Back to Insights
AI & Governance

Two Copilots, One Name: What Microsoft Commits To When Staff Use Copilot Without a License

Prepared by DP3  ·  Published August 2026

Table of Contents
  1. The Question
  2. Two Copilots, One Name
  3. What Applies With a Work Account
  4. Does OpenAI See It? Does Anyone Read It?
  5. The One Carve-Out: Web Search
  6. What Actually Binds Microsoft
  7. The Consumer Side
  8. Drafting the Engagement Letter
  9. Where DP3 Fits
Share

The Question

A client came to us recently with a question that had come up while their attorneys were revising the AI section of the firm’s engagement letter. It went roughly like this:

A while back we discussed the privacy of information entered into Copilot by users who don’t have a Copilot license — people who just open the Copilot app on their computer and start asking questions or entering data. You told us that anything they enter stays private to them and to our tenant, and isn’t used to train the model. Do you have documentation from Microsoft confirming that? Our attorneys would like to see something from Microsoft directly.

It is exactly the right question to ask, and it is one we hear in some form from nearly every firm that has started letting people use AI tools before it has finished writing down the rules for them. The short answer is yes — Microsoft documents this, in public, in writing, and in more than one place.

What follows is that documentation, laid out without the Microsoft vocabulary. We have translated the terminology deliberately, because most of the confusion in this area comes from Microsoft using one word for two genuinely different products.

Two Copilots, One Name

Microsoft offers a consumer version of Copilot and a business version. They look nearly identical on screen. They share a name. They operate under completely different terms.

Which one a person is in is determined by the account they sign in with — not by which computer they happen to be sitting at, and not by whether the firm bought anything extra.

If someone signs in with their work email address, they are in the business environment, and the firm’s contract with Microsoft governs. If someone signs in with a personal Microsoft account — the kind you would set up for an Xbox or a Hotmail address — they are in the consumer environment, and Microsoft’s public consumer terms govern instead. Microsoft is explicit about the divide, describing the second one plainly: “Microsoft Copilot is for personal use.” [6] Microsoft Learn Manage Microsoft 365 Copilot Chat View source ↗

Microsoft renamed the work experience to make the split visible. Its own documentation notes that since January 2025, “the Copilot experience for work and education no longer shares the same name as the Copilot experience for personal use,” and lists the entry points for each side separately. [6] Microsoft Learn Manage Microsoft 365 Copilot Chat View source ↗ The work side is reached through the Microsoft 365 Copilot app and copilot.cloud.microsoft. The personal side lives at copilot.microsoft.com and a handful of Bing addresses.

The practical test

Forget the icon and the app name. Ask one question: which account is signed in? A work account puts the user under the firm’s contract. A personal account does not. Everything else in this article follows from that single fact.

There is a second layer of protection here that catches the specific scenario in the question above — a user opening “the Copilot app on their computer.” Microsoft’s admin documentation states that the standalone consumer app “doesn’t work for commercial users authenticating with a Microsoft Entra account” at all. [6] Microsoft Learn Manage Microsoft 365 Copilot Chat View source ↗ An Entra account is the work account your people sign in with every morning. So a staff member who tries to use the consumer app with firm credentials is not quietly landing in the consumer environment — they are being redirected to the work one.

What Applies With a Work Account

Microsoft calls the business-side protection enterprise data protection. In practical terms it means Microsoft handles what your people type the same way it already handles the firm’s email and documents in Microsoft 365 — as the firm’s data, held under the firm’s contract, with Microsoft acting as a vendor processing it on your instructions rather than using it for its own purposes.

Microsoft draws that comparison itself, stating that prompts and responses “are protected by the same contractual terms and commitments widely trusted by our customers for their emails in Exchange and their files in SharePoint.” [1] Microsoft Learn Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat View source ↗ That is a useful sentence for counsel, because it anchors a new product to a set of obligations the firm already accepted years ago.

The specific commitment the attorneys asked about is stated by Microsoft under its own heading: “Your data isn’t used to train foundation models.” [1] Microsoft Learn Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat View source ↗ Training the model is the thing people actually worry about — the fear that information typed into an AI tool gets absorbed into the product and could surface in someone else’s answer later. Microsoft says that does not happen here, and repeats it in its Copilot Chat FAQ: “No, prompts and responses aren’t used to train foundation models under enterprise data protection.” [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗

The trigger is the sign-in, not the license

This is the part that answers the original question most directly. Microsoft states that Copilot Chat “uses your work or school account for authentication and automatically provides enterprise data protection when you’re signed in with that account.” [2] Microsoft Support Data protection when using Microsoft 365 Copilot Chat for work or school View source ↗

