Planner + Copilot CoworkEU AI Act Conformity Readiness Programme
ScenarioEU AI Act Conformity Readiness ProgrammeLaunching cross-functional readiness ahead of Article 6 conformity assessment — Legal, Privacy, Product, Security, Public Policy, Communications, and Executive Governance, coordinated in Planner and Copilot Cowork.

CELA demonstration script — presenter companion

From task visibility to governed execution

Planner as the commitment layer, Cowork as the coordination layer

The challenge for CELA programme managers is not only visibility of work. It is trusted coordination across legal, privacy, policy, product, security, communications, and executive stakeholders. Planner holds the commitments. Cowork accelerates the coordination. Human validation, source traceability, and approval checkpoints preserve accountability at every step.

Run of show

ActWhat it showsUnderlying message
Act 1Planner board for the readiness programmePlanner is the system of record for cross-functional commitments
Act 2Cowork reviews tasks, surfaces risk and bottlenecksCowork accelerates coordination — it does not replace PM judgment
Act 3Human validation checkpoint before anything movesAI supports the PM; it does not become the accountable owner
Act 4Source validation view linking output to evidenceTrust comes from traceability, not polished output
Act 5Stakeholder-specific communication draftsThe right communication is the appropriate one, not the fullest one
Act 6Executive decision memo, drafted post-validationExecutives get decision clarity, not a task dump
Act 7Calendar checked, review meeting scheduled, Teams messages drafted and sent to task ownersCoordination becomes real action — still gated by PM approval before anything sends
Act 8Approval checklist and final sign-off pathGovernance is explicit, not assumed
Act 9Pilot measurement frameworkThe model must prove improvement, not just look impressive

Governance architecture

Every act in this demo maps onto a single governance chain. Watching where each act sits on the spine is how the audience sees that acceleration never skips accountability.

Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Every Cowork output moves through this chain before it becomes a stakeholder or executive action. No stage is skipped, and no stage is performed by the tool itself.
“Think of Planner as the commitment layer and Cowork as the coordination layer. The commitment layer never moves without a human. The coordination layer accelerates everything up to — but not past — the point of human judgment.”Presenter framing

Planner board setup

This is the live board Cowork reads from throughout the demo — the EU AI Act Conformity Readiness Programme, shown as a Planner board with 10 workstream buckets and 11 commitments. Every prompt you run below is grounded in exactly these tasks, owners, dates and evidence — nothing is invented.

P

EU AI Act Conformity Readiness Programme

Planner · Board view

Regulatory Interpretation

1

Map relevant EU AI Act obligations

Ready

Map applicable EU AI Act obligations to product portfolio

Completed last week1DW
Add task

Legal Review

1

Complete legal interpretation note

RestrictedOverdue

Complete legal interpretation note on high-risk classification

Blocks executive memo and public policy position.

Overdue by 4 days11MF
Add task

Privacy & Data Protection

1

Assess GDPR and privacy implications

At risk

Assess GDPR overlap and data-processing implications

Due in 2 days11PA
Add task

Product Readiness

1

Prepare product impact summary

Ready

Prepare product impact summary for affected features

Due in 5 days1TO
Add task

Security Review

1

Review security control evidence

Ready

Review security control evidence against conformity requirements

Due in 6 days1SR
Add task

Policy & External Affairs

1

Draft public policy position

Awaiting validationBlocked

Draft public policy position statement

Blocked pending final legal interpretation note.

Due next week1LD
Add task

Executive Governance

2

Prepare executive decision memo

Awaiting validation

Prepare executive decision memo for governance review

Cannot be finalised until legal and privacy inputs are validated.

Due in 3 days2DW
Awaiting validation

Validate Cowork risk scan before executive use

Explicit governance checkpoint — accountability remains with the PM.

Due in 1 day1DW
Add task

Communications Readiness

1

Create stakeholder communication plan

Awaiting validation

Create stakeholder communication plan

Due next week1NB
Add task

Implementation Tracking

1

Confirm regional stakeholder impacts

At riskOverdueNo owner

Confirm regional stakeholder impacts (EU markets)

No owner assigned — coordination gap.

Overdue by 2 days
Add task

Evidence & Audit Trail

1

Attach final approved evidence pack

Awaiting validation

Attach final approved evidence pack to audit trail

Due at programme close13DW
Add task
"Notice what the board already tells us before any AI runs: a legal note is overdue, a policy task is blocked behind it, and one regional task has no owner at all. Cowork's job is to make those coordination gaps impossible to miss — not to decide what to do about them."Presenter framing
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Before Cowork — Planner alone, establishing visibility

Act 1

Establish the programme control surface

Show Planner as the structured source of truth for programme work — before Cowork is introduced at all.

