Microsoft’s Copilot Cowork is now generally available for commercial tenants worldwide. More than half the Fortune 500 is already running it. Government Community Cloud (GCC) tenants are blocked. No public timeline has been announced for when that changes.
This is the most significant capability shift in the M365 Copilot stack since its original launch, and the gap between commercial availability and government availability is not something to sit out. It is the preparation window that separates the agencies who deploy Cowork cleanly from the ones who spend the next year triaging oversharing incidents and stalled adoption. Every major Copilot release has followed this pattern. The organizations that used the lag time to do the boring, unglamorous governance work came out ahead. The ones that waited until the feature dropped and then scrambled did not.
What Copilot Cowork Actually Does (and Why It’s Different From Everything Before It)
Copilot Cowork is not a rebrand of Copilot Chat. It is a fundamentally different mode of AI-assisted work inside Microsoft 365. You describe an outcome, and Cowork decomposes it into steps, executes those steps across Outlook, Teams, SharePoint, Excel, Word, and your calendar, then delivers a finished result. Not a draft. Not a recommendation. A completed deliverable with real actions taken on real systems.
It runs in a sandboxed cloud environment, which means tasks keep executing when your laptop is closed. It is grounded through Microsoft’s Work IQ intelligence layer, pulling context from your organizational data: emails, meetings, files, org chart, and permissions. At general availability, Cowork runs on Anthropic’s Opus 4.8 and Sonnet 4.6 models, with GPT 5.5 available through the Frontier early-access program and a purpose-built model called Cowork 1 expected in the coming weeks.
The pricing model is new for M365. Cowork requires the existing M365 Copilot user subscription license, then adds usage-based billing on top via Copilot Credits. Pay-as-you-go costs $0.01 per credit, with charges driven by four factors: model usage, context retrieval, tool calls, and runtime. Microsoft ships spending limits at the tenant, group, and user level, plus customizable usage alerts. Cowork is off by default. Admins control when it turns on, who gets access, and how much can be spent. Nine partner plugins are available at launch, including integrations with Miro, monday.com, Moody’s, S&P Global Energy, and Dynamics 365. Adobe, Atlassian, Box, Canva, and Databricks are coming soon.
For commercial organizations, this is available today. For government M365 Copilot environments, the question is not “if” but “when,” and more importantly, “will we be ready.”
Cowork Inherits Your Permissions. That’s the Problem.
Cowork operates within the M365 trust boundary and respects existing user permissions. Microsoft has been consistent about this, and it is true. It is also exactly why the security risk is higher than most organizations expect.
Everything a user can access, Cowork can access. Every overshared SharePoint site, every library with “Everyone except external users” permissions from 2019, every folder with broken inheritance that nobody has audited. Copilot Chat already surfaced this problem. Cowork makes it worse because it doesn’t just retrieve content. It takes action on it. It sends emails, creates documents, posts in Teams, and updates spreadsheets. The blast radius of a permission gap goes from “someone saw something they shouldn’t have” to “the AI sent it to a distribution list.”
Microsoft’s own framing puts the biggest security risk from Copilot as data oversharing, not hallucination, not prompt injection. The compliance surface at GA includes audit logging, Data Security Posture Management, eDiscovery, Communication Compliance, and sensitivity label inheritance. DLP is listed as “coming soon,” which means the single most common governance lever for government security teams is not available at Cowork’s commercial launch. When Cowork reaches GCC, the DLP story will matter even more. Your government AI governance posture needs to account for an agentic system that acts, not just responds.
The Adoption Numbers Tell the Real Story
Copilot’s commercial adoption data should be required reading for anyone planning a government rollout. The overall M365 Copilot workplace conversion rate sits at 35.8% as of Q2 2026, per Stackmatix. Gartner reports that only 24% of Copilot pilots expand beyond 20% of workers, and 71% cite governance concerns as the reason. McKinsey’s research found 46% of leaders identify skill gaps as the single largest barrier to AI adoption. ManpowerGroup’s 2026 Global Talent Barometer shows AI usage climbing 13% to reach 45% of workers, while confidence in using that technology dropped 18%.
The pattern is clear. Organizations buy the licenses. They skip the training. Adoption plateaus within weeks. Users try the tool, get inconsistent results because nobody taught them how to prompt effectively or what the tool can actually reach, and then they go back to doing things the old way. The agency still pays for the licenses.
Cowork amplifies this dynamic because the stakes of a bad delegation are higher than the stakes of a bad prompt. When a user gives Copilot Chat a poor prompt, they get a poor answer they can ignore. When a user gives Cowork a poorly scoped delegation, Cowork executes multi-step workflows on real data, in real systems, with real outputs. Structured Copilot training built for government environments is not a nice-to-have. It is the difference between adoption that sticks and a six-figure line item that produces nothing.
