ITPro reports that Manchester CIO PJ Hemmaway expects student rollout to begin around September or October 2026, with the full programme finishing by year-end. But the university’s own latest public rollout update, published in July, says only that the final wave of colleagues is receiving full Microsoft 365 Copilot licences. A June university update described the student programme as a future rollout still being shaped through a summer “Test, Learn and Adapt” study and a Copilot Student Advisory Group.
The distinction is important. Manchester is no longer merely announcing a large Copilot purchase: it has deployed across its workforce and postgraduate researchers, built training and retention controls around the service, and is now confronting the harder part of institutional AI adoption — putting a generative tool into undergraduate learning and assessment without turning access into an academic-integrity free-for-all.
The “65,000 users” claim is a target, not a completed deployment
Microsoft and the University of Manchester announced their strategic collaboration in January 2026. Microsoft’s UK publication described Manchester as the first university in the world to provide Microsoft 365 Copilot access and training to all 65,000 students and staff, while also saying the rollout would be completed by summer 2026.
The university’s own records show a different, more granular sequence. An early-adopter cohort of roughly 2,000 colleagues began receiving licences and training in April after a pilot involving more than 1,100 users during 2024 and 2025. Professional Services staff began receiving access in May. Teaching, research and postgraduate-research colleagues followed in June. By July 20, the university said the final wave of colleagues was receiving full licences.
That adds up to a substantial operational rollout, but it is not evidence that 65,000 people had been enabled by July. Nor does it support the January past-tense formulation that Manchester “has become” the first university to provide Copilot universally. The staff phase has moved quickly; the student phase remains a separate project with its own research, governance and support design.
ITPro’s August report is the first public indication of a September or October 2026 student start and an end-of-year completion target. The university has not, in its publicly available AI Hub updates, posted a matching student launch date, licence-assignment schedule, or cohort breakdown. That does not mean the plan is wrong; it means the timeline currently rests on Hemmaway’s account to ITPro rather than a published implementation plan.
Manchester and Microsoft also describe the programme as a global first. Both organisations can credibly describe the scale of their own deployment, but neither has published a comparative method showing that no other university worldwide has offered equivalent institution-wide access, training, and a comparable Microsoft 365 Copilot licence. Readers should treat “first in the world” as a vendor-and-university positioning claim, not an independently established ranking.
This is a Microsoft 365 Copilot rollout, not a generic chatbot giveaway
The product choice matters for Windows administrators and Microsoft 365 teams watching the project. Manchester is not simply directing students to a public Copilot website or giving everyone access to a consumer AI assistant. It is deploying Microsoft 365 Copilot inside its existing tenant: Word, Excel, PowerPoint, Outlook, Teams, OneDrive and related Microsoft 365 services, including the Researcher and Analyst agents cited in the original announcement.
The university’s AI in Teaching and Learning Policy makes the boundary explicit. It distinguishes Copilot for Microsoft 365, which uses organisational data and is integrated with the university’s Microsoft 365 environment, from Copilot Chat, the standalone conversational tool. Both are described as operating under the university’s existing permissions and data-security controls.
That arrangement reduces one of the biggest risks in a rushed AI rollout: creating a parallel information environment that bypasses existing identity, access and compliance controls. Copilot does not give a user blanket visibility across Manchester’s tenant. It can retrieve information the user can already access. In the February town hall transcript, Hemmaway framed that limitation plainly: Copilot has access to a person’s data, not to “the University’s data” as one pooled knowledge base.
But inherited permissions are not the same as inherited readiness. Microsoft 365 Copilot can make content that was technically accessible but difficult to find far easier to discover, summarize and reuse. That is why Copilot projects tend to expose old SharePoint oversharing, stale team memberships, poorly classified files, and broadly shared mailboxes. Manchester’s public materials do not provide an audit result for those conditions, nor do they state how it measured or remediated permission sprawl before licence expansion.
For IT teams, Manchester’s approach demonstrates the correct order of operations: keep the service in the managed tenant, keep identity and data controls in scope, and avoid treating a Copilot licence as an independent security boundary. It also shows the limit of that approach. Existing Microsoft 365 permissions are the starting point, not the completion criterion, for safe AI retrieval.
Training results show confidence, not proven productivity
Manchester has invested heavily in adoption rather than relying on an all-user licence assignment. In May, the university said nearly 3,000 colleagues had attended more than 30 live sessions, with an average feedback rating of 4.6 out of five. It reported that 80% of participants felt confident or very confident using Microsoft 365 Copilot after learning sessions, up from 24% beforehand.
