Author: Dan Briggs | Published: 14 September 2026 | Reading time: 17 minutes
Executive summary: Two Microsoft 365 Copilot features reach general availability this month, and together they change what “AI in your business documents” actually means. Structured Document Generation turns a Word template into an AI-powered form, so anyone can generate a contract, NDA, offer letter or proposal by filling in a handful of fields rather than opening the master document. Deep Citations lets Copilot link straight to the paragraph, clause or slide it drew an answer from, instead of just naming the source file. Microsoft’s own roadmap lists general availability for Deep Citations in Word and PowerPoint, across desktop, Mac and web, for worldwide standard multi-tenant customers, in September 2026 (roadmap ID 523223). Structured Document Generation with forms reached general availability in SharePoint the same month, according to Microsoft Learn documentation updated 26 August 2026. Neither feature is a compliance product. Both quietly assume your permissions, template ownership and version control are already in good shape — and in the Australian client environments we support, that assumption is usually wrong before it’s right. This paper explains what each feature does, where the real risk sits, and gives you a 30/60/90-day plan to get ahead of it rather than clean up after it.
What’s actually changing this month
Microsoft ships hundreds of small changes to Microsoft 365 every month, and most of them don’t warrant a second look. These two do, because they change who can produce an official-looking business document and how much anyone has to trust Copilot’s word for what’s in it.
Structured Document Generation lets a content manager turn any Word template into a web form. A staff member fills in names, dates and a handful of other fields, hits submit, and a fully formatted document lands in a governed SharePoint library seconds later — no copying, no manual edits, no version drift. Microsoft’s documentation lists contracts, NDAs, statements of work, settlement and vendor agreements, purchase orders, offer letters, employment verification letters, and visa support letters as the intended use cases.
Deep Citations changes how Copilot backs up what it tells you. Today, when Copilot answers a question by summarising a policy or a board deck, it names the source file. From September, Microsoft’s roadmap has it linking to the specific paragraph, clause or slide the answer came from — Word and PowerPoint first, with meetings, the web and PDFs following in later phases.
Put those two together and the shift is obvious: Copilot is moving from a tool that helps you write and summarise things, to a tool that produces the actual business record — the contract that gets signed, the letter that goes to a former employee, the proposal that goes to a client — and then tells you, with apparent precision, where its reasoning came from. That precision is genuinely useful. It is also a reason to check your foundations before you lean on it.
Both features require a Microsoft 365 Copilot licence for the person building the template or asking the question, which puts them squarely in the cost conversation Australian businesses are already having this year as Microsoft raises prices on lower-tier plans from 1 July 2026 and pushes more security and AI capability into higher tiers. If your business is weighing up a Copilot licence upgrade for other reasons, these two features are worth adding to that business case — but budget for the governance work alongside the licence cost, not after it.
Structured Document Generation: Word templates become AI forms
The mechanics are straightforward once you’ve seen it work. A content manager — someone with edit access to a SharePoint document library and a Copilot licence — uploads a Word template with placeholder text such as {Client Name} or [Start Date]. Copilot in SharePoint reads the document structure and suggests fields automatically: names, dates, addresses, dollar amounts, responsibilities. The content manager confirms which fields are required, renames them to match house terminology, and can set up conditional sections — for example, a clause that only appears in the generated document if the submitter selects a particular state or country.
Once published, the form gets a shareable link that can go out over Teams, email or a SharePoint page. A content consumer — anyone with the link, not necessarily anyone with access to the source library — fills in the requested fields and submits. Microsoft’s documentation is explicit that submitters don’t need access to the destination library to generate a document, only to view it afterwards, which is a deliberate design choice to let junior staff or even external parties generate documents without being handed broader access.
Every generated document gets a permanent reference number, and the library automatically captures structured metadata from the submission — so a law firm or accounting practice using this for engagement letters, for instance, ends up with a searchable, filterable library of every letter generated, who generated it and when, without anyone building that tracking by hand. That’s a genuine improvement over the shared-drive-full-of-Word-documents approach most SMBs run today.
The feature can output either Word or PDF, and forms can be wired into Power Automate so document generation triggers off a business event — a new starter in the HR system, a deal marked won in the CRM — rather than a person filling in a form at all.
| Who does what | Role | What they need |
|---|---|---|
| Builds and governs the template | Content manager | Copilot licence, Edit permission on the library |
| Fills in the form to generate a document | Content consumer | Just the form link — no library access required |
Deep Citations: Copilot shows its working
Standard Copilot citations already tell you which document, presentation or site contributed to an answer. That’s provenance, not proof — you still have to open the file and hunt for the relevant part yourself. Deep Citations is meant to close that gap by linking directly to the paragraph, clause or slide that supports the claim, rather than just the file it came from.
It’s worth being precise about what this does and doesn’t do, because the distinction matters more than the feature name suggests. A deep citation tells you where Copilot got its context. It does not tell you that Copilot interpreted that context correctly. Microsoft’s own guidance is that generative AI responses aren’t guaranteed to be completely factual, and a citation that opens the exact right clause doesn’t stop Copilot from overstating what that clause says, missing an exception two lines further down, or blending language from two different versions of the same document.
