Where does Copilot send your data?

Your prompts and files stay inside your organisation's own area of Microsoft's cloud. Web searches and connected add-ons do not.

Microsoft changes Copilot monthly, including where the data goes.

Microsoft 365 Copilot reads your prompts and your files inside your organisation’s own separated area of Microsoft’s cloud, which Microsoft calls your tenant, and it does not use any of that content to train the model underneath. That one fact is what most people get wrong, in both directions. Some assume it is learning from their documents. Others assume “inside the tenant” means nothing ever leaves their control. Neither is right.

What stays inside

Your prompts, the mail and files Copilot opens in order to answer you, and the answers it writes are all handled inside your Microsoft 365 service boundary: the contractual and technical line drawn around your tenant, covered by the same commitments as the rest of your organisation’s data. By default, your business content is not fed back into model training.

Copilot also inherits your permissions exactly. It will only show a person content that person could already have opened for themselves. That is a real protection with a well-known failure mode: it inherits over-sharing just as faithfully, which is what the rollout guide spends most of its time on.

What crosses the line

The model runs on infrastructure Microsoft manages, so your prompt and whatever content Copilot gathered to answer it are sent there to be processed. They do not stay on your laptop. Web searches leave the tenant by design, because leaving is what a web search is, though what leaves is smaller than people assume: a query of a few words that Copilot writes from your prompt, sent to Bing with your name and your organisation’s identifiers removed. Microsoft’s terms say those queries are not used for advertising or to train its models. And any plugin or agent your organisation has connected, meaning an add-on that lets Copilot reach a system outside Microsoft 365, sends data to that provider under that provider’s terms rather than under Microsoft’s. Microsoft’s federated connectors, generally available since September 2026, work the same way: they query the outside system live, signed in as you.

The boundary protects you from training and from other tenants. It does not mean the data never moves. It means the data moves under contract, not into a public model.

”Copilot” is no longer one model

Microsoft now offers a choice of underlying model in some apps, including models from OpenAI and from Anthropic. Excel is the clearest example, where either can be selected. The product has a new name too: Microsoft’s documentation now calls the paid licence Microsoft Copilot, and says the rename brings “no changes to security, compliance, and privacy”.

Most of the commitments above hold whichever company built the model. Anthropic works as what Microsoft calls a subprocessor, a supplier handling data on Microsoft’s behalf under Microsoft’s own contract, so the no-training promise still applies when Claude does the work. The exception is any model Microsoft labels “Anthropic models with Data Retention”, which runs under Anthropic’s own terms and has to be switched on separately. And one commitment does not carry over at all: Anthropic’s models are excluded from Microsoft’s EU Data Boundary, its promise to keep European customers’ data processed in Europe, and from in-country processing commitments. That is why Microsoft switches them off by default for organisations in the EU, EFTA and UK. Newer organisations there are the catch: a separate setting turns Claude on by default in Word, Excel and PowerPoint for tenants created after 25 March 2026.

Two more things change. Answers can differ between models for the same prompt, so “Copilot said” has become an ambiguous thing to say in a meeting. And if your organisation’s AI policy names one model provider, it may quietly have stopped being accurate.

What you can check, and what you cannot

One claim on this page you can test yourself, in about a minute. Ask Copilot for something out of a file you know you should not have access to. If it produces it, the sharing on that file is wrong, and that is worth reporting to whoever owns it.

The rest is not visible from where you sit. Only whoever administers Microsoft 365 where you work can see which model providers are switched on for your organisation, which plugins and connectors have been approved, whether web search is turned on, and what your tenant’s data-handling terms actually say. Those settings live in the Microsoft 365 admin centre, the control panel for the whole organisation; the model question sits under a setting called “AI providers operating as Microsoft subprocessors”, which is the phrase to ask about. If you are the administrator, read them there rather than in a blog post, because the specifics change monthly, and count every connected plugin as its own path out of the boundary.

Why this matters for governance

Knowing where the line falls is the prerequisite for the harder questions: data loss prevention, the shadow-AI problem of colleagues using tools with no boundary at all, and rolling Copilot out without turning years of quiet over-sharing into a working search engine. The boundary described here belongs to the paid Microsoft 365 Copilot. If you are not certain that is the one you have, start with which Copilot is which.

Sources

Everything above was checked against these on 26 Sept 2026. Providers change things without notice. If a detail matters to a decision, follow the link.

  1. Data, privacy, and security for Microsoft CopilotMicrosoft Learn
  2. Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot ChatMicrosoft Learn
  3. Anthropic models in Microsoft Online ServicesMicrosoft Learn
  4. Enterprise data protection in Microsoft Copilot and Microsoft Copilot ChatMicrosoft Learn
  5. Release notes for Microsoft 365 CopilotMicrosoft Learn

Search