← AI Assistants
D

Microsoft Copilot

Serious concerns
Microsoft · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
Manufacturer: Microsoft

The bottom line

Microsoft says you can opt out of Copilot training. But the privacy policy still allows using your data for "advertising," "product improvement," and "compliance." Opting out of training doesn't opt you out of collection. Researcher Arvind Narayanan found Microsoft's privacy controls create an "illusion of choice" — the data still flows, just under different legal justifications. Copilot is embedded in Windows, Edge, Office, and Bing — you can't use a modern Windows PC without encountering it. Microsoft's privacy policy discloses 801 advertising partners. The AI that reads your documents, emails, and search queries feeds into the same ecosystem that serves you ads. Microsoft doesn't disclose how many of those 801 partners receive Copilot-derived data.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
D
Parent company: Microsoft
PRISM participant since 2007, Telemetry across all products, SolarWinds + Storm-0558 breaches
3 structural risks · 15 products →
Spying
2/4 MODERATE
Is someone spying on me?
Data Sharing
4/4 EXTREME
Who gets my data?
Security
4/4 EXTREME
Is it actually secure?
Honesty
4/4 EXTREME
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
Privacy-respecting alternatives
Claude
Less aggressive on training data retention, no persistent memory by default
Paid for full features, smaller ecosystem than ChatGPT
Easy switch
See report →
13Contradictions
0Critical
12High
1Medium
17Sources
Findings by concern
Spying 2/4 MODERATE 1 finding
⚡ highfirmware analysis vs regulatory findings
Microsoft was the first company on the NSA's PRISM slides in 2007. Now it's embedded AI into Windows, Office, Edge, and Outlook. Copilot reads your documents, summarises your emails, and attends your meetings. Microsoft has never published a transparency report specific to Copilot data requests. The largest surveillance partner in tech history now has an AI reading your work.

What they claim: Copilot data is handled securely.

What we found: US jurisdiction (FISA, NSLs). 18-month retention. Human review. PRISM first. No Copilot-specific transparency report.

Data Sharing 4/4 EXTREME 4 findings
⚡ highpolicy claims vs firmware analysis
Microsoft says you can opt out of Copilot training. But the privacy policy still allows using your data for "advertising," "product improvement," and "compliance." Opting out of training doesn't opt you out of collection. Researcher Arvind Narayanan found Microsoft's privacy controls create an "illusion of choice" — the data still flows, just under different legal justifications.

What they claim: Users can opt out of Copilot training.

What we found: Consumer: training by default. Opt-out excludes training but NOT product improvements, advertising, safety, compliance. Human reviewers. 18-month retention. Files 30 days.

⚡ highfirmware analysis vs policy claims
Copilot is embedded in Windows, Edge, Office, and Bing — you can't use a modern Windows PC without encountering it. Microsoft's privacy policy discloses 801 advertising partners. The AI that reads your documents, emails, and search queries feeds into the same ecosystem that serves you ads. Microsoft doesn't disclose how many of those 801 partners receive Copilot-derived data.

What they claim: Copilot enhances productivity while respecting privacy.

What we found: In Windows, Edge, M365. Same infrastructure: Outlook (801 partners), DiagTrack, Bing. PRISM first (2007). Difficult to avoid on Windows.

⚡ highprivacy policy vs regulatory findings
Microsoft promised enterprise customers their data stays in-country — a critical commitment for government and regulated industries in 15 countries. Then in January 2026 they quietly added Anthropic as a subprocessor, and Anthropic's models are explicitly excluded from EU data boundary promises and in-country processing commitments. Your data was supposed to stay in Australia or Germany or the UK. Now it might be processed by a different company's AI, in a different country, under different rules. Microsoft's own timeline for actually delivering in-country processing keeps slipping.

What they claim: Microsoft says enterprise Copilot data is not used to train foundation models and respects data residency commitments

What we found: Starting January 7, 2026, Anthropic became a subprocessor for Microsoft 365 Copilot. Anthropic models are explicitly out of scope for the EU Data Boundary and in-country LLM processing commitments. Enterprise data processed by Anthropic models may leave the promised geographic boundaries. Microsoft's in-country processing expansion for 15 countries is still being "refined" as of April 2026, with timelines slipping.