  • Buckets, task owners, due dates, labels, priority
  • Checklist items, attachments, linked documents
  • Comments or activity history, where available
Let us begin where CELA programme management actually begins: with commitments. This board represents a live cross-functional readiness programme. The important point is that Planner gives us structured visibility. But visibility alone does not move the programme. The PM still has to interpret risk, chase dependencies, prepare decision material, and coordinate stakeholders. That is where Cowork becomes useful.Presenter script
Transition: "Now we will move from visibility to trusted coordination."
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Cowork Output — first pass analysis, not a governance answer

Act 2

Cowork programme risk scan

Cowork analyses the Planner task set and prepares a risk-based programme view — organising evidence, not making legal judgments.

Notice the instruction: Cowork is not being asked to make the legal decision. It is being asked to organise the programme evidence, identify coordination risks, and recommend where human attention is needed.Presenter script
This is the first change from a normal productivity demo. We are not celebrating speed alone. We are demonstrating a governed synthesis.
Cowork prompt — programme risk scan
# Role
Act as a CELA Programme Management assistant supporting an EU AI Act Conformity Readiness Programme.

# Context
Use the Planner board as the system of record for programme commitments. Review tasks across Legal, Privacy, Product, Security, Policy, Communications, and Executive Governance workstreams.

# Objective
Prepare a programme risk scan for the CELA PM team.

# Analyse
Identify:
- overdue tasks
- tasks due soon
- missing owners
- blocked tasks
- approval bottlenecks
- workstreams with insufficient evidence
- dependencies that may affect executive sign-off
- actions requiring Legal, Privacy, Security, Product, or Policy input

# Output
## 1. Programme Health
Classify the programme as: On Track / At Risk / Off Track. Explain the classification based only on available Planner and Microsoft 365 context.

## 2. Critical Risks
For each risk: description, affected workstream, related Planner task, likely implication, recommended next action, recommended human owner for validation.

## 3. Approval Bottlenecks
Identify approvals or reviews that may delay executive sign-off.

## 4. Immediate PM Actions
Recommend actions for the PM team to take next.

## 5. Information Gaps
Clearly state any information that is missing or not available.

Do not invent owners, approvals, dates, legal conclusions, or regulatory interpretations.
Live — runs against the actual Planner board above.
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Source Review → Human Validation — the checkpoint before anything moves

Act 3 — the pivotal act for this audience

Governance trust layer

Answers the exact question Legal, Privacy, and Security will ask: how do we trust the AI-generated synthesis?

On-screen: a Planner task titled "Validate Cowork Risk Scan Before Executive Use."

Before any recommendation goes to executives, the workflow introduces a validation step. Cowork has generated a programme risk view, but accountability remains with the named human owner. The PM does not forward the output blindly. The PM verifies the source trail, checks the underlying Planner tasks, confirms whether the evidence is complete, and routes the recommendation to the correct decision owner.Presenter script

Board update · validation checkpoint active

Cowork produced a risk synthesis in Act 2. Before anything is escalated, the governance checkpoint is now live on the board: the named PM is verifying the synthesis against the underlying tasks. Accountability stays with the human — and the board shows it.

P

EU AI Act Conformity Readiness Programme

Planner · Board view

Executive Governance

2

Prepare executive decision memo

Awaiting validation

Prepare executive decision memo for governance review

Cannot be finalised until legal and privacy inputs are validated.

Due in 3 days2DW
Awaiting validationUpdated

Validate Cowork risk scan before executive use

Validation in progress — Diane is checking the underlying Planner tasks and evidence completeness.

Due in 1 day1DW
Add task
This is the core of the demo for CELA. AI acceleration is valuable only when it is embedded inside an accountability model.
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Source Review — every recommendation must trace to evidence

Act 4

Source traceability and human review

Recommendations must link back to underlying tasks, files, or evidence — and say plainly when they can't.

  • Not every AI output is automatically executive-ready
  • Some items should be marked "needs additional evidence" — that is a feature of the model, not a weakness
  • The PM role gets stronger: a structured validation queue, not a blind forward
In this workflow, uncertainty is not hidden. It is surfaced, routed, and governed.
Cowork prompt — source validation view
# Objective
For the programme risk scan you prepared, create a source validation view.

