Microsoft Copilot has quietly become the go‑to AI assistant across New Zealand’s public sector, not through open competition but by piggybacking on existing Microsoft 365 contracts. Documents obtained under the Official Information Act show agency after agency activated Copilot as an add‑on to software they already used, skipping the formal procurement a dedicated AI platform would normally require. For businesses watching, the government’s story is a preview of how lock‑in happens—and a playbook for staying in control.
What Actually Happened
The details emerged when B2B News filed OIA requests and obtained internal survey data. The picture they paint is clear: Microsoft Copilot is the primary AI tool in a growing number of agencies, and its adoption was largely frictionless because the government already had an all‑of‑government volume licensing agreement with Microsoft.
That umbrella contract—the Microsoft Cloud, Software and Service Agreement (MCSSA)—covers Windows, Office, Azure, Power Platform, Dynamics 365, and M365 Copilot. It runs from 1 October 2024 to 30 September 2027 with a further three‑year renewal option. By having Copilot bundled into the same agreement, individual agencies could skip the lengthy step of justifying a new vendor and simply add licences to their existing tenant.
One OIA response, from the Ministry for Regulation, spelled out the economics: the agency used Microsoft 365 Copilot Chat at no extra cost because it was included in the core suite, while an upgraded M365 Copilot subscription was listed at NZ$567.60 per staff member per year. The ministry said staff were using AI for literature reviews, draft‑document analysis, transcription, and summarisation. All of this happened without a dedicated procurement exercise for AI software.
The backdrop was a major public‑sector overhaul. Finance Minister Nicola Willis announced plans to cut about 8,700 positions, bringing the core public service headcount to roughly 55,000 by mid‑2029, with AI and digitisation expected to help remaining staff maintain productivity. An internal cross‑agency survey by the Government Chief Digital Officer revealed that 55 operational AI use cases were already deployed, covering assisted search, workflow automation, and data analysis—a sharp jump from the 15 reported a year earlier.
Some agencies, like Inland Revenue, adopted a more cautious path. They ran small pilots, defined high‑value use cases, required role‑based training, and insisted that people stay “firmly in the loop.” Their published rollout material explicitly notes that productivity gains shouldn’t automatically equal workforce reductions. But for many others, Copilot arrived as a simple switch to flip.
What It Means for You
For IT Administrators and Procurement Teams
The government’s experience is a real‑world case study in convenience driving AI adoption. If your organisation runs on Microsoft 365, the temptation to just “turn on Copilot” will be strong—and that’s not automatically wrong. But it does mean you inherit a checklist of urgent hygiene tasks:
- Permissions audit: Copilot surfaces only data a user already has access to. Years of overshared SharePoint sites, stale Teams channels, and forgotten access groups suddenly become exposed. Microsoft’s own guidance stresses that permissions health is critical before enabling AI.
- Data governance: Understand where prompts, responses, and interaction logs are stored. Microsoft says this data is encrypted, stays within your tenant, and isn’t used to train foundation models, but you’ll want to align Copilot activity with your existing retention and e‑discovery policies.
- Exit planning while you can: Even if you’re happy today, document how you would extract data, what export tools you rely on, and which alternative AI services could theoretically slot in. This is the leverage you bring to a renewal negotiation.
For Business Owners and Decision Makers
The bigger worry isn’t a single Copilot licence—it’s the slow drift from “using a tool” to “depending on an ecosystem.” The government ended up with a default AI policy because procurement convenience replaced deliberate strategy. In the private sector, you might face the same drift when a new feature appears in your existing dashboard and someone says, “Let’s just try it.”
The real risk is not price gouging tomorrow. It’s that you stop comparing. If email, file storage, collaboration, cloud infrastructure, identity management, and now AI all come from one vendor, the cost of ever changing anything becomes enormous. That’s lock‑in in its most practical, per‑day form.
For Everyday Windows Users
If you’re a frontline employee, you’ll probably encounter Copilot inside the apps you already use. That’s great for getting started, but it also means you need to be the human in the loop. Microsoft’s documentation cautions that AI output is “not guaranteed to be completely factual.” The advice from New Zealand’s Ministry for Regulation echoes that: staff must scrutinise, validate, and verify AI‑generated material before using it. Treat every AI draft as a first draft, never a finished product.
