AI Chatbots & Assistants

Microsoft Copilot

Medium risk

Microsoft's AI assistant, spanning the free consumer Copilot and Microsoft 365 Copilot embedded across Word, Excel, Outlook, and Teams.

Verified 2026-08-31Microsoftcopilot.microsoft.com

Is Microsoft Copilot safe for confidential data?

Microsoft Copilot is two very different products under one name. Microsoft 365 Copilot runs inside the tenant boundary: prompts and grounded content are not used to train foundation models and inherit the customer's Microsoft 365 compliance terms. The free consumer Copilot is a public chatbot whose conversations may be used to improve models subject to user settings. Employees signed into a personal Microsoft account get the consumer terms — on the same machine where the corporate tenant lives.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Copilot (free, personal account)
Conditional

Consumer terms; conversations may be used for model training unless the user opts out in Copilot privacy settings; no tenant visibility or controls.

Microsoft 365 Copilot
No training

Tenant boundary, no foundation-model training, Purview audit, DPA and enterprise terms.

Data handling

Training on inputs

Microsoft 365 Copilot: prompts, responses, and data accessed via Microsoft Graph are not used to train foundation models. Consumer Copilot: conversations may be used for model improvement, subject to the user's privacy settings.

Retention

Microsoft 365 Copilot interactions are stored in the tenant (searchable via Purview) under the customer's retention policies. Consumer Copilot chat history is kept for 18 months by default, manageable via the Microsoft account's privacy dashboard.

Residency

Microsoft 365 Copilot honors the tenant's data-residency commitments, including the EU Data Boundary. Consumer Copilot processes in Microsoft's global cloud.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAAConditional

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • Tenant data boundary (M365 Copilot)
  • Purview audit and eDiscovery of Copilot interactions
  • Sensitivity-label enforcement
  • EU Data Boundary residency
  • Microsoft DPA / product terms coverage

Frequently asked questions

Does Microsoft Copilot train on my data?

Microsoft 365 Copilot does not use your prompts or tenant content to train foundation models. The free consumer Copilot may use conversations for model improvement depending on the user's privacy settings — and it's the consumer version employees reach at copilot.microsoft.com with a personal login.

Is Microsoft 365 Copilot safe for confidential documents?

Contractually it is one of the stronger options: content stays in the tenant, under your retention, audit, and residency settings. The residual risk is oversharing — Copilot surfaces anything the user already has permission to see, so stale broad permissions become instant leaks to the wrong colleague.

How do I tell whether employees are using consumer Copilot or the tenant version?

The browser can't tell the difference by URL alone, and network blocks break the sanctioned version too. Sanitized AI identifies the destination and account context at the prompt layer, redacts sensitive fields either way, and reports usage by tool.

Policy changelog

  • Initial entry published from Microsoft's published documentation.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Microsoft Copilot is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles