AI & Machine Learning

Copilot Cowork is GA: a rollout and cost-control playbook

By Technspire TeamJune 19, 202612 views

Copilot Cowork reached worldwide general availability on 16 June 2026. Microsoft describes it as an agentic system for complex, long-running, multi-tool work: you hand it an outcome, and it plans, executes across documents, apps and organizational data, and returns completed results rather than drafts. It went through a three-month Frontier preview starting 30 March, during which, according to Microsoft, more than half of the Fortune 500 used it, including Accenture, Capital Group and Zurich Insurance. As of this week it is available to every Microsoft 365 Copilot license holder whose admin switches it on.

Two details make this more than another feature announcement for a Swedish IT department. First, billing: Cowork usage is not included in the Microsoft 365 Copilot license. It is metered through Copilot Credits, a consumption billing model priced at 0.01 US dollars per credit on pay-as-you-go, and billing started on GA day for new tenants. Second, models: at launch Cowork runs on Anthropic's Opus 4.8 and Sonnet 4.6, with GPT-5.5 available through the Frontier program and Microsoft's own fine-tuned Cowork 1 model promised in the coming weeks. A consumption-billed autonomous agent, running on a third-party model by default, inside your production Microsoft 365 tenant: that combination deserves a deliberate rollout, not a default one.

What actually shipped at GA

The model lineup, and why Anthropic-by-default matters

Cowork's launch models are Anthropic Opus 4.8 and Sonnet 4.6, matched to the work being done. GPT-5.5 is available to Frontier tenants, and Microsoft has said Cowork 1, a fine-tuned model of its own, is coming shortly after GA. Microsoft even leaned into the comparison in its GA post, claiming Cowork averaged 30 to 40 percent cheaper than Claude Cowork with the Microsoft 365 connector when using Opus 4.8. Treat that as a vendor benchmark, but note what it tells you: Microsoft is positioning Cowork directly against running Anthropic's own product over your Microsoft 365 data.

For EU tenants, the model lineup is not a trivia item. Your existing data-processing documentation for Microsoft 365 Copilot was almost certainly written when the answer to "whose model processes our data?" was OpenAI models operated by Microsoft. If Cowork requests are served by Anthropic models by default, your records of processing and any DPIA covering Copilot should be updated to reflect that. The operational questions to put to your Microsoft account team are concrete: where does inference for each Cowork model run, does the EU Data Boundary commitment cover it, and what are the subprocessor arrangements for the Anthropic-served paths? Do not assume the answers carry over from the Copilot Chat documentation you reviewed last year.

Security and compliance surface

Cowork operates inside the Microsoft 365 trust boundary and honors existing permissions. At GA it plugs into the Purview stack: audit logging, eDiscovery, data lifecycle management, Data Security Posture Management and Insider Risk Management are supported, with DLP listed as coming soon. Sensitivity labels and role-based access controls apply. That last gap is worth registering: if your Copilot governance today leans on DLP policies to stop sensitive content leaving a boundary, Cowork does not yet enforce them, so scope your pilot accordingly.

Plugins, Dynamics 365 and browser use

GA also brought nine third-party plugins (Enosix, Harvey, LSEG, Miro, monday.com, Moody's, Morningstar, S&P Global Energy and TeamsMaestro), with Adobe, Atlassian, Box, Canva, CB Insights, Databricks, MoneyForward and Templafy announced as coming soon. The Dynamics 365 plugin suite is generally available, which matters for the many Swedish organizations running Business Central or Dynamics 365 Sales alongside Microsoft 365. Frontier tenants additionally get browser use via Edge, where Cowork can browse the web under enterprise policies. Each plugin you enable widens the agent's reach and your review surface; enable them one at a time, with an owner per plugin.

The billing model: Copilot Credits in practice

Cowork requires two things: a Microsoft 365 Copilot user license, and usage-based billing configured in the Microsoft 365 admin center. No Cowork usage is bundled with the license. Consumption is metered in Copilot Credits, and the credit burn of a task is driven by four factors: which model runs it, how much context is retrieved, how many tool calls it makes, and how long it runs. Microsoft classifies tasks as light (single knowledge source, minimal reasoning, one output), medium (multiple sources, structured reasoning, two or more outputs) and heavy (broad aggregation, deep reasoning, many outputs), and the admin experience shows per-task pricing in credits.

