On September 3, Microsoft announced a new key security feature added to its AI system development platform, Copilot Studio, which allows developers to enforce an approval process by humans for AI agents and the specific tools they use. This feature sets clear security boundaries for enterprise-level AI agents' autonomous operations, effectively addressing compliance and asset loss risks that could arise from fully autonomous large model operations.

Under this new mechanism, when an AI agent attempts to perform sensitive actions such as sending emails, closing customer service tickets, or processing financial payments, the system will pause and trigger an approval request, explaining the user's intent, allowing the user to decide whether to approve, allow the current session to continue, or completely reject it. This approval requirement is independent of the agent's built-in instruction set; even if the AI logic determines the action is the best next step, it must wait for human authorization.
To improve collaboration efficiency, approval requests will be directly embedded into work channels like Microsoft Teams and Microsoft 365 Copilot, without requiring users to switch to the Copilot Studio backend. Currently, this feature is available as a formal function in the Copilot Studio Web version, released globally through Microsoft's standard multi-tenant cloud platform, with product roadmap number 570434.
As AI agents are increasingly applied in deep-level scenarios of core business operations within enterprises, how to leverage automation efficiency while preventing失控 risks has become a focus of industry attention. By restructuring the human-machine collaboration workflow with hard rules, Microsoft not only enhances the system's security defenses but also provides a reference model for the commercial implementation of AI agents in sensitive situations.