# Instructions
For each major risk or recommendation:
1. Identify the related Planner task.
2. Identify the source or evidence used — linked files, task notes, meeting references, comments, or available communications.
3. State whether the evidence is sufficient for PM review.
4. Identify what a human reviewer must validate before this can be used in an executive briefing.
5. Mark each item as:
   - Ready for PM validation
   - Needs additional evidence
   - Requires Legal review
   - Requires Privacy review
   - Requires Security review
   - Requires Product confirmation

# Output Format
A validation table with: Risk or recommendation / Related Planner task / Source or evidence reference / Evidence sufficiency / Human validation owner / Required next step / Executive briefing readiness.

Do not assume evidence exists if it is not available.
Live — runs against the actual Planner board above.
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Human Validation — routing the right detail to the right audience

Act 5

Cross-functional access boundary scenario

Not every stakeholder needs the same information. Product needs to know a dependency exists — not the privileged legal reasoning behind it.

Product readiness — ReadySecurity evidence — ReadyPrivacy assessment — At RiskLegal interpretation — Restricted / requires Legal validation
Now let us introduce a realistic CELA constraint. Product may need to know that a legal dependency exists. It may not need privileged legal reasoning. Executives need decision implications. Communications needs approved language only.Presenter script
For CELA, the right communication is not the fullest communication. It is the appropriate communication.
Cowork prompt — stakeholder-specific communications
# Objective
Create stakeholder-specific communication views for the EU AI Act Conformity Readiness Programme.

# Context
The programme has different stakeholder groups with different information needs.

# Instructions
Using the available Planner and Microsoft 365 context, prepare separate communication drafts for:
1. Executive leadership
2. Legal team
3. Privacy team
4. Product team
5. Security team
6. Communications team

For each stakeholder group:
- include only the information relevant to that group
- avoid unnecessary legal or sensitive detail
- distinguish between confirmed facts, pending reviews, and recommendations
- identify what action is needed from that group
- state where human approval is required before sending

# Output (per stakeholder group)
## Audience
## Purpose of message
## Draft message
## Information sensitivity note
## Required human approval before sending

Do not send or finalise any communication without human review.
Live — runs against the actual Planner board above.
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Cowork Output — a draft, explicitly not a final position

Act 6

Executive decision memo

Executive-ready material — but only after validation logic has already been demonstrated in Acts 3 and 4.

  • Highlight the Ready / At Risk / Not Ready / Awaiting Validation classification
  • Highlight "items not ready for executive escalation" — named explicitly, not buried
  • Highlight named human owners against every open decision
This gives executives what they need: not a task dump, but decision clarity.
Cowork prompt — executive decision memo
# Role
Act as a CELA PM briefing assistant.

# Objective
Prepare an executive decision memo for the EU AI Act Conformity Readiness Programme.

# Important Governance Constraint
This memo is a draft for human review. It must not be treated as the final legal, policy, privacy, or executive position.

# Inputs to Use
Validated Planner task status, confirmed risks, approved evidence references, known approval bottlenecks, documented pending decisions.

# Output Structure
## 1. Executive Summary
## 2. Current Readiness Position — classify each workstream: Ready / At Risk / Not Ready / Awaiting Validation
   Workstreams: Legal, Privacy, Product, Security, Public Policy, Communications, Executive Governance
## 3. Key Risks — description, workstream, decision impact, mitigation, follow-up owner
## 4. Decisions Required — decision, options, recommended path, implication of delay, accountable owner
## 5. Items Not Yet Ready for Executive Decision
## 6. Recommended Governance Actions

# Tone
Concise, factual, risk-aware. Do not overstate readiness. Do not invent legal conclusions. Do not present recommendations as approved decisions.
Live — runs against the actual Planner board above.
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Human Validation — coordinating the room and the people who validate, before anything is sent

Act 7

Coordination in action — calendar, meeting, and team messages

This is where the demo moves from synthesis to real execution. Cowork checks calendar availability, schedules the governance review meeting, and drafts individual Teams messages to task owners — every action still gated by PM approval before it leaves the workspace.

Calendar & meeting

Cowork prompt — calendar and meeting
# Objective
Check calendar availability for the Legal reviewer, Privacy lead, Security reviewer, and Executive sponsor over the next three business days.

# Instructions
Propose two meeting time options for a 45-minute "EU AI Act Conformity Readiness — Governance Review" session, based on genuine overlap in their calendars.
Do not schedule anything yet — present the two options to the PM for confirmation first.

Once the PM confirms a time, schedule the meeting with an agenda covering:
- outstanding legal interpretation items
- privacy assessment status
- security control evidence
- governance sign-off recommendation

Do not schedule the meeting until the proposed time is explicitly confirmed by the PM.
Live — runs against the actual Planner board above.

