Eyal Marcus / Copilot and confidential data
Copilot security · Oversharing · Updated: October 2026

Is Copilot Safe for Confidential Information? What It Can See, and How Oversharing Happens

The short answer: signed in with your work account, Copilot only surfaces company data you already have at least view permission for. Your prompts, responses and the data it reads aren't used to train the models, and they're covered by the same contractual terms as your Exchange email and SharePoint files.

The real risk is oversharing. Copilot uses the access people already have, and if that access is too broad, Copilot makes it very easy to find. Plus 2 exceptions to know: web search queries and Anthropic models. I'm not a lawyer and this isn't legal advice. It's what Microsoft documents, as of October 2026.

0Training on your prompts
2Exceptions to know
1Real risk: oversharing
Written byEyal Marcus · 264 AI sessions in 112 organisations · working with AI since early 2022

01.

What Copilot can see

1Only what you can already open

Microsoft's wording: Microsoft Copilot (the new name for Microsoft 365 Copilot) "only surfaces organizational data to which individual users have at least view permissions." The Semantic Index and data from Graph connectors follow the same rule.

2Labels and encryption still apply

For content encrypted with Microsoft Purview Information Protection (through sensitivity labels or IRM), Copilot honors the usage rights you have. Copilot in Outlook isn't supported on signed or encrypted emails, or emails with IRM. And a Copilot draft's sensitivity label can go up if the generated text carries a higher one.

32 people, 2 different answers

Meeting prep summaries in Outlook are trimmed to each person's permissions, so your colleague may see a different summary. That's the permission model working.

4Third-party agents are different

Microsoft tells you to check the privacy statement and terms of use of any agent you add, because they define how that agent handles your data.

02.

What happens to what you type

1No training, no human review

Prompts, responses and Microsoft Graph data aren't used to train foundation models. Microsoft Copilot services have also opted out of the human abuse-monitoring review that Azure OpenAI offers.

2The contract

Enterprise data protection puts Copilot and Copilot Chat under Microsoft's Data Protection Addendum (DPA) and Product Terms, with Microsoft as data processor. Free Copilot Chat gets it too, with a work (Entra) sign-in (more in Copilot Chat vs Microsoft 365 Copilot). Microsoft says the rename changed nothing about security, compliance or privacy.

3It's a company record

Your chat history is stored encrypted, and admins can search it with Content search or Microsoft Purview. You can delete your own history in the My Account portal. My rule: don't type anything into Copilot that you wouldn't put in a work email.

4Memory has fewer controls

Copilot Memory is on by default. Admins can't restrict what goes into it, Purview retention policies don't apply to it, and memory actions don't create audit log entries. Worth knowing before you tell it a client's name "for next time".

03.

Exception 1: web search

When Copilot searches the web, it sends Bing a short generated query, not your prompt. Microsoft lists what's never in it: your entire prompt (unless the prompt is very short), whole files or emails, files you uploaded, and identifiers like your username or tenant ID.

But a document's theme can shape the query. Microsoft's own example: Copilot reads a document, spots "clean energy policy" as a major theme, and adds those words to the Bing query. Ask about your manager and the query can be your manager's name. So topics and names can reach Bing. Whole documents don't.

1Outside the DPA and the EU Data Boundary

Microsoft commits that these queries aren't used for ads, profiling or model training, and treats them as customer confidential information. But the DPA, HIPAA and the EU Data Boundary don't apply to them, and Microsoft acts as data controller.

2On by default

If IT doesn't configure the "Allow web search in Copilot" policy, web search is available in both Microsoft Copilot and Copilot Chat. The policy has 3 settings, including one that turns it off in work mode only.

3Your own switch

In the Microsoft Copilot app: Settings > Personalization > Advanced, then turn off Web search. In Copilot Chat you can also see the exact queries that were sent, for 24 hours.

04.

Exception 2: Anthropic models and the EU Data Boundary

EU traffic stays within the EU Data Boundary. Traffic from outside the EU may be processed in the US, the EU or other regions. And models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary, on 2 Microsoft pages. That matters because some features, like the Word, Excel and PowerPoint agents in Copilot Chat, need Anthropic models switched on.