By the July staff-rollout update, the figures had grown to more than 50 learning sessions and over 11,700 attendees. The university has also adjusted its rollout using feedback: longer learning windows, clearer onboarding and signposting, and more Manchester-specific examples rather than generic prompt demonstrations.
Those are useful adoption metrics. They are not yet evidence that Copilot has improved university productivity, research output, administrative throughput, or student attainment. Manchester has publicly listed likely uses — drafting first versions, summarizing meetings and documents, organizing workloads and analysing information — but it has not published task-time measurements, quality assessments, error rates, usage rates by faculty, or evidence that time saved was actually redirected to higher-value work.
That omission is normal at this stage, but it changes how the rollout should be read. The university has measured immediate learner confidence, not the claimed institutional benefit. A confident user can still produce inaccurate summaries, poor analysis or plausible-but-wrong prose. At a university, where output may become teaching material, research support or assessed work, that gap between usability and reliability is not a minor implementation detail.
Manchester’s staff guidance acknowledges the human-review requirement in a more concrete way than the launch rhetoric. Its Teams retention notice says formal meeting records should still be produced with human review and that AI summaries must be checked for accuracy. Hemmaway’s statement to ITPro — that Copilot is a support tool rather than a substitute for professional expertise, decision-making or accountability — is therefore consistent with the actual operational policy.
The assessment policy is the real student rollout
The student launch will matter less for the number of licences issued than for how assessment instructions change on September 1, 2026. Manchester’s Senate-approved AI in Teaching and Learning Policy takes effect at the start of the new academic year and requires every assessment to be placed into one of four categories: AI Prohibited, AI Minimal, AI Permitted, or AI-Integrated.
The categories create a more workable model than a blanket ban or blanket permission. “AI Minimal” allows presentation-level support such as grammar, fluency and formatting without changing a student’s ideas, arguments or conclusions. “AI Permitted” allows AI use under stated conditions. “AI-Integrated” makes AI use necessary for achieving the intended learning outcomes, while still limiting the types of use permitted.
Students may opt out of AI use unless an assessment is marked AI-Integrated. That is a significant safeguard in a programme sold partly on universal access: equity is not the same as compulsory use. Faculties must also communicate the assigned category in the assessment brief and course information, and students who fail to document generative-AI use can face an academic-malpractice issue depending on the assessment rules.
The policy also creates a practical data-handling distinction. Students may upload university-owned material, including available lecture recordings, into their university-provided Microsoft 365 Copilot service for learning purposes. They must not upload lecture recordings, slides, question papers, handouts or other university-owned materials to external AI tools. Staff handling student-identifiable or confidential information are restricted to the university-provided Microsoft 365 Copilot service.
That is the heart of Manchester’s integrator strategy. It is using managed Copilot access as the preferred route for work involving institutional material, while accepting that students may use other AI tools when assessment and intellectual-property rules allow it. The challenge will be ensuring every department describes those boundaries consistently enough that students do not face different AI rules for superficially similar work.
The 30-day deletion rule undercuts the “AI memory” assumption
Manchester has also set a policy that many Copilot deployments leave unaddressed: Copilot conversations are not a permanent personal notebook. From July 10, the university began deleting Copilot chat interactions more than 30 days old across the Copilot app, Teams, Outlook and Office apps. Teams recordings, transcripts and AI summaries now also expire after 30 days by default, down from 60 days, although organizers can extend retention when there is a legitimate need.
The university says deleted chats can remain available within Microsoft 365 during the 30-day period for incident-management purposes. Users who need a result for longer must export it to Word, Copilot Pages, or another approved record. That is a defensible compliance posture for a university dealing with personal data, informal meeting remarks and potentially sensitive research or student discussions.
It also means users need to learn the difference between an AI interaction and an institutional record. A good prompt may be disposable. A decision, draft, research note or agreed meeting action must be saved in an approved location and reviewed by a person. Teams that treat Copilot history as a searchable archive will lose material; teams that export everything will create a different records-management problem.
Manchester’s project is therefore better understood as a controlled organisational deployment than a 65,000-seat experiment in AI enthusiasm. The staff rollout is largely in place, the student rollout is still being designed, and the first hard deadline is September 1, when assessment categories take effect. By then, the university will need more than access to Word, Excel and PowerPoint copilots: it will need every course team to explain exactly when AI may help, when it may not, and how students prove that the submitted work remains their own.