The feature also doesn’t grant new access. Copilot can only surface content a user already has permission to view, so a deep citation to a sensitive file will simply fail — or, more precisely, it will make existing oversharing easier to stumble onto, because a precise link is easier to follow than a vague one. If a SharePoint site has been shared more broadly than intended, Deep Citations doesn’t create that problem, but it does make it more visible, faster.
The initial rollout covers Word and PowerPoint on desktop, Mac and web, for worldwide standard multi-tenant customers. Meetings, web content and PDFs are scheduled for later phases, and Microsoft has flagged that roadmap dates are targets rather than guaranteed tenant-by-tenant delivery dates, so don’t set a hard internal launch date off the roadmap month alone.
A simple habit is worth building into how your team uses this from day one, well before it becomes second nature: open the citation, check who owns the document and when it was last updated, read the paragraph or two around the cited passage rather than just the highlighted line, and only then treat the answer as reliable enough to act on. That takes an extra thirty seconds per check. It is considerably cheaper than acting on a citation that technically points at the right file but the wrong version of it.
Why this matters more here than the release notes suggest
Read in isolation, both features sound like productivity wins, and for a lot of routine paperwork, they are. Where it gets more interesting is in the specific mix of industries All IT Services supports — professional services, hospitality, and not-for-profits across Sydney, Brisbane, Melbourne and Central West NSW — because these are exactly the businesses that run on templated documents with real legal and financial weight.
A law or accounting practice in Orange, Bathurst or Dubbo generates engagement letters, NDAs and standard client agreements dozens of times a month, usually by a paralegal or admin copying the last one and hoping they caught every field. Structured Document Generation is a legitimate improvement on that process — provided the underlying template is current and someone owns it. A hospitality group on Sydney’s Northern Beaches generating offer letters and visa support letters for seasonal staff gets the same benefit, and the same exposure if the template hasn’t been checked against the current Fair Work minimum obligations. A not-for-profit in Brisbane or Melbourne issuing grant agreements and volunteer letters at scale can move faster — right up until a generated agreement goes out with last year’s funding conditions still baked into a “hidden” conditional section nobody remembered to update.
None of this is a reason to avoid the feature. It’s a reason to treat “who owns this template, and when did they last check it” as a governance question with a named owner, not an assumption.
The risk we’re already seeing in client environments
Across the Australian client environments we support, the most common document governance gap isn’t misuse of AI — it’s a template with no current owner. We regularly find contract or letter templates last properly reviewed by someone who left the business over a year ago, still being used to generate new agreements every week, because nobody was ever assigned to check them and nothing in the old process forced the question. Structured Document Generation doesn’t create that problem. It does make it faster to produce a lot more documents from that same unreviewed template, and it adds a permanent reference number and searchable metadata to each one — which is a real improvement for finding problems later, but doesn’t stop them from being generated in the first place.
The pattern with Deep Citations is a mirror image of the same issue. Businesses that have never had a formal SharePoint permissions review are the ones most likely to be surprised by what Copilot can now point to precisely, because the content was always technically accessible — it just wasn’t easy to find until a citation put a direct link in front of someone. Microsoft’s own guidance for the deep citations rollout recommends reviewing sharing links, ownerless sites, and guest access before, not after, the feature reaches your tenant.
Put plainly: both features reward businesses that already have clean templates and clean permissions, and expose businesses that don’t. Neither problem is new. Both are now more visible, faster.
How this lands on top of what’s already on your compliance calendar
These two features don’t arrive in isolation. They land in the middle of a compliance calendar that Australian businesses are already tracking, and it’s worth joining the dots rather than treating each item separately.
The Australian Signals Directorate updated the Information Security Manual this month with 44 new controls covering AI agents, third-party app consent and IT provider access — we covered the detail of that update in our September ISM briefing. A Copilot workflow that auto-generates and distributes contracts using Power Automate is exactly the kind of AI-agent activity the update has in its sights, so if you’re extending Structured Document Generation with automation, the same governance questions apply.
Separately, two Privacy Act deadlines land on 10 December 2026: mandatory disclosure of automated decision-making in your privacy policy, and the new Children’s Online Privacy Code. We’ve set out what the automated decision-making rule requires in an earlier piece on that deadline. If a Copilot-generated document is later used to inform a decision about a person — a loan, a lease, an employment outcome — the disclosure obligation is worth checking against how your business actually uses these new features, not just how the vendor markets them.
For professional services firms specifically, we’ve published a broader compliance and governance playbook covering APES 110, APRA CPS 230 and the Cyber Security Act 2024 alongside the Privacy Act changes — it’s worth reading in full if AI-assisted document work touches client files. And if you haven’t yet audited what AI tools your staff are already using without IT’s knowledge, our piece on shadow AI is a reasonable starting point before you formally roll out anything new.
