๐Ÿค– AI & Technology

Work IQ and the New AI Agent Challenge

Microsoft Work IQ shows why reliable business context and controlled access now matter as much as the AI model behind an agent.

TG
Thind Global Services
28 September 2026 ยท 11 min read
Work IQ and the New AI Agent Challenge

Microsoft is putting Work IQ into preview

Microsoft is making Work IQ available in preview from 30 September 2026, with rollout continuing throughout October 2026. According to Microsoft, Work IQ is an intelligence layer designed to ground Microsoft Copilot and AI agents in the business data that matters to an organisation.

The important part is not simply that another AI product is arriving. Microsoft describes Work IQ as a way to connect and model business information once, then reuse that understanding across multiple experiences instead of rebuilding the same context for every individual agent.

That distinction matters for businesses considering AI agents. The difficult question is increasingly not whether a model can generate a useful answer. It is whether an agent can understand the right customer, transaction, contract or operational record, and whether it is allowed to see or act on that information.

Our view is that this is where many practical business AI projects will now succeed or fail. Model capability still matters, but context, data quality and permissions determine whether that capability can be used safely inside day-to-day operations.

What Work IQ is designed to connect

Microsoft says Work IQ can reason across productivity and business data and connects several parts of its business software estate. That includes Dynamics 365 applications such as Sales, Customer Service, Finance and Operations; Power Platform products including Power Apps and Copilot Studio; and Microsoft 365, including its apps, Teams and Outlook.

The idea is significant because business information rarely sits in one neat database. A customer relationship might span email, a sales system, a customer service record and a contract management process. An agent working from only one of those sources can easily operate with an incomplete picture.

Microsoft illustrates this through a sales renewal scenario involving PowerApps911, where Work IQ connects customer signals across sales, service and contract management systems. The example points towards an important design principle: an agent becomes more useful when the surrounding system can identify and relate the business information needed for the task.

For smaller businesses, the names of the systems may differ, but the problem is familiar. Customer details, order information, finance records and operational notes often live in separate tools. Connecting that context is usually more difficult than writing an impressive AI prompt.

Why context is becoming the harder problem

An AI assistant answering a question can often tolerate limited context because a person remains responsible for interpreting the answer and deciding what happens next. An agent that takes actions has a higher burden. It needs enough context to choose the correct record, understand the relevant situation and operate within defined limits.

AreaAssistant that answers questionsAgent that takes actions
Primary roleProvides information for a person to considerPerforms or initiates a business task
Context requirementMay work with the information supplied for a questionOften needs connected business context before acting
PermissionsAccess determines what information can be returnedAccess determines both what can be understood and what can be changed
Human involvementA person normally decides what to do with the answerThe system may progress work without a person making each individual step
Main operational concernWhether the answer is useful and appropriately groundedWhether the context, permissions and resulting action are appropriate

This is why connecting information is only part of the problem. A system also needs to distinguish what different users and agents are permitted to access. Without that control, giving an agent more context can simply increase the amount of information exposed to the wrong process.

Our view is that businesses should treat context architecture and access design as core parts of an AI agent project, not as technical housekeeping to complete after the agent has already been built.

Permissions are becoming part of the product

Microsoft says Work IQ lets IT administrators choose the business context that agents use and control which users, agents and applications can access business data. It describes coordinated controls spanning the Microsoft 365 admin centre, Power Platform admin settings, and configuration available to makers and developers.

That reflects a practical reality. An agent should not automatically inherit access to every system merely because connecting those systems is technically possible. A customer service process may need service history but not every finance record. A sales workflow may need contract information but not unrestricted access to unrelated operational data.

For business owners, this changes the questions worth asking vendors and internal teams. Instead of asking only what an agent can do, ask what information it can see, why it needs that information, what applications it can interact with and how those permissions are controlled.

Our view is that those questions should be settled before an agent receives meaningful operational authority. It is easier to expand controlled access later than to discover after deployment that access was broader than the business intended.

The UK government is looking at the same risk

The same shift towards agent controls is visible outside Microsoft. GOV.UK reported on 31 August 2026 that the UK government had launched the first procurement competitions under a ยฃ100 million Sovereign AI R&D Procurement Scheme.

One of its four initial challenges, run with the National Cyber Security Centre, focuses specifically on agent security and resilience testing. According to GOV.UK, the challenge supports technologies intended to help organisations understand, manage and mitigate risks associated with increasingly capable AI agents.

The other initial challenges cover NHS productivity, compute efficiency and integrating AI across Defence mission environments. Successful companies retain the intellectual property they create under the scheme.

Microsoft's Work IQ announcement and the government programme are different initiatives with different purposes. However, they point towards the same operational issue: as agents become capable of doing more, organisations need better ways to control what those agents know, what they can access and how their behaviour is tested.

A preview is not a reason to rush

Work IQ enters preview on 30 September 2026. That word matters. A preview gives organisations an opportunity to understand a technology and explore where it might fit, but it should not automatically be treated as a signal to rebuild important business processes around it immediately.

Microsoft also directs customers to usage-based billing information. That means businesses evaluating Work IQ should consider not only whether an agent is technically useful but also how its use could translate into ongoing cost. A workflow that looks attractive in a demonstration still needs a commercial case.

