Microsoft 365 Copilot

microsoft.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
52 / 100D
Procurement decision
Approve with conditions
3 conditions outstanding
  • No formal subprocessor register disclosed
  • No clear commitment that your data will not train their models
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
“Your data is your business, and you may access, modify, or delete it at any time. Microsoft will not use your data without your agreement, and when we have your agreement, we will use your data to provide only the services you have chosen.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models (including, without limitation, the generative AI foundational models and speech recognition and natural language understanding models) and features of Dragon Copilot and successor products and services;”
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The standard terms regarding “Data Retention and Deletion”, including the 90-day retention period following expiration or termination of a Customer’s subscription, will apply to free trials of Dragon Copilot.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

For Microsoft Dragon Copilot (a clinical documentation product), the Product Terms instruct Microsoft and its subprocessors to process Customer Data, including through human review, to train and develop the generative AI, speech-recognition and language models behind Dragon Copilot and successor products. This is a different product from Microsoft 365 Copilot and does not by itself describe Microsoft 365 Copilot.

Requires written confirmation — see Before you sign ↓

Evidence
“Your data is your business, and you may access, modify, or delete it at any time. Microsoft will not use your data without your agreement, and when we have your agreement, we will use your data to provide only the services you have chosen.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models (including, without limitation, the generative AI foundational models and speech recognition and natural language understanding models) and features of Dragon Copilot and successor products and services;”
!How long do they keep your data?Ask the vendor

The Product Terms refer to a standard Data Retention and Deletion term under which Customer Data is retained for 90 days after a subscription expires or terminates; the reference appears in the Dragon Copilot section (applying it to free trials) and the standard term itself is not in the stashed documents.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The standard terms regarding “Data Retention and Deletion”, including the 90-day retention period following expiration or termination of a Customer’s subscription, will apply to free trials of Dragon Copilot.”
✓Who else can access your data?Clear

Microsoft publishes an Online Services Subprocessor List of authorised subprocessors, states they are audited in advance against security and privacy requirements, may only perform the functions they were engaged for, and are bound by the same contractual privacy commitments Microsoft gives customers. No subprocessor is named in the stashed pages.

Evidence
“Subcontractors or subprocessors deployed by Microsoft to perform work that requires access to your data can perform only the functions they were hired to provide. They’re bound by the same contractual privacy commitments that Microsoft makes to you. The Microsoft Online Services Subprocessor List identifies authorized subprocessors who have been audited in advance against a stringent set of security and privacy requirements.”
!Where is your data processed?Ask the vendor

The Product Terms commit that, for tenants provisioned in a listed Geo, stored content of interactions with Microsoft 365 Copilot and Microsoft 365 Copilot Chat is kept at rest within that Geo, alongside Exchange, SharePoint, OneDrive and Teams content.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Microsoft will store the following Customer Data at rest only within that Geo: (1) Exchange Online mailbox content (e-mail body, calendar entries, and the content of e-mail attachments), (2) SharePoint Online site content and the files stored within that site, (3) files uploaded to OneDrive (work/school), (4) Microsoft Teams chat messages (including private messages, channel messages, meeting messages and images used in chats), and for customers using Microsoft Stream (Classic) (on SharePoint) meeting recordings, and (5) any stored content of interactions with Microsoft 365 Copilot or Microsoft 365 Copilot Chat to the extent not included in the preceding commitments or subject to Data Residency for Microsoft 365 Copilot and Copilot Chat .”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Microsoft 365 Copilot, Microsoft 365 Copilot Chat, Communications Compliance, eDiscovery and Audit, Insider Risk Management, Information Barriers, Microsoft Intune, Priva Privacy Risk Management, Priva Subject Rights Management, Microsoft Viva Answers, Microsoft Viva Connections, Microsoft Viva Engage, Microsoft Viva Glint, Microsoft Viva Insights, Microsoft Viva Learning, and Microsoft Viva Pulse”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Remote Access . Microsoft personnel located outside the EU Data Boundary may remotely access data processing systems in the EU Data Boundary as necessary to operate, troubleshoot, support, and secure the EU Data Boundary Services.”
✓What happens in a security incident?Clear

Microsoft provides documentation on data breach notification, DPIAs and data subject requests for customers to incorporate into their own GDPR accountability programmes. No security incident response process, vulnerability disclosure channel or notification timeline specific to Microsoft 365 Copilot appears in the stashed pages.

Evidence
Vendor publishedMicrosoft Accessibility | Microsoft Trust Center ↗retrieved Oct 5, 2026
“Documentation for Data Protection Impact Assessments (DPIAs), Data Subject Requests (DSRs), and data breach notification is provided to incorporate into your own accountability program in support of the GDPR.”

Email to send the vendor7 items to confirm in writing

Subject: Supplier assessment: written confirmation requested for Microsoft 365 Copilot
Hello Microsoft team,

We are assessing Microsoft 365 Copilot (Microsoft) as part of our supplier review. Before we proceed, please confirm the following in writing:

1. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
2. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
3. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
4. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
5. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
6. Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
7. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Microsoft 365 Copilot is explicitly inside Microsoft's contractual and audit perimeterStrong

The public Product Terms name Microsoft 365 Copilot as an Office 365 Service and Core Online Service. That classification brings it under the DPA (which prevails over other terms), the Appendix A security measures, SOC 1 Type II and SOC 2 Type II attestations for Office 365 Services, a data-at-rest Geo commitment that specifically covers stored Copilot interaction content, and EU Data Boundary scope.

Many AI add-ons sit outside a vendor's core contractual commitments. Here the product-specific commitments on location and attestation scope are stated in the contract document itself, not just marketing, so a buyer can rely on them without special negotiation.

Evidence
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Microsoft will store the following Customer Data at rest only within that Geo: (1) Exchange Online mailbox content (e-mail body, calendar entries, and the content of e-mail attachments), (2) SharePoint Online site content and the files stored within that site, (3) files uploaded to OneDrive (work/school), (4) Microsoft Teams chat messages (including private messages, channel messages, meeting messages and images used in chats), and for customers using Microsoft Stream (Classic) (on SharePoint) meeting recordings, and (5) any stored content of interactions with Microsoft 365 Copilot or Microsoft 365 Copilot Chat to the extent not included in the preceding commitments or subject to Data Residency for Microsoft 365 Copilot and Copilot Chat .”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Microsoft 365 Copilot, Microsoft 365 Copilot Chat, Communications Compliance, eDiscovery and Audit, Insider Risk Management, Information Barriers, Microsoft Intune, Priva Privacy Risk Management, Priva Subject Rights Management, Microsoft Viva Answers, Microsoft Viva Connections, Microsoft Viva Engage, Microsoft Viva Glint, Microsoft Viva Insights, Microsoft Viva Learning, and Microsoft Viva Pulse”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Online Service SSAE 18 SOC 1 Type II SSAE 18 SOC 2 Type II Office 365 Services Yes Yes”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Office 365 Services The following services, each as a standalone service or as included in an Office 365 or Microsoft 365-branded plan or suite: Customer Lockbox, Exchange Online Archiving, Exchange Online Protection, Exchange Online, Microsoft Bookings, Microsoft Forms, Microsoft Planner, Microsoft Stream (Classic), Microsoft Teams,  Microsoft To-Do, Microsoft Defender for Office 365, Office for the web, OneDrive for work or school, Project, SharePoint, Sway, Viva Insights, Whiteboard, Viva Engage, and Microsoft 365 Copilot.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“In the event of any conflict or inconsistency between the DPA and any other terms in Customer’s licensing agreement (including these terms), the DPA shall prevail.”
!No Microsoft 365 Copilot-specific statement on model training or prompt retention in the collected pagesGap

The only training-related commitment for the target is the organisation-wide purpose-limitation language on the Privacy Principles page (data used only to provide the services chosen; no mining for advertising). The Trust Center's 'Data for AI Training' page and the DPA text were not in the stash. The 90-day post-termination retention term is referenced only indirectly. By contrast, the same Product Terms show Microsoft does instruct itself to train models on Customer Data for Microsoft Dragon Copilot, so a product-by-product answer matters.

A buyer cannot assume the Dragon Copilot training clause applies to Microsoft 365 Copilot (it does not by its terms), but equally cannot cite an explicit 'no training' statement for Microsoft 365 Copilot from these pages. The favorable data_training verdict here rests on organisation-level language and should be confirmed in writing.

