AI Works Council Agreement: What to Settle With the Works Council Before Copilot

Why Microsoft 365 Copilot triggers co-determination rights in Germany, what belongs in an AI works council agreement, and how it differs from an AI acceptable use policy. With an outline of the key clauses.

An AI works council agreement (Betriebsvereinbarung) is a written agreement between an employer and the works council that sets binding rules for AI use in the company: which tools are deployed, for which purposes, what happens to the employee data these tools generate, and what must never happen with it. If your German company has a works council and you want to roll out Microsoft 365 Copilot, this agreement is usually not a friendly gesture. It is legally required. Skip it, and the works council can stop the rollout, including after the fact.

This post explains why Copilot triggers co-determination, what belongs in the agreement, and the order in which to proceed.

Does the works council have to approve a Copilot rollout?

In almost all cases, yes. The lever is Section 87(1) No. 6 of the German Works Constitution Act (BetrVG): the works council has a co-determination right over the introduction and use of technical systems that are designed to monitor the behavior or performance of employees.

At first glance, Copilot does not sound like the target. Nobody buys a writing assistant to surveil their staff. But the Federal Labor Court has interpreted this provision broadly for decades: intent does not matter, what matters is whether the system is objectively capable of monitoring. And Copilot is. User interactions appear in the Microsoft Purview audit log, prompts and answers are stored in each user’s mailbox, and the admin center provides usage reports showing who uses Copilot and how intensively. Whether you ever intend to use this data for performance evaluation is irrelevant for co-determination. It is enough that you could.

The consequence: if an employer introduces Copilot without involving the works council, the council can demand that use be stopped. You cannot route around co-determination by keeping the project quiet. If the two sides cannot agree, a conciliation committee decides (Section 87(2) BetrVG). The far better path is to involve the works council early and settle the conditions together in a works council agreement.

What other participation rights does the works council have on AI?

Beyond Section 87, two provisions have explicitly mentioned artificial intelligence since the Works Council Modernization Act of 2021:

Information and consultation (Section 90(1) No. 3 BetrVG). The employer must inform the works council about planned AI use in good time and consult with it on the planned measures. In good time means during the planning phase, not when the licenses are ordered. If the works council learns about the Copilot rollout from the intranet, that train has already left.

External experts (Section 80(3) sentence 2 BetrVG). When the works council has to assess the introduction or use of AI, bringing in an external expert is deemed necessary by law. The council no longer has to justify the need. Budget for this realistically and do not treat it as a provocation. A works council that understands the technology negotiates more constructively than one that has to distrust it.

Taken together, this means: the works council belongs at the table before the pilot phase starts, with real information about data flows, logging, and evaluation capabilities.

Works council agreement or AI acceptable use policy: what is the difference?

The two documents are often confused, but they do different jobs.

The AI acceptable use policy is a one-sided instruction from the employer to the workforce: which tools are approved, which data may go into prompts, and which never may. It points downward, at the users.

The works council agreement is a two-sided contract between employer and works council. Its core subject is what the employer may do with the employee data that AI use generates: logs, usage statistics, audit entries. It has normative effect, meaning it applies directly to all employees, and it binds the employer too.

In practice you need both, and the order is not arbitrary: first the framework is agreed with the works council, then the acceptable use policy is issued within that framework. A common setup is to attach the policy as an annex to the agreement, so both sides carry it together.

What belongs in an AI works council agreement?

A workable AI works council agreement for Copilot covers these points:

  1. Scope and tool list. Which AI tools are covered? A proven approach is an annex listing the approved tools, updatable through an agreed procedure without renegotiating the whole agreement. AI features now land in existing software monthly, and a rigid list goes stale fast.
  2. Purposes of use. What Copilot is used for (drafting, summaries, search across the company’s own data) and what it is not used for (for example, automated evaluation of individuals).
  3. Exclusion of performance and behavior monitoring. The centerpiece. The agreement states that usage data, logs, and audit trails will not be used to evaluate individual employees, and defines the narrow exceptions (such as concrete suspicion of a criminal offense) including the procedure and works council involvement.
  4. Access to logs. Who may view audit logs and usage reports, for what purpose, and with what logging of the access itself? This is also the place to require that usage reports run anonymized where administration allows it. Microsoft 365 has a setting that conceals user names in reports.
  5. Retention and deletion periods. How long are Copilot interactions kept? I covered the technical side, retention policies in Purview, in the post on Copilot settings. The binding period belongs in the agreement.
  6. Training. Everyone who uses Copilot gets trained. This lines up with the AI literacy obligation under Article 4 of the EU AI Act, which has applied since February 2025 anyway. The agreement turns it into an enforceable employee entitlement.
  7. Pilot phase and evaluation. A defined pilot group first, then a joint review, then rollout. This takes the pressure off both sides to get everything perfect on the first attempt.
  8. Term and revision. A review clause (for example, annual) is not a formality on a topic moving this fast. It is the mechanism that keeps the agreement alive.

None of these clauses is decoration. Each answers a question that otherwise ends up in front of the conciliation committee.

Yes, with caveats. Article 88 GDPR explicitly allows collective agreements to regulate the processing of employee data, and Section 26 of the German Federal Data Protection Act (BDSG) picks this up for Germany. A works council agreement can therefore be the legal basis for processing employee data in Copilot operations, for example in logs.

Two honest caveats. First: the agreement must not fall below the GDPR’s level of protection. Article 88(2) GDPR requires suitable and specific measures to safeguard employees’ interests, transparency in particular. An agreement that blanket-approves everything will not hold up as a legal basis. Second: the agreement replaces neither the data protection impact assessment nor the involvement of your data protection officer. It is one building block in the overall package, not the package.

What if there is no works council?

Many firms and smaller companies have no works council. Then there is no co-determination under the BetrVG and no obligation to conclude a works council agreement. The underlying questions do not disappear, though: even without a works council, you have to define who may view usage data, how long interactions are stored, and that Copilot logs do not quietly become a performance monitoring tool. Without a council, the place for this is the acceptable use policy plus a documented decision in the DPIA.

My advice from practice: put the exclusion of performance monitoring in writing even without a works council. It costs one paragraph, builds trust in the team, and preempts one of the most common conflict points if a works council is founded later.

The sensible order

When Copilot is on the roadmap and a works council exists, this sequence has proven itself:

  1. Inform the works council under Section 90 BetrVG while the rollout is still being planned
  2. Provide an information package: data flows, logging, evaluation capabilities, planned settings
  3. Negotiate the agreement along the eight points above, including a pilot phase
  4. Align the DPIA and the agreement with each other, the monitoring exclusion doubles as a DPIA measure
  5. Issue the acceptable use policy within the agreed framework and train the team
  6. Review the pilot together, then roll out

The next step

If a Copilot rollout is ahead of you and you want to set up the framework with works council, DPIA, and acceptable use policy properly, get in touch. I support the negotiation preparation, the information package for the works council, and the alignment of the agreement with your data protection documentation.


Jose Lugo is a CISSP-certified AI compliance consultant with an M365 Endpoint Administrator certification. He advises companies in Germany on GDPR-compliant Microsoft 365 Copilot rollouts.