Let's Connect
Platform privacy

Does Microsoft Copilot Use Your Data for Training?

Microsoft Copilot data use depends on the product. Compare Microsoft 365 Copilot, Copilot Chat, enterprise data protection, agents, and web grounding.

4 min read

The answer depends on which Microsoft Copilot product and protection apply. Microsoft 365 Copilot and Microsoft 365 Copilot Chat with enterprise data protection are not the same governance context as a consumer experience, an agent, a connector, or a third-party Copilot-branded product.

Last verified: August 13, 2026. Microsoft products and documentation change frequently. Confirm the current product, license, tenant settings, agent terms, and official documentation before making a decision.

The direct answer for Microsoft 365 organizational use

Microsoft says prompts, responses, and data accessed through Microsoft Graph in Microsoft 365 Copilot and Microsoft 365 Copilot Chat with enterprise data protection are not used to train foundation models.

Microsoft also says prompts and responses can be logged and retained for audit, eDiscovery, and Microsoft Purview capabilities under enterprise data protection. “Not used to train foundation models” does not mean “not processed, retained, logged, or governed.” Those are separate questions.

Microsoft 365 Copilot

Microsoft 365 Copilot can use organizational context and Microsoft Graph data that the user is permitted to access. Existing permissions therefore matter. Copilot can make overshared or poorly governed information easier to find without changing the underlying permission.

Before rollout, review identity, access, sharing, data-loss prevention, labels, retention, audit, eDiscovery, and which apps or features are enabled. Employees need to understand that Copilot follows their access context; it is not a substitute for sound information governance.

Microsoft 365 Copilot Chat

Copilot Chat with enterprise data protection operates within the Microsoft 365 service boundary. Microsoft states that prompts and responses are not used to train underlying foundation models.

Web grounding adds another data flow. Microsoft explains that generated web search queries are sent to Bing with user and tenant identifiers removed, handled separately, and not used to train foundation large language models. Organizations should still teach employees that a prompt can be transformed into a shorter web query and to avoid including unnecessary sensitive context.

Agents, connectors, and third-party services

An agent may access additional knowledge, invoke tools, or take actions. Microsoft advises customers to review the privacy statement and terms for agents because data handling can depend on the agent and connected service.

The same caution applies to plugins, connectors, Copilot Studio components, and third-party products that use the Copilot name. Record what information each component can access, where it sends data, which actions it can perform, and who owns approval.

Training data is not the only risk

A strong rollout also answers:

  • which Copilot product and license are approved
  • which users and groups have access
  • what Microsoft 365 content they can retrieve
  • whether permissions and sharing are appropriate
  • which agents, connectors, and web grounding features are enabled
  • how prompts and responses are retained and audited
  • what outputs require human review
  • which actions require approval
  • how incidents and oversharing are reported

These choices determine whether Copilot fits the organization's workflow and risk tolerance.

What employees should check

Teach employees to verify:

  1. They are signed into the approved organizational account.
  2. The Copilot surface displays the expected enterprise protection.
  3. The information is appropriate for the intended workflow.
  4. Any linked file or message has the right permissions and audience.
  5. The answer is supported by the cited organizational or web sources.
  6. A human with authority reviews high-impact content or actions.
  7. Any agent or connector is approved for the data and action involved.

Role-specific examples make the rules usable. A meeting summary, customer proposal, HR document, financial analysis, and agent-triggered update should not all use the same review standard.

What administrators and governance teams should document

Maintain a current product record with the tenant, license, eligible users, enterprise data protection status, enabled apps, Graph and connector access, agents, web grounding, retention, audit, eDiscovery, DLP, support owner, and last review date.

Reassess when permissions, connectors, agents, models, terms, or use cases change. A one-time platform review does not cover every future configuration.

Practical takeaway

For Microsoft 365 Copilot and Copilot Chat under enterprise data protection, Microsoft says prompts, responses, and Microsoft Graph data are not used to train foundation models. The organization must still manage permissions, retention, audit, web grounding, agents, connected services, human review, and employee behavior.

Use the exact product name in policy and training. “Copilot” alone is too broad to define the data rules.

Where to go next

Continue into the commercial pages and adjacent guides that support this topic.

Sources referenced

What informed this guide

Selected external resources used for current market and platform context.

Get started

Turn the framework into an operating plan.

AJAIA helps organizations connect AI strategy, workflow design, governance, implementation, and workforce adoption.

Talk to AJAIA