Question for vendor: Please confirm in writing, with reference to the DPA and the Microsoft 365 Copilot Product Terms, that prompts, responses and data accessed via Microsoft Graph by Microsoft 365 Copilot are not used to train or fine-tune foundation models, and state the retention period for Copilot interaction history and memory data.

Evidence
“Your data is your business, and you may access, modify, or delete it at any time. Microsoft will not use your data without your agreement, and when we have your agreement, we will use your data to provide only the services you have chosen.”
“We don’t share your data with advertiser-supported services or mine it for any purposes, such as marketing research or advertising.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models (including, without limitation, the generative AI foundational models and speech recognition and natural language understanding models) and features of Dragon Copilot and successor products and services;”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The standard terms regarding “Data Retention and Deletion”, including the 90-day retention period following expiration or termination of a Customer’s subscription, will apply to free trials of Dragon Copilot.”
“Memory in Microsoft 365 Copilot enables the AI assistant to retain information about users across conversations to provide contextually relevant responses.”
!Model provider and request-path recipients are not named for Microsoft 365 CopilotGap

The Microsoft 365 Copilot transparency summary says only that the product uses large language models. The pages name OpenAI models only in the Azure OpenAI transparency note, which is a different product and cannot be read across. Subprocessor disclosure is via a generic Online Services Subprocessor List with no entities named in the stash. Separately, the Product Terms exclude Bing-powered components from the DPA; whether this reaches web grounding in Microsoft 365 Copilot is not stated.

Buyers assessing AI supply-chain risk need to know which model developer, hosting path and any third-party grounding services sit in the request path, and under which terms. The Bing carve-out in particular would move part of the data flow from the DPA to the consumer privacy statement.

Question for vendor: Which foundation models and hosting environments process Microsoft 365 Copilot prompts, is any third party (including OpenAI) a subprocessor for that processing, and does the Bing DPA exclusion apply to web grounding in Microsoft 365 Copilot?

Evidence
“An AI-powered productivity tool that helps enhance your creativity, productivity, and skills by using large language models (LLMs) and content that you have access to.”
“Use OpenAI models to generate natural language, code, and images. Integrated content filtering and abuse detection is included.”
“Subcontractors or subprocessors deployed by Microsoft to perform work that requires access to your data can perform only the functions they were hired to provide. They’re bound by the same contractual privacy commitments that Microsoft makes to you. The Microsoft Online Services Subprocessor List identifies authorized subprocessors who have been audited in advance against a stringent set of security and privacy requirements.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The Data Protection Addendum does not apply to Bing Search Services or to any use of Bing within a Product. For any component of a Product that is powered by Bing, as disclosed in the product documentation, the Microsoft Privacy Statement ( https://privacy.microsoft.com/privacystatement ) applies.”
!Change management not evidenced; target-specific testing evidence is thinGap

change_management is marked not_evidenced rather than not_applicable: a hosted, continuously updated generative AI service plainly can publish how model, feature and subprocessor changes are notified, and other vendors do. The only change-related commitment in the stash concerns Azure Core Services data location. No domain was marked not_applicable. On testing, the Microsoft 365 Copilot-specific evidence is a Sensitive Use review case study and a NIST RMF-based method statement; the concrete red-teaming narrative concerns Browse with Copilot, a different feature, and so does not lift the target's status beyond partial.

Without a stated change-notification practice a buyer cannot tell when the underlying model or data handling for Microsoft 365 Copilot changes, and without product-specific evaluation evidence cannot judge how safety testing was applied to this product rather than to Microsoft's AI portfolio generally.

Question for vendor: How are Microsoft 365 Copilot customers notified of model changes, new data-processing features (such as memory) and subprocessor changes, and can Microsoft share the evaluation and red-teaming summary for Microsoft 365 Copilot specifically?

Evidence
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Refer to the Microsoft Trust Center (which Microsoft may update from time to time, but Microsoft will not add exceptions for existing Services in general release) for more details.”
“This case highlights how the team navigated the Sensitive Use review process to develop and deploy capabilities like memory safely with high standards of privacy and security.”
“Explore how Microsoft applies responsible AI practices across real-world systems—demonstrated through case studies grounded in the NIST Risk Management Framework and our AI principles.”
“This case illustrates how Browse with Copilot, a feature enabling AI to perform web-based tasks, was developed responsibly by mapping prompt injection and privacy risks, red teaming realistic attacks, adding layered mitigations, and launching through preview with user controls and feedback loops.”
✓Mature, published responsible AI governance programme applied to the targetStrong

Microsoft publishes six AI principles, a Responsible AI Standard that sets product development requirements, and annual Responsible AI Transparency Reports. The 2026 report includes a case study on Microsoft 365 Copilot memory passing the Sensitive Use review process, which is the one piece of governance evidence in the stash that is explicitly about the target product.