EU AI Act Conformity Readiness — Governance Review

Scheduled ✓ confirmed via Outlook Calendar

[Date] · [Time] · 45 min · Microsoft Teams

LGPRSCEXPM
Legal · Privacy · Security · Executive · PM

Agenda

  • Outstanding legal interpretation items — Legal
  • Privacy assessment status — Privacy
  • Security control evidence — Security
  • Governance sign-off recommendation — Executive sponsor
"Coordination isn't only synthesis — it's action. Cowork checked calendar availability across Legal, Privacy, Security, and our executive sponsor, and found a slot that actually works for all four. I confirmed the time before anything was scheduled. Now it's on every calendar, with an agenda that maps directly to the open items in Planner."Presenter script

Team messages

Cowork prompt — team messages
# Objective
Draft individual Teams messages to each Planner task owner with an overdue or at-risk item ahead of the governance review meeting.

# Instructions
For each task owner:
- name the specific task and its current status
- state what is needed from them before the review meeting
- include the confirmed meeting time
- keep the tone direct and collegial

Output one message block per recipient, labelled with name and role, followed by "Draft — pending PM approval."
Do not send any message until the PM has reviewed and approved the draft.
Live — runs against the actual Planner board above.
LG

Legal reviewer

Legal Review

Sent ✓

Hi — the legal interpretation note on Article 6 classification is still open in Planner. Could you confirm status before our review at [time] on [date]? Flagging it as the one open item Privacy is waiting on to close their assessment.

PR

Privacy lead

Privacy & Data Protection

Sent ✓

Hi — the GDPR impact assessment is still pending your sign-off. Bringing it to the review at [time] on [date] as a decision item — could you have a position ready going in?

SC

Security reviewer

Security Review

Draft — awaiting PM approval

Hi — the security control evidence attachment is still open. Could this be closed out before [time] on [date]? It's the last item standing between Security and a Ready status.

"Every message went out as a draft first. I approved each one before it sent — Cowork prepared them, it did not decide to send them."
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Decision Owner Approval → Stakeholder Action — nothing moves without sign-off

Act 8

Human approval before action

Explicitly shows that stakeholder communication or executive escalation requires human review — before anything leaves the PM workspace.

  • PM validates Cowork executive memo
  • Legal confirms legal risk language
  • Privacy confirms privacy assessment status
  • Security confirms control evidence
  • Executive sponsor approves the governance pack
  • Communication sent only after approval
Before this briefing leaves the PM workspace, the workflow requires human validation. Legal reviews legal language. Privacy validates privacy status. Security confirms evidence. The PM ensures the programme narrative is accurate. Only then does the output become an executive communication or stakeholder action.Presenter script

Board update · after human approval

Now the board reflects governed execution. The overdue legal note has been validated and signed off, the blocked policy task is released, the unowned regional task has a human owner, and the validation checkpoint is closed — every change made by an accountable person, with Cowork only surfacing where attention was needed.

P

EU AI Act Conformity Readiness Programme

Planner · Board view

Legal Review

1

Complete legal interpretation note

ReadyUpdated

Complete legal interpretation note on high-risk classification

Signed off by Legal — dependency cleared.

Completed11MF
Add task

Policy & External Affairs

1

Draft public policy position

ReadyUpdated

Draft public policy position statement

Unblocked — legal interpretation note now finalised.

Due next week1LD
Add task

Executive Governance

2

Prepare executive decision memo

At riskUpdated

Prepare executive decision memo for governance review

Legal and privacy inputs now validated; memo in executive review.

Due in 3 days12DW
ReadyUpdated

Validate Cowork risk scan before executive use

Checkpoint closed — human validation complete.

Completed1DW
Add task

Implementation Tracking

1

Confirm regional stakeholder impacts

ReadyOverdueUpdated

Confirm regional stakeholder impacts (EU markets)

Owner assigned by the PM after Cowork surfaced the coordination gap.

Overdue by 2 daysLD
Add task
The workflow uses AI to accelerate preparation, not to bypass governance.
Optional prompt — approval checklist generator
Cowork prompt — approval checklist generator
Create a human approval checklist for the executive decision memo.

Include: PM validation, Legal review, Privacy review, Security review, Product confirmation, Executive sponsor approval.

For each approval step, specify: what must be checked, who should validate it, what evidence should be reviewed, what should happen if the reviewer disagrees, how the Planner task should be updated after approval.
Live — runs against the actual Planner board above.
Cowork Output
Source Review
Human Validation
Decision Owner Approval
Stakeholder Action
Outside the chain — this act proves the model, not just the demo

Act 9

Outcome and measurement layer

A CELA PM team will not adopt this workflow because it looked impressive. It has to move real programme metrics.