Nothing in that sentence is conditioned on holding a paid Copilot license. Microsoft is explicit elsewhere that “Copilot Chat is automatically included and available to organizations that have a Microsoft 365 subscription,” [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗ and that it “offers enterprise data protection (EDP) to users who sign in with a Microsoft Entra account — no IT admin action is required.” [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗ The eligible subscriptions are listed by name and cover the ordinary Business Standard, Business Premium, E3, and E5 plans most firms already hold. [6] Microsoft Learn Manage Microsoft 365 Copilot Chat View source ↗

So the firm’s existing Microsoft 365 subscription is what makes Copilot Chat available and protected. The paid Copilot add-on buys additional capability on top of that — principally the ability to reason over the firm’s own documents, email, and calendars through Microsoft Graph. Microsoft is clear that without the add-on, “Copilot Chat can’t access the user’s shared enterprise data, individual data, or external data indexed via Microsoft Graph connectors.” [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗

Write the commitment against the account, not the license

If your engagement letter says something like “staff with Copilot licenses use it under enterprise terms,” it is narrower than reality and will age badly the first time someone without a license opens the app. The protection attaches to the work account. Draft it that way.

Does OpenAI See It? Does Anyone at Microsoft Read It?

These are the two follow-on questions we get almost every time, and both have direct answers in Microsoft’s documentation.

The other company

Microsoft’s AI is built partly on technology from other model developers, which reasonably prompts the question of whether those companies see the data. Microsoft addresses it head-on in its FAQ: “No, your data is not available to OpenAI or used to train OpenAI models.” [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗

One nuance worth knowing while you are drafting: the roster of model providers is not fixed. Microsoft now names both OpenAI and Anthropic as subprocessors within Microsoft 365 Copilot experiences, publishes a separate documentation page for each, and notes that administrators “can decide whether to use these models” and that additional terms may apply. [4] Microsoft Learn Data, Privacy, and Security for Microsoft 365 Copilot View source ↗ None of that changes the training commitment above — but it does mean a policy that names one vendor by hand will need maintaining. Describe the commitment, not the vendor list.

The human reader

Microsoft offers a review process on some of its other AI services under which staff can read customer content to check for misuse. For this product, it has switched that off. In Microsoft’s words: “While abuse monitoring, which includes human review of content, is available in Azure OpenAI, Microsoft 365 Copilot services have opted out of it.” [4] Microsoft Learn Data, Privacy, and Security for Microsoft 365 Copilot View source ↗

One thing that is not switched off: feedback

Microsoft notes that it may use customer feedback — the thumbs-up and thumbs-down buttons, and the comment box that opens behind them — to improve the service, while stating that feedback is not used to train the foundation models. [4] Microsoft Learn Data, Privacy, and Security for Microsoft 365 Copilot View source ↗ Feedback submission is optional and administrators can control it centrally. It is a small surface, but it is one place where a user can voluntarily hand text to Microsoft outside the ordinary flow, and staff should know that the comment box is not the place to paste a client matter.

What Actually Binds Microsoft

Not every source cited in this article carries the same weight, and an engagement letter should reflect that difference rather than paper over it.

Most of what we have quoted comes from Microsoft’s own documentation pages. These are authoritative descriptions of how the products behave, published by the vendor and written to be relied on — but they are pages Microsoft maintains and can revise. Each one carries a last-updated date, and those dates move. The core enterprise data protection page was last revised in May 2026; the main privacy page in July 2026. Useful, but a moving target.

The Data Protection Addendum is different in kind. [5] Microsoft Licensing Microsoft Products and Services Data Protection Addendum (DPA) View source ↗ It is the contract Microsoft enters into with business customers, and it is what actually binds Microsoft legally. Microsoft’s own documentation points back to it, stating that use of Copilot and Copilot Chat by organizations “is covered by the terms of the Microsoft Products and Services Data Protection Addendum (DPA) and Microsoft Product Terms, with Microsoft acting as a data processor.” [1] Microsoft Learn Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat View source ↗

The Addendum is versioned by date, and prior editions remain archived on the same page. That means counsel can cite a specific edition rather than a URL whose contents may change underneath the citation.

Cite the Addendum by edition date

In the engagement letter, reference the Data Protection Addendum by its edition date and keep a copy of that PDF with the file. Cite the documentation pages as supporting explanation, with the date you accessed them. That way the firm’s representation to its clients rests on the instrument that binds Microsoft, and the plain-English pages sit behind it as commentary rather than doing the load-bearing work.

The Consumer Side, and Why It Points Back to the Same Answer

For completeness, it is worth seeing what the other set of terms says — both because someone will eventually ask, and because the consumer page turns out to contain the cleanest confirmation of the business answer.

