Ten seats inside a dashed boundary, four of them lit and six dark

Why Your Copilot Licences Sit Idle

Idle AI licences are rarely a training problem. They are an access problem, and the arithmetic of the waste is easy to run on your own tenant.

Your organisation bought Copilot licences. Maybe fifty, maybe five hundred. A year on, the usage report is uncomfortable reading, and the response in most companies is to schedule more training.

More training will not fix it, because the problem is almost never that people do not know how to prompt.

Run the number on your own tenant first

Before accepting anyone’s statistic about this market, including ours, pull your own Microsoft 365 usage report and sort it properly. Not by whether someone logged in, which is the number your dashboard reports, but by what they did in the last thirty days.

You are looking for three groups.

People who activated the licence and stopped. They opened it, asked it to rewrite an email, decided it was underwhelming, and never came back.

People who use it daily but shallowly. Email reformatting, meeting summaries, general questions. Real usage, genuine minor time savings, no change to how any work gets done.

People building things. Connecting systems, automating a workflow end to end, producing something that runs without them.

Every deployment we have looked at produces the same shape: a large first group, a moderate second, and a small third that generates most of the value. The exact split matters less than the shape, and the shape is remarkably stable across organisations.

What that costs, as arithmetic

Take a hundred licences at roughly KES 3,500 a month. Substitute your own contracted rate, which is the only number that matters for your case.

LicencesMonthlyAnnual
Total purchased100KES 350,000KES 4,200,000
Effectively idle40KES 140,000KES 1,680,000

KES 1.68M a year, for software nobody opens. That figure is worth putting in front of a CFO precisely because it is calculated from their own contract and their own usage export, not from a vendor’s slide.

Why the licences sit idle

The assistant cannot see the business

A Copilot licence gives an assistant access to Microsoft 365. Outlook, Teams, SharePoint, Word, Excel. That is a real corpus and it is genuinely useful for drafting.

It does not include M-Pesa transaction history. Or KRA iTax filings and TCC status. Or core banking. Or the SACCO management platform. Or Sage. Or the custom ERP that runs operations.

Which produces the moment that kills adoption in a Kenyan finance team. Someone asks how much came in via M-Pesa last week, and the assistant answers that it does not have access to that information.

That is not a defect. No global AI vendor has built a connector to the Daraja API or to KRA GavaConnect, and none has a particular commercial reason to. But from the user’s chair it is indistinguishable from the tool being useless, and they do not ask a second time.

The people who abandoned their licence are not lazy. They tried to use it for their actual job, discovered it could not reach their actual data, and drew the obvious conclusion.

The work moved somewhere you cannot see

Meanwhile the same finance team still needs the reconciliation done. So:

  1. Export the M-Pesa statement to CSV
  2. Export the unpaid invoices from Sage
  3. Paste both into a consumer AI tool
  4. Ask it to reconcile them and flag discrepancies
  5. Clear the chat history, because they know they should not have done that

This is the part that should worry a CIO more than the wasted licence fee. The licence is idle and the work is still happening, just outside every control the organisation has. Your security lead probably suspects it. Your compliance officer probably suspects it. Nobody has offered a better route.

Compliance blocks the useful version

Under the Data Protection Act 2019, an organisation has to know what personal data is being processed, by whom, for what purpose, and be able to demonstrate it on request.

Consumer AI tools give you none of that. No user attribution, no access control, no record of what was retrieved. So when a compliance function is asked to approve connecting an assistant to customer data, the honest answer is no, and the licences stay in their shallow, harmless, useless state.

Governance is not what is slowing AI down here. The absence of governed infrastructure is what is slowing it down, because it forces every serious use case to be refused.

The pattern is not unique to Kenya

Markets that moved earlier on enterprise AI went through the same sequence, and the lesson repeats: connectivity precedes intelligence.

Organisations buy assistant licences first, because they are easy to buy and easy to justify. Adoption looks fine on the dashboard and nothing measurable changes in the business. The projects that eventually work are the ones that stopped buying more AI and started connecting what they already had, usually by consolidating a sprawl of point integrations onto a single governed layer.

The Kenyan version has an extra turn. In most markets the systems an assistant needs to reach have vendor built connectors available. Here, the systems that matter most, M-Pesa, KRA, CRB, the local core banking platforms, have none. So the gap between having AI and using AI is wider, and it will not close on its own.

What integration infrastructure actually does

Four things, and the fourth is the one that gets it past compliance.

  1. Connects the assistant to real systems. M-Pesa, KRA, Sage, Salesforce, core banking, through one endpoint rather than a bespoke project per system.
  2. Controls who can reach what. Role based access, so finance can query collections and cannot query HR records.
  3. Records everything. Every call attributed to a named person, with what was touched and when.
  4. Filters what comes back. Sensitive fields stripped from responses before they reach the model.

What becomes possible

These are the shapes of work that change first, in every deployment.

Finance reconciliation

Before, someone exports M-Pesa statements, exports unpaid invoices from Sage, checks each supplier’s KRA TCC status by hand on the portal, and reconciles it in a spreadsheet over about three days.

After, they ask for May’s M-Pesa collections reconciled against unpaid Sage invoices with any expired supplier TCCs flagged, and read the exceptions.

Pipeline review

Before, a sales manager checks the CRM, checks payments separately, scrolls back through conversations, and drafts follow ups.

After, they ask which deals moved to negotiation this week, whether those clients have paid, and get drafts back for the ones that have not.

Compliance checks

Before, the compliance officer raises a ticket, IT exports transaction data, exports filings, and someone reconciles it manually.

After, the officer asks directly, and every query they ran is itself in the audit log.

Notice what is common to all three. Nobody became a prompt engineer. The work did not change shape. The retrieval step, which was most of the elapsed time and none of the value, disappeared.

Prove it in two days, on your own data

A six month integration programme is the wrong way to test this, because it commits you before you know anything.

Two days is enough to answer the only question that matters at this stage: can an assistant, given governed access to our systems, do a piece of work our team currently does by hand?

A short proof of concept typically runs a governed gateway, connects one or two systems that matter, gives a small group of real users their actual work to try, and then checks the audit log to confirm every call was recorded and attributed.

What to measure, and what not to. Do not measure licence activation, which will not move in two days and is the metric that misled you in the first place. Measure whether a specific workflow completed correctly, how long it took against the manual baseline you timed beforehand, and whether the audit trail is complete enough to hand to your compliance officer.

Time the manual baseline before you start. Almost nobody does, and without it the result is an anecdote.

What each seat around the table should ask

If you are the CFO, the question is not what the ROI on AI is. It is what proportion of your existing licence spend is currently doing nothing, which you can calculate this afternoon from your own usage export, and whether the work those licences were bought to do is instead happening in unlogged consumer tools.

If you are the CIO, the question is whether AI access to business systems runs through infrastructure you control. If the answer is that people paste exports into a chat window, you do not have an AI adoption problem. You have an unmanaged integration running through your staff.

If you are the compliance officer, the question is whether you could produce a record of every AI query that touched customer data last week, showing who asked and what was returned. If not, that gap exists today, whether or not anyone has asked about it.

The bottom line

Idle licences are a symptom. The cause is that the assistant cannot reach the data the business actually runs on, and the work has quietly moved to tools where nobody can see it.

More training does not fix that. Connecting the systems does.


Msharti is the AI access layer for African enterprise, connecting AI assistants to M-Pesa, KRA, Sage, core banking and Microsoft 365 through one governed endpoint with role based access and query level audit. Built in Nairobi. Talk to us.

See it running against your own systems.

Book a 20-minute demo. We'll connect one of your systems live.

Talk to Us