This is how the workflow moves from demo to operating model.
MetricBeforeAfterTarget direction
Risk identification cycle timeBaselineMeasuredReduce delay
Executive briefing preparation effortBaselineMeasuredReduce manual effort
Approval bottleneck visibilityBaselineMeasuredImprove earlier escalation
Stakeholder follow-up completionBaselineMeasuredImprove closure rate
Decision ageingBaselineMeasuredReduce unresolved decisions
Evidence completenessBaselineMeasuredImprove readiness quality

Replace "Baseline / Measured" with real pilot figures before delivery — an unquantified table invites the exact challenge it is meant to pre-empt.

Measurement framework prompt
Cowork prompt — measurement framework
# Objective
Create a measurement model for the Planner + Cowork CELA PM workflow.

# Context
The workflow supports an EU AI Act Conformity Readiness Programme involving Legal, Privacy, Product, Security, Policy, Communications, and Executive Governance.

# Output
Create a measurement framework with: Adoption metrics, Governance metrics, Coordination metrics, Risk management metrics, Executive decision metrics, Evidence quality metrics.

For each metric: name, what it measures, why it matters, possible data source, suggested review cadence, owner accountable for reviewing it.

Avoid claiming improvement without measured evidence.
Live — runs against the actual Planner board above.

Closing script

The real value of Planner and Cowork for CELA PMs is not faster task management. It is trusted coordination. Planner holds the commitments. Cowork accelerates analysis, synthesis, communication drafting, and decision preparation. Human owners validate the evidence, approve the recommendations, and remain accountable for decisions. For CELA, that is the right model: faster coordination without weakening governance.
The one-line anchorThis workflow demonstrates not just how AI helps CELA PMs move faster, but how AI-enabled work can remain governed, traceable, and human-accountable while accelerating complex programme execution.

Leave-behind: the master briefing prompt

The full end-to-end prompt a CELA PM can keep and reuse. Run it live to generate a complete governed programme briefing from the board above.

Cowork prompt — master executive briefing (reference version)
# Role
Act as a CELA Programme Management assistant supporting a legal, privacy, policy, product, security, communications, and executive governance programme.

# Scenario
We are managing an EU AI Act Conformity Readiness Programme in Planner. Planner is the system of record for programme commitments, including tasks, owners, due dates, workstreams, dependencies, evidence links, and approval actions.

# Objective
Prepare an executive-ready programme briefing that supports governance review and decision-making.

# Governance Constraint
This output is a draft for human review. Do not present legal, privacy, security, regulatory, or executive conclusions as final unless explicitly confirmed in the available source context.
Clearly distinguish between: confirmed facts, pending reviews, recommendations, assumptions, information gaps.
Do not invent owners, dates, approvals, evidence, or legal conclusions.

# Analyse
Review available Planner tasks and related Microsoft 365 context where accessible. Identify: overall programme health, workstreams on track / at risk / blocked, overdue tasks, missing evidence, critical path dependencies, pending approvals, stakeholder groups requiring follow-up, decisions required from leadership, risks with legal, privacy, security, regulatory, reputational, policy, or delivery implications.

# Structure
## 1. Executive Summary
## 2. Programme Health — On Track / At Risk / Off Track / Awaiting Validation, with evidence-based rationale
## 3. Workstream Status — Regulatory Interpretation, Legal Review, Privacy & Data Protection, Product Readiness, Security Review, Policy & External Affairs, Communications Readiness, Executive Governance, Evidence & Audit Trail
## 4. Key Risks and Implications — prioritised, with severity and validation owner
## 5. Decision Requirements — for senior leadership, with urgency and required validation
## 6. Source and Evidence Validation — classify each conclusion: Ready for executive use / Needs PM validation / Requires Legal, Privacy, Security, or Product review / Not enough information available
## 7. Stakeholder Coordination Plan — Legal, Privacy, Product, Security, Public Policy, Communications, Executive Sponsors, Regional or Market Teams
## 8. Immediate PM Actions
## 9. Executive Talking Points — 5 to 7, clear, factual, risk-aware, non-alarmist, action-oriented
## 10. Draft Communications — executive briefing email, governance meeting agenda, Legal/Privacy follow-up note, risk escalation note, stakeholder coordination message. Each draft states the human approval required before sending.

# Output Requirements
Polished executive format. Avoid generic project management language. Focus on governance discipline, legal and regulatory readiness, privacy and security validation, stakeholder alignment, decision velocity, evidence completeness, risk mitigation, execution confidence.
Where information is missing, state: "Information not found or not available in the current context."
Live — runs against the actual Planner board above.