A governance structure that is documented, repeated annually and demonstrably applied to the product under assessment is stronger evidence than principles alone. Most of the remaining governance evidence is organisation-level, and the report labels it as such.

Evidence
“We've identified six principles that we believe should guide AI development and use.”
“Additionally, the Responsible AI Standard at Microsoft helps define product development requirements for responsible AI.”
“This case highlights how the team navigated the Sensitive Use review process to develop and deploy capabilities like memory safely with high standards of privacy and security.”
“Microsoft also offers the Responsible AI Transparency Report , which provides insights into how Microsoft builds apps with generative AI, oversees the deployment of those apps, supports customers as they build their own AI apps, and fosters a responsible AI community.”
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Use OpenAI models to generate natural language, code, and images. Integrated content filtering and abuse detection is included.”
“Subcontractors or subprocessors deployed by Microsoft to perform work that requires access to your data can perform only the functions they were hired to provide. They’re bound by the same contractual privacy commitments that Microsoft makes to you. The Microsoft Online Services Subprocessor List identifies authorized subprocessors who have been audited in advance against a stringent set of security and privacy requirements.”
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Use OpenAI models to generate natural language, code, and images. Integrated content filtering and abuse detection is included.”
“Subcontractors or subprocessors deployed by Microsoft to perform work that requires access to your data can perform only the functions they were hired to provide. They’re bound by the same contractual privacy commitments that Microsoft makes to you. The Microsoft Online Services Subprocessor List identifies authorized subprocessors who have been audited in advance against a stringent set of security and privacy requirements.”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Use OpenAI models to generate natural language, code, and images. Integrated content filtering and abuse detection is included.”
“Subcontractors or subprocessors deployed by Microsoft to perform work that requires access to your data can perform only the functions they were hired to provide. They’re bound by the same contractual privacy commitments that Microsoft makes to you. The Microsoft Online Services Subprocessor List identifies authorized subprocessors who have been audited in advance against a stringent set of security and privacy requirements.”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score60
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
“We've identified six principles that we believe should guide AI development and use.”
“Additionally, the Responsible AI Standard at Microsoft helps define product development requirements for responsible AI.”
“This case highlights how the team navigated the Sensitive Use review process to develop and deploy capabilities like memory safely with high standards of privacy and security.”
“Microsoft also offers the Responsible AI Transparency Report , which provides insights into how Microsoft builds apps with generative AI, oversees the deployment of those apps, supports customers as they build their own AI apps, and fosters a responsible AI community.”

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
“An AI-powered productivity tool that helps enhance your creativity, productivity, and skills by using large language models (LLMs) and content that you have access to.”
“Memory in Microsoft 365 Copilot enables the AI assistant to retain information about users across conversations to provide contextually relevant responses.”
“When using Copilot at work, all your existing security and compliance requirements are inherited, so only people with the right permissions can access the content it generates.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
“This case highlights how the team navigated the Sensitive Use review process to develop and deploy capabilities like memory safely with high standards of privacy and security.”
“Explore how Microsoft applies responsible AI practices across real-world systems—demonstrated through case studies grounded in the NIST Risk Management Framework and our AI principles.”
“This case illustrates how Browse with Copilot, a feature enabling AI to perform web-based tasks, was developed responsibly by mapping prompt injection and privacy risks, red teaming realistic attacks, adding layered mitigations, and launching through preview with user controls and feedback loops.”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced
Evidence — Change management
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Refer to the Microsoft Trust Center (which Microsoft may update from time to time, but Microsoft will not add exceptions for existing Services in general release) for more details.”

