Microsoft’s 2026 update to Copilot is the biggest change to the product since it launched. Two new capabilities sit at the centre of it: Copilot Work IQ, which gives Copilot a persistent understanding of how each user works, and Agent 365, which lets Copilot run multi-step business processes without a human at the keyboard. Both are genuinely useful for UK SMBs, and both raise security, governance and licensing questions that need a plan. As a Microsoft Direct Cloud Solution Provider holding the Microsoft Support Service Designation, Lanmark helps decision makers at 20 to 500-user firms work out what is hype, what is real, what to do in the next 90 days, and how to do it without exposing the firm to new risks. This guide explains what is changing in Microsoft Copilot 2026, what Work IQ and Agent 365 actually do, the security picture, and a sensible action plan.
What is changing in Microsoft Copilot in 2026
Two themes run through Microsoft’s 2026 update. The first is personalisation. Copilot is moving from a chat assistant that responds to single prompts towards a system that learns how each user writes, reasons and prioritises, and applies that context to every interaction. The second is agency. Copilot is moving from drafting and summarising to actually running tasks: scheduling, raising, approving, escalating, and routing work between applications and people.
The 2026 update is delivered as feature releases inside the Copilot you already pay for, not as a separate SKU. For most UK SMBs already on Microsoft 365 Copilot Business, the new capabilities arrive in the existing licence over the course of 2026. Some advanced agent capabilities will sit behind a separate Agent 365 add-on, where pricing has not yet been confirmed for UK SMB tenants.
The practical effect is that Copilot in mid-2026 looks materially different from the Copilot a firm rolled out in 2024 or early 2025. Any firm that ran a Copilot pilot a year ago should plan a refresh.
Copilot Work IQ: personal context that travels with the user
Work IQ is Microsoft’s term for the layer of personal context that Copilot maintains for each user. In practice, it is a structured memory of how a user writes, the projects they work on, the people they collaborate with most, the documents they reference repeatedly, and the patterns in their week.
For an FD, that means Copilot eventually understands which board pack lines need the most rigour, which clients drive the cash flow conversation, and which suppliers tend to run late. A draft reply or a summary is shaped by that context rather than written from a blank slate every time.
Work IQ is built from data the user already generates inside Microsoft 365: emails, calendar items, documents authored, Teams conversations, and SharePoint activity. The context is held inside the user’s tenant boundary, governed by the firm’s existing Microsoft 365 retention, eDiscovery and information protection policies. The user can inspect what Copilot has learned, edit it, and clear it.
The benefit is real. The first 50 prompts of a Copilot session in 2024 produced generic output until the user learned to load context into each prompt manually. With Work IQ, that context is loaded automatically, and the output quality at prompt one matches what previously took 20 prompts to reach.
The risk is also real. If sensitivity labels and SharePoint permissions are loose, Work IQ will accelerate the wrong kinds of access. A junior user whose access has drifted over years now has a personalised assistant that surfaces sensitive material faster than they could find it manually. The governance work that should have been done before the first Copilot rollout in 2024 becomes more urgent in 2026.
Agent 365: business processes that run themselves
Agent 365 is the second pillar of the 2026 update and the one that changes Copilot from an assistant to a system that performs work. An agent is a configured workflow inside Copilot that runs a multi-step business process on the user’s behalf, handing off to humans only when it needs an approval or a judgement call.
The realistic SMB use cases are not the science-fiction examples Microsoft demonstrates on stage. They are smaller and more useful. A “new client onboarding” agent receives a signed engagement letter, creates the SharePoint folder structure, sets the access permissions, drafts the welcome email for the partner to review, books the kick-off call into the right people’s calendars, and raises the relevant tasks in the firm’s CRM. A “supplier invoice triage” agent reads incoming invoices, matches them to purchase orders, flags exceptions for the finance team, and approves the rest within policy limits. A “monthly compliance check” agent walks through a checklist, gathers evidence from named sources, drafts the report, and routes it for sign-off.
Each agent is built once and runs continuously. The firm specifies the steps, the sources, the approvers and the exception conditions. Microsoft provides the runtime, the connectors to common applications, and the auditing and observability layer.
The administrative shift this requires is significant. Agents act on behalf of users. They need their own identity in Entra ID, their own permission scope, their own audit trail. They can read data, send emails, raise tickets and approve work. A firm that has not modernised its identity and access management since the Copilot rollout will struggle to deploy Agent 365 safely.
Security, governance and the SMB risk picture
Agentic Copilot is a meaningful change to the SMB threat model and the regulatory picture. Three issues sit at the top of the list.
First, identity sprawl. Each agent is a non-human identity with permissions, and the population of non-human identities in a typical SMB tenant will grow quickly through 2026 if agents are deployed without governance. The firm needs an inventory, an owner per agent, and a regular review cycle, in the same way it should already maintain a service-account inventory.
