The short version
Start with the commercial Microsoft 365 product and a work account covered by the relevant terms. Microsoft says prompts, responses and Graph data are not used to train foundation models. Permissions still matter: information shared too broadly can be easier to discover. Review what users and approved agents can access, and check important outputs against their sources.
- Copilot respects existing permissions. That is the reassurance and the risk in one sentence.
- Commercial no-training commitments do not mean every request is processed inside your tenant or only in the UK.
- Review data governance, connected services, output accuracy and the specific use case together.
What Copilot can and cannot see
Microsoft documents permission-based access to organisational content and contractual protections for commercial Copilot. It also describes web search, third-party agents and model subprocessors, which require their own review. Processing location is not established by your tenant’s name or the location of a SharePoint file. Read Microsoft’s data, privacy and security documentation (opens in new tab) before relying on a UK-only or tenant-only assumption.
Check whether current permissions reflect who should see what. Broad sharing links, open sites or old guest access can expose information beyond its intended audience. This is a concrete issue to investigate, rather than an assumption that every tenant has the same problem.
The real risks, plainly
- Oversharing. An important access risk. Files and sites shared too broadly mean Copilot can pull sensitive content into an answer for the wrong person.
- Sensitive information controls. Labels can classify content and apply configured protection, but a label alone does not prevent every disclosure. Test the relevant encryption and DLP behaviour in the applications people use.
- Weak identity. If an account is compromised and lacks multi factor authentication, the attacker now has an assistant that can find the valuable data for them.
- No usage policy. Staff using Copilot for things it should not touch, with no guidance and no record, is a governance gap an auditor will find.
How to make Copilot safe to use
Start with the intended users and data. Review permissions, configure the relevant labels and DLP, harden identity and agree acceptable uses. Test the selected controls and review important outputs. Expand from a measured pilot, with an owner for ongoing review. Our Microsoft Copilot security guide covers the technical checks.
For regulated, finance, and defence-supply firms the bar is higher, because you also need an auditable record of what AI can and cannot do. That is squarely a governance question, and it is why we treat governed AI as part of compliance rather than a separate gadget. Our Copilot readiness and governance service exists to settle all of this before the first licence is switched on.
Common questions
Does Microsoft use my data to train Copilot?
Microsoft states that commercial Copilot prompts, responses and data accessed through Microsoft Graph are not used to train foundation models. This does not mean there is no processing, retention, web-search activity or third-party agent access. Review the selected product, work account, agents and contractual terms.
Can Copilot see files it should not?
Copilot’s access to organisational content follows the user’s permissions. Over-sharing can therefore make information available to people who should not have that access. Also review content supplied in prompts and the permissions and terms of connected agents; access controls do not replace those checks.
What is the single most important thing to do first?
Start with the data and use case: identify what staff need, what is sensitive and who should have access. A permissions review is a useful early step, alongside account security and a review of connected agents and processing terms.