Under the personal-account version, Microsoft’s terms are close to the opposite of the business ones. Users are given a setting controlling whether their conversations are used to “train our generative AI models,” and Microsoft states that “some Copilot conversations are subject to both automated and human review for product improvement and digital safety purposes.” [7] Microsoft Support Privacy FAQ for Microsoft Copilot View source ↗

That same page is useful for a different reason, though. It publishes a list of data categories excluded from model training, and the very first entry Microsoft names is “users signed into Copilot with an organizational Entra ID account” — an Entra ID account being the work account your people sign in with. [7] Microsoft Support Privacy FAQ for Microsoft Copilot View source ↗ The page also opens by stating outright that it “does not apply to the use of Microsoft 365 Copilot when signed in with Entra ID.” [7] Microsoft Support Privacy FAQ for Microsoft Copilot View source ↗

That is the cleanest answer to the scenario the client raised. Even standing on a consumer Copilot surface, signing in with a work account takes the user out of the consumer training terms — stated by Microsoft, on Microsoft’s own consumer privacy page, against its own interest. And as noted earlier, the consumer app will not accept a work account in the first place. [6] Microsoft Learn Manage Microsoft 365 Copilot Chat View source ↗

Drafting the Engagement Letter

The documentation above should give counsel what they need to cite. A few observations from having watched several firms go through this exercise:

1. Anchor the commitment to the account, not the license.

The protection follows the work account. A clause written around licensed users understates what is true and creates an unnecessary gap for everyone else.

2. Disclose the web search carve-out rather than hoping it stays quiet.

It is narrow, and it is far easier to describe up front than to explain after a client finds Microsoft’s footnote themselves. If the exposure is unacceptable for a particular practice group, turn web search off for that group and say so.

3. Remember that privacy is not the only question — retention is the other one.

Under enterprise data protection, Microsoft states that “prompts and responses are logged, retained, and available for audit, eDiscovery, and advanced Microsoft Purview capabilities.” [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗ That is a feature, not a flaw — it is what lets the firm supervise and search AI use. But it means Copilot conversations are firm records. They should sit inside the firm’s retention schedule like any other communication.

4. Account for uploaded files.

Even without a Copilot license, users can upload documents directly into Copilot Chat. [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗ The protection follows them — Microsoft states that “per enterprise data protection promises, uploaded files aren’t used to train the model” — and those files are stored in the user’s OneDrive for Business, where the firm’s existing controls apply. [3] Microsoft Learn Frequently asked questions about Microsoft 365 Copilot Chat View source ↗ This is the most likely route by which an actual client document reaches Copilot, so it deserves an explicit line in the policy.

5. Date your citations.

Documentation pages change. Record the date each page was accessed, and cite the Data Protection Addendum by edition.

Terms are not the same thing as controls

Everything above describes what Microsoft commits to do with data your staff enter. None of it governs what your staff choose to enter in the first place. Contractual protection is not a substitute for a written AI policy, training, and the administrative controls to back both up — and a client asking about your engagement letter is usually really asking whether the firm has thought this through.

Where DP3 Fits

We work with law firms and professional services organizations in New York and Chicago on exactly this kind of question — the point where a technical configuration detail turns into something a firm has to represent to its clients in writing.

If your firm is revising an engagement letter, writing an AI policy, or simply trying to establish what your people are already doing with tools that arrived without anyone deciding to deploy them, we would be glad to have a conversation. The configuration work here — scoping web search, confirming which accounts are in use, bringing Copilot activity into your retention and supervision framework — is straightforward once someone owns it.

The firms that handle AI well are not the ones that waited for perfect answers. They are the ones that found out what was actually true, wrote it down, and told their clients.

Contact us to discuss AI governance for your firm

References

  1. [1] Microsoft, "Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat," Microsoft Learn. Accessed August 5, 2026. Link
  2. [2] Microsoft, "Data protection when using Microsoft 365 Copilot Chat for work or school," Microsoft Support. Accessed August 5, 2026. Link
  3. [3] Microsoft, "Frequently asked questions about Microsoft 365 Copilot Chat," Microsoft Learn. Accessed August 5, 2026. Link
  4. [4] Microsoft, "Data, Privacy, and Security for Microsoft 365 Copilot," Microsoft Learn. Accessed August 5, 2026. Link
  5. [5] Microsoft, "Microsoft Products and Services Data Protection Addendum (DPA)," Microsoft Licensing. Accessed August 5, 2026. Link
  6. [6] Microsoft, "Manage Microsoft 365 Copilot Chat," Microsoft Learn. Accessed August 5, 2026. Link
  7. [7] Microsoft, "Privacy FAQ for Microsoft Copilot," Microsoft Support. Accessed August 5, 2026. Link

This article is provided for informational purposes by DP3. It is not legal advice. All quotations are drawn from Microsoft’s published documentation as accessed on August 5, 2026; Microsoft revises these pages and the terms they describe, and firms relying on them should confirm the current language and the applicable edition of the Data Protection Addendum. The client question that prompted this article is described with identifying details removed.