We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
All AI tools
Microsoft Copilot

Microsoft Copilot

Microsoft Corporation

Low riskProductivityHow we rate

Short answer

Short answer: Microsoft 365 Copilot is enterprise-safe for teams already on M365 — it stays inside your tenant's compliance boundary and doesn't train on your data. The free consumer Copilot is a different product with consumer terms that trains by default.

At a glance

Vendor / legal entity
Microsoft Corporation
Headquarters
🇺🇸 Redmond, US
Category
Productivity
Ownership / jurisdiction
US public company (Microsoft Corporation), Redmond, Washington.
Trains on your data?
On by default — opt-out available
Data hosting & residency
Microsoft 365 Copilot is an EU Data Boundary service and honours your existing M365 tenant data-residency commitments. (Note: some model sub-processors may sit outside the EUDB — check current Microsoft documentation.)
Sub-processors
Sub-processors are documented via Microsoft (per-model pages on learn.microsoft.com; full list on the Trust Center).
Enterprise tier
M365 Copilot inherits your tenant's compliance boundary (EU Data Boundary where configured), SSO via Entra ID, and the Microsoft Products & Services DPA. The free consumer Copilot has consumer terms.
Certifications
ISO 27001 · ISO 42001 · SOC 1/2/3 · ISO 27017/27018/27701 · HIPAA (BAA) · GDPR

Why this rating

Low risk

Microsoft 365 Copilot runs inside your tenant: prompts, responses and Graph data are not used to train foundation LLMs, it's an EU Data Boundary service, governed by Microsoft's DPA, with a very broad certification set (ISO 27001, ISO 42001, SOC 1/2/3, HIPAA). The separate free consumer Copilot trains by default with an opt-out. Low for the M365 product; the consumer app is the caveat.

How we rate

What it is

Microsoft 365 Copilot runs inside your tenant and inherits your existing Microsoft compliance commitments — data-residency (including the EU Data Boundary), a DPA, and no training on your tenant data. That makes it one of the lower-risk options for organisations already on M365. Note the separate free consumer Copilot, which carries consumer terms and trains on conversation activity by default.

Legal & compliance examples

How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.

High riskEU AI Act — Annex III(4) high-risk · Art. 5(1)(f) prohibited

Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.

Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.

These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.

Check your EU AI Act risk class →

Frequently asked questions

Is Microsoft 365 Copilot safe for work?

Yes — it inherits your M365 tenant's compliance boundary, DPA, and data-residency (EU Data Boundary), and does not train on your data. Confirm you mean M365 Copilot, not the free consumer Copilot.

Does Copilot train on your data?

M365 Copilot does not use your tenant data to train foundation LLMs. The free consumer Copilot uses conversation activity for training by default — you can opt out.

How do I govern Copilot use at work?

For the enterprise product, use Microsoft's admin controls; for the consumer Copilot and every other browser AI tool, Qadar AI Shield gives you discovery, redaction, and an allow-list across the board.

Sources

Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.

  • •M365 Copilot: no training, EU Data Boundary, DPA, certifications
  • •Consumer Copilot training & opt-out

Govern this tool

Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.

Book a demoSee how Shield Web governs AI

Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·