Data Protection with Copilot and AI Builder in Power Automate
How Copilot and AI Builder in Power Automate handle your data, which GDPR points SMEs should consider, and what to do in practice.
Power Automate and Copilot Studio agent flows look similar, but they are separate products with their own licensing and purpose.
For a long time the answer was clear: anyone who wanted to automate something in Microsoft 365 ended up in Power Automate. Since Copilot Studio introduced its own Agent Flows, that clarity has disappeared. Both tools look similar at first glance, both connect triggers with actions, both partly use the same connectors, and yet they are two different products with their own licensing, their own limits, and their own purpose. Many SMEs, still working from the state of affairs from a year or two ago, simply don't know that this second automation track now exists and when it pays off. As of: July 2026.
This article sorts out the new boundary: what is a cloud flow in Power Automate, what is an agent flow in Copilot Studio, and by which criteria you, as a decision-maker, make the choice without getting lost in licensing details.
Copilot Studio was originally a tool for building chat agents with topics and conversation flows. In the meantime, it has gained its own automation layer, the so-called agent flows. According to the official FAQ about agent flows in Microsoft Copilot Studio agent flows are "automated sequences of actions that are triggered by specific events or conditions" and offer "a creation experience similar to Power Automate workflows, natively integrated into Copilot Studio". This very similarity causes confusion: visually and functionally, an agent flow strongly resembles a cloud flow, but technically and in licensing terms, they are separate worlds.
Cloud flows are what most people understand by Power Automate. They connect apps and services via connectors and, according to the Power Automate documentation on cloud flows, can be divided into three types:
Cloud flows require their own Power Automate license, access a broad connector ecosystem, and can be shared with colleagues, given co-owners, or passed on with run-only rights. For classic process automation independent of AI, this remains the right place to go.
Agent flows serve a different purpose. According to the Overview of agent flows and workflows, they are designed to provide "a native interface for building and integrating agents into business models", with a focus on AI-driven automation. An agent flow can be attached to an agent as a tool, which calls it at runtime to fetch data or perform actions on behalf of the user. It can just as well run as a standalone automation, entirely without chat interaction.
The most striking difference lies in billing. Cloud flows require an individual Power Automate license, whereas agent flows are billed on a consumption basis through Copilot Studio capacity, without separate per-user licensing. This can make sense at larger scale, but it comes with restrictions: according to the documentation, agent flows cannot be copied, cannot be given co-owners, and cannot be shared with run-only rights. Desktop flows, i.e. classic RPA automation on the desktop, also currently cannot be called from within agent flows.
For everyday practice in an SME, a simple rule of thumb pays off. If the automation runs independently of a chat agent and is meant to be shared long-term, jointly maintained, or combined with classic desktop RPA, Power Automate remains the right choice. If, on the other hand, the automation is meant to run as a tool within an AI agent, for example to automatically pull data from a system or obtain an approval during a customer request, it belongs in Copilot Studio as an agent flow.
In addition, there has recently been a third, still experimental layer: the new "workflows" in Copilot Studio, currently in public preview, with a redesigned visual designer and node-level testing, as described by the Overview of Copilot Studio. This is not yet suitable for production use, but you should keep it in mind for strategic planning, since Microsoft explicitly states that these preview features are not yet intended for production use.
Important for companies that already have many Power Automate flows in use: before converting individual flows into agent flows to save on license costs, you should check whether sharing, co-ownership, or desktop connectivity are relevant for that particular flow. Because these are exactly the features lost in the one-way conversion. NordFlux helps companies set up digital workers and automations so that, in the end, you know exactly which tool handles which task, while retaining control over license costs, data flow, and maintainability.
No. According to the documentation, agent flows are billed on consumption via Copilot Studio capacity and are not a Power Automate entitlement. For cloud flows in Power Automate, however, a separate license remains necessary.
Yes, for that the flow must be part of a solution and the target environment must have Copilot Studio capacity. However, the conversion is a one-way step: a flow that has already been converted cannot be turned back into a classic cloud flow because of the changed billing logic.
Desktop flows, i.e. classic RPA automation on the screen, currently cannot be called from within agent flows. Anyone who needs desktop automation stays with Power Automate for that part.
No, these are two different formats within the same workflows page. Agent flows are the established format, while the new workflows are still in public preview with a redesigned designer and are not yet intended for production use.
No, this is one of the most practically important differences. According to the documentation, agent flows cannot be copied, cannot be given co-owners, and cannot be shared with run-only rights, whereas that is exactly standard practice for cloud flows in Power Automate.
NordFlux builds digital employees for organisations: automations and AI agents that take over repetitive work. You stay in control.
How Copilot and AI Builder in Power Automate handle your data, which GDPR points SMEs should consider, and what to do in practice.
AI Builder Credits and Copilot Credits are two different billing systems. Here's how to tell them apart and plan your capacity correctly.
Microsoft officially calls Copilot in Power Automate “optimized for English.” The honest hands-on test in German: what works, what doesn't.
Power Automate and Copilot Studio increasingly overlap, and the wrong choice early on means duplicated development work later. We assess your specific use case and show whether a classic cloud flow or an agent flow is the more viable solution. That way you plan with an architecture that still holds up as requirements grow.