Copilot in Business Central – how to safely manage AI in an ERP system?

Damian Tomalka Damian Tomalka February 11, 2026

AI in ERP is already the standard but is it secure?

In 2026, artificial intelligence in ERP systems is no longer a novelty. It has become a market standard. Microsoft Dynamics 365 Business Central with Copilot now works as a digital assistant, helping users analyze data, post invoices, and monitor financial liquidity.

However, for management boards and IT departments, one key question remains:

How can you use AI in ERP without risking data security and regulatory compliance?

The answer is not to avoid AI, but to manage it consciously and responsibly.

Copilot in Business Central is part of the system, not an add-on

In the latest versions of Business Central, Copilot is an integral part of the ERP system. This means greater control options for administrators.

Instead of a simple “on/off” switch, administrators gain access to advanced AI management settings that allow them to control:

As a result, AI acts as operational support rather than an uncontrolled source of risk.

Key levels of AI Control in Business Central

Data Flow Control

If the ERP environment operates in a different region than Azure OpenAI services, the system requires explicit approval to send queries. This is particularly important for organizations that prioritize:

AI Agent Selection

You decide which AI agent to enable. For example, the Payables Agent acts like a digital trainee. It monitors the mailbox, extracts invoices, and prepares draft entries in the system. The user remains in control, while AI serves as an assistant.

Permission System

Copilot respects existing roles and access rights within the ERP system.

If a user does not have access to payroll data:

➡️ Copilot will not display it
➡️ it will not use it in analysis
➡️ it will not infer it based on other available data

Examples of secure Copilot usage

Mini Case 1: manufacturing and margin protection

A manufacturing company was concerned about exposing margin data. The solution:
Result: automation without the risk of exposing trade secrets.

Mini Case 2: organization with high security requirements

The administrator blocked the submission of feedback to Microsoft. As a result:

Controlled internet access

Some Copilot features may use the Bing search engine. Administrators can:

Key AI risks in ERP

Compliance and data residency

This becomes especially important in regulated industries. If you do not properly configure data transfer settings, Copilot may process sensitive information outside the protected region, which could lead to penalties during an audit.

Data quality and the quality of truth

AI is only as good as the data it works with. If there are errors or duplicates in the system, the assistant may generate incorrect financial forecasts. Based on these, you could make the wrong decision, such as blocking a customer or granting unnecessary credit.

Shadow AI and excessive permissions

Copilot connects information faster than a human. If ERP permissions are too broad, an employee may gain access to information they should not see, such as confidential supplier pricing, which may result in internal data leaks.

How to safely implement Copilot in Business Central?

Principle of Least Privilege

Conduct a role audit. Make sure that only individuals who are truly responsible for sensitive areas have access to AI in those parts of the system.

Source Data Hygiene

Clean your database before activating AI algorithms. AI amplifies what it receives. The better the data you provide, the more reliable the forecasts will be.