AI & Machine Learning

Copilot August 2026: Authoritative Sites and model choice

Av Technspire TeamAugust 26, 202614 visningar

Microsoft published two dense batches of Microsoft 365 Copilot release notes this month, on 11 and 25 August 2026, and together they touch almost every complaint we hear from Swedish enterprises running Copilot at scale. SharePoint administrators can now mark sites as Authoritative so that official content outranks stale copies in Copilot Search. Word users on the web can pick Anthropic models alongside OpenAI models, with Sonnet 5 appearing in the models menu at a higher default reasoning level. Edit with Copilot in Excel can execute Python for advanced analysis. Copilot Notebooks gained Outlook emails and Teams meetings as knowledge sources. Developers get a unified Work IQ REST endpoint for invoking agents and workflows. And a new Viva Insights Consumption Dashboard tracks Copilot credit usage, which matters now that more Copilot capabilities meter against credits under usage-based billing.

For an Azure-first organisation in Sweden, three of these deserve real configuration work rather than a passive rollout: Authoritative Sites, because grounding quality is the single biggest driver of whether users trust Copilot answers; model choice, because enabling Anthropic models changes where your data is processed; and the Consumption Dashboard, because credit-metered features without cost visibility is how AI budgets get burned. The rest of the wave is useful but largely self-serve. This piece covers what shipped, how to configure the three items that need decisions, and what the model-choice change means for your GDPR documentation.

What shipped on 11 and 25 August

SharePoint Authoritative Sites

The 11 August notes introduce the Authoritative Sites feature: administrators can classify certain SharePoint sites as authoritative, and content from those sites, such as company news and policies, is then prioritized in Copilot Search. Microsoft's own framing is telling: previously, content ranking in Copilot Search did not distinguish official sources. Anyone who has watched Copilot cite a 2019 draft of a travel policy while the current version sat in a communications site knows exactly which problem this addresses. The mechanics are simple: open the SharePoint admin center, select a site, and choose the option to mark it as an authoritative site. The hard part is deciding which sites qualify, which we cover below.

Model choice in Word: Anthropic models and Sonnet 5

Two related entries land here. On 11 August, Copilot in Word on the web gained support for selecting Anthropic models alongside the existing OpenAI models for document editing. On 25 August, Sonnet 5 appeared in the Word models menu, with Microsoft noting that Copilot uses a higher default reasoning level with Sonnet 5 for more accurate drafting and edits. Users pick the model from a selection menu inside the Copilot pane.

This is the feature with governance teeth. Microsoft's documentation on Anthropic models in Microsoft 365 is explicit: when your organisation chooses to use an Anthropic model, data sent to that model is processed outside Microsoft-managed environments, and Microsoft's data-residency commitments, audit and compliance controls, and the Data Processing Addendum do not apply to that processing. Use of the Anthropic models is governed by Anthropic's Commercial Terms of Service and Anthropic's Data Processing Addendum instead. Access is off until an admin enables it in the Microsoft 365 admin center, so nothing changes for your tenant until you decide it should.

Python in Excel through Edit with Copilot

From 25 August, Edit with Copilot in Excel on Windows, Mac and the web can execute Python code for advanced analysis, automation and data transformation, with results written directly into the workbook. Ask Copilot to summarise trends, clean data or build a visualisation, and it can now reach for Python rather than being limited to formulas. Microsoft states that existing security and execution controls manage how the code runs, meaning the Python in Excel container model your security team already reviewed still applies. For finance and operations teams this quietly removes the gap between "people who can use Python in Excel" and "people who could benefit from it".

Notebooks, unified chat and the Work IQ endpoint

The 25 August batch reworks Copilot Notebooks with a streamlined UX and, more usefully, two new knowledge-source types: Outlook emails and Teams meetings. A notebook grounding a project brief can now reference the email thread where scope was agreed and the meeting where it changed. The same batch unifies web and work chat into a single interface with a dedicated Work IQ button controlling access to work data; work data is on by default and users can toggle it. On the developer side, the 11 August notes ship a unified Work IQ REST endpoint for invoking agents and workflows, replacing multiple legacy Copilot Chat endpoints. If you have integration code pointed at the older endpoints, put the migration on the backlog now rather than waiting for a deprecation notice.

The Consumption Dashboard

Also from 11 August: a Consumption Dashboard in Viva Insights that shows Copilot credit consumption for Cowork and Work IQ API services. Access is scoped to managers with at least five direct reports, Insights analysts and Global administrators. It is enabled by default but only becomes meaningful once usage-based billing is set up through Cost Management in the Microsoft 365 admin center. A Cost Management query template in Advanced Insights supports deeper analysis. Modest as it sounds, this is the first native answer to a question every Swedish IT controller has asked since credit-metered Copilot features appeared: who is spending the credits, and on what?

Configuring Authoritative Sites so they actually help

The feature is a ranking signal, not an access control. Marking a site authoritative does not hide anything else; it tells Copilot Search that when official content and informal copies compete, the official content should win. That framing should drive your selection. The failure mode to avoid is the enthusiastic one: if a third of your sites are authoritative, none of them are, and you have reproduced the ranking soup you started with.

A site earns the authoritative flag when all four are true:

  • 1. It is the system of record. The site is where the current version of a policy, process or announcement officially lives, not a team's working copy.
  • 2. It has an owner who curates it. Someone is accountable for the content being current. An authoritative site full of expired content is worse than no flag at all, because Copilot will now confidently prefer the stale version.
  • 3. Its content is broadly readable. Prioritising a site most employees cannot open does nothing for them. Intranet home, HR policy and communications sites are typical candidates; a finance team site with restricted permissions usually is not.
  • 4. Its content answers questions people actually ask Copilot. Policy, HR, IT how-to and company news dominate real Copilot Search queries. Start there.

