07Field guide · updated August 2026

The 7 Copilot mistakes small firms actually make

These are not compiled from other people's articles. Each one cost real time in a live deployment at a firm of the size this site is written for, 20 to 150 people, and each has a fix your own team can start this week.

1. Rolling it out while folder permissions do the security work

Copilot retrieves whatever the signed-in user can technically reach. If sensitive files are protected only by 'that folder is not shared with the wrong people', Copilot becomes the search engine that finds what nobody was supposed to stumble on. Sensitivity labels are the control it respects; folder discipline is not.

Fix: label the confidential estate before the first licence is assigned, not after.

2. Buying seats before choosing the first three jobs

A licence with no job assigned is shelfware with a monthly fee. 'Turn it on and see what happens' produces a month of novelty and then silence.

Fix: name three concrete, recurring tasks per team before rollout, and check in on exactly those.

3. Nobody owns adoption

In one live deployment, 4 of 33 licensed people produced any recorded usage in the first 90 days. The technology worked the whole time. Nothing in the organisation made using it anyone's job.

Fix: one named owner, a weekly ten-minute review of what was tried, and leadership using it visibly.

4. One training session instead of changed work

A launch webinar transfers vocabulary, not habits. The tool sticks when it is wired into a job people already do every week, a recap they must produce, a document they must draft, a mailbox they must clear.

Fix: rebuild two real weekly tasks around the tool, and let those carry the training.

5. Treating it as an IT project

The pattern from every regulatory rollout repeats here: the technology is the easy half. Who holds which permission, who checks the output, whose job changes, that is where implementations stall, and no installer fixes it.

Fix: run it as a work-organisation change with an IT component, not the reverse.

6. Ignoring the paperwork the AI Act already requires

Using AI you did not build makes you a deployer under the EU AI Act, and Article 50 transparency duties have applied since 2 August 2026. The high-risk rules moved to December 2027, but the inventory, the disclosures and the oversight note are due now, and they are cheap to produce today and expensive to reconstruct later.

Fix: a one-page register of AI in use, who owns each tool, and where it touches customers.

7. Measuring seats instead of jobs

Licence counts and login stats flatter the rollout and hide the truth. The only number that matters is jobs that no longer exist: the report nobody writes by hand any more, the approval that routes itself.

Fix: keep a short list of retired manual tasks, and review it monthly. If it stops growing, so did adoption.

All seven come from the same root: the licence is treated as the finish line. It is the starting position. The capability is paid for; the work of making it someone's actual working day is the implementation.

Which of the seven is happening in your company?Tell me