A 30/60/90-day governance checklist
You don’t need to block these features to be sensible about them. A staged approach gets the benefit without inheriting the risk.
| Timeframe | Action | Why it matters |
|---|---|---|
| Next 30 days | List every Word template currently used to generate contracts, letters or agreements, and assign a named owner to each one. | You can’t govern a template nobody is responsible for. This is the single highest-value action on this list. |
| Next 30 days | Run a permissions review on SharePoint sites and libraries holding contracts, HR documents, financial records and legal templates. | Deep Citations makes existing oversharing easier to find — fix the access, don’t just wait for someone to notice. |
| Next 60 days | Pilot Structured Document Generation on one low-risk template (an internal form or a standard NDA), not a client-facing contract. | Lets your content managers learn the conditional-logic and field-mapping behaviour before it touches anything with real legal weight. |
| Next 60 days | Draft a one-page internal policy: which documents may be AI-generated, who approves the template, and what still needs a lawyer or senior review before it’s signed. | Turns “we’re using this feature” into a decision your business can point to, rather than something that happened by default. |
| Next 90 days | Test Deep Citations against a handful of known-answer questions on your own policy and contract documents, and check the citations actually land on the right clause. | Confirms the feature works as advertised in your tenant before staff start relying on it for anything consequential. |
| Next 90 days | Review retention settings for generated documents and Copilot interaction records via Microsoft Purview. | If a generated contract or its source template changes later, you may need the original version preserved for audit or dispute purposes. |
If you only do one thing from this list this month, make it the first line: name an owner for every document template your business relies on. Everything else on this page assumes that step has already happened.
Running a practical first pilot
Most of the trouble we see with new Copilot capability isn’t the technology failing — it’s businesses skipping straight from “we heard about this feature” to “everyone’s using it on live client work” without a step in between. A proper pilot is a few weeks of deliberate, low-risk testing, and it’s worth doing in this order.
Start with the template, not the technology. Before anyone touches Copilot, pull up the Word document you’re planning to turn into a form and read it properly. Is this the current version? Does it reflect current Fair Work, Australian Consumer Law or industry-specific obligations? Who last checked it, and when? If you can’t answer those questions confidently, fix the template first — Structured Document Generation will faithfully reproduce whatever is in it, mistakes included, at considerably higher volume than a person copying and pasting.
Pick one template with genuinely low stakes for the first form — an internal request form, a standard visitor NDA, a leave request letter — rather than a client-facing contract or an employment agreement. Have your content manager build the form, test the field mapping and conditional logic themselves, and generate three or four sample documents to check the output matches what a human would have produced by hand.
Only then hand the form link to a small group of real users — five to ten people, not the whole team — and ask them to flag anything that reads oddly or maps to the wrong place in the document. Review what they generated before it goes anywhere near a client, a staff member or an external party. If that batch comes back clean, you have a reasonable basis to extend the template list. If it doesn’t, you’ve found the problem while it still only affects a handful of internal test documents rather than a signed agreement.
The same staged approach applies to Deep Citations. Rather than announcing the feature business-wide, ask two or three people who already use Copilot heavily for policy or contract questions to run their usual prompts once the feature reaches your tenant, and specifically check whether the citation opens the exact clause it claims to support, or something merely adjacent to it. That handful of real tests will tell you more about how the feature behaves in your own document library than any vendor briefing will.
Frequently asked questions
Do we need a Microsoft 365 Copilot licence to use Structured Document Generation or Deep Citations?
Yes for the people building templates or forms — content managers need a Copilot licence and edit access to the relevant SharePoint library. Content consumers filling in a form to generate a document typically don’t need a Copilot licence at all, just the form link, which is part of why the feature spreads quickly through a business once one template is set up.
Can a generated contract or letter be treated as legally binding without a human reviewing it?
The feature produces a formatted document from an approved template, not legal advice, and Microsoft explicitly cautions that generative AI output should be reviewed rather than treated as verified fact. Whether a specific document needs qualified legal review before it’s sent should depend on what it is and what it commits your business to, not on how the document was produced.
Does Deep Citations mean Copilot can now see documents it couldn’t see before?
No. Copilot only ever surfaces content a user is already authorised to view under your existing SharePoint and OneDrive permissions. What changes is how easy it is to find and open something that was already technically accessible, which is why a permissions review matters more now, not because the access rules have changed.
We’re a not-for-profit with a small team and no dedicated IT governance function — is this relevant to us?
Arguably more relevant, not less. Smaller teams tend to have fewer people checking who owns a given template or who has access to a given SharePoint site, which is exactly the gap these features expose. The 30-day actions in this paper — naming a template owner and running a basic permissions review — don’t require a large IT team, just someone assigned to do them.
What should we do if we don’t currently have Copilot licences at all?
Nothing urgent. Neither feature is available without a Copilot licence, so there’s no immediate exposure. It’s still worth putting a permissions review and template ownership on your list, because both are good practice regardless of whether or when you adopt Copilot.
Where to start
If you’re not sure which of your SharePoint sites are overshared, which contract templates nobody currently owns, or whether your Copilot licensing already covers these features, that’s a conversation worth having before the rollout reaches your tenant rather than after something goes out the door with the wrong clause in it.
Call All IT Services on 1300 425 548 or get in touch here and we’ll walk through what a properly governed rollout looks like for your business.
