Where does your data go when you use Copilot?
Business Copilot runs inside the organization's 365 environment, and business tiers typically commit that organizational data will not be used to train the underlying models. As always, that is a contractual commitment to verify in its current version — but with Copilot it isn't the main story. The primary risk points the other way: what the tool reveals inside the organization.
Why is SharePoint over-permissioning the real problem?
Most organizations carry years of over-broad sharing: libraries opened to 'the whole company' for one project, sharing links that never expired, inherited folder permissions. Until now this was a dormant risk — someone had to know where to look. Copilot removes the looking step: it retrieves any accessible file to answer an innocent question.
- Example: an employee asks 'what are our salary bands?' — and Copilot answers from an HR spreadsheet accidentally shared org-wide.
- The principle: Copilot breaks nothing. It respects permissions — and precisely because of that, it turns every over-grant from a theoretical flaw into an actual disclosure.
- The conclusion: rolling out Copilot is the moment of truth for permission hygiene — an access-control duty most security frameworks already impose.
What should you do before enabling Copilot?
- Permission audit — find SharePoint sites and OneDrive folders shared too broadly, stale sharing links, and 'everyone' groups.
- Reduce to need-to-know — every sensitive store accessible only to people who need it for their work.
- Classify and label — mark sensitive documents (sensitivity labels) so they can be excluded from Copilot's reach.
- Anonymize what doesn't need identities — working copies, samples and training materials don't need real names. Consistent anonymization keeps them useful without the risk.
- An employee policy — what may be asked, what to do when an answer surfaces data that shouldn't be accessible, and who to report it to.
What about documents that leave the 365 environment?
Copilot is only part of the picture: employees also copy content into external tools — free chatbots, transcription services, slide generators. Those lack 365's organizational safeguards, and the rules of what never to paste into a chatbot apply in full. The one answer that covers both worlds: an anonymized document is safe in any tool — because there is nothing in it to expose.
This is also the honest framing for AI adoption across the business: internal assistants and external chatbots fail differently, but both can only reveal what the data actually contains.