.png)
Artificial Intelligence
Does Microsoft Copilot use company data to train AI?
By Steve Harper | 8 min read | Last updated:
12 August 2026 at 08:13:29

TL;DR
Microsoft states that prompts, Copilot responses and organisational data accessed through Microsoft Graph are not used to train the foundation language models behind Microsoft 365 Copilot.
However, Copilot still processes permitted business information to answer prompts. Copilot interactions may also be retained and available through Microsoft 365 security, audit, retention and compliance tools.
Businesses must therefore continue to manage permissions, sensitive information, employee usage and any third-party agents or connectors connected to Copilot.
Key Takeaways
Microsoft says Microsoft 365 Copilot does not use company prompts or Graph data to train foundation models.
Copilot still processes company information to produce relevant answers.
“Not used for training” does not mean prompts are never stored or governed.
Copilot respects the existing access permissions of the user.
Poor permissions can expose information to employees who already have unintended access.
Third-party agents, connectors and other AI products require separate review.
Businesses still need an AI usage and data-governance policy.
Do you know what company information Copilot could use?
IT Desk can review your Microsoft 365 permissions, data structure, security and Copilot configuration before rollout. We can help identify overshared information, define suitable use cases and give employees practical guidance for using AI safely.
Does Microsoft 365 Copilot train its AI on my company’s data?
According to Microsoft, no.
Microsoft states that the following are not used to train foundation large language models, including the models used by Microsoft 365 Copilot:
User prompts
Copilot’s responses
Organisational data accessed through Microsoft Graph
Microsoft Graph can provide Copilot with authorised context from services such as Outlook, Teams, SharePoint, OneDrive and other parts of Microsoft 365.
Copilot uses this context to answer the current user’s request. This process is known as grounding.
Grounding a response in company information is different from using that information to train the underlying foundation model.
What is the difference between processing and training data?
Processing means using information to carry out the current task.
For example, if an employee asks Copilot to summarise a document, Copilot needs to process that document to create the summary.
Training means using data to change or improve the underlying AI model so that it influences how the model responds in the future.
Microsoft 365 Copilot processes permitted organisational information to provide relevant results. Microsoft states that it does not use that information to train the foundation models.
This distinction matters because saying “Copilot uses company data” can mean several different things.
Activity | Does Microsoft 365 Copilot do this? |
Process a permitted document to summarise it | Yes |
Use permitted work data to answer a prompt | Yes |
Generate a response based on emails or meetings | Yes, where the user and feature have access |
Apply existing Microsoft 365 permissions | Yes |
Use prompts to train foundation models | Microsoft says no |
Use Graph-accessed company data to train foundation models | Microsoft says no |
Does Microsoft Copilot send company data to OpenAI?
Microsoft states that organisational data used with Microsoft 365 Copilot and Microsoft 365 Copilot Chat under enterprise data protection is not made available to OpenAI or used to train OpenAI’s models.
Microsoft 365 Copilot operates within Microsoft’s commercial data-protection and service commitments rather than as an employee directly entering information into a separate consumer AI account.
This does not mean every AI tool displaying the word “Copilot” has identical terms and controls. Businesses should identify the exact product, licence, account and data-protection arrangement being used.
Is Microsoft 365 Copilot the same as consumer Copilot?
No.
Microsoft provides several Copilot-branded experiences, including:
Microsoft 365 Copilot
Microsoft 365 Copilot Chat
Consumer Microsoft Copilot
Copilot features inside particular Microsoft products
Microsoft Copilot Studio
Custom agents and connected applications
The available data protection, organisational controls and terms can depend on:
Whether the user is signed in with a work or personal account
Whether enterprise data protection applies
Which Copilot service is being used
Whether a Microsoft 365 Copilot licence is assigned
Which agents, plugins or connectors are involved
Whether information is sent to another service
Businesses should not assume that a protection statement applying to Microsoft 365 Copilot automatically applies to every AI application an employee can access.
Does Copilot store employee prompts?
Copilot interactions may be stored and managed within the Microsoft 365 environment.
Depending on the service, licensing and configuration, prompts and responses may be subject to:
Audit
Retention
eDiscovery
Data-loss prevention
Communication compliance
Security investigation
Legal or regulatory requirements
This means “not used to train the foundation model” does not mean “immediately deleted” or “visible only to the employee”.
Employees should be informed that work-related Copilot activity may form part of the organisation’s managed business records.
Can Microsoft administrators see Copilot prompts?
Authorised administrators and compliance personnel may be able to search, investigate or govern Copilot interactions using supported Microsoft 365 tools, subject to their permissions and the organisation’s configuration.
This may be required for:
Security investigations
Data-loss prevention
Compliance monitoring
Legal discovery
Retention obligations
Investigation of inappropriate AI use
Access to this information should itself be restricted and governed. Administrators should not receive broader privileges than their role requires.
Can Copilot access confidential company information?
Copilot can use information the employee is already authorised to access, subject to the particular feature and context.