GCC Is Not Commercial M365 With a Compliance Checkbox
Every major Copilot feature that has reached GCC arrived with constraints that commercial training materials don’t cover. Web grounding is off by default. Security Copilot remains unavailable in U.S. government clouds. Feature parity lags commercial by months, sometimes longer. The admin who reads a commercial governance guide and configures controls accordingly will set up things that don’t exist in their tenant.
Cowork’s multi-model architecture adds a new dimension. The commercial GA runs on Anthropic models with Microsoft as a sub-processor. How that sub-processor relationship translates to FedRAMP-authorized GCC boundaries, and whether the Anthropic toggle will work the same way in government clouds, is an open question. EU and EFTA tenants already have the Anthropic sub-processor toggle off by default for data sovereignty reasons. Government clouds will have their own set of constraints, and agencies need to plan for them before the feature shows up in the admin center.
The compliance environment is also moving independently. OMB’s M-25-21, published April 2025, requires federal agencies to designate Chief AI Officers, stand up governance frameworks, and invest in workforce upskilling. M-26-04, published December 2025, adds LLM procurement transparency and bias documentation requirements. Washington State’s WaTech adopted its statewide AI policy (DATA-04) in December 2025, grounded in the NIST AI Risk Management Framework, with the AG’s AI Task Force final report due July 2026. State and local agencies across the country are tracking these same directions. The governance requirements exist now. The tooling is catching up. Organizations that wait for the feature to arrive before thinking about governance will find themselves building the plane after it’s already taken off.
What Preparation Actually Looks Like
If Cowork follows the same rollout cadence as previous Copilot capabilities in GCC, organizations have a finite window to do the work that makes deployment safe and productive. That work is not exciting, and it is the highest-leverage investment available right now.
Start with permissions. Run data access governance reports and SharePoint permission state reports. Identify sites with organization-wide sharing, broken inheritance, and no active owner. Use Restricted Content Discovery and Restricted Access Control to wall off the worst offenders. This matters for Copilot today and will matter significantly more when Cowork arrives with the ability to act on what it finds, not just surface it.
Get your Purview posture right. DSPM for AI, sensitivity labels, and retention policies should be configured and validated before any agentic capability goes live. If your labels are inconsistent or your DLP rules haven’t been updated for Copilot’s data surfaces, Cowork will inherit those gaps at scale.
Address agent sprawl before it starts. Copilot Studio, Agent Builder, and Copilot Studio publishing to Teams are already live in GCC. Cowork adds another layer of autonomous action on top of that foundation. If your agency doesn’t have an agent inventory, a risk-tier classification for agents that touch regulated data, and Managed Environments scoping production agents away from default, you’re building on a surface you can’t see. Gartner has projected that more than 40% of agentic AI projects will fail before 2027 because organizations skip this groundwork.
Train your people. Not on the tool generically, but on the specific constraints and realities of their environment. Admins need to understand spending policies, Anthropic sub-processor controls, and the compliance surface that ships with Cowork. Users need to understand the difference between a prompt and a delegation, what Cowork can reach, and where the guardrails are. GCC-native Copilot and Power Platform training covers this. Commercial training from a Tier 1 vendor does not, because commercial training is written for commercial environments.
For Primes Watching the GCC AI Pipeline
If you hold a prime contract that touches M365 in government and you see Cowork on the horizon, you’re looking at a new category of work that most of your bench is not staffed for. Agentic AI governance, Copilot Studio agent engineering, Purview-integrated compliance architecture, and usage-based cost modeling in GCC are all specialized skills with a thin talent pool. The demand curve is steep and the supply is not keeping up.
Puget Sound AI provides custom AI agent development and AI automation consulting built specifically for GCC. All work is architected within Microsoft’s FedRAMP-authorized GCC boundary and aligned to NIST 800-171 control objectives. If you need a sub who builds production AI in government and can hit the ground running, that’s the engagement model.
Who’s Behind This
I’m Jacob, founder of Puget Sound AI. Navy veteran, M365 and AI engineer. I’ve spent years engineering production AI and automation inside GCC: citation-bound agents, natural-language admin tooling, records classification, license reclamation. Puget Sound AI is a veteran-owned small business. You get the engineer who builds it. No account managers, no layers, no handoffs.
If your agency or organization needs to get ready for what’s coming, whether that’s training your team, standing up governance, or building the agent infrastructure to make agentic AI actually work inside GCC, let’s talk.
Written in a personal capacity. Views are the author's own and do not represent any employer. No client or employer systems, data, or configurations are described.