For a drafted paragraph, every fact in it becomes yours the moment you send it. "The AI wrote it" is not a defence anybody accepts. The habit costs a minute, and the alternative costs your credibility once, permanently. Funcognito holds itself to the same rule: AI answers here are labelled and can be checked.
- Same either way: keep the data questions straight, and ask them of your own organisation. Prompts and responses stay inside the organisation's boundary and are not used to train the public models, which is Microsoft's commercial commitment. But your organisation's administrators may keep a record of use. Anything Copilot writes into a document is as permanent as anything you type, and as available to a future investigation. Here is the simple guide. Prompt with the same care you would put into an email, because in terms of records that is roughly what it is.
- Same either way: sort your own weekly tasks into two groups, and use Copilot only in the first. The first is changing the shape of sources you already have: summarising, rewriting, drafting from an outline, reformatting. The second is producing facts you do not have: the numbers, the references, the state of the world. The first group is where the tool earns its licence. The second is where it quietly manufactures your next embarrassment.
Try it
With or without a licence, take your three most repetitive writing tasks and sort them into the two groups. For one task in the first group, write down what you would check before sending the output. That checklist is the habit this lesson exists to install.
Check yourself
What does Copilot in Microsoft 365 actually see?
Your own context: the open file, your mail and calendar, and documents shared with you. Its usefulness and its risk to the organisation are both exactly that reach.
Where is it reliable, and where does it invent?
It is reliable when changing the shape of sources it can read: summarising, rewriting, drafting from your material. It invents when asked to supply facts it was not given, and the figures, references and names arrive fluent and unchecked.
State the checking habit in one sentence.
Never send out a number, name, date or reference that you did not check against a source yourself. How fluent the text is changes nothing about your ownership of what it claims.
What is the simple guide for prompts and records?
Prompt as carefully as you would write an email. The content stays inside the organisation's boundary and is not training data, but administrators may keep records, and whatever lands in a document is permanent.
Go deeper
We haven't checked most of these for screen reader use yet.
Back to Copilot: what it can and cannot do: work through the checklist