What Copilot Can (and Can't) Actually Review in a Contract
Ask Copilot in Word to "review this contract" and you'll get an answer that sounds like a review: organized, confident, reasonable-sounding paragraphs about risk. Whether it's actually caught the thing you needed caught is a separate question, and the honest answer is that it depends heavily on what you asked for and how you asked for it. For anyone using a personal Microsoft 365 subscription rather than a firm's enterprise Copilot deployment with legal-specific tooling, that gap matters even more, because the base capability is general-purpose document AI, not a legal review product. The Beginner's Guide to Copilot covers the general fundamentals this article assumes.
Scanning for a specific clause type, which it does reasonably well
Copilot's most reliable use in contract review is a targeted, named search: find every instance of a specific clause type and summarize what it says. This plays to a real strength, reading a full document and pulling out every place a pattern appears, faster than doing it by eye across a fifty-page agreement.
Read through this contract and find every clause related to termination: termination for convenience, termination for cause, and any notice period required before termination. List each one with the section number, quote the relevant language, and note whether notice periods differ between the two parties.
”That last part, checking whether notice periods differ between the two parties, is a genuinely useful thing to ask for directly, because an asymmetric termination clause (the counterparty needs 90 days' notice, you only get 15) is exactly the kind of detail that's easy to miss reading a dense section start to finish, and exactly the kind of thing a clause-type-specific prompt is well suited to surface.
Find every indemnification clause in this contract. For each one, tell me who is indemnifying whom, what triggers the obligation, and whether there's a cap on the amount.
”Liability caps, indemnification triggers, assignment restrictions, and exclusivity language all work well as this kind of named, structured request. The pattern that works is always the same: name the specific clause type, ask for specific attributes of it (who, what triggers it, what limits it), and ask Copilot to quote the actual language rather than paraphrase it, so you can check its reading against the real text yourself.
What "review this contract" actually gets you, and why it's not enough
A broad, unscoped request for a general review produces a broad, unscoped answer: a reasonable-sounding list of "areas of potential concern" that reads like due diligence but wasn't built against any specific standard, any specific deal history, or any specific client risk tolerance. It's not that the answer is wrong, exactly. It's that "concerning" isn't a legal judgment Copilot is positioned to make responsibly; it's a pattern-matched guess at what a contract review often flags.
A general review is not a substitute for legal judgment
Copilot has no knowledge of the jurisdiction's specific case law, no knowledge of how a particular clause has actually been litigated, and no knowledge of your client's specific risk tolerance or negotiating history with this counterparty. A response that sounds like a thorough review can still miss the one issue that actually matters for this deal, and state its findings with the same confident tone whether it caught the real issue or not. Use it to scan for named clause types and organize what it finds. Do not use it as the final legal judgment on whether a contract is safe to sign.
A worked example: catching what a broad ask misses
Take a hypothetical services agreement with this clause in Section 14:
Illustrative clause only, not a real agreement
Section 14 (Limitation of Liability): Except for claims arising from a breach of Section 9 (Confidentiality), in no event shall either party's aggregate liability under this Agreement exceed the total fees paid by Client in the twelve (12) months preceding the claim.
Section 9's own definition of "Confidential Information" in this hypothetical draft is broad enough to cover most of the technical documentation the parties exchange, which matters, because it means the exception is not a narrow edge case, it's the category most likely to actually get litigated.
A broad, unscoped prompt run against that document produces something like this:
A broad 'review this contract for risk' prompt run on the clause above, illustrated
That response isn't false. It mentions the cap exists. It never mentions the carve-out that removes the cap for confidentiality claims, which is the one detail that changes what the clause actually protects against. A narrower, targeted prompt catches it because it's built to look for exactly that structure:
Find the limitation of liability clause in this contract. Quote it in full. Then check whether any other clause in the document creates an exception or carve-out to that cap, such as for confidentiality breaches, IP infringement, or gross negligence, and quote those too.
”The targeted, clause-plus-carve-out prompt run on the same document, illustrated
This is the shape worth reusing for any clause where the real risk lives in the interaction between two separate sections rather than in either one alone: name the primary clause, then explicitly ask it to hunt for carve-outs or exceptions elsewhere in the document.
That contrast is also where the line between what Copilot can and can't do actually sits. Finding the carve-out is defined-pattern matching: you named two clause types and asked whether one modifies the other, which is a checkable, mechanical task against the document in front of it. What Copilot still can't tell you is whether a 12-month fee cap is generous or thin for a services agreement of this size and industry, whether this particular counterparty's negotiating history suggests the carve-out is a line they'd actually hold on, or how a court in the governing jurisdiction has treated similar carve-out language when it's been litigated. Those are judgment calls built on context that lives outside the four corners of the document, and no amount of prompt precision gets Copilot access to context it was never given.
- 1
Name the clause type specifically
"Find the indemnification clause" or "find the termination clause," not "review the contract." A named target gets a checkable answer; a vague request gets a vague one.
- 2
Ask it to quote, not paraphrase
A direct quote lets you verify Copilot's reading against the actual contract language in seconds. A paraphrase can drift from what the clause actually says without either of you noticing.
- 3
Ask about interactions between clauses, not just isolated ones
The riskiest contract terms are often two clauses interacting (a cap and its carve-out, a term length and an auto-renewal clause), which a single clause-by-clause read can miss.
- 4
Verify every citation against the actual document, and never against outside law
Copilot summarizing a clause from the document in front of it is checkable work. Copilot stating what the law requires in your jurisdiction is a different kind of claim entirely, and needs independent verification through actual legal research, not this workflow.
What a personal Microsoft 365 subscription doesn't include
It's worth being explicit about the gating here: a personal Copilot subscription (Personal, Family, or Premium) is general-purpose document AI running inside Word, not a legal-specific contract review product with citation checking against case law, clause libraries benchmarked against market standards, or redlining workflows built for outside counsel. Firms using dedicated legal AI tools, or an enterprise Microsoft 365 Copilot deployment with legal-specific extensions, are working with a materially different tool than what's described here. One more point matters for client work: a personal account and a work account fall under different data-protection terms. Before pasting confidential client material into any Copilot, confirm which terms apply to the account you're signed in with and what your firm's policy and professional obligations require. For an individual using a personal subscription, the honest framing is: useful as a fast first pass that surfaces named clause types for you to verify, not a substitute for the judgment a qualified reviewer brings to a contract that actually matters.
Name the specific clause type you want found and reviewed, every time
Ask for direct quotes so you can verify the reading yourself
Ask explicitly about carve-outs and exceptions elsewhere in the document
Never treat a broad "review this contract" answer as a finished legal review
Remember a personal subscription is general-purpose AI, not a legal review product
Official sources
Checked on September 21, 2026. Features, plans and names change often, so the vendor's own pages are the final word.