A worker reviews a Copilot action approval screen with prompt injection and sensitive data warnings.
Microsoft’s Copilot Cowork now makes users explicitly approve sensitive actions before an AI agent sends a message, changes an account setting, submits data to a website, or performs a purchase-related step. That is a sensible control for an agent that can work across Outlook, Teams, OneDrive, SharePoint, calendars, documents, and browser-based tasks—but the newly prominent warnings also underline an uncomfortable operational fact: Microsoft is putting the final accountability for an agent’s actions on the person who clicks Approve.

Neowin highlighted the warning language in newly published Microsoft Support documentation for Copilot Cowork on September 16. Microsoft’s own guidance says the service can make mistakes, misinterpret instructions, and be manipulated by malicious hidden instructions. It advises people to monitor results and scrutinize tasks involving payments, personal information, communications, files, and account changes.

That warning is more substantive than the usual “AI may be inaccurate” disclaimer. Cowork is designed to carry out multi-step work, rather than merely draft a response for a user to copy and paste. Microsoft’s Copilot Cowork overview says the agent can send email, schedule meetings, create Office documents, post to Teams, search an organization’s resources, manage cloud files, and run scheduled prompts. The larger the action surface, the less useful a generic accuracy warning becomes—and the more important each approval checkpoint is.

Approval dialogs are the control plane​

Microsoft’s new “Take control of Microsoft Copilot Cowork actions before they run” support page defines the practical safeguard: before Cowork performs certain actions, it presents a preview and an action-specific button such as Send, Post, or Create. The user can approve that individual step or cancel it.

The page also says a session can be paused while Cowork is working, then resumed or cancelled entirely. That gives users a way to stop a task after discovering the agent is pursuing the wrong interpretation, rather than waiting for a potentially long workflow to reach its next checkpoint.

Microsoft lists several categories where it may require approval or hand control back:

  • Monetary transactions, including purchases and payment submissions, require the user to intervene.
  • Submitting names, addresses, phone numbers, or other personal information to external websites requires explicit approval.
  • Actions affecting other people, including email and messages, require user review.
  • Account-altering actions, including cloud-storage changes, subscription cancellations, and account-setting changes, can trigger a checkpoint.
  • Health, government, and security-related submissions are treated as sensitive actions.

The operational detail that matters is in Microsoft’s wording: Cowork can ask for approval, but it can also hand control back when a website resists automated interaction, requests an additional sign-in step, or requires manual input. In other words, approval is not a blanket authorization for the whole assignment. It is a step-by-step mechanism with technical and policy boundaries.

For administrators, that is the right model to insist on. A user’s original instruction is not enough evidence that every downstream action is appropriate. An instruction such as “clean up my inbox and reschedule conflicts” can turn into email deletions, calendar edits, replies to other people, and changes based on inferred priorities. The approval prompt is where the employee must confirm that Cowork has identified the correct recipients, content, account, and consequences.


The warning addresses prompt injection, but does not remove the risk​

Microsoft’s documentation specifically says Copilot may be “deceived by malicious hidden instructions.” That is a direct reference to prompt injection: untrusted content—an email, document, web page, attachment, or other data source—contains instructions intended to manipulate the AI agent handling it.

This is a particularly relevant risk for an agentic product. A conventional chatbot can be misled into producing a bad answer. A work agent that can read material and then act in Microsoft 365 can potentially convert a bad interpretation into a sent message, a modified file, a calendar event, or an attempted browser transaction.

Microsoft’s design mitigates that risk by seeking approvals for actions it classifies as sensitive. But the safeguard depends on a user recognizing a bad action in the preview. The company’s warning therefore assigns an active review job to the person at the keyboard: verify recipients, content, and parameters rather than treating an approval window as a routine interruption.

There is also a limitation worth keeping in mind. Microsoft’s documentation gives users an option to allow similar actions without repeated prompts within the current conversation. This may reduce friction in legitimate repetitive work, but it also reduces the number of moments at which a user can catch an agent drifting from its intended task. Organizations should be conservative about telling staff to use that convenience option, especially for communications, records, or externally facing work.

