← Policies & standards

AI & Microsoft Copilot Usage Policy

Consolidated responsible AI, agent and prompt governance

Version: 2.0 Updated: 06 August 2026

1. Purpose

This policy governs the use, development and deployment of AI across TFG. AI may support productivity, analysis, content, data products and workflows, but does not replace professional judgement. Users remain accountable for the accuracy, legality, suitability and client impact of work produced with AI.

2. Scope

The policy applies to all personnel, operating companies, AI tools, models, copilots, agents, prompts, connectors, retrieval systems, automation, embedded AI features and AI-generated outputs used for TFG business.

3. Approved use

Use approved enterprise tools for business activity.

Follow client contracts, documented restrictions and information classification.

Use only the minimum information required for the task.

Review and verify outputs against authoritative sources.

Disclose material AI use where contract, law, policy or professional context requires it.

Record owner, purpose, sources and lifecycle status for deployed agents and applications.

4. Prohibited use

Entering client-prohibited, restricted, credential, security-sensitive or special-category information into an unapproved AI service.

Using consumer or personal AI accounts for confidential TFG or client work.

Allowing an agent to take high-impact external action without defined approval and rollback controls.

Presenting fabricated citations, unverifiable claims or synthetic data as factual.

Using AI for unlawful discrimination, deceptive impersonation, unauthorised surveillance or rights-infringing activity.

Circumventing safety, access, logging, content or client controls.

5. Prompt and data handling

Prompts and outputs are information assets. They must be classified according to their content, stored only where approved, shared on a need-to-know basis and retained according to the approved schedule. Source permissions must be corrected before connecting Copilot or an agent; AI must not be used as a workaround for weak access governance.

6. Agent governance baseline

Control

Minimum requirement

Ownership

Named business owner and technical owner.

Purpose

Documented use case, users, value and prohibited uses.

Identity and access

Managed identity where supported; least privilege; no shared credentials.

Data

Approved sources, classification, lawful basis, retention and deletion.

Actions

Allow-listed tools/actions, human approval for high impact, rollback/disable route.

Evaluation

Accuracy, source quality, harmful output, prompt injection, privacy and security testing.

Observability

Usage, errors, actions and security events logged where architecture supports it.

Lifecycle

Status recorded as concept, test, live, suspended or retired; periodic review.

7. Microsoft service controls

Use Microsoft 365 and Entra permissions as the primary access boundary for Microsoft Copilot experiences.

Use sensitivity labels, retention, DLP, audit and Purview AI capabilities where licensed, configured and appropriate.

Review oversharing and stale access before enabling broad AI discovery.

Use approved Copilot Studio/Azure environments, connectors and deployment pipelines for built agents.

Do not state that a control is active solely because Microsoft offers it; configuration and evidence are required.

8. Human oversight

Human review is required for client recommendations, media investment, regulatory or legal content, public statements, sensitive people decisions, financial commitments, contractual interpretation and actions that change production systems or external platforms.

9. Incident and reporting

Unexpected disclosure, harmful output, prompt injection, unsafe action, model/provider issue, excessive access or policy breach must be reported immediately under the Incident Response Plan. The affected tool or agent may be suspended while investigated.

10. Governance and assurance

The AI Governance Committee maintains the approved-tool register, risk tiers, agent inventory and exceptions. High-risk or client-facing deployments require documented approval. Training is mandatory for users of approved AI services. This policy is reviewed at least annually and following material legal, supplier, model or architecture change.

11. Microsoft reference basis

Microsoft Cloud Adoption Framework: governance and security baseline for AI agents.

Microsoft Purview guidance for data security and compliance controls for generative AI.

TFG Information Security Policy, ISMS Scope, GDPR Policy and Incident Response Plan.