Security, Trust and Compliance with AI

productivity tools Feb 10, 2026
Generative AI. Security, trust and compliance with AI. Copilot Chat

Security, trust and compliance with AI

Post 4 of the series: Starting with Copilot Chat

So far in this series we have mostly focused on how to get work done faster, to a high level and more consistently at that level.

We have looked at where Copilot Chat helps, particularly when we start using it with the Microsoft 365 tools many of us work with every day. Outlook, Teams, PowerPoint, Word, Excel and the rest.

We have looked at where Copilot can be misunderstood, and what really changes when you start using it alongside these everyday tools.

What changes in terms of productivity.

The thing is, when AI moves from being something people experiment with occasionally to a true copilot that they work with on a daily basis, there is another conversation that becomes unavoidable.

What information are people putting into these tools, which tools are they using, and does the business actually know?

That is where AI becomes a conversation about productivity, security, trust, responsibility and compliance.


AI is already being used in work

AI use is already part of everyday work in many companies.

Someone in Sales might use it to prepare for a customer meeting.

Someone in HR might ask it to improve an employee communication.

Procurement might use it to compare supplier information and build out a view of which supplier best meets a particular requirement.

A manager might use it to review a strategy document before a meeting.

Someone in Marketing might upload research, campaign results and customer information and ask AI to help them work through what they should do next.

These are all typical use cases and they can add real value to the way people work.

There are then some important questions that need to be answered.

  • Which AI tool are they using?
  • Are they using a personal account or an account provided and managed by their employer?
  • What information are they providing?
  • What has the business told them they can and cannot use?
  • And do people actually understand that guidance when they are sitting in front of the tool doing their work?

Those questions matter because simply knowing that employees are using ChatGPT, Copilot or another AI tool tells you very little about what is actually happening.


The account people are using matters

One area where I still see quite a lot of confusion is when we talk about tools such as ChatGPT and Copilot as though there is one version of each.

There are different accounts, different plans and different levels of control.

For example, when someone uses Microsoft Copilot Chat while signed in with their work account, Microsoft provides enterprise data protection. Microsoft also states that prompts, responses and data accessed through Microsoft Graph are not used to train its foundation models.

Microsoft 365 Copilot then goes further because it can work with the information that person already has permission to access across Microsoft 365.

ChatGPT also has business environments.

ChatGPT Business and ChatGPT Enterprise have different data controls from personal ChatGPT accounts. OpenAI states that information from these business workspaces is not used to train its models by default.

Personal ChatGPT accounts have their own data controls, including the ability to switch off the use of new conversations for model training.

So when someone says:

"We use ChatGPT."

Or:

"We use Copilot."

There is still quite a lot we need to understand.

  • Which account?
  • Which version?
  • Who controls it?
  • What information is being used with it?
  • What rules has the company put around that use?


Why Microsoft 365 is important in this conversation

For companies already working heavily within Microsoft 365, there is an obvious reason why Copilot gets so much attention.

Your people already have Microsoft identities.

They already have access to certain Teams, SharePoint sites, documents, emails and other information.

You may already have sensitivity labels, retention rules, access controls and other policies in place.

Copilot works within those existing Microsoft 365 controls.

This becomes particularly important as people start asking Copilot to work with information from Outlook, Teams, Word, PowerPoint, SharePoint and other parts of Microsoft 365.

The tool is suddenly much closer to the work people are already doing and the information they already use to do that work.

And that means your existing Microsoft 365 environment becomes very important.


Permissions need attention

This is one area I think businesses need to pay particular attention to before and during a wider Microsoft 365 Copilot rollout.

Copilot respects the access somebody already has.

If somebody already has permission to access a document, Copilot can potentially use that document when helping them with their work.

Think about what happens inside a company over several years.

Someone joins a project and gets access to a SharePoint site.

They move departments.

Teams change.

New folders are created.

People get added to different groups.

Access gets given and it does not always get reviewed again later.

Over time you can end up with people having access to information that they probably no longer need.

AI makes information much easier to find, bring together and work with.

That makes reviewing your existing permissions and information access an important part of preparing properly for Microsoft 365 Copilot.

The underlying issue may have existed for years. Copilot can make that issue much easier to see.


And what about ChatGPT?

There is another part of this conversation that I think has changed quite significantly over the last couple of years.

For a while, many companies treated ChatGPT as something employees might use personally and Microsoft Copilot as the business AI tool.