The support material does not say that every risky outcome will be caught automatically. It says Cowork will seek approval or hand control back for certain actions. That is an important difference. Administrators should view the approval layer as a human-review mechanism, not as proof that the preceding reasoning, retrieved data, or planned sequence of actions is correct.

Cowork is generally available at work, but personal use remains preview​

One point blurred by the alarmed framing around the support notice is product status. Microsoft announced Copilot Cowork’s general availability for work and school accounts in June 2026. Its current Microsoft Learn overview says Cowork for work or school is generally available, while Cowork for personal Microsoft accounts remains in preview.

That split matters because the personal-account support documentation carries both the prominent AI warning and a separate preview disclaimer. Microsoft says its preview product information may change substantially before release and is supplied without warranties. A personal subscriber experimenting with Cowork should not read the interface as an enterprise-grade service commitment simply because the similarly named work product is generally available.

For business users, access is not automatic just because an organization has Microsoft 365. Microsoft’s setup documentation says an active Microsoft 365 Copilot license, Cowork availability in the tenant, and usage-based billing must be enabled. The built-in App skill is further restricted to members of Microsoft’s Frontier program.

The product also does not have unlimited reach into a workstation. Microsoft’s Cowork FAQ says it cannot access or edit files stored locally on a device; it works with OneDrive and SharePoint files. It also says Cowork cannot delete OneDrive or SharePoint files or folders, cannot read encrypted files, and cannot access attachments larger than 200 MB. Those boundaries reduce some obvious worst-case scenarios, but they do not eliminate the risk of inappropriate changes to cloud content the user is already allowed to modify.


The financial control needs to be as deliberate as the action control​

Neowin called Cowork expensive, and that characterization has a basis in the service’s billing model—but it needs more precision. Microsoft requires a Microsoft 365 Copilot User Subscription License and then meters Cowork usage separately through Copilot Credits. Microsoft’s published pay-as-you-go rate is $0.01 per credit, while each task can consume credits based on model use, context retrieval, tool calls, and runtime.

So the relevant cost is not a simple per-seat charge and not a fixed price per prompt. A light request to draft a document and a long-running task that searches organizational content, invokes skills, performs browser work, and uses a higher-effort model can have materially different costs.

Microsoft provides a /cost command in Cowork that shows an estimated credit count for the current task and the user’s remaining monthly credit allowance. The company explicitly says that figure is an estimate rather than a billing ledger, so finance and IT teams should use the Microsoft 365 admin center and actual billing data for reconciliation.

Microsoft also offers spending limits, group-level allocation, and usage reporting. Those are not optional housekeeping features for a broadly deployed agent. They are the counterpart to approval prompts: one governs whether Cowork should carry out an action; the other governs whether the organization should keep paying for the work it is being asked to do.

A rollout that enables Cowork without budgets, user-group limits, or a clear set of sanctioned use cases can create two problems at once. Employees may delegate sensitive actions faster than their review habits develop, while IT receives a variable bill that grows with long-running, tool-heavy workflows.

What IT teams should change before broad deployment​

Microsoft’s warning is not evidence of a newly discovered vulnerability or a Cowork-wide incident. It is Microsoft documenting the ordinary risk of giving an AI system permission to take actions across business services. The practical response is to configure and govern Cowork as an automation platform, rather than presenting it as a more capable chat window.

Before enabling Cowork for a broad group, administrators should define which users can access it, enable usage caps and alerts, and restrict initial deployments to workflows where a human can quickly validate the output. High-volume external messaging, financial activity, personnel actions, sensitive records, and security changes should not be early candidates for unattended or lightly reviewed agent use.

Users need specific instruction as well: read every approval dialog, including the recipient list and any expanded parameters; pause tasks if the plan diverges; and cancel rather than approve when a request contains unfamiliar destinations, unexpected data, or actions outside the original scope. A vague instruction is not an excuse to accept a vague action.

Copilot Cowork’s approvals are a meaningful safeguard, and Microsoft deserves credit for making them explicit rather than obscuring them behind a one-time consent screen. But the company’s own support language is clear about where responsibility lands. Cowork may do the work; the employee who approves it, and the organization that enabled it, own the result.