⚫ mediumpolicy claims vs regulatory findings
Enterprise Copilot promises your data stays private. Consumer Copilot feeds into Microsoft's advertising and product improvement pipeline. Same product, same name, different rules. If your employer pays, you get privacy. If you use the free version at home, you get data collection. Microsoft doesn't make this distinction obvious — you have to read the enterprise agreement to know the difference.

What they claim: Microsoft protects all Copilot users equally.

What we found: Enterprise M365: no training. Consumer: training + review + retention + ads. Three privacy tiers by payment level.

Security 4/4 EXTREME 5 findings
⚡ highmarketing vs third party research
Microsoft disclosed three critical security holes in Copilot on May 7, 2026. One was a command injection bug in Edge's Copilot Chat scored 7.5 out of 10. In companies where Copilot can see everything — which is the default — an attacker could have extracted trade secrets, confidential emails, and internal records through the AI assistant Microsoft told everyone to trust.

What they claim: Microsoft markets Copilot as a secure AI assistant integrated across Microsoft 365 with enterprise-grade data protection.

What we found: On May 7, 2026, Microsoft disclosed three critical vulnerabilities in Copilot: CVE-2026-26129 (information disclosure in Business Chat), CVE-2026-26164 (information disclosure), and CVE-2026-33111 (command injection in Edge Copilot Chat, CVSS 7.5). In environments with broad data access, impact could include exposure of intellectual property and confidential communications.

⚡ highmarketing claim vs third party research
Microsoft is turning Copilot into a super app that connects to everything — HubSpot, Canva, Notion, Moody's, your company files, your email, your meetings. Every connection is a new door. OWASP was so alarmed by AI agents like this that they published a dedicated top 10 risk list in 2026. Microsoft's own security team keeps finding the same problems: agents shared with everyone, data exposed without a password, AI running with more privileges than it should have. They're building the world's most connected AI while their own researchers keep finding holes in the walls.

What they claim: Microsoft positions Copilot as a trusted "super app" — a single workspace with expanding data access via federated connectors to HubSpot, Canva, Notion, and other platforms

What we found: Every expansion of Copilot's data access multiplies the attack surface. OWASP published a dedicated top 10 for agentic AI systems in 2026 covering risks like unsafe tool invocation and privilege escalation across LLM trust boundaries. Microsoft's own security research found agents shared too broadly, data exposed without authentication, agents running with excessive privileges, and credentials stored directly in agent definitions.

⚡ highmarketing vs regulatory
Three high-severity vulnerabilities in Microsoft Copilot, patched in May 2026. Any of them could have let an attacker pull sensitive company data through the AI assistant. The tool marketed as your enterprise productivity partner was a potential data leak waiting to happen.

What they claim: Microsoft positions M365 Copilot as a secure enterprise AI assistant

What we found: Microsoft disclosed and patched three high-severity information disclosure vulnerabilities (including CVE-2026-26129) in M365 Copilot and Copilot Chat in Edge on May 7, 2026. The vulnerabilities could allow unauthorised disclosure of sensitive organisational data over a network.

⚡ highmarketing vs third party research
A security firm showed that one click on a link could make Microsoft Copilot silently hand over your files, home address, and vacation plans to an attacker. The trick: send two requests — safety checks only applied to the first one. No special software needed. Microsoft patched it, but the class of attack persists.

What they claim: Microsoft markets Copilot as a secure AI assistant

What we found: In January 2026, Varonis Threat Labs disclosed "Reprompt" — an attack against Microsoft Copilot Personal exploiting the URL q parameter to auto-execute prompts. A double-request technique bypassed safety guardrails. Could extract files accessed, home address, and vacation plans with a single click. No plugins or permissions required. Patched January 14, 2026.

⚡ highmarketing vs regulatory
Microsoft says Copilot is secure enough for the world's largest organisations. The U.S. House of Representatives disagreed — they banned it for congressional staff because they couldn't trust it not to leak sensitive data to the cloud.

