---
title: "Copilot & embedded AI agents · assistants inside the tools you use · Agent Fieldbook"
url: https://agentfieldbook.org/catalog/copilots_embedded/
description: "Copilots and embedded agents live inside a host product and keep a human in the loop: they suggest, draft and act where the work already happens. Often a frontier model scoped into one workflow, each specced against primary sources and drawn as a topology specimen."
section: "Catalogue · Copilots & Embedded"
source: Agent Fieldbook — generated from the published page
---

# Copilots & embedded agents

Agents that live inside a host product rather than as a standalone app: copilots that suggest and act while a human stays in the loop, and embedded agents that inherit their surface's data and permissions. Convenient because the work is already there, bounded because the host sets the reach. Click a card for its full spec.

## 9 agents Live data · click a specimen for its anatomy

## Field notes

A frontier capability scoped into a host product, human in the loop

Copilots do not ask the user to go anywhere. They sit inside a surface someone already uses, the editor, the document, the CRM record, and act on the context that is already open.

That makes distribution, not capability, the decisive asset in this category. A copilot inside a tool with millions of daily users starts ahead of a better-reasoning agent that needs a new tab. The pattern to watch is incumbents embedding assistants into existing surfaces faster than standalone agents can build an audience.

- [Brandon Chaplin](https://www.linkedin.com/in/brandon-chaplin-digital-marketing-strategist)

## Common questions

### What is an AI copilot?

An AI assistant built into a tool you already use, such as an editor, an inbox or a CRM. It drafts and suggests while you work, and you accept or reject each change. The person stays in control of what actually happens.

### What is the difference between a copilot and an AI agent?

How much runs without you. A copilot proposes and waits for approval. An agent takes a goal and works through several steps by itself. Many copilots use the same underlying model as a full agent, just kept on a shorter leash.

### Can an AI copilot see my company data?

It inherits whatever the host product can already see, under your own account permissions. That is what makes it useful and also what limits it. Check the vendor terms for where prompts are stored and whether they are used for training.

### Why build an AI agent into an existing product instead of a separate app?

Because the work is already there. Embedding removes the copy-and-paste step, reuses the product’s data and permissions, and lets the assistant act on exactly what is open on screen. The cost is reach: it can only touch what the host exposes.

### Are AI copilots safe to use at work?

Safer than an autonomous agent, because a person approves each change. The live risks are the data you feed it and prompt injection, where hidden text inside a document or email steers the assistant. OWASP ranks prompt injection the top risk for LLM applications [(OWASP)](https://owasp.org/www-project-top-10-for-large-language-model-applications/).

## Next in the learning path

- [Frontier agents The general reasoners copilots often wrap](https://agentfieldbook.org/catalog/frontier/)

- [Deployment modalities Embedded is one place an agent can run](https://agentfieldbook.org/catalog/modalities/)

- [Agent platforms Where standalone agents are built instead](https://agentfieldbook.org/catalog/platforms/)

- [Human oversight The approval seam copilots are built around](https://agentfieldbook.org/security/oversight/)

## Entries

_9 entries listed on this page._

| name | description | subjectOf |
| --- | --- | --- |
| GitHub Copilot | Agnostic coding surface increasingly governed by usage-based economics. | https://github.com/features/copilot |
| GitHub Copilot Cloud Agent | Cloud execution makes Copilot more agentic and more compute-intensive. | https://github.com/features/copilot |
| Microsoft 365 Copilot | Grounding (Microsoft Graph) and enterprise distribution are the moat. | https://www.microsoft.com/microsoft-365-copilot |
| M365 Copilot Chat | Free included chat is a distribution wedge into paid Copilot. | https://www.microsoft.com/microsoft-365-copilot |
| Cursor | The model router disguised as an IDE, model choice is a feature, not a backend detail. | https://docs.cursor.com/models |
| Sourcegraph Cody | Owns code context and enterprise controls, not the frontier model. | https://sourcegraph.com/cody |
| Notion Enterprise Search | Strong citation-first enterprise search pattern. | https://www.notion.com/product/enterprise-search |
| Slack AI | Search and permissioning are central to Slack's AI moat. | https://slack.com/features/ai |
| Databricks Assistant | Databricks AI assistant, SQL/PySpark generation + notebook copilot for lakehouse work. | https://www.databricks.com/product/databricks-assistant |