How We Got Here
New Zealand’s government has been building a Microsoft‑first stack for decades. Windows, Office, Exchange, SharePoint, and Teams became the workplace layer across most departments. The MCSSA was designed as a bulk‑buying mechanism—a way to get better pricing and standardised support across government. It worked, and there’s nothing improper about it.
When AI assistants arrived, Microsoft wove Copilot directly into that existing world. For an agency CIO, enabling Copilot didn’t feel like adopting a disruptive new platform; it felt like adding a feature to tools the workforce already understood. Compare that to procuring a standalone AI system: you’d need a separate vendor assessment, security review, data‑handling agreement, integration project, and training programme. For a busy department, the path of least resistance was almost indistinguishable from the Microsoft 365 admin centre’s “add licence” button.
The public‑sector reform gave this convenience extra urgency. With headcounts shrinking, leaders were openly looking for AI to fill the gap. The combination of time pressure and an easy‑to‑activate solution produced—almost by accident—a nationwide AI strategy.
The private sector hasn’t faced the same political pressure, but the technical dynamics are identical. And the privacy implications are no lighter. The Office of the Privacy Commissioner has made clear that the Privacy Act applies to all AI tool use in New Zealand and recommends completing a Privacy Impact Assessment. The Commissioner also advises: “When in doubt, don’t use AI tools to handle personal information.” That guidance applies as much to a 20‑person accounting firm as to a government ministry.
What to Do Now: A Practical Framework
You don’t need to swear off Microsoft or launch a dramatic exit. You need an informed dependence plan. Here’s how to build one.
1. Start with a specific workload, not a product
Instead of asking “Should we buy Copilot?”, identify a concrete business pain: staff spending hours hunting for policy documents, meeting notes that pile up unread, repetitive draft responses in customer service. A narrow workflow gives you a yardstick to measure whether any AI tool—including Copilot—actually solves the problem.
2. Run a proportionate options comparison
For a small pilot, a quick side‑by‑side test might suffice. For AI touching financial reports, legal documents, or HR data, do a more formal evaluation. At minimum, pit Copilot against one credible alternative and one non‑AI improvement (e.g., a better search index or revised process). The goal is to confirm Copilot wins on merit, not just on proximity.
3. Lock down data permissions first
Before anyone types a Copilot prompt that could surface sensitive information, clean up your digital attic. Close down overshared folders, revoke stale guest access, apply sensitivity labels, and review retention policies. This isn’t an AI‑specific step—it’s overdue hygiene that AI now makes urgent.
4. Write the rules for human review
Decide which AI outputs can fly solo and which must have an accountable human sign‑off. As a baseline, neither you nor your staff should ever treat AI‑generated content as final when it concerns: employment decisions, contracts, financial forecasts, customer commitments, safety instructions, or any form of personal or health data. The higher the consequence, the more explicit the human checkpoint.
5. Keep your exit door propped open
Preserving choice isn’t about planning to leave Microsoft tomorrow. It’s about keeping the ability to leave if you ever need to. That means:
- Document all custom workflows and integrations that depend on Microsoft APIs.
- Store critical data in portable formats whenever possible.
- Track licence counts, renewal dates, and usage metrics.
- Maintain a shortlist of two or three alternative AI tools—updated once a year—so you never negotiate from a position of ignorance.
The Outlook
New Zealand’s government is now in a position where its AI future is tightly bound to a single supplier. Regulators and watchdogs may soon push for more transparent procurement rules around AI. Businesses should watch that space: any new guidelines for the public sector will likely filter into best‑practice expectations for private companies, too.
Microsoft, for its part, will continue expanding Copilot’s reach because integration is its superpower. That’s not malicious—it’s good engineering. But it puts the onus on every organisation to be the deliberate decider. You can choose Microsoft 365 Copilot wholeheartedly, but only after you’ve asked the hard questions and proven to yourself that it’s the right tool for the right job.
At the end of the day, the government’s story isn’t really about a software licence. It’s about what happens when a convenient default becomes an unexamined destiny. Your business gets to write a different script.