It does not create new access permission merely because a Copilot licence is assigned. However, Copilot can make existing information easier to find, summarise and combine.
This means an old permissions problem can become more visible after Copilot is introduced.
For example, an employee may already have access to:
A salary spreadsheet shared too widely
An old confidential project site
A folder inherited from a previous role
Sensitive meeting notes
An unrestricted HR document
A historic customer database export
The employee might never have discovered that information manually. Copilot may make it easier to surface if the user asks a relevant question.
The problem is not that Copilot has ignored permissions. The problem is that the existing permissions were too broad.
Our separate guide explaining whether Copilot can access all company files covers this in more detail. Add the link after that Quick Answer page is published.
Does Microsoft use Copilot data to improve the service?
Microsoft may use operational data and feedback to maintain, secure and improve its services under the applicable product terms and data-protection commitments.
This is not necessarily the same as using the contents of company prompts, responses and Microsoft Graph data to train foundation language models.
Businesses needing a precise understanding should review:
The current Microsoft Product Terms
Microsoft’s Data Protection Addendum
The Microsoft 365 Copilot privacy documentation
Their tenant configuration
Optional diagnostic and feedback settings
Any connected third-party services
Contractual, regulatory or highly sensitive deployments may require review by the organisation’s legal, compliance and data-protection teams.
What happens when Copilot uses web search?
Some Copilot experiences can use public web information to improve a response.
This may involve generating a web search query based on the employee’s prompt. Businesses should understand how web search is configured and avoid including unnecessary confidential information in prompts.
A user should not assume that every part of a sensitive prompt must be included simply because the AI tool operates within a business account.
Employees should provide the minimum information necessary for the task and follow the organisation’s AI policy.
What about Copilot agents and plugins?
Agents and connected applications can introduce additional data flows.
An agent may access:
SharePoint sites
Microsoft 365 information
Business applications
Customer databases
External websites
Third-party services
Custom knowledge sources
The agent may be governed by Microsoft’s commitments, a third party’s terms or a combination of both, depending on how it was built and connected.
Before enabling an agent, the business should check:
Who developed and published it
Which information it can access
What actions it can perform
Where data is processed
Whether information leaves Microsoft 365
Which privacy and retention terms apply
Whether administrators can monitor its activity
How access can be withdrawn
Whether users understand its limitations
Installing an agent should be treated as granting a new application access to business information—not merely adding a convenient Copilot feature.
Can employees put personal data into Microsoft Copilot?
The fact that foundation models are not trained on company prompts does not remove the organisation’s data-protection responsibilities.
Businesses must still consider:
Whether there is a lawful basis for processing personal information
Whether the use is necessary and proportionate
Whether sensitive information is involved
Whether the employee is using an approved account and tool
Whether retention and access are appropriate
Whether individuals need to be informed
Whether a data-protection impact assessment is required
Whether AI output will be used to make decisions about people
Employees should not paste personal, confidential or regulated information into Copilot simply because the training protection exists.
Is company data completely risk-free in Copilot?
No technology can make information completely risk-free.
The most significant practical risks may come from how the organisation configures and uses the platform, including:
Excessive SharePoint permissions
Poorly protected user accounts
Unmanaged devices
Sensitive data without labels
Unapproved agents
Employees entering unnecessary information
Inaccurate AI-generated answers
Weak retention and compliance processes
Lack of user training
No process for reviewing AI usage
Microsoft’s training commitment addresses an important concern, but it does not replace identity, access, data and device security.
What should a business check before using Copilot?
Before rollout, review:
The exact Copilot product and licence being introduced.
Microsoft 365 user and administrator security.
SharePoint, Teams and OneDrive permissions.
Sensitive and overshared information.
Retention, audit and compliance requirements.
Approved and prohibited use cases.
Agents, plugins and external connectors.
Employee training and prompt guidance.
Human review of AI-generated output.
Incident reporting and ongoing monitoring.
The business should also explain the distinction between consumer AI tools and approved work accounts so employees know where company information may be used.
Related Insights
So, why IT Desk?

Proactive & Reactive Support
In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.
Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

Award Winning
Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!
Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

Experienced & Certified
Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.
From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent
Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.
With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.
Innovative Solutions for Businesses
20+
Years of Experience
A legacy of excellence in digital solutions.
100%
Zero Carbon
Doing our part for the environment.
Certified by British Gas.
99.9%
Client Satisfaction Rate
Trusted by businesses across all sectors for superior service.
1200+
Projects Completed
Delivering cutting-edge solutions for a seamless digital future.












