Langley Township council approved an AI-use policy on July 27, 2026 that mandates human review for all generative AI tools, including Microsoft Copilot, and limits deeper Microsoft 365 integration to cautious testing. The policy, effective immediately, applies to staff and elected officials alike, and requires immediate reporting of any suspected AI misuse or privacy breaches.
The Policy’s Core: AI Is a Tool, Not a Stand-In for Judgment
The policy, detailed in a report to council by IT director Jim Makela and adopted unanimously, is built on three pillars: human oversight, privacy protection, and information security. It permits staff to use approved AI services for routine drafting, summarization, and information discovery—but only if the human user remains responsible for reviewing all output and safeguarding records and personal data.
“These tools can support productivity, improve access to information, assist with routine drafting and summarization, and create capacity for higher-value work,” Makela’s report states. “At the same time, AI introduces privacy, cybersecurity, records management, legal, reputational, operational, and cost risks that require clear governance and appropriate oversight.”
In practice, that means an employee can ask Microsoft Copilot Chat to draft a memo or summarize a report, but the employee must verify the result before it becomes official. The Township is also testing its first agentic AI tool, the Open Meeting Researcher Agent, which searches a database of publicly accessible council meeting records. Starting with a bounded, low-risk dataset is a deliberate strategy to evaluate AI’s usefulness without exposing sensitive internal information.
What’s Permitted—and What’s Not
Langley’s IT department is already using GovAI and Microsoft Copilot Chat under the new policy. Meanwhile, a limited pilot of M365 Copilot Premium—the version that plugs into the full Microsoft 365 suite—is underway. That distinction is critical: Copilot Chat operates in a browser or mobile app with web-grounded data, but M365 Copilot Premium can access an organization’s emails, SharePoint sites, Teams messages, and OneDrive files based on a user’s existing permissions.
The policy treats the full M365 integration as a separate risk tier. Makela’s report warns that “deeper integration with Microsoft 365 information may create additional privacy, security, records, and cost considerations.” The pilot is proceeding with what the Township calls a “measured approach,” and no date has been set for broader deployment.
Councillor Michael Pratt asked whether the policy would cover council members’ use of AI. Chief administrative officer Chan Kooner confirmed that elected officials are bound by the same rules as staff.
Why This Matters for Windows and Microsoft 365 Administrators
For IT pros who manage Windows endpoints, Microsoft 365 tenants, and Copilot rollouts, Langley Township’s policy is a crystallized example of the governance overhead that Copilot—especially the premium tier—introduces.
Here are three key takeaways:
-
Permissions are now your frontline defense. M365 Copilot respects the same permissions that a user already has. If your SharePoint and Teams permissions are too broad, Copilot will happily surface documents an employee shouldn’t see. Langley’s policy is, by extension, a reminder to run a permissions audit before enabling Copilot.
-
Start with a bounded dataset. The Open Meeting Researcher Agent pilot is a proof-of-concept that any organization can replicate. By beginning with public meeting records—a curated, low-sensitivity corpus—the Township can test whether an agent saves time without creating new data-exposure channels. For corporate IT, the equivalent might be a pilot that only searches policy docs, training manuals, or other non-confidential content.
-
Incident reporting must be built into daily operations, not tacked on later. The policy requires that suspected AI misuse and privacy breaches be reported immediately. That means help desk staff and security teams need documented procedures for AI-related incidents from day one.
How the Township’s Approach Fits Into a Growing Pattern
Langley isn’t the first municipality to adopt an AI policy, but its document highlights a shift in thinking about enterprise AI. In early 2026, Luzerne County in Pennsylvania published a similar policy emphasizing human accountability and data classification. Across the public sector, the message is coalescing: blanket bans are impractical, but unchecked deployment invites compliance nightmares.
Microsoft itself has been pushing organizations toward Copilot with aggressive bundling and constant feature drops. Windows 11 updates in 2025 and 2026 added Copilot to the taskbar and embedded it into core apps like Notepad and Paint. Yet, the nuanced challenges of information governance in a Microsoft 365 context remain largely the customer’s problem. Langley’s decision to keep M365 Copilot Premium in testing while using chat-based tools more broadly reflects a pragmatic compromise: capture the low-hanging productivity gains without turning the entire SharePoint estate into an AI search index overnight.
What Windows and M365 Admins Should Do Now
If you manage a Microsoft 365 environment, Langley’s policy offers a blueprint for your own AI governance strategy. Here’s a concrete checklist:
- Audit Microsoft 365 permissions. Use tools like Microsoft Purview or PowerShell scripts to identify over-privileged users and groups. Clean up sharing links and legacy access.
- Classify data sensitivity. Apply Microsoft Information Protection labels systematically so that Copilot can honor them when processing content.
- Define an acceptable-use policy. Emulate Langley’s top-level rules: which AI tools are approved, what data can be fed into them, and what human review steps are mandatory. Communicate this to all staff.
- Limit Copilot scope initially. Consider piloting M365 Copilot with a controlled group and a restricted set of data sources. Disable its ability to search all sites until you are confident in your information architecture.
- Create an AI incident response plan. Update your security incident SOP to include scenarios like a user inadvertently exposing PII through a Copilot prompt or a prompt injection attack. Ensure staff know how to report such events.
- Monitor cost closely. M365 Copilot Premium is priced per user per month, and the “metered” AI actions can drive up costs. Track usage against productivity gains to justify expansion.
For everyday Windows users not in an enterprise setting, the lesson is simpler: treat AI output as a first draft, not the final word. Copilot in Windows and consumer Microsoft 365 plans can help with tasks, but you are still responsible for verifying facts, correcting errors, and protecting personal information.
The Outlook: More Guardrails Ahead
Langley Township’s policy is unlikely to remain an outlier. As AI becomes embedded in productivity suites, governments and enterprises will demand similar frameworks. Microsoft may eventually build more governance controls into the product—tenant-wide content exclusions and mandatory human-in-the-loop for sensitive workflows—but for now, the burden is on IT leaders to write the rules themselves.
For anyone evaluating Copilot’s next steps, the Township’s cautious expansion of M365 Copilot Premium bears watching. If the pilot succeeds without major privacy incidents, it could become a template for mid-sized organizations. If it stumbles, expect the brakes to come on harder. Either way, the human review requirement is here to stay.