Where Does Our Data Go? The Answer, and One Nuance to Know
Contractually: not used to train AI models. Geographically: stored within the EU. GDPR: fully in scope. One exception worth knowing before you deploy in a regulated environment.

Every single time I discuss Copilot Agents with someone in a regulated sector, whether it's utilities, pharma, public sector infrastructure, finance, the same question comes up within about five minutes and within an hour for other businesses.
"Where does our data go, and is Microsoft using it to train their AI?"
It's exactly the right question and one everyone should ask about every piece of software they use, not just MS products, regardless of its function.
On Training
Microsoft has a formal contractual commitment — not just a policy page — that your prompts, responses, and organisational data accessed through Copilot are not used to train their AI models. This is backed by the Microsoft Data Protection Addendum. It applies to everything Copilot accesses through your Microsoft 365 environment.
On Data Location
For EU-based organisations, Copilot falls under Microsoft's EU Data Boundary commitment. Your interaction data — what you ask, what it responds — is stored and processed within the EU. It doesn't leave European jurisdiction.
One Nuance Worth Knowing
The EU Data Boundary commitment applies to the standard Copilot experience, which runs on Azure OpenAI. If you're building custom agents in Copilot Studio using third-party AI models, the data residency picture is more complex and those models aren't automatically covered by the same guarantees. Worth checking before anything goes near a regulated environment.
The data governance question used to be a genuine blocker for Copilot adoption in sectors like utilities and infrastructure. At this point, for most EU commercial organisations, it doesn't need to be — but it does need to be answered properly.
Glossing over it doesn't build confidence. Having the answer ready does.