AI Assistant for Productivity in Microsoft 365
Inform
What it collects
- Organizational Microsoft 365 data including emails, documents, and calendars accessed via Microsoft Graph to provide personalized workplace assistance. The register states no personal information is involved, indicating this data is treated as organizational rather than personal in nature.
- Run by
- Canada Energy Regulator (CER)
- Where
- No fixed location
- Kept
- Not stated by the Helpful Places.
- Shared with
- Accountable organization, Vendor
What it is for
Microsoft 365 Copilot is an AI-powered assistant used by Canada Energy Regulator employees within everyday productivity tools like Word, Excel, and Teams. It draws on organizational data such as emails, documents, and calendars to help staff draft content, summarize information, and automate routine tasks. The system does not process personal information about members of the public. Employees are informed that AI is in use when they interact with this tool.
What it collects and what happens to it
Data taken in
- Organizational Microsoft 365 data including emails, documents, and calendars accessed via Microsoft Graph to provide personalized workplace assistance. The register states no personal information is involved, indicating this data is treated as organizational rather than personal in nature.
Processing
- Large language models (LLMs) provided by Microsoft underpin Copilot's ability to generate content, summarize text, and respond to natural-language prompts within Microsoft 365 applications.
- Microsoft Graph is used to retrieve relevant organizational data — emails, documents, meetings — to ground generated responses in the user's specific Microsoft 365 context.
What it does
- Generates new text content such as document drafts, meeting summaries, and email replies within Microsoft 365 apps. A human employee reviews and decides whether to use, edit, or discard the generated content.
- Provides insights, summaries, and analysis across the Microsoft 365 data suite — for example, surfacing key points from documents or identifying trends in data. Outputs are advisory; the employee decides how to act on them.
- Understands and retrieves relevant organizational context from emails, documents, and calendars via Microsoft Graph to ground its responses in the user's actual work environment.
Outputs
- Produces new text content — document drafts, meeting transcriptions and summaries, email replies, and data insights — within Microsoft 365 applications for review and use by GC employees.
Run by
- The Canada Energy Regulator (CER) is the federal department that has deployed Microsoft 365 Copilot for use by Government of Canada employees within its organization.
Built by
- Microsoft is the vendor that builds, supplies, and licenses Microsoft 365 Copilot, integrating large language models and Microsoft Graph into the Microsoft 365 suite of productivity applications.
Kept for
Not stated by the Helpful Places.
Shared with
- Output data (generated content, summaries, transcriptions) is available to Canada Energy Regulator employees who use the system within their Microsoft 365 environment.
- As the technology provider, Microsoft processes organizational Microsoft 365 data to operate the Copilot service. The extent of Microsoft's data access is governed by the enterprise service agreement.
Stored
- Data processed by Microsoft 365 Copilot is stored in Microsoft's cloud infrastructure. Specific data residency and storage jurisdiction details are governed by the Government of Canada enterprise Microsoft 365 agreement.
- Duration: Not specified in the register
How to read the colours
Can it identify you?
- Anonymized data
- Data about people with the link to who is broken. Stripped of identifiers, blurred, aggregated, or noised so this system can’t reasonably tie a record back to an individual.
- Pseudonymous data
- Each person’s data is tied to a token (hash, ID, template) that lets this system recognise the same person across events, but the token itself doesn’t reveal a name. Reidentification is possible with extra information.
- Identifiable data
- The data either contains a direct identifier (name, address, account name, recognisable face or voice, plate number) or carries a token this system uses to look up legal identity during processing.
Who completes the loop?
- Human decides
- This mode suggests; a person decides what to do next. The AI is always advisory — a human is in the loop on every decision. Example: a triage tool ranks cases for a clinician who chooses which to see first.
- Human executes
- This mode decides; a person carries out the result. Example: an optimizer plans the day’s trash-collection routes, and drivers run them.
- Autonomous
- This mode decides and acts on its own. No person reviews each decision or carries out the resulting action.
Definitions from the DTPR standard. Amber is about your data, violet about who decides. The fuller the shape and the deeper the colour, the more identifying the data or the less a person is involved.
- AI registerGovernment of Canada Algorithmic Impact Assessment Register — M365 CoPilot (2526-CER-REC-002)Canada Energy Regulator, AI Register entry 2526-CER-REC-002.
- AI registerGovernment of Canada AI Register — Department field
- AI registerGovernment of Canada AI Register — Vendor field
- Register entryPublished by the Helpful Places. Reference 24a5bf88. This disclosure was drafted with AI assistance.Schema: ai@2026-05-06-beta
What you can do
Ask about this system
Questions go to the Helpful Places, not the vendor.
Your rights
- Right to Be Informed of AI UseGovernment of Canada employees are informed that AI is in use when they interact with Microsoft 365 Copilot. The register confirms AI use is disclosed to users.
- Right to Algorithmic TransparencyThe system's inclusion in the Government of Canada AI Register provides public transparency about its deployment. Microsoft publishes documentation on how Microsoft 365 Copilot works, including its use of large language models and Microsoft Graph.
Risks and safeguards
- Psychological harmAI-generated content (hallucinations or inaccurate summaries) could mislead employees and create workplace stress or erode trust in organizational information.Safeguard: AI use is disclosed to users; outputs are advisory and require human review before acting upon them.
- Societal & cultural harmWidespread use of a single vendor's LLM for government drafting could homogenize public communications and create dependency on a proprietary system.Safeguard: The system is limited to internal employee productivity use; public-facing communications remain subject to human authorship and approval.