Our view is that businesses should use the preview period to learn rather than race. Identify a contained process, establish what information the process actually needs, define its permissions and decide how success would be assessed before expanding the scope.

There is little value in connecting every available system to an agent before the business has established a clear operational purpose for doing so.

Eight readiness checks before building agents

Businesses with information spread across several systems do not need perfectly clean data before they can begin exploring AI. They do, however, need to understand where important information lives and where contradictions or access problems could affect an agent. Our view is that the following checks are a sensible starting point.

  1. Choose one business process. Start with a specific operational task rather than a general ambition to introduce AI across the company.
  2. Map the information the process uses. Identify which systems contain the customer, order, finance, service or contract information required to complete the task.
  3. Find duplicate records. Look for places where the same customer, product or transaction may appear differently across systems, because an agent needs a reliable way to relate them.
  4. Identify the authoritative system. Decide which application should be trusted when two systems contain different versions of the same business fact.
  5. Review current permissions. Check which employees and applications can already access the relevant information before adding another automated user of that data.
  6. Define the agent's minimum access. Give the workflow only the information and capabilities needed for its specific task rather than broad access for convenience.
  7. Separate recommendations from actions. Decide where the agent may prepare or suggest something and where a person should still approve what happens next.
  8. Plan how you will observe failures. Establish how the business will notice incorrect context, inappropriate access or an unwanted action and how the process can be corrected.

This exercise often reveals that the first useful AI project is partly a data and process project. That is not a failure. Improving those foundations can make later automation easier to govern and more useful.

Messy data does not automatically block AI

Many smaller businesses have grown their systems gradually. Sales information may be held in one application, service information somewhere else, while important operational knowledge remains in email or other collaboration tools. Replacing everything with one system is rarely a practical prerequisite for an AI project.

The more useful question is whether the business can establish enough reliable context for one process. If an agent needs to support customer renewals, for example, the business should determine where the relevant customer, service and contract information comes from and how those records relate to each other.

Our view is that businesses should resist connecting data simply because it exists. Every additional source introduces another question about accuracy, ownership and permission. A narrower set of trusted information can be more useful than a large collection of poorly understood data.

This is also why AI readiness should involve operational staff, not only technical specialists. The people who work with customers, orders, finance or service processes often know where system records are incomplete and where important exceptions occur.

What businesses should take from Work IQ

Microsoft's Work IQ direction suggests that reusable business context will become an increasingly important part of its approach to Copilot and AI agents. Instead of rebuilding an understanding of the organisation for each new agent, Microsoft is proposing an intelligence layer that can connect and model information once and make that understanding reusable across different experiences.

For businesses, the broader lesson matters more than any individual product announcement. The competitive question is no longer simply which AI model can produce the best answer. It is whether the organisation can give an agent dependable context while maintaining sensible control over who and what can access business information.

The UK government's agent security and resilience challenge reinforces the importance of that second part. More capable agents create more reasons to understand, manage and mitigate the risks around their use.

Our view is that businesses should respond by improving the foundations rather than rushing into deployment. Map the process, understand the data, decide which systems are authoritative, minimise permissions and introduce action gradually. Work IQ may provide Microsoft customers with another way to support that approach, but its preview status and usage-based pricing are good reasons to evaluate it against a clear business case rather than adopt it for its own sake.

Questions we are being asked

What is Microsoft Work IQ?

Microsoft describes Work IQ as an intelligence layer that grounds Copilot and agents in business data and reasons across relevant productivity and business information. It connects and models information so the same business understanding can be reused across different experiences. Microsoft says it connects products across Dynamics 365, Power Platform and Microsoft 365, with administrators able to control the business context and access available to users, agents and applications.

When does Microsoft Work IQ become available?

Microsoft says Work IQ will be available in preview starting on 30 September 2026, with rollout continuing throughout October 2026. Because this is a preview, our view is that businesses should treat it as an opportunity to evaluate suitable use cases rather than a reason to move important processes immediately. Microsoft also directs customers to usage-based billing information, so cost should form part of any practical evaluation.

How should a business prepare its data for AI agents?

Start by choosing a specific process and identifying the systems that contain the information needed to complete it. Check for duplicate or conflicting records, decide which system is authoritative, and review who already has access. Our view is that an agent should receive the minimum data and permissions required for its task. Businesses should also decide where human approval remains necessary and how incorrect context or unwanted actions will be identified.

Why do permissions matter more when AI agents take actions?

An assistant can provide information while leaving a person to decide what happens next. An agent may be able to progress work directly, so access determines not only what it can understand but also what it may affect. Microsoft says Work IQ includes controls over which users, agents and applications can access business data. The UK government's agent security challenge also focuses on technologies for understanding, managing and mitigating risks around increasingly capable agents.

Related reading on this blog: shadow AI at work covers the unapproved tools staff already use, and MCP explained covers the other route businesses use to plug assistants into their own systems.

Need help putting this into practice?

Talk to our Birmingham team โ€” free consultation, no obligation, fixed quotes.

Get a free quote