Copilot Agent Governance: Guardrails for Custom AI Agents
Governing the Autonomous Workforce: Establishing Guardrails for Custom Copilot Agents
A partner at a mid-size firm once described her ideal assistant: someone who reads every matter file, drafts the first version of every routine document, and never sleeps.
Not long ago, that assistant would have needed a job offer and a background check. Today, she can build one herself, in an afternoon, with no IT ticket required.
That is the quiet shift happening inside Copilot Studio. And it is exactly why CIOs and general counsel are starting to ask questions about something that sounds, on paper, like a pure productivity win.
The Shift Nobody Approved
For the past two years, AI in legal work was mostly conversational.
A lawyer asked a question. AI gave an answer. A human reviewed it before anything important happened.
That model had a built-in safety net. If the answer was wrong, it generally stayed there until someone decided to use it.
Custom agents change that.
An agent can do more than answer a question. It can update a matter record, draft client correspondence, pull information from a CRM, or trigger a workflow.
And because these agents can be built with low-code tools, the person creating one may have nothing to do with IT.
It could be a paralegal automating client intake. A knowledge manager is building a research assistant. Or an associate trying to save an hour before a filing deadline.
None of that is reckless. In fact, that is exactly what these tools are designed to enable.
The problem starts when the agent becomes more capable than the guardrails around it.
When Nobody's Watching: How a Small Shortcut Becomes a Legal Risk
Consider a simple example.
An associate is working on a litigation matter and builds a "matter research assistant" to speed up drafting. To get it working quickly, the agent is connected to the SharePoint libraries the associate can access.
The setup works.
But there is a problem: the associate has access to more information than this matter requires.
A few weeks later, a partner reviews a draft brief and notices a sentence that looks strangely familiar. After checking the source, the team discovers that the wording came from a memo belonging to an unrelated matter involving the same opposing counsel.
That information was sitting behind an ethical wall.
The associate did not deliberately access it. Nobody was trying to bypass control. The agent simply had more access than the task required, and nobody had checked its scope before it went live.
Now a productivity tool has potentially created a much bigger problem: a conflicts issue, a possible client disclosure obligation, and an uncomfortable explanation if the matter reaches a judge during discovery.
And that is one agent.
Now imagine dozens of similar agents being created across practice groups over the course of a year.
The risk does not just grow. It compounds.
Why This Is a Legal Issue, Not Just an IT Issue
It is tempting to treat agent governance as another technology project.
But once an AI agent can access client information or act on the firm's behalf, the issue moves directly into legal and compliance territory.
The numbers make that clear:
-
A recent governance survey found that 63% of organizations cannot enforce purpose limits on their AI agents, while 60% cannot quickly shut an agent down when it starts misbehaving.
-
More than half of boards still do not rank AI governance among their top five priorities, and those organizations trail materially on measures of AI maturity.
-
Law firm AI adoption has risen sharply over the past two years, while many firms still lack a written policy explaining how AI should be used and supervised.
-
Stanford research on legal AI tools has found 17% to 34% error rates in unverified outputs, while courts have already sanctioned lawyers for submitting hallucinated citations.
There is also a straightforward accountability problem.
ABA Formal Opinion 512 makes the principle clear: saying "I didn't build the tool" does not remove professional responsibility.
If an agent acts on a firm's behalf, the firm's responsibility does not disappear simply because an employee created the agent in an afternoon.
The Four Risks That Grow Together
Once agents start multiplying across a firm, four problems tend to appear together.
- Data exposure. An agent can inherit the permissions of the systems it connects to. Those permissions may be much broader than what the agent actually needs.
- Compliance drifts. An agent created outside the firm's review process may not align with existing retention, security, or data loss prevention controls.
- Cost sprawl. Different practice groups may build similar agents without realizing that another team has already created one, adding unnecessary licenses and compute costs.
- Identity ambiguity. When something goes wrong, the firm needs to know who created the agent, what information it accessed, what actions it took, and who approved it.
The common thread is simple:
If nobody has visibility into the agents being created, nobody has reliable control over them either.
What Good Governance Actually Looks Like
Firms that are approaching this well are treating agents much like they would treat a new employee who needs access to client information: give them the access they need, define what they can do, and make sure someone is accountable for their actions.
That means:
-
Approval before deployment.An agent should go through central administrative review before it goes live, rather than waiting for something to go wrong.
-
Defined access.Agents should be limited to specific Microsoft 365 users or groups instead of being left open-ended.
-
Governed data.Agents should work from the firm's approved document and matter data rather than pulling information indiscriminately from the open web.
-
Complete traceability.Firms should be able to see what an agent accessed and changed, creating a record that can be explained to a client, regulator, or judge if necessary.
-
A named owner.Every agent should have one accountable owner in the tenant. When something goes wrong, there should be no question about who is responsible for it.
Every agent has a defined scope. Every action can be traced. And when something goes wrong, the firm can explain what happened instead of trying to reconstruct it under pressure.
The autonomous workforce is already inside the firm.
The question for legal leadership is no longer whether employees will build AI agents. It is whether those agents will have a supervisor.