For the legal and residency side, read Microsoft Copilot, GDPR and EU data residency. For routing, Copilot flex routing and the EU Data Boundary.

05.

How oversharing happens, and the controls

Microsoft puts this job on you: use SharePoint's permission models so the right people have the right access. A site shared with "Everyone except external users" (EEEU, a built-in group of all internal users) was always open to the whole company. Copilot just makes it searchable in plain language.

Microsoft's guide for this was the "oversharing blueprint". It's now called Secure and govern Microsoft Copilot: Foundational deployment guidance, with 3 pillars: remediate oversharing, set up guardrails, meet regulations.

1SharePoint Advanced Management comes with the licence

Assign at least 1 Copilot licence and SharePoint admins get SAM's oversharing features, including Restricted Content Discovery, restricted access control, EEEU insights, permission state reports and site access reviews. One exception: restricted site creation by apps needs the SAM Plan 1 add-on.

2Restricted Content Discovery

Hides chosen SharePoint sites from organization-wide search and Copilot without changing permissions, and removes the Copilot button there. Microsoft designed it as a temporary control while you fix access. It doesn't work on OneDrive, doesn't affect a document a user already has open, and can take over a week on sites with more than 500,000 items.

3Restricted SharePoint Search is retiring

New enablement is blocked from 31 July 2026, and Microsoft's own page says it isn't a security boundary. Don't start with it now.

4Find the overshared sites

Data access governance reports show site permissions, sensitivity labels, sharing links and EEEU sharing. E5 without SAM gets the reports but not the other SAM features.

06.

Purview DLP: what it blocks, and what it doesn't by default

1Sensitive prompts

A DLP policy can stop Copilot and Copilot Chat from answering prompts with sensitive data (a credit card or passport number, for example) and from using that data in web or internal searches. It can also block web search alone for those prompts.

2Labeled files and emails

Copilot won't read the content, but the item can still show up as a citation. It works in Copilot Chat, Word, Excel and PowerPoint, for emails sent from 1 January 2025, not calendar invites.

3The default policy only watches

Microsoft ships a default DLP policy for Copilot interactions, in simulation mode. It alerts, it doesn't block, until IT turns it on. Microsoft's DLP page doesn't name the licence, so ask your Microsoft contact.

Before you type a client file into Copilot: check you're in the Work account, ask IT whether web search and DLP are on, and ask who else can open that file today. If the answer to the last one surprises you, that's your oversharing problem, with or without Copilot.
07.

Questions about Copilot and confidential data

Is Copilot safe for confidential information?

With a work account, Copilot only surfaces data you can already view, doesn't train models on your prompts or data, and falls under Microsoft's DPA and Product Terms. The risks are files shared too widely, web search queries, and Anthropic models sitting outside the EU Data Boundary.

Does Copilot train on my company data?

No. Microsoft states that prompts, responses and data accessed through Microsoft Graph aren't used to train foundation models, including those used by Microsoft Copilot.

Can Copilot see files I don't have access to?

No. It only surfaces organizational data you have at least view permission for. But if a file is shared more widely than intended, you do have access, and Copilot can find it.

What is Copilot oversharing?

Content with permissions that are too broad, like a SharePoint site shared with Everyone except external users. Copilot leaves permissions alone and simply makes that content easy to surface. The fix is permissions, with tools like Restricted Content Discovery as a temporary brake.

What is the Copilot oversharing blueprint?

Microsoft's deployment guide, now titled Secure and govern Microsoft Copilot: Foundational deployment guidance. It has 3 pillars: remediate oversharing, set up guardrails and meet regulations.

Does Copilot web search send my documents to Bing?

No. It sends a short generated query without whole files, emails or your identity. But a document's topic or a person's name can end up in that query, and those queries are outside the DPA and the EU Data Boundary.

Executive briefing

Need your leadership team on the same page?

I run Copilot sessions for leadership teams, live online, for groups of up to 20 and from 1.5 to 4 hours.

Updated: 1 October 2026 · by Eyal Marcus · AI consultant and trainer, 264 AI sessions in 112 organisations