Today it is more complicated than that.

ChatGPT Business and Enterprise provide businesses with managed workspaces and business data protections.

Companies may therefore decide to provide employees with Microsoft Copilot, ChatGPT, or both.

And there can be good reasons for that.

A task involving emails, Teams meetings, SharePoint documents or work being completed directly inside Microsoft 365 may naturally fit Copilot.

Another task involving research, analysing several documents, developing an idea over multiple stages or working through a complex problem may work very well in ChatGPT.

What matters is that people understand what they have available to them and how each tool should be used.

Because once people have access to several AI tools, they are going to make choices.

  • Which one should I use for this?
  • Can I upload this document?
  • Can I include customer information?
  • Can I use employee information?
  • Can I paste this email into the tool?
  • Can I connect this data source?

These are very practical questions and people need practical answers.


Compliance is part of how AI is used

This is also where compliance enters the conversation.

A technology provider can give you strong security controls, privacy commitments and tools for managing data.

The company using the technology still needs to decide how AI can be used within its own environment.

Think about some of the questions that come up very quickly.

  • What type of information is being processed?
  • Is customer information involved?
  • Is employee information involved?
  • Is the information confidential?
  • Are there contractual restrictions around how that information can be used?
  • Who should have access to it?
  • Does somebody need to review the AI output before anything happens as a result of it?

Different companies, industries and countries will have different requirements.

In Europe and across the GCC, these questions can be particularly important when businesses are deciding which AI tools they will approve and how those tools will be used.

Security, legal, privacy and compliance teams all have a role to play here.

And then employees need to understand what all of that means when they are actually doing their work.


Policies need to make sense to the person doing the work

You can create an AI policy.

You can tell people not to put sensitive information into an unapproved AI tool.

You can give people a list of approved technologies.

All of that has value.

Then someone sits down on Tuesday morning with a supplier proposal in front of them and wants AI to help compare it against three others. Can they upload it?

Someone in HR has an employee communication they need help writing. Can they include the employee's information?

Someone in Sales wants help preparing for a customer meeting. Can they use the customer's emails?

This is where policy has to be relevant for the work it is governing.

People need to understand the rules well enough to make a good decision at that moment.

"Sensitive information" can sound very clear when it appears in a policy document.

It can feel much less clear when someone is halfway through a task and trying to decide whether the information in front of them falls into that category.

This is why AI guidance and practical AI training need to connect.

Blocking tools only covers part of the problem

There will be situations where a company decides that a particular AI tool should be restricted.

That is a perfectly reasonable control.

People still need to know what they can do.

If ChatGPT is restricted, can they use Copilot for the task? If personal AI accounts are restricted, which business account should they use? What information can be provided? Which tasks need additional approval? When does someone need to involve Legal, Information Security or another team?

AI is developing quickly and people are finding new ways to use these tools every week.

Clear guidance helps them make better decisions as those situations come up.


Trust comes from understanding how AI fits into the work

Trust is a big part of AI adoption.

People need to trust that they are allowed to use the tool.

They need to understand what information they can provide.

They need to know what the tool can access.

And they need to understand where their own responsibility sits.

AI can produce something that looks extremely convincing and is still wrong.

It can miss information, misunderstand the task, make assumptions. It can create an answer that sounds good and falls apart when somebody checks it properly.

So security and compliance also connect back to the way people have been taught to work with AI.

Understand the task.

Give the tool the right information.

Work through the task properly.

Review what comes back.

Check the important details.

Take responsibility for the final result.

These are productivity skills and they are also part of responsible AI use.


Start by understanding what is happening today

If AI is already being used across your business, one of the most useful things you can do is understand what people are actually doing with it.

  • Which tools are they using?
  • Which accounts are they using?
  • What work are they using AI for?
  • What information are they providing?
  • Where are people uncertain about what they are allowed to do?
  • Where are different teams making different decisions?

Once you understand that, the next steps become much clearer.

You may need clearer guidance.

You may need to move people away from personal accounts and provide managed business tools.

You may need to review Microsoft 365 permissions.

You may need to provide practical training.

There may also be areas where Security, Legal, Privacy or Compliance need to become more involved.

The aim is to give people enough clarity to use AI productively, safely and consistently in their everyday work.

Because AI use is already moving beyond experimentation.

For many people it is becoming part of how the work gets done.

And once that happens, productivity, security, trust and compliance all become part of the same conversation.