There are two ways to pay. Pay-as-you-go is 0.01 US dollars per credit, billed against an Azure subscription. The P3 option commits to a usage volume in advance in exchange for a discount. The arithmetic of PayGo is at least easy to reason about: a tenant budget of 50,000 credits is 500 dollars, roughly 4,800 SEK at current exchange rates, and a spending limit at that level is a hard ceiling on your exposure while you learn what your organization's real task mix costs. Start on PayGo, measure for a quarter, and only then decide whether a P3 commitment pays off.

Dates that matter for existing preview tenants. Tenants that had at least one user in the Frontier program between 30 March and 16 June get a billing grace period: Cowork usage is free until 1 July 2026. From 23 June, users in those tenants start receiving expiration notifications. On 1 July, any tenant without usage-based billing configured loses Cowork access entirely. If your organization touched the preview, the admin task of wiring up billing (or deliberately deciding not to) belongs in this sprint, not next month's backlog. New tenants enabling Cowork now are billed from day one.

The cost-governance tooling is better than what we usually get at a GA launch. Cowork is off by default. Admins enable it per tenant and assign access, set spending limits at tenant, group and user level, configure usage alerts, and get usage reporting at all three levels. Users can request additional credits rather than silently hitting a wall. In other words, the primitives for a controlled rollout exist; the failure mode is not missing controls but nobody being assigned to use them.

A rollout playbook for Swedish IT

  • 1. Decide the default posture first. Cowork ships disabled. Write down, before anyone asks, whether your organization's posture is "off until reviewed", "pilot group only" or "on with limits". An explicit decision beats an accumulating pile of individual exceptions.
  • 2. Handle the 1 July deadline if you were in Frontier. Check whether any user in your tenant used Cowork during the preview. If so, decide before 1 July whether to configure billing or let access lapse, and communicate it, because those users will get expiration notices from 23 June and will come asking.
  • 3. Wire billing to a dedicated Azure subscription. Point Copilot Credits at a subscription with its own cost alerts and a clear owner, not at a shared production subscription where Cowork spend disappears into the noise.
  • 4. Set spending limits at all three levels. A modest tenant ceiling, group limits per department, and per-user limits for the pilot. Generous limits can be granted later; clawing back an open tap is harder.
  • 5. Pick a pilot group with measurable work. Choose 10 to 30 users whose Cowork tasks produce reviewable outputs (report packs, cross-document comparisons, structured research) so you can judge both quality and credits-per-task after a month.
  • 6. Update your Copilot DPIA and Article 30 records. Add Cowork as a processing activity, name the launch models, and record the open questions you have put to Microsoft about inference location and the EU Data Boundary.
  • 7. Defer DLP-sensitive scenarios. Until DLP enforcement ships for Cowork, keep the pilot away from data whose protection depends on DLP policies rather than permissions and sensitivity labels.
  • 8. Review plugins individually. Treat each of the nine GA plugins as its own vendor assessment. A legal-research plugin and a whiteboard plugin do not carry the same risk profile.
  • 9. Instrument before you scale. Use the per-task credit reporting to build a picture of your task mix. That data is what makes the later PayGo-versus-P3 decision an informed one.

When Cowork beats building your own Foundry agent

Many teams we talk to have spent the last year building custom agents on Azure AI Foundry, and the obvious question this week is which workloads now belong in Cowork instead. This is our framing, not Microsoft's, but the decision falls out fairly cleanly from what each option controls.

Choose Cowork when the work lives in Microsoft 365. If the task is fundamentally about your tenant's documents, mail, meetings and the systems already wired in through connectors and plugins, Cowork gives you grounding, permissions trimming, Purview integration and a finished admin surface for free. Rebuilding that in Foundry means rebuilding the Microsoft 365 security model yourself, and getting it subtly wrong is the most common failure we see in custom agent projects. Microsoft's example scenarios from the preview (comparing nearly 4,000 files across product versions, pipeline reviews assembled in a morning) are exactly this shape: broad aggregation over tenant data with human-readable deliverables.

