Microsoft Word's AI Can Now Read Your Emails: What Every UK Employee Must Know in 2026

UK office worker looking at laptop showing Microsoft Word AI Copilot suggestions panel in modern London office
Rhys Rhys MorganInformation Technology
7 min read September 21, 2026

When you type a sentence into Microsoft Word and Copilot finishes your thought, it may already have read your last 90 days of emails to do so. That is the reality of Microsoft 365 Copilot's Work IQ feature, which expanded to UK business accounts throughout 2026. For many employees, the shift happened silently — no notification, no opt-in prompt. Suddenly, the word processor they have used for decades became a system that knows their projects, their colleagues, and their past conversations. IT security specialists and employment lawyers across Britain are now fielding an unusual volume of calls about exactly this.

What Microsoft Word's AI Accesses in the Background

Microsoft's Work IQ is the engine behind Copilot's latest capabilities inside Word. The system ingests a user's organisational data — emails, calendar entries, meeting transcripts, and past documents — to build what Microsoft calls "contextual intelligence." The goal is smarter document drafting: type "write a proposal for the Henderson account" and Word draws on your previous emails with that contact, relevant meeting notes, and company files accessible through your permissions.

The feature also introduces multi-step background workflows. Copilot can now execute complex tasks autonomously, flagging checkpoints for human review, according to guidance published by UK Microsoft partner Wavenet in August 2026. For standard business correspondence and internal reports, this is genuinely efficient. For documents containing sensitive employment data, client financials, or confidential negotiations, it raises immediate legal and security questions.

In July 2026, the UK Information Commissioner's Office (ICO) issued specific guidance on autonomous workplace AI systems, requiring organisations to maintain clear accountability for every action taken by AI agents. Microsoft responded by introducing an AI Action Ledger — an immutable log of Copilot agent activity — but critics note that most employees never see it, and most employers have not integrated it into their data protection documentation.

Why UK Regulators Are Watching Closely

The Data (Use and Access) Act 2025, which came fully into force on 19 June 2026, significantly strengthened employees' rights around automated decision-making. Under the updated Article 22A of UK GDPR, employees now have an explicit right to challenge decisions that were significantly influenced by automated systems and to request human review.

The ICO's March 2026 enforcement report found that a majority of UK employers using AI tools in their workflows are not compliant with automated decision-making rules. The core failures identified were threefold: insufficient transparency about what the AI accesses, no documented lawful basis for processing employee communications, and no clear privacy notice informing staff of what is being monitored or why.

For employees, this creates a concrete dilemma. If your employer's Microsoft 365 deployment gives Copilot access to your emails and meeting notes, have you been told this data is being processed? Has your employer provided a privacy notice covering this specific use? These are not hypothetical questions — they are compliance obligations that UK employers owe to their staff, as set out in the ICO's official guidance on AI and data protection.

Similar patterns have emerged across AI tools embedded in communication platforms. The privacy questions raised by WhatsApp's AI features in the UK follow the same regulatory framework: transparency, lawful basis, and proportionality. Microsoft Word is simply a higher-stakes environment because it sits at the centre of professional document work.

A Concrete Scenario: When the AI Knows Too Much

Consider a senior account manager at a mid-sized UK marketing agency. Their employer rolled out Microsoft 365 Copilot in April 2026 as part of a routine software upgrade. Work IQ was enabled by default under the company's Microsoft tenant settings — this is the standard configuration for most business accounts unless IT administrators actively opt out.

By June 2026, Copilot in Word was generating draft client reports that pulled in figures and context from internal email threads. One draft proposal auto-populated a specific client discount figure — a figure that had only ever appeared in a private email chain between two senior directors. The employee had been CC'd on that message nine months earlier. Copilot treated it as legitimate contextual data.

Under the Data (Use and Access) Act 2025, that employee can request an explanation of how the automated system processed their communications. If the employer cannot produce a documented lawful basis — typically legitimate interest supported by a completed Data Protection Impact Assessment (DPIA) — the employer is in breach of UK GDPR. ICO enforcement fines start at £8.7 million or 2% of global annual turnover, whichever figure is higher.

The critical threshold is this: if Copilot's output directly influenced a business decision — a client proposal, a performance review summary, a redundancy selection shortlist — it qualifies as an automated decision under Article 22A. If that decision materially affected someone's employment terms, human review is not optional; it is a legal right.

If the employee from the scenario above was later overlooked for promotion, and the manager's assessment was drafted using Copilot-generated summaries of that employee's communications, the employee would have grounds for a data rights complaint. An employment lawyer and an IT security specialist together would need to reconstruct the evidence trail from the AI Action Ledger — assuming the employer makes it available.

This is precisely why consulting an expert early, before a complaint becomes a tribunal claim, is the more cost-effective route for both parties.

Your Rights as a UK Employee in 2026

The core protections under UK law are now clearly defined:

Transparency: Your employer must tell you what AI tools process your work communications and for what purpose. A vague "we use technology to improve productivity" clause in an employment contract is not sufficient under UK GDPR.

Lawful basis: Processing your emails and documents to power an AI system requires a documented lawful basis. Legitimate interest is most commonly used — but it requires a formal balancing test demonstrating that processing does not override your rights as an employee.

Right to object: Under UK GDPR, you have the right to object to processing based on legitimate interest. Your employer must either cease that processing or demonstrate compelling grounds that override your privacy interests.

Right to human review: Where AI significantly contributes to a decision affecting your employment, you have the right to request that a human reviews that decision — not a summary generated by the same system.

Subject Access Request: Under the Data (Use and Access) Act 2025, you can submit a Subject Access Request (SAR) to obtain all personal data your employer holds on you, including AI-generated summaries, contextual profiles built by Copilot, and any automated assessments. The employer has 30 days to respond.

When to Consult an IT Expert or Employment Lawyer

Most UK employees are not in a position to audit their employer's Microsoft 365 configuration independently. You cannot see what permissions Copilot has been granted, which data sources it draws from, or whether a DPIA was completed before deployment.

An IT security consultant can map the technical exposure: which data Copilot accesses in your organisation, whether the tenant settings follow ICO recommendations, and what activity logs exist. Microsoft 365 compliance auditing has become a dedicated specialism in 2026 — a discipline that barely existed two years ago, precisely because these questions are now commercially critical.

An employment lawyer becomes essential if you believe an AI-influenced decision has already affected your employment — an inconsistent performance review, an unexplained redundancy selection, or a promotion decision where the stated rationale does not hold up. These situations now have a specific legal pathway: SAR, followed by a challenge under Article 22A, followed by a potential complaint to the ICO if the employer does not respond adequately.

For businesses and managers navigating this landscape, the stakes are equally high. The broader shift toward AGI-level tools in UK workplaces means that IT governance policies drafted in 2023 are almost certainly out of date. An IT consultant specialising in AI governance can review your current Microsoft 365 deployment against the ICO's 2026 standards before an employee complaint forces the issue.

"Word" may just be a trending search term today, but for thousands of UK employees and employers, it is where the most pressing questions about workplace AI, privacy, and professional rights are being played out right now.

Disclaimer: This article provides general information on UK employment and data protection law and does not constitute legal advice. For concerns specific to your workplace situation, consult a qualified employment lawyer or IT security specialist.

format_used: Expert reaction

Advantages

Quick and accurate answers to all your questions and requests for assistance in over 200 categories.

Thousands of users have given a satisfaction rating of 4.9 out of 5 for the advice and recommendations provided by our assistants.