Blog

Why Law Firm CMOs Should Push IT to Enable Copilot Cowork

Written by Guy Alvarez | Sep 28, 2026, 4:22:46 PM

In my work with law-firm marketing and business development teams, one problem keeps coming up. A firm approves Microsoft Copilot as its official AI tool. A team member needs deeper research, stronger writing, or a longer piece of work than that approved tool seems able to handle.

So the person turns to a different AI system, deletes any client or case details, generates the material there, and pastes the result back into Copilot. For a marketing and BD team already stretched across RFPs, thought leadership, and social content, that extra loop adds friction to work that felt urgent in the first place.

The person doing this may believe it respects the firm's rules. But every transfer adds manual work, strips away useful context, and creates another place where sensitive information can slip through the cracks.

It also leaves the firm with less visibility into how the work actually got made. This behavior shows up in the numbers, too.

The Thomson Reuters Institute's 2026 legal report found that 34% of law-firm professionals use AI tools their firms have not approved for work. That means firms carry the risk of unapproved AI use whether or not their policies say those tools are off-limits.

Microsoft Copilot Cowork gives CMOs, IT leaders, and firm leadership another option. It lets teams pull more of that work back inside the approved Microsoft environment and build real controls around how people use it.

The Workaround Has Become a Workflow

Look at the actual steps behind this copy-paste detour. The professional removes client, lawyer, matter, and firm details.

The cleaned-up material goes into an outside AI model. The response comes back into Copilot, where someone has to restore the missing context and check the output again.

A task meant to save time ends up gaining an extra production step. For a marketing and BD team handling RFPs, thought leadership, lawyer biographies, directory listings, social posts, competitive research, and pitch materials, those extra steps pile up fast.

The process also breaks the paper trail. Firm leaders might know where the final document lives, but they often can't trace which outside AI system shaped it along the way.

The Thomson Reuters number puts a real scale on that pattern. More than one in three surveyed law-firm professionals admitted to using AI tools their firm hadn't approved.

A simple ban only offers partial protection when the approved system can't handle the work people actually need to get done.

I'd treat this workaround as a signal worth paying attention to rather than a rule violation to punish. Employees are pointing to a gap between what the approved tools can do and what the job requires.

Cracking down harder may just push the behavior further out of sight. Giving people a better, sanctioned option might bring it back into view, where the firm can actually manage it.

Copilot's Model Story Has Changed

Some of the frustration with Microsoft Copilot came from earlier comparisons with newer models available through ChatGPT or Claude. Those comparisons are worth revisiting, because Microsoft's underlying models have moved fast.

According to Invite Networks' July 2026 analysis, GPT-5.6 became Copilot's preferred model across Word, Excel, PowerPoint, Chat, and Cowork that same month. Claude also became selectable inside Copilot Chat for complex analysis and document work.

Microsoft reportedly pushed more than 40 updates to Copilot in July 2026 alone. A firm policy that treats "Copilot" as one fixed, unchanging tool may already be out of date.

Which model actually answers a request can depend on the app, the task, the license, and how an administrator configured the settings. The quality a marketer experiences can come down to configuration as much as the name printed on the product.

A broad complaint that "Copilot produces weaker work" might actually point to several separate problems. The wrong model may be selected, permissions may be too limited, or a simple chat interface may be doing a job that needs several steps instead.

Each of those calls for a different fix. Tracing the real cause before buying a new tool might reveal that the answer sits inside existing settings rather than a new purchase.

What Cowork Adds

Microsoft describes Copilot Cowork as an agentic system, meaning it can plan out a task, carry it through multiple steps, and deliver finished work across different apps, files, and data sources. Standard Copilot chat usually answers one request at a time.

Cowork can string together a longer sequence involving several tools and stages. That distinction matches how law firm marketing and business development work actually gets built. Cowork shows up inside the same Copilot web page or app people already use, once a firm turns it on.

That keeps the interface familiar while extending what it can actually coordinate. For a CMO weighing this, the real distinction is between prompt assistance and managed task execution.

Chat helps draft, revise, summarize, and brainstorm. An agentic system can carry context across a longer assignment, still governed by the firm's permissions and approval rules.

