Microsoft says you can opt out of Copilot training. But the privacy policy still allows using your data for "advertising," "product improvement," and "compliance." Opting out of training doesn't opt you out of collection. Researcher Arvind Narayanan found Microsoft's privacy controls create an "illusion of choice" — the data still flows, just under different legal justifications. Copilot is embedded in Windows, Edge, Office, and Bing — you can't use a modern Windows PC without encountering it. Microsoft's privacy policy discloses 801 advertising partners. The AI that reads your documents, emails, and search queries feeds into the same ecosystem that serves you ads. Microsoft doesn't disclose how many of those 801 partners receive Copilot-derived data.
What they claim: Copilot data is handled securely.
What we found: US jurisdiction (FISA, NSLs). 18-month retention. Human review. PRISM first. No Copilot-specific transparency report.
What they claim: Users can opt out of Copilot training.
What we found: Consumer: training by default. Opt-out excludes training but NOT product improvements, advertising, safety, compliance. Human reviewers. 18-month retention. Files 30 days.
What they claim: Copilot enhances productivity while respecting privacy.
What we found: In Windows, Edge, M365. Same infrastructure: Outlook (801 partners), DiagTrack, Bing. PRISM first (2007). Difficult to avoid on Windows.
What they claim: Microsoft says enterprise Copilot data is not used to train foundation models and respects data residency commitments
What we found: Starting January 7, 2026, Anthropic became a subprocessor for Microsoft 365 Copilot. Anthropic models are explicitly out of scope for the EU Data Boundary and in-country LLM processing commitments. Enterprise data processed by Anthropic models may leave the promised geographic boundaries. Microsoft's in-country processing expansion for 15 countries is still being "refined" as of April 2026, with timelines slipping.
What they claim: Microsoft protects all Copilot users equally.
What we found: Enterprise M365: no training. Consumer: training + review + retention + ads. Three privacy tiers by payment level.
What they claim: Microsoft markets Copilot as a secure AI assistant integrated across Microsoft 365 with enterprise-grade data protection.
What we found: On May 7, 2026, Microsoft disclosed three critical vulnerabilities in Copilot: CVE-2026-26129 (information disclosure in Business Chat), CVE-2026-26164 (information disclosure), and CVE-2026-33111 (command injection in Edge Copilot Chat, CVSS 7.5). In environments with broad data access, impact could include exposure of intellectual property and confidential communications.
What they claim: Microsoft positions Copilot as a trusted "super app" — a single workspace with expanding data access via federated connectors to HubSpot, Canva, Notion, and other platforms
What we found: Every expansion of Copilot's data access multiplies the attack surface. OWASP published a dedicated top 10 for agentic AI systems in 2026 covering risks like unsafe tool invocation and privilege escalation across LLM trust boundaries. Microsoft's own security research found agents shared too broadly, data exposed without authentication, agents running with excessive privileges, and credentials stored directly in agent definitions.
What they claim: Microsoft positions M365 Copilot as a secure enterprise AI assistant
What we found: Microsoft disclosed and patched three high-severity information disclosure vulnerabilities (including CVE-2026-26129) in M365 Copilot and Copilot Chat in Edge on May 7, 2026. The vulnerabilities could allow unauthorised disclosure of sensitive organisational data over a network.
What they claim: Microsoft markets Copilot as a secure AI assistant
What we found: In January 2026, Varonis Threat Labs disclosed "Reprompt" — an attack against Microsoft Copilot Personal exploiting the URL q parameter to auto-execute prompts. A double-request technique bypassed safety guardrails. Could extract files accessed, home address, and vacation plans with a single click. No plugins or permissions required. Patched January 14, 2026.
What they claim: Microsoft positions Copilot as enterprise-grade and secure enough for government use
What we found: The U.S. House of Representatives banned congressional staff from using Microsoft Copilot due to concerns about data security and the risk of leaking House data to unauthorised cloud services.
What they claim: Microsoft positions Copilot as an assistant that helps with the task at hand
What we found: Copilot's new design pulls from emails, files, chats, and meetings inline — all at once, all the time. It no longer waits for you to ask about a specific document. It proactively reads across your entire Microsoft 365 workspace to surface suggestions. Your private draft, your Teams DM, your calendar — all fair game for AI summarisation.
What they claim: Microsoft claims Copilot respects sensitivity labels and data loss prevention (DLP) policies to protect classified information.
What we found: A code defect in Microsoft 365 Copilot bypassed sensitivity labels on Outlook emails for approximately four weeks in early 2026, exposing confidential content in Sent Items and Drafts — the second such failure in eight months. The European Parliament responded by disabling AI-powered features across 8,000 employee devices on February 17, 2026.
What they claim: Microsoft markets Copilot as enterprise-ready with data loss prevention controls that respect confidentiality labels
What we found: Microsoft confirmed bug CW1226324 in February 2026 caused Copilot Chat to read and summarise emails marked with confidentiality labels, bypassing customers' data loss prevention policies for weeks. Microsoft would not disclose how many customers were affected. Enterprises trusting DLP labels had confidential content surfaced by the AI without authorisation.