AI Tool Risk Directory ← All 26 tools Verdict assessed 29 July 2026

Is Microsoft Copilot for M365 safe for work? Verdict: Approved

Approved

Microsoft Copilot for M365 is generally safe for workplace use on a corporate plan. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Approved. Microsoft states prompts, responses and Graph data are not used to train foundation LLMs, and the interaction stays inside a tenant your admins already govern. The biggest real risk is oversharing: Copilot surfaces whatever the user already has permission to see, so sloppy SharePoint permissions become very visible.

This verdict reflects Microsoft’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.

Microsoft Copilot for M365 at a glance

VendorMicrosoft
CategoryProductivity suite AI
Our tier verdictApproved (assessed 29 July 2026) — Microsoft states prompts, responses and Graph data are not used to train foundation LLMs, and the interaction stays inside a tenant your admins already govern. source
Trains on your data?No (per vendor terms)
No. Microsoft states that prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft 365 Copilot. source
Data retentionCopilot interaction history is stored in the tenant under the Microsoft 365 retention and eDiscovery policies your admins already control. source
Admin controlsFull tenant-level control: license assignment, Purview sensitivity labels, DLP, audit logging, retention policies. source
Compliance certificationsMicrosoft’s Copilot privacy documentation references ISO 27001, HIPAA and the ISO 42001 AI management standard for the service source
HIPAA / BAAYes — Microsoft states it enters into Business Associate Agreements with its covered-entity and business-associate customers for its enterprise products and services. Confirm that Copilot is in scope for your licence and configuration — a BAA covering Microsoft 365 is not automatically a decision about every feature you turn on. source

Does Microsoft 365 Copilot train on your data?

No. Microsoft states that prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft 365 Copilot.

Retention: Copilot interaction history is stored in the tenant under the Microsoft 365 retention and eDiscovery policies your admins already control.

Is Microsoft 365 Copilot HIPAA compliant?

Microsoft states it enters into Business Associate Agreements with its covered-entity and business-associate customers for its enterprise products and services. Confirm that Copilot is in scope for your licence and configuration — a BAA covering Microsoft 365 is not automatically a decision about every feature you turn on. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Comparing vendors on this specifically? See BAA status for all 26 tools →

Is Microsoft 365 Copilot SOC 2 certified?

Not from anything we could verify. Microsoft’s Copilot privacy documentation references ISO 27001, HIPAA and the ISO 42001 AI management standard for the service — but SOC 2 specifically was not among the documents we read on this check date. Ask for the current report under NDA rather than inferring it from the other certifications. A certification is also not a contract: it describes how Microsoft 365 Copilot runs its controls, not what your agreement with them permits.

Industry risk notes

Healthcare

HIPAA is the gate: Microsoft states it enters into Business Associate Agreements with its covered-entity and business-associate customers for its enterprise products and services. Confirm that Copilot is in scope for your licence and configuration — a BAA covering Microsoft 365 is not automatically a decision about every feature you turn on. Until a BAA is confirmed in writing, treat Microsoft Copilot for M365 as off-limits for anything containing PHI — patient names, appointment details, clinical notes, even "anonymized" summaries that could be re-identified.

Financial services

For SEC/FINRA-regulated firms the questions are recordkeeping and confidentiality: can communications through Microsoft Copilot for M365 be captured for books-and-records requirements, and do the data terms hold up in vendor due diligence? Full tenant-level control: license assignment, Purview sensitivity labels, DLP, audit logging, retention policies.

Legal & professional services

The privilege question comes first: entering client-confidential facts into any third-party AI service must be evaluated as a potential disclosure. Microsoft Copilot for M365’s no-training terms on corporate plans help, but confidentiality duties still require client-consent and matter-sensitivity judgment.

Primary sources

Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. All of them were read on 29 July 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.

Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.

Why the tier verdict is "generic": Approved is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies Microsoft Copilot for M365 and 25 other tools specifically for your industry, company size, and the data your team handles.

And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.

Frequently asked questions

Is Microsoft 365 Copilot safe for work?

Microsoft Copilot for M365 is generally safe for workplace use on a corporate plan. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Approved. Microsoft states prompts, responses and Graph data are not used to train foundation LLMs, and the interaction stays inside a tenant your admins already govern. The biggest real risk is oversharing: Copilot surfaces whatever the user already has permission to see, so sloppy SharePoint permissions become very visible.

Does Microsoft 365 Copilot train on your data?

No. Microsoft states that prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft 365 Copilot.

Is Microsoft 365 Copilot HIPAA compliant?

Microsoft states it enters into Business Associate Agreements with its covered-entity and business-associate customers for its enterprise products and services. Confirm that Copilot is in scope for your licence and configuration — a BAA covering Microsoft 365 is not automatically a decision about every feature you turn on. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Is Microsoft 365 Copilot SOC 2 certified?

Not from anything we could verify. Microsoft’s Copilot privacy documentation references ISO 27001, HIPAA and the ISO 42001 AI management standard for the service — but SOC 2 specifically was not among the documents we read on this check date. Ask for the current report under NDA rather than inferring it from the other certifications. A certification is also not a contract: it describes how Microsoft 365 Copilot runs its controls, not what your agreement with them permits.

What tier should Microsoft Copilot for M365 be in an AI acceptable use policy?

We classify Microsoft Copilot for M365 as Approved for a typical 50–500 person company, assessed 29 July 2026. Microsoft states prompts, responses and Graph data are not used to train foundation LLMs, and the interaction stays inside a tenant your admins already govern. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.

New to the topic? Start with what shadow AI is — definition, examples and risks, then measure your own exposure with the shadow AI scorer.

Your team is using Microsoft 365 Copilot. Does your AI policy cover it?

Most policies name a handful of tools and go stale the month after they are written. Two ways to find out where yours stands: check an existing policy for gaps in 30 seconds, or generate a policy that classifies Microsoft 365 Copilot by name — free preview, no account. Starting from scratch? The free 14-section AI acceptable use policy template is the document itself, ungated.

Get the full policy kit

$79 one-time

A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies Microsoft Copilot for M365 and 25 other tools for your company, industry, and data. Generated in about 10 minutes.

Generate my policy kit →

Keep it current with Monitor

$149/mo

We re-check vendor terms monthly and alert you when Microsoft Copilot for M365’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.

See Monitor plan →

Work out where Microsoft 365 Copilot leaves you exposed

Compare with productivity-suite and business-platform AI

Already have an AI policy? Check it for gaps in 30 seconds →