Law Firms Already Have the Foundation

Microsoft already holds a strong position in legal AI adoption generally. LawSites' coverage of ILTA's 2026 Technology Survey found that 94% of more than 500 surveyed firms use or are exploring generative AI.

Microsoft 365 Copilot led every other product on the list, used by 76% of firms, with 52% reporting full deployment among their lawyers. Those adoption figures don't confirm that Cowork itself has spread widely across firms.

What they suggest is that the underlying Microsoft foundation already exists in most law-firm environments. Most firms already manage Microsoft logins, permissions, documents, and Copilot access.

Their employees already have some familiarity with the interface, too. That context changes the internal conversation.

Bringing in a brand-new AI platform usually means vendor review, procurement, security checks, and new logins, plus data mapping and training. Cowork still needs review, but much of the surrounding Microsoft environment is likely already in place.

That existing groundwork can shorten how long evaluation takes, since IT teams aren't starting from scratch with an unfamiliar vendor. The practical path forward looks more like controlled expansion than a blanket rollout.

Firms can decide which MBD roles get access, which tasks qualify, and where a human has to approve the output. Existing Copilot use gives those conversations a real starting point instead of a blank page.

Governance and Cost Need Real Design

Cowork costs more than a standard Microsoft 365 Copilot subscription. According to the Microsoft Copilot Credits Guide, firms need a qualifying Copilot license plus separate Copilot Credits to run it.

How many credits get used depends on which model runs the task, how much information it has to pull in, and how long the task takes to finish. That setup requires active budget management rather than a one-time purchase decision.

A firm can define which tasks qualify for Cowork, track how many credits those tasks burn, and compare the cost against the manual hours the task used to take.

Any financial case should start from the firm's own numbers instead of an outside benchmark. Security controls matter just as much as cost.

Microsoft states that Cowork inherits the same Microsoft 365 permissions, sensitivity labels, and audit settings a firm already has in place. The system can pause and ask for approval before taking a sensitive action.

Microsoft Purview documentation says relevant Cowork activity can show up in the same unified audit log firms already use to track other Microsoft 365 activity. Those controls still depend on someone actually configuring and supervising them.

The American Bar Association's digital advertising guidance holds lawyers responsible for supervising staff, vendors, and any AI tool used in marketing. Human review doesn't disappear just because a task runs through an agentic system.

The Team Feels the Capability Gap

Access to strong AI tools shapes recruiting and retention now, beyond its effect on day-to-day production. The same Thomson Reuters report found that 24% of surveyed law-firm professionals would turn down a job offer if it meant no access to professional-grade AI tools.

Among people who felt they had an AI capability gap at work, 14% said they were considering leaving within the next 12 months, compared with just 5% of everyone else. That gap should worry any CMO trying to recruit legal marketers with strong research, writing, and technology skills.

Talented people can compare their day-to-day tools with what their peers get at consulting firms, accounting firms, agencies, and corporate marketing departments. A tightly restricted setup can feel especially frustrating when employees already know stronger tools exist inside the very software the firm pays for.

Access alone won't build a capable team, though. People still need clear task standards, rules about which data sources they can pull from, and training tied to real MBD work.

Without that structure, Cowork risks becoming another feature nobody actually uses. With it built in, the firm can test whether authorized agentic work actually cuts down on manual transfers and frees up time for higher-value judgment calls.

I'd bring the team into that design process directly. Their current workarounds already point to which tasks are worth examining first.

Their feedback can also show where Cowork performs well, where a human still needs to stay in the loop, and where the firm's existing process is honestly fine as is.

Bring the Work Back Inside

The copy-paste routine works as a useful diagnostic tool. People go outside the approved system when they believe that system can't finish the job.

That belief might come from an old, outdated experience with the tool, a configuration problem, or a real gap in what the tool can do. Cowork gives firms a chance to test which of those causes is actually driving the behavior, all within Microsoft's existing environment.

That evaluation should cover licensing, credits, permissions, data access, and human review. It should also track whether the change actually reduces how often people reach for outside AI tools.

From my vantage point in legal marketing, the stronger path is deliberate access paired with visible controls. A clear policy can then govern the work people are already trying to do, instead of the narrower slice of work an older version of the approved tool could handle.