What they claim: Microsoft positions Copilot as enterprise-grade and secure enough for government use

What we found: The U.S. House of Representatives banned congressional staff from using Microsoft Copilot due to concerns about data security and the risk of leaking House data to unauthorised cloud services.

Honesty 4/4 EXTREME 3 findings
⚡ highmarketing vs app
Microsoft Copilot just got a redesign. Now it reads your emails, files, chats, and meetings all at once — not when you ask, but constantly. That draft you haven't sent? Copilot read it. That Teams message to your colleague about the boss? Copilot summarised it. Microsoft calls this "a new design." It's actually the end of any boundary between your work and Microsoft's AI.

What they claim: Microsoft positions Copilot as an assistant that helps with the task at hand

What we found: Copilot's new design pulls from emails, files, chats, and meetings inline — all at once, all the time. It no longer waits for you to ask about a specific document. It proactively reads across your entire Microsoft 365 workspace to surface suggestions. Your private draft, your Teams DM, your calendar — all fair game for AI summarisation.

⚡ highpolicy vs regulatory
Microsoft's Copilot ignored confidentiality labels on emails for a month in early 2026 — the second time in eight months it failed to keep secrets secret. The European Parliament's response was immediate: they disabled Copilot on all 8,000 of their devices. When the people who write privacy laws won't trust your AI with their own emails, that tells you everything.

What they claim: Microsoft claims Copilot respects sensitivity labels and data loss prevention (DLP) policies to protect classified information.

What we found: A code defect in Microsoft 365 Copilot bypassed sensitivity labels on Outlook emails for approximately four weeks in early 2026, exposing confidential content in Sent Items and Drafts — the second such failure in eight months. The European Parliament responded by disabling AI-powered features across 8,000 employee devices on February 17, 2026.

⚡ highmarketing vs third party research
Companies label emails "Confidential" and trust Microsoft's security tools to keep them sealed. For weeks in early 2026, a bug let Copilot read and summarise those confidential emails anyway — bypassing every data loss prevention policy the company had set. Microsoft wouldn't say how many businesses were exposed.

What they claim: Microsoft markets Copilot as enterprise-ready with data loss prevention controls that respect confidentiality labels

What we found: Microsoft confirmed bug CW1226324 in February 2026 caused Copilot Chat to read and summarise emails marked with confidentiality labels, bypassing customers' data loss prevention policies for weeks. Microsoft would not disclose how many customers were affected. Enterprises trusting DLP labels had confidential content surfaced by the AI without authorisation.

Latest Risks & Threats
New developments that compound existing privacy concerns. 1 active threat.
THREAT Copilot Reads Your Documents 🤖 Ai Launched 2024-01-15
Microsoft embedded Copilot AI into Word, Excel, PowerPoint, Outlook, Teams, and Windows itself. It reads your emails, summarizes your meetings, and drafts responses using your data. Microsoft 365 Copilot costs $30/user/month and processes everything through Microsoft servers. Your employer pays for AI to read your work — and Microsoft keeps the training signal. The same company caught reading Outlook emails to target ads now has an AI that reads everything.
Sources
What happened to real people
Documented incidents involving Microsoft products and user data.
First PRISM participant (2007). 31% of US legal demands come with secrecy orders — 1,974 gag orders in H1 2025 alone. Users never told their data was demanded. [source]
Storm-0558: Chinese hackers used a stolen Microsoft signing key to access US government officials' email accounts. Microsoft's own infrastructure was the attack vector. [source]
What your data is worth to governments
Microsoft complied with 6,288 government data requests in H1 2025. That's 31% of demands include secrecy orders. Microsoft has been a confirmed PRISM participant since 2007. Under this programme, the NSA collects stored communications. The company is legally prohibited from telling you. Jurisdiction: US (CLOUD Act, FISA Section 702, Patriot Act).
Documented: First PRISM participant (2007). 31% of US legal demands come with secrecy orders — 1,974 gag orders in H1 2025 alone. Users never told their data was demanded.
Documented: Storm-0558: Chinese hackers used a stolen Microsoft signing key to access US government officials' email accounts. Microsoft's own infrastructure was the attack vector.
What is PRISM? · What is the CLOUD Act? · Transparency report
Sources