October 1, 2026
Governing the Apps AI Builds: What Microsoft's Copilot Managed Runtime Means for Enterprise Shadow IT
Somewhere in your company right now, an employee is describing an internal tool to an AI assistant and getting a working app back in minutes. It might be a vendor-onboarding tracker, a renewals dashboard, or a small workflow that replaces three spreadsheets. It is useful, it is fast, and there is a good chance IT has never heard of it.
On September 25, 2026, Microsoft announced Copilot Managed Runtime, now in public preview. It is a Microsoft-hosted environment, inside the Microsoft 365 tenant boundary, for running apps that AI builds. Each app gets Microsoft Entra sign-in, policy enforcement, and an entry in a central admin inventory from the day it is created.
This post covers what the launch includes, why the problem it targets is real, where the gaps remain, and how to prepare your own governance model whichever vendor’s platform you use.
What Microsoft Actually Announced
Copilot Managed Runtime is a hosting and governance layer rather than another code generator. According to Microsoft’s admin documentation, the key features are:
- Microsoft Entra authentication and authorization built in.
- More than 1,500 connectors callable directly from JavaScript and TypeScript.
- A native Git workflow with a repository for each app.
- Automatic adherence to IT policy, including sharing limits, conditional access, advanced connector policies, and data loss prevention (DLP).
- A centralized inventory in the Microsoft 365 admin center covering usage, health, and compliance state.
Three ways in, plus an SDK
The runtime already powers apps built in Copilot Cowork, Copilot Code, and Copilot Studio. Microsoft is also opening it to third-party tools and professional developers through an SDK and command-line interface. Lan Roche of Lovable is quoted in Microsoft’s announcement saying that “an app made with Lovable can now run inside your Microsoft tenant, the same way everything else does: same sign-in, same policies, same app inventory.”
Safe by default, with admin switches
Governance is designed in rather than bolted on. Each maker works in an isolated personal developer environment that inherits tenant policies. Admins decide which creation paths are on. In public preview, the Copilot Studio path is on by default, the CLI path is off by default, and Cowork-based creation is tied to the tenant’s Frontier program onboarding. Admins can also restrict Copilot Studio app creation to a security group, and a separate setting controls whether developers may deploy prebuilt artifacts built outside Microsoft’s build system. That setting is off by default.
The cost model
Building apps consumes Copilot Credits, and admins can set separate spending policies for running them. During the preview, a user who does not meet the credit requirements gets a warning, and access is blocked after 20 app operations or five minutes of use, whichever comes first. The takeaway is that app sprawl now has a metered bill as well as a security dimension.
Why This Problem Is Real
It is tempting to treat “AI-built internal apps” as a niche concern. The data says otherwise.
Employees are already building outside IT
A Retool survey of 817 builders and customers, conducted in late 2025, found that 60% had built tools outside IT oversight in the past year, and 25% said they did so frequently. The respondents’ stated reasons were mostly practical: speed, unmet needs in existing software, and approval processes they considered too slow. The same survey found that 35% had replaced at least one SaaS tool with a custom build and 78% expected to build more in 2026. This is the same dynamic we described in our look at why enterprises are skipping software purchases for agentic coding tools.
The security record of unmanaged builds is weak
A Cloud Security Alliance research note collects several worrying figures. It cites IDC research finding that 56% of employees use unauthorized AI tools while only 23% use IT-governed alternatives. It also reports that a review of 5,600 production vibe-coded apps found none with CSRF protection, security headers, or properly scoped access policies, and that AI-generated commits expose secrets at roughly twice the rate of human-written ones (3.2% versus 1.5%, citing GitGuardian). Treat these as directional rather than definitive, since they are secondary compilations of other studies. The pattern still matches what security teams describe: apps that work but were never reviewed.
Ownership is the hidden risk
Most governance conversations focus on data leakage. A quieter problem is ownership. When the person who built an app leaves, who maintains it, who patches it, and who turns it off? A central inventory that records owner, usage, and health answers those questions. A spreadsheet maintained by hand will not. This builds on themes from our earlier pieces on shadow AI and AI agent sprawl.
Where the Gaps Remain
A governed runtime is a meaningful step, but it is not a complete answer.
It governs what runs, not whether it is correct
Entra sign-in and DLP policies control who can use an app and what data it can reach. They do not tell you whether the app’s logic is right. An approval-routing tool can be perfectly authenticated and still route invoices to the wrong person. Review and testing practices still matter, a point that echoes our warning on technical debt in the age of AI.
