The College of Policing has made a national e-learning course on responsible use of Microsoft Copilot available to officers and staff across England and Wales, putting a simple but consequential rule at the center of generative AI use in policing: Use. Check. Own.

The new training, announced by the College of Policing on August 25, is intended for forces that can access Copilot through the national Microsoft 365 agreement. Its immediate value is less about teaching staff to write better prompts than establishing what must happen after Copilot produces an answer: a police employee must verify it and retain personal responsibility for the final work.

That sounds elementary. It is also the part of enterprise AI deployment most likely to be diluted when a tool moves from controlled trials into routine email drafting, meeting summaries, document preparation and information retrieval. The College’s move turns that expectation into national training rather than leaving each force to make up its own local guidance.

Police officers review an AI-generated incident briefing, emphasizing verification, human judgment, and data security.A training rollout, not evidence of a full Copilot rollout​

The announcement says officers and staff can access the course; it does not say every force has deployed the same Copilot product, assigned the same licences or enabled access to police data. Those are materially different stages of adoption.

Microsoft uses “Copilot” as a family name for several services with different data access models. Microsoft’s own documentation distinguishes Copilot Chat, which can be grounded in public web information for eligible work accounts, from the paid Microsoft 365 Copilot add-on that can draw on work data a user already has permission to access, including material in Outlook, Teams, OneDrive and SharePoint.

For a police force, that distinction is operationally important. A user asking a web-grounded assistant for a first draft of a generic briefing faces one set of risks. A user asking a work-grounded assistant to summarize internal documents, correspondence or case-related material faces another: the answer may be assembled from information the user can technically open but should not combine, circulate or rely on for the particular task at hand.

The College’s announcement does not identify which Copilot experiences are in scope, whether web access is enabled, whether any force-level information barriers or sensitivity labels are required, or whether the course is mandatory. It also does not set out a timetable for completion or report how many officers and staff have access to the relevant Microsoft licences.

Those omissions do not weaken the training itself. They do mean IT leaders should read the announcement accurately: this is a national baseline for user behaviour, not a public declaration that policing has standardized a single technical Copilot configuration.

“Check” must include the source, not only the wording​

The College says users must recognize AI tools’ limitations and apply professional judgment to AI-generated content. In policing, verification cannot mean merely proofreading output for bad grammar, implausible names or obvious factual errors.

A reliable checking process has to establish where an assertion came from, whether the underlying material is current, whether it is complete, and whether it is suitable for the decision being made. Generative AI can produce a fluent summary that accurately reflects some supplied text while excluding exceptions, qualifications, conflicting evidence or a crucial date. It can also present an invented detail with the confidence and formatting of a real finding.

That risk is not theoretical in Microsoft’s public-sector deployments. The UK government’s June 2025 cross-government Microsoft 365 Copilot experiment recorded concerns about accuracy and reliability, especially in work requiring deep domain knowledge. It also found that some users struggled to identify the exact documents used in responses generated from OneDrive content. That is a serious limitation for any environment in which a professional may need to explain the basis for a recommendation, preserve an audit trail, or distinguish confirmed evidence from a preliminary lead.

The experiment involved 20,000 government employees between September and December 2024, rather than police forces specifically. Still, it offers a useful warning against treating a Copilot response as a transparent research product. The study reported strong user satisfaction and self-reported time savings, but it also found lower confidence and lower benefits in some work involving nuance or competing source material.

For officers and staff, “check” therefore needs to include a practical habit that training courses often leave implicit: go back to the original record. Review the actual policy, report, statement, case note, statutory guidance, system entry or document rather than accepting a generated synthesis as the evidence itself.

“Own” keeps accountability with the human user​

The most important word in the College’s formula may be “Own.” It establishes that Copilot is a drafting and assistance tool, not an author, decision-maker, supervisor or evidential authority.

That matters most in work where a generated text could influence an operational decision, case assessment, safeguarding action, intelligence product, disclosure process, personnel matter or public-facing statement. A polished draft can make it easier to miss its weaknesses. Once the wording has been copied into an official document, its machine-generated origin may be invisible to the next person who reads it.

Professional ownership means the named officer or staff member remains accountable for accuracy, relevance, proportionality, compliance and the decision to use the output at all. It also means supervisors should not infer that a document has been properly checked merely because it is well written or arrived quickly.

The College has already been developing wider guidance for forces building AI-enabled tools and systems. That guidance stresses the need to equip officers with knowledge of how a tool works, along with its risks and limitations. The Copilot course appears to put that broader principle into a short operational model that can travel across roles and forces.

The approach is sound because it avoids a false promise: no amount of user training converts a probabilistic language model into a source of record. Training can reduce preventable mistakes, help people recognize unsuitable uses, and reinforce escalation routes. It cannot make a generated answer self-validating.

Permissions remain a deployment problem​

Microsoft 365 Copilot is designed to respect existing user permissions when it accesses organizational data. Microsoft says the service can only reference internal material a user is already authorized to access. That is an important control, but it is not the same thing as an assurance that every response will be appropriate to share or use.

Enterprise Copilot deployments tend to surface the consequences of years of loosely managed SharePoint sites, broad Teams memberships, inherited permissions, duplicated folders and old documents that remain searchable. If a user has access to content more widely than intended, Copilot can make that overexposure easier to discover and summarize. The model did not create the underlying entitlement problem; it can make it visible at machine speed.

The UK government experiment explicitly noted concern that the tool could surface files users should not see, and said organizations could limit search options and internet access. Most organizations in that trial disabled internet access in order to rely only on internal sources. The College of Policing announcement does not say whether comparable controls apply across policing.

For force Microsoft 365 administrators, the practical implication is straightforward. Training must sit beside identity and information-governance work, not substitute for it. Before expanding Copilot access, administrators should know which service they are enabling, which users are licensed, whether web grounding is available, what connectors or agents can reach, and whether high-risk repositories have been reviewed for oversharing.

A useful deployment standard would require forces to test real workflows with representative users before making a capability routine. That includes asking whether a user can identify the source documents behind an answer, whether sensitive content can be unintentionally combined in a summary, whether the output can be retained and audited appropriately, and what a user should do when an answer conflicts with a source record.

Productivity claims need a policing-specific test​

The government’s cross-department experiment found high adoption after licence rollout and reported average self-assessed time savings of 26 minutes a day. It also found the strongest everyday use in Teams, Outlook and document drafting, while use in Excel and PowerPoint remained comparatively low.

Those results make a reasonable case for training people to use Copilot productively in routine administrative work. They do not establish that the same savings transfer to policing, let alone to frontline or investigative decisions where checking the output may take as long as writing it independently.

The College has not claimed a productivity figure for police forces, and it should not be assumed. A generated meeting summary may save time for one team while creating new review work for another. A draft can accelerate a first pass through repetitive material but be unsuitable where the missing nuance is exactly what matters.

That is where the new course is most useful. It frames competence as responsible use rather than as maximal usage. The success measure should be fewer avoidable errors, clearer boundaries around sensitive work and better-quality human review—not merely a rising count of Copilot prompts.

The College of Policing has now provided a national rule of thumb for forces using Microsoft Copilot. The next hard work belongs to force leaders and Microsoft 365 administrators: ensure that **“Check” is supported by source visibility and sensible data controls, and that “Own” still has a named human behind every consequential output.