Practically: start with a shortlist of five to ten sites, typically the intranet landing site, the HR policy site, the IT self-service site and the official communications site. Pair the rollout with a content review, because the flag amplifies whatever is on the site. Then re-test the queries your users complained about. Before-and-after spot checks on your ten most common internal questions is a cheap way to demonstrate the improvement to stakeholders, and it tells you whether your site selection was right.

The model-choice decision: what enabling Anthropic actually changes

Model choice in Word sounds like a user-preference feature. For an EU organisation it is a data-flow decision, and it should go through whoever owns your Article 28 processor documentation, not just the M365 admin team.

With the default OpenAI-hosted models, Copilot processing stays within Microsoft-managed environments and inherits the commitments in your Microsoft agreements, including the Data Protection Addendum and, where applicable, EU Data Boundary commitments. With Anthropic models enabled, prompts and content sent to those models are processed outside Microsoft-managed environments under Anthropic's terms. Microsoft says this plainly in its documentation, listing data residency commitments, audit and compliance requirements, service level agreements and the Customer Copyright Commitment as items that do not apply to Anthropic model usage.

That does not make the feature unusable. It makes it a decision with a paper trail. A reasonable sequence for a Swedish enterprise:

  • Leave it disabled by default. The tenant setting is opt-in. Nothing needs to be done to stay in the current posture.
  • Run a DPIA-style review before enabling. Read Anthropic's Commercial Terms and DPA, identify where processing occurs, and map which document categories would flow through Word editing. Legal and the DPO sign off, or they do not.
  • If you enable, tell users what changes. The model picker gives no compliance context. A one-page internal note explaining when the Anthropic option is appropriate costs an hour and prevents the scenario where someone edits a document containing personal data through a processing path your records do not cover.
  • Log the decision. Whether you enable or not, record the assessment. Procurement and audit will ask, and "we evaluated it in September 2026 and here is the reasoning" is the answer you want available.

For teams whose main interest is Sonnet 5's editing quality, note that the evaluation is worth doing on merit. Microsoft does not set higher default reasoning levels casually, and having two frontier model families selectable inside Word is genuine leverage for heavy drafting workloads. The point is to enable it with your eyes open, not to avoid it.

Credits: get the dashboard in place before the features spread

Copilot's commercial model has been drifting from pure per-seat licensing toward a mix of seats plus credit-metered consumption, with Cowork and the Work IQ APIs on the metered side. The Consumption Dashboard is Microsoft acknowledging that customers cannot manage what they cannot see. Two setup notes matter. First, the dashboard reads from usage-based billing, so if Cost Management in the Microsoft 365 admin center is not configured for Copilot billing, do that first; the dashboard has nothing to show without it. Second, the access scoping (managers with five or more direct reports, Insights analysts, Global admins) means your FinOps or controller function may need one of those roles assigned deliberately, because the people who watch cloud spend are not always the people who hold Viva Insights roles today.

Treat Copilot credits the way you already treat Azure consumption: a monthly review, an owner, and a threshold that triggers investigation. The Cost Management query template in Advanced Insights gives the analyst side a starting point. Doing this now, while credit-metered usage is still small, means the process exists before the numbers get interesting.

The Swedish and EU angle

Data residency splits by model family. Most Swedish enterprises adopted M365 Copilot partly on the strength of Microsoft's EU commitments. Those commitments continue to apply to the default experience, and explicitly do not extend to Anthropic model processing. Your records of processing and any customer-facing security documentation should reflect which paths are enabled in your tenant. If you operate under sector guidance, for example in financial services or the public sector, assume the Anthropic option needs its own assessment rather than inheriting the original Copilot approval.

Authoritative Sites is a compliance aid, not just a search feature. Organisations subject to NIS2-era governance expectations are asked to show that employees can find current security policies and procedures. A configured authoritative intranet that Copilot Search demonstrably prioritises is evidence of exactly that, and it reduces the operational risk of staff acting on outdated policy text surfaced by an AI assistant. It also strengthens the answer to a question auditors have started asking: how do you control what your AI assistant tells employees about internal rules?

Cost transparency supports procurement discipline. Swedish public-sector buyers and cost-conscious enterprises alike struggle to forecast AI spend under consumption pricing. A native dashboard tied to Cost Management gives you actuals to base renewals and upphandling estimates on, instead of vendor projections. Start collecting that history now; a year of real consumption data is the strongest negotiating position available when the license mix comes up for review.

Rollout checklist

  • 1. Shortlist five to ten SharePoint sites against the four criteria above, review their content for currency, then mark them authoritative in the SharePoint admin center.
  • 2. Re-run your ten most common internal Copilot Search queries and record before/after answer quality.
  • 3. Confirm the Anthropic model toggle state in the Microsoft 365 admin center. If disabled, log that as the current decision. If you want it, schedule the DPIA-style review with your DPO before flipping it.
  • 4. Set up usage-based billing in Cost Management and verify the Viva Insights Consumption Dashboard is populating; assign analyst access to whoever owns AI spend.
  • 5. Inventory integrations calling legacy Copilot Chat endpoints and plan migration to the unified Work IQ REST endpoint.
  • 6. Notify Excel power users about Python through Edit with Copilot, and confirm your existing Python in Excel security settings reflect current policy.
  • 7. Brief users on the unified chat interface and the Work IQ button, since work data access is on by default in the new experience.

The August wave rewards tenants that do the configuration work. Authoritative Sites only improves answers if the right sites carry the flag, model choice is only safe if someone owns the data-flow decision, and credit tracking only prevents surprises if billing is wired up before consumption grows. Two focused sprints cover all seven items.

Sources