It is still a preview
Independent analysts have been cautious. MnzAI Labs notes that the preview does not provide independent results on production security, performance, or cost, and that a list of controls is not evidence those controls satisfy every enterprise requirement. Pilot it with limited internal apps and non-sensitive data first.
It governs one ecosystem
Copilot Managed Runtime is strongest if your organization already lives in Microsoft 365. Teams building on other platforms still need their own inventory and policy model. Microsoft’s documentation says apps surfaced in familiar Microsoft 365 experiences help reduce shadow IT, but that only covers apps built through its paths. If you run multiple vendors’ tools, the broader argument in our piece on the control plane era applies.
What to Do Now
You do not need to adopt Microsoft’s runtime to act on the lesson behind it. Here is a practical sequence.
1. Find out what already exists
Ask teams, check SSO app registrations, and review API key usage for AI services. You are looking for tools that employees built, not just tools they bought.
2. Register, don’t gatekeep
The CSA note recommends lightweight application registration rather than heavyweight review gates. If registering an app takes five minutes, people will do it. If approval takes weeks, the Retool data suggests they will route around it.
3. Tier your apps by risk
Separate personal productivity tools, team tools touching internal data, and apps that handle regulated data or take autonomous actions. Each tier gets proportionate controls rather than one policy for all.
4. Assign an owner and a sunset date
Every app should have a named owner and a review date. Orphaned apps should be flagged automatically when the owner changes roles or leaves.
5. Scan what the AI wrote
Extend secrets scanning and dependency checks to AI-generated code, wherever it is hosted. The elevated secret-exposure rates reported by GitGuardian make this a basic hygiene step.
6. Budget for running costs
Metered runtime billing, like the Copilot Credits model, means a popular internal app can create a real recurring cost. Decide who pays before the first app takes off.
Conclusion
The significance of Copilot Managed Runtime is less the product than the shift it signals. Vendors now accept that employees will build software with AI, and that the safest response is to give those apps a governed home instead of pretending they will not exist. For business leaders, the actionable steps are straightforward: take inventory, make registration easy, tier by risk, assign owners, scan the code, and budget for runtime. Whether you do that with Microsoft’s tooling or your own, the organizations that start now will find governance far cheaper than cleanup later.
If you want help designing an AI-app governance model or evaluating platforms, the Promact team works with enterprises on exactly this.
Frequently Asked Questions
What is Microsoft Copilot Managed Runtime?
It is a Microsoft-hosted environment inside the Microsoft 365 tenant boundary that runs apps built with Copilot Cowork, Copilot Code, Copilot Studio, or SDK-compatible third-party tools, with Entra identity, policy enforcement, and an admin inventory built in. It entered public preview on September 25, 2026.
Can apps built with tools like Lovable run on it?
Yes, in principle. Microsoft says the SDK lets third-party tools build apps that run in your tenant with the same sign-in, policies, and inventory, and Lovable is quoted in the announcement. SDK compatibility will vary by tool, so check each vendor.
Does it stop shadow IT completely?
No. It governs apps built through its supported paths. Employees can still use unsanctioned tools elsewhere, so you still need discovery, easy registration, and clear policies.
Is it ready for production use?
It is a public preview, and Microsoft’s documentation describes it as prerelease and subject to change. Pilot it with limited internal apps and non-sensitive data before wider rollout.
How much does it cost?
Building apps consumes Copilot Credits under the spending policy of the product used to create them, and admins can set separate runtime spending policies. Users with Power Apps Premium licenses have some runtime entitlements, per Microsoft’s documentation.
What should companies not on Microsoft 365 do?
Apply the same principles with your own tools: maintain an app inventory, assign owners, tier by risk, scan AI-written code, and set clear budgets for running costs.
Sources
- Microsoft Copilot Blog: Managed Runtime announcement - Microsoft’s September 25, 2026 announcement of the public preview
- Microsoft Learn: Copilot Managed Runtime overview for admins - features, governance model, enablement defaults, and billing
- Retool: The Build vs. Buy Shift report 2026 - survey of 817 builders on shadow tools and custom builds
- Cloud Security Alliance: The Vibe Coding Governance Gap - research note on risks and recommended controls for citizen developers
- MnzAI Labs: Copilot Managed Runtime analysis - independent commentary and preview caveats
Have a project like this in mind?
Tell us what you're building — we'll help you scope it and ship it.
Talk to usKeep reading

September 26, 2026
Home, Code, and Autopilot: What Microsoft's Copilot Overhaul Means for Enterprise AI Governance

September 25, 2026
Jev's Record Launch: What TypeSafe AI's 'System One' Judgment Model Means for Your AI Automation Bill

September 25, 2026