Build in Foundry when you need control Cowork does not offer. A custom agent is the right call when you must pin the model version and region for compliance, when the agent is embedded in your own product or a line-of-business system rather than the Microsoft 365 surface, when you need deterministic orchestration with your own evals and rollback, or when the workload's economics reward optimization (a high-volume, narrow task where you can use a small model and aggressive caching rather than paying agentic-runtime credits per execution). Cowork's credit meter charges for model use, retrieval, tool calls and runtime; a purpose-built pipeline for a repetitive task will usually undercut a general agent doing the same thing.

The hybrid pattern is legitimate. Nothing stops you exposing a Foundry-built capability to Cowork through a connector or plugin, letting Cowork handle orchestration and the human interface while your controlled backend does the regulated or high-volume part. For teams with existing Foundry investments, that is often the migration path worth evaluating first, before either wholesale adoption or wholesale dismissal of Cowork.

The licensing backdrop: read this GA together with the spring changes

Cowork's GA lands in a quarter where Microsoft has been redrawing the Copilot licensing map. Since 15 April 2026, the Copilot features inside Word, Excel, PowerPoint and OneNote require a paid Microsoft 365 Copilot license; unlicensed users keep Copilot Chat via the app and web, and Copilot in Outlook remains available. Separately, Microsoft has a global Microsoft 365 pricing and packaging update taking effect across purchasing channels on 1 July 2026, with partners actively pushing renewals before that date. And Cowork itself adds a consumption meter on top of the per-seat license.

Put together, the shape of Microsoft 365 AI licensing is now: per-seat for the assistant features, consumption for the agentic ones. For budgeting purposes that means your Copilot line item stops being a flat number of seats times list price. Finance will want a forecast model with a variable component, and the only credible input to that model is a quarter of measured pilot data, which is one more reason to start the pilot small and instrumented now rather than large and blind in the autumn.

The Swedish and EU angle

Data protection paperwork needs a real update, not a footnote. Cowork is a new processing activity with new characteristics: autonomous multi-step execution, third-party models in the serving path by default, plugins that move data to external services, and (in Frontier) web browsing. Each of those belongs in your Article 30 records and, for most organizations, in an updated DPIA. The questions about Anthropic model hosting and EU Data Boundary coverage should be asked in writing through your account team or CSP partner, and the answers filed with the assessment.

Public sector and regulated buyers should watch the plugin boundary. Swedish municipalities and agencies that have cleared Microsoft 365 Copilot through their security reviews cleared a specific scope. Cowork's plugins, and especially browser use, extend that scope beyond the tenant boundary. Keeping Cowork enabled but plugins off is a defensible intermediate posture while reviews catch up, and it is exactly the kind of granular decision the admin controls support.

Consumption billing changes procurement conversations. Swedish enterprise agreements and public framework contracts handle per-seat licensing well; metered consumption with spending limits looks more like Azure than like Microsoft 365, and your procurement function should treat it that way, with the same budget-owner and cost-review routines you apply to cloud spend. If you buy through a CSP, ask them for the Cowork cost-estimation guidance Microsoft has published to partners; making them earn their margin on cost modeling is fair game.

Direct takeaways

  • Copilot Cowork is GA worldwide as of 16 June 2026, off by default, and requires both a Microsoft 365 Copilot license and configured usage-based billing.
  • Pricing is 0.01 US dollars per Copilot Credit on pay-as-you-go, with credit burn driven by model use, retrieval, tool calls and runtime. No usage is bundled with the license.
  • Frontier preview tenants are unbilled until 1 July 2026 and lose access on that date without billing configured. Decide and communicate before 23 June, when user notifications start.
  • Launch models are Anthropic Opus 4.8 and Sonnet 4.6, with GPT-5.5 in Frontier and Cowork 1 announced. Update DPIAs and Article 30 records, and get written answers on inference location and EU Data Boundary coverage.
  • DLP enforcement is not yet available for Cowork. Scope pilots to data protected by permissions and sensitivity labels.
  • Set spending limits at tenant, group and user level before enabling anyone, and bill to a dedicated Azure subscription with an owner.
  • Route Microsoft-365-centric aggregation work to Cowork; keep regulated, embedded and high-volume workloads on Azure AI Foundry, and evaluate the plugin-based hybrid before committing either way.

Sources