If your firm has been using Copilot in Word or Outlook, you have a clear picture of what it does. It drafts a first pass on a letter. It summarizes a deposition transcript. It waits for you to ask before it touches anything.

That picture is out of date now.

Microsoft announced Copilot Wave 3 in March 2026, and the headline feature is not another drafting improvement. It is the ability for anyone at your firm to build their own AI agent inside Word, Excel, PowerPoint, and Outlook: a task-specific assistant that runs on its own once it is set up, without someone approving every step it takes.

That is a genuine capability for a firm buried in routine drafting and formatting. It is also a question worth being able to answer before your malpractice carrier or the State Bar asks it for you: can you say, right now, what client data the agent your paralegal built last week is touching?

What Copilot Wave 3 adds

The core of Wave 3 is agent-building inside the apps your firm already runs on. An agent can be narrower than a full AI assistant: something that formats intake documents the same way every time, or drafts a first pass on routine client status updates. Someone at the firm describes the job once, and the agent runs it after that without a partner reviewing every output.

Copilot’s chat window also picked up more reach. It can now edit a document, spreadsheet, or email directly from the conversation, instead of the user clicking between screens to make the change themselves.

Microsoft is also rolling out Work IQ, which lets Copilot read your firm’s own data, past correspondence, and internal files so its answers fit how your practice runs, instead of a generic answer that could apply to any business. Copilot is no longer running on Microsoft’s models alone, either. It now supports Anthropic’s Claude and OpenAI’s GPT, which means the model touching a client matter can change depending on what Microsoft routes it through. It’s the same reasoning behind why firms should think twice before using AI browsers that route data through third-party models.

Still in preview: Copilot Cowork, which lets an agent run a longer, multi-step task on its own and check back in once finished, rather than answering a single prompt.

Reasonable efforts doesn’t cover an agent nobody approved

Here is the part that matters more than the feature list. An AI agent with access to your firm’s files and inbox is not a shortcut. It is functionally a new hire, one who never sat through an intake meeting, was never told what a matter is, and has whatever access the person who built it decided to give.

That is the duty of confidentiality showing up in a form the rule never anticipated. Under the ABA Model Rules, Rule 1.6(c) frames that duty around reasonable efforts to prevent inadvertent or unauthorized disclosure of client information. An agent built on a Tuesday afternoon, pointed at a shared inbox, with nobody checking which matters it can see, is close to exactly what the rule is aimed at. California firms carry a comparable obligation through Business and Professions Code section 6068(e), California Rule 1.1’s duty of competence, and Formal Opinion 2010-179 on the reasonable use of technology. Different path, same practical question: can the firm describe what its own tools are doing?

The competence side is just as real. ABA Formal Opinion 512, issued in July 2024, addressed generative AI directly: the lawyer stays responsible for the work product, confidentiality obligations apply to whatever gets fed into the tool, and supervision doesn’t disappear just because the assistant is software instead of a person. California’s State Bar published its own practical guidance on generative AI in November 2023, covering much of the same ground. Neither document had self-built AI agents inside Word and Outlook in mind, because the feature didn’t exist yet. The obligations underneath it did, and they don’t pause for a Microsoft product update.

The associate who built the agent can probably tell you what it does today. Whether anyone remembers in six months, once she’s moved to a different matter and the agent is still running quietly in the background, is a different question.

What to sort out before someone builds one

Microsoft is also launching Agent 365 on May 1, 2026, at $15 per user: a management platform built so an organization can see and govern the AI agents its people create. That Microsoft built this at the same moment it opened up agent-building to everyone is worth noticing. It’s a quiet admission that ungoverned agents are a real problem, not a hypothetical one. Microsoft is bundling Agent 365 into a new top-tier package too, the Frontier Suite, at $99 per user alongside Copilot, Entra, Defender, Intune, and Purview. That bundle is aimed at larger, security-heavy organizations, and most firms in this audience won’t need the whole package to get the governance piece right.

What the firm actually needs before anyone builds an agent is smaller than that bundle. Decide who can create one: an associate testing a drafting shortcut is a different risk than a contract paralegal with access to five active matters. Decide what each agent can reach: a specific client’s SharePoint folder is a different exposure than the firm’s shared Outlook inbox. That same instinct — controlling what runs automatically and with what access — is worth applying to startup apps in Windows 11 too. And decide who reviews what the agent is doing, whether that’s through Agent 365 or a lighter process your IT provider sets up and documents. For most firms in this audience, mapping that starts in two places: whatever lives in Clio, and whatever lives across Word, Outlook, and SharePoint.

If the firm isn’t on Copilot yet, that’s not a reason to wait either. It’s a reason to have the access and governance conversation before the first agent gets built, not after one already has.

Back to where this started. Could you say, right now, what client data every AI agent at your firm can reach, and who approved it? For most firms the honest answer is no, not because anyone did anything wrong, but because the feature is a few months old and nobody has drawn the lines yet. The same visibility gap shows up in smaller ways too, like assuming incognito browsing protects more than it actually does. We help firms map where client data actually lives, set rules for who can build an agent and what it can touch, and document the answer before a regulator, an insurer, or opposing counsel asks the question first. It’s easier to do that now, while the feature is new, than after an agent has already touched a matter it shouldn’t have.