Second, data exposure through agent reasoning. An agent that has access to multiple data sources can combine them in ways no individual user was authorised to do. A “new client onboarding” agent that reads the engagement letter, the conflicts database and the firm’s historical client list could surface a conflict that was previously known only to a partner. That can be the right outcome or it can be a breach of professional confidentiality depending on who sees the agent’s output. Output routing rules and sensitivity labels need to be applied as carefully as access controls.
Third, regulatory observability. UK SMBs in financial services and legal services are subject to FCA and SRA expectations on the use of AI in client-facing processes, and the EU AI Act applies to firms with EU clients or operations. Agents must be logged, auditable and explainable. Microsoft Purview, Defender for Cloud Apps and the audit logs across Microsoft 365 are the tooling for this; configuring them correctly is the work. The NCSC guidance on AI security principles is the right framework reference for any UK SMB taking Copilot agents into production.
Lanmark’s managed detection and response service monitors Copilot and agent telemetry as part of the 24×7 SOC, so unusual agent behaviour, mass data access, prompt-injection attempts and anomalous output patterns are detected and contained rather than discovered weeks later in an audit.
What UK SMBs should do now
The action plan for the next 90 days has four steps.
Step one is a governance audit. Sensitivity labels, SharePoint permissions, Conditional Access policies and identity hygiene need to be in a known-good state before Work IQ accelerates personal context and before agents start acting on behalf of users.
Step two is a Copilot maturity review. If a firm rolled out Copilot in 2024, the 2026 features are not free upgrades in practice; they are a refresh that benefits from a fresh user survey, a usage data pull from the Microsoft 365 admin centre, and a recalibration of training and adoption.
Step three is a small agent pilot. Pick one process that is well-documented, repeatable and not high-risk: a meeting room booking workflow, a routine HR onboarding step, or an internal status report. Run it for six weeks with a named owner, capture the time saved, and use the experience to write the firm’s agent governance policy.
Step four is licensing planning. Where Agent 365 sits behind a separate add-on, the cost-benefit case needs to be built per agent. Where features arrive in the existing Copilot Business licence, no spend decision is required, but the firm should review whether the current licence mix still fits.
Why work with Lanmark on Copilot 2026 planning
Lanmark holds the Microsoft Support Service Designation, an accreditation awarded to a small number of Microsoft partners worldwide for the highest standards of cloud expertise. Lanmark is a Microsoft Direct CSP, with direct billing and support relationships with Microsoft and the partner-channel pricing that comes with it.
Copilot 2026 planning at Lanmark sits inside the AI Capability Ladder, a four-rung framework that places Copilot Work IQ and Agent 365 in the context of an SMB’s broader AI maturity. Underneath sits the Microsoft 365 platform work and the free Microsoft 365 licence review; around it sits the managed detection and response service that secures Copilot interactions and agent activity in production.
Every engagement starts with a free AI readiness and Microsoft 365 licence review, delivered as a written report with no obligation to commit. Contact us to book a review and a Copilot 2026 planning session before the next round of features lands in your tenant.
Frequently asked questions
Do I need a new licence for Copilot Work IQ?
No. Work IQ is being delivered inside the existing Microsoft 365 Copilot Business and Copilot for Microsoft 365 licences over the course of 2026. There is no separate Work IQ SKU. Firms already paying for Copilot will see Work IQ features arrive in their tenant on Microsoft’s release schedule.
Is Agent 365 included in Microsoft 365 Copilot Business?
Some agent capabilities are included; advanced agent features are expected to require a separate Agent 365 add-on, with pricing still being confirmed for UK SMB tenants. Lanmark will publish the SMB-specific licensing position as soon as Microsoft confirms it through the Direct CSP channel.
Can Copilot agents access data that individual users cannot?
Only if the firm explicitly grants them broader permissions. Agents have their own identity in Entra ID and their own permission scope. Best practice is to give each agent the minimum permissions it needs and to apply sensitivity-label-aware output routing. Lanmark builds this into every agent deployment.
How is data residency handled for Work IQ and agents?
UK tenant data residency remains available on request via Microsoft’s UK data region. Work IQ context and agent state are held inside the tenant compliance boundary and governed by the firm’s existing Microsoft 365 retention and information protection policies. Microsoft does not use this data to train its public foundation models.
What is the biggest mistake firms make with Copilot in 2026?
Treating the 2026 update as an automatic upgrade. The features arrive in the existing licence, but the governance, identity and adoption work that should accompany them does not arrive automatically. A firm that does not plan for Work IQ and Agent 365 will see Copilot deliver less value and create more risk than a firm that does.
Does Lanmark help with the agent governance policy?
Yes. Lanmark provides a Copilot 2026 readiness review covering Work IQ governance, agent identity and permissions, output routing rules, audit and monitoring, and a phased rollout plan. The review is delivered as a written report at no cost as the first step of any Copilot 2026 engagement.