Insights  /  Is Microsoft Copilot safe for client data? What small firms need to check

Insights

Is Microsoft Copilot safe for client data? What small firms need to check

Insights By Helio Guard  ·  6 October 2026  ·  6 min read

Is Microsoft Copilot safe for client data? What small firms need to check

Microsoft 365 Copilot, used with a work account, can be safe for client data. Free consumer Copilot, used with a personal account, is a different product with different terms and should not see client data. Which one your staff use, and how your files are shared, decides the answer. So is Copilot safe for client data? Only the right Copilot, set up the right way.

This guide is for owners and practice managers who have just been offered Copilot. It covers which version to allow, the settings worth checking, and where client data still leaks out.

Two products with one name

Microsoft uses the word Copilot for several things. For a small firm, two matter.

Free Copilot with a personal account

This is the consumer version. Anyone can open it in a browser or on a phone. They sign in with a personal Microsoft account, or not at all.

It sits outside your business. You cannot see who uses it. You cannot set rules for it. What staff type is covered by Microsoft's consumer terms, not your business agreement.

Copilot with a work account

This is Copilot signed in with the account your firm gives staff. It comes in two forms. Copilot Chat is included with many Microsoft 365 business plans. Microsoft 365 Copilot is a paid add-on that also works inside Word, Excel, Outlook and Teams, and can read your firm's files.

With a work account, Microsoft applies what it calls enterprise data protection. In plain terms, Microsoft says prompts and answers stay within your Microsoft 365 agreement and are not used to train its general AI models. Check Microsoft's current pages before you rely on that, as terms do change.

Rule of thumb: allow Copilot only when staff are signed in with their work account. Treat personal Copilot like any other public AI tool.

How to tell which one someone is using

Staff often cannot tell. The page looks almost the same.

The sign-in is the clue. A work account shows your firm's email address in the corner. Microsoft also marks protected chats with a small shield or a note about protection. If neither appears, assume it is the consumer version.

Show staff what the work version looks like. A two-minute screenshot in a team meeting saves a lot of guessing.

The settings that matter before you switch it on

Most of the risk with Microsoft 365 Copilot is not Microsoft. It is your own file sharing.

Check who can see what

Microsoft 365 Copilot can only read what the person asking can already open. That sounds safe. It is safe only if your permissions are tidy.

A common pattern is old folders shared with "everyone in the company". A payroll spreadsheet. A client's tax file. A disciplinary note. Nobody went looking for them before. Copilot makes them easy to find with one question.

Before you switch it on, ask your IT provider to review sharing in SharePoint, OneDrive and Teams. Pay attention to links shared with the whole firm or with anyone.

Use sensitivity labels if you have them

Some Microsoft 365 plans include sensitivity labels. These mark files as confidential and can limit what Copilot does with them. They are part of a Microsoft tool called Purview. Setting them up takes time and some skill, so most small firms need their IT provider for it.

Block or discourage consumer Copilot

Your IT provider can often steer the Copilot icon in Windows and Edge to the work version. They can also block personal sign-ins on work devices. Ask what is possible on your plan.

Write it into your AI policy

A short policy helps. Say which Copilot is allowed. Say which tools are not. Say what must never be pasted anywhere, such as bank details or National Insurance numbers. Get each person to agree to it, with a date.

Where staff still paste client data

Allowing the right Copilot does not stop people using other tools. Habits are hard to shift.

Picture Ashcombe, a small accountancy practice. They roll out Microsoft 365 Copilot. Priya still prefers ChatGPT for rewording letters. Tom uses Gemini on his phone at lunch. Jo pastes a client list into Claude to tidy the formatting. None of them means any harm.

Copilot's protections do nothing here. Those are separate services under separate terms. Your Microsoft settings do not reach them.

The usual places client data slips out:

  • ChatGPT, Gemini, Claude, Perplexity and DeepSeek in the browser.
  • Personal Copilot opened by mistake.
  • File uploads, such as a client's spreadsheet or a scanned PDF.
  • Phones and home computers, which your settings may not cover.
Approving one AI tool does not switch the others off.

Deciding which Copilot to allow

For most small firms handling client data, the choice is straightforward.

OptionClient data?What you need first
Free Copilot, personal accountNoBlock or discourage it
Copilot Chat, work accountWith careClear policy, staff know the work version
Microsoft 365 CopilotWith carePermissions review, policy, ideally labels

Start with Copilot Chat on work accounts if you are unsure. It does not read your files, so the permissions risk is smaller. Move to Microsoft 365 Copilot once your sharing is tidy.

Before you switch on Microsoft 365 Copilot: review shared folders, agree a written AI policy, and decide how you will handle the other AI tools staff already use.

The controls you still need alongside Copilot

Copilot settings cover Copilot. You still need something for everything else.

Your options, roughly:

  • Policy and training. Cheap and worth doing. It relies on people remembering.
  • Blocking AI sites. Simple, but staff often move to phones. You also lose the benefit of AI.
  • Microsoft Purview. Powerful, and part of some Microsoft plans. It needs real setup time and skill.
  • A tool that checks what goes into AI sites. It catches sensitive data before it is sent, whichever AI tool is used.

Helio Guard is the last kind. It runs on each Windows PC and adds an extension to Chrome and Edge. It checks every paste, message and file upload on listed AI sites, including ChatGPT, Copilot, Gemini, Claude, Perplexity and DeepSeek. Card numbers, UK bank details, National Insurance numbers and lists of people are taken out and swapped for labels. The question still goes through. Client names can become a stand-in such as "Client A", and turn back into the real name when the answer is copied.

The checks run on the PC with fixed rules, not an AI model. We never see what your team types. Only a short record reaches your account: the kind of data, the site, the person, the outcome and the time. It also records each person's dated agreement to your AI policy.

It has limits. It covers Windows PCs with Chrome and Edge. Not Mac. Not phones. If you already pay for Microsoft's tools, our comparison of Helio Guard and Microsoft Purview sets out where each one fits. If it suits your firm, the pricing page shows the current costs. Either way, AI is welcome. The aim is simply that client data stays out of it.