Change management: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
“An AI-powered productivity tool that helps enhance your creativity, productivity, and skills by using large language models (LLMs) and content that you have access to.”
“Use OpenAI models to generate natural language, code, and images. Integrated content filtering and abuse detection is included.”
Customer data15% of the score65
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
“When using Copilot at work, all your existing security and compliance requirements are inherited, so only people with the right permissions can access the content it generates.”
“Your data is your business, and you may access, modify, or delete it at any time. Microsoft will not use your data without your agreement, and when we have your agreement, we will use your data to provide only the services you have chosen.”
“We don’t share your data with advertiser-supported services or mine it for any purposes, such as marketing research or advertising.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Microsoft will store the following Customer Data at rest only within that Geo: (1) Exchange Online mailbox content (e-mail body, calendar entries, and the content of e-mail attachments), (2) SharePoint Online site content and the files stored within that site, (3) files uploaded to OneDrive (work/school), (4) Microsoft Teams chat messages (including private messages, channel messages, meeting messages and images used in chats), and for customers using Microsoft Stream (Classic) (on SharePoint) meeting recordings, and (5) any stored content of interactions with Microsoft 365 Copilot or Microsoft 365 Copilot Chat to the extent not included in the preceding commitments or subject to Data Residency for Microsoft 365 Copilot and Copilot Chat .”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Microsoft 365 Copilot, Microsoft 365 Copilot Chat, Communications Compliance, eDiscovery and Audit, Insider Risk Management, Information Barriers, Microsoft Intune, Priva Privacy Risk Management, Priva Subject Rights Management, Microsoft Viva Answers, Microsoft Viva Connections, Microsoft Viva Engage, Microsoft Viva Glint, Microsoft Viva Insights, Microsoft Viva Learning, and Microsoft Viva Pulse”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Remote Access . Microsoft personnel located outside the EU Data Boundary may remotely access data processing systems in the EU Data Boundary as necessary to operate, troubleshoot, support, and secure the EU Data Boundary Services.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models (including, without limitation, the generative AI foundational models and speech recognition and natural language understanding models) and features of Dragon Copilot and successor products and services;”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The standard terms regarding “Data Retention and Deletion”, including the 90-day retention period following expiration or termination of a Customer’s subscription, will apply to free trials of Dragon Copilot.”

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the scoreorganisation-level evidence40

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
“Subcontractors or subprocessors deployed by Microsoft to perform work that requires access to your data can perform only the functions they were hired to provide. They’re bound by the same contractual privacy commitments that Microsoft makes to you. The Microsoft Online Services Subprocessor List identifies authorized subprocessors who have been audited in advance against a stringent set of security and privacy requirements.”
Security foundation15% of the scoreorganisation-level evidence65

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedMicrosoft Accessibility | Microsoft Trust Center ↗retrieved Oct 5, 2026
“Documentation for Data Protection Impact Assessments (DPIAs), Data Subject Requests (DSRs), and data breach notification is provided to incorporate into your own accountability program in support of the GDPR.”
Independent assurance evidence10% of the score59
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Online Service SSAE 18 SOC 1 Type II SSAE 18 SOC 2 Type II Office 365 Services Yes Yes”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Office 365 Services The following services, each as a standalone service or as included in an Office 365 or Microsoft 365-branded plan or suite: Customer Lockbox, Exchange Online Archiving, Exchange Online Protection, Exchange Online, Microsoft Bookings, Microsoft Forms, Microsoft Planner, Microsoft Stream (Classic), Microsoft Teams,  Microsoft To-Do, Microsoft Defender for Office 365, Office for the web, OneDrive for work or school, Project, SharePoint, Sway, Viva Insights, Whiteboard, Viva Engage, and Microsoft 365 Copilot.”
“Your control over your data is reinforced by Microsoft compliance with broadly applicable privacy laws, such as GDPR and privacy standards. These include the world’s first international code of practice for cloud privacy, ISO/IEC 27018.”
Reasoned inferenceMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The  Data Protection Addendum  applies to the Product, except (1) the DPA's statement of compliance with ISO 27001, ISO 27002, and ISO 27018 does not apply, and (2) use of all data processed by Internet-based Features is governed by the Microsoft Privacy Statement ( aka.ms/privacy ) and not the DPA, unless other terms accompany such Internet-based Features.”
Vendor publishedManaging Cloud Compliance | Microsoft Trust Center ↗retrieved Oct 5, 2026
“Verify technical compliance and control requirements with help from our reports and resources for information security, privacy, and compliance professionals.”
Registry verifiedCSA STAR Registry record — CSA STAR Level 2 ↗retrieved Oct 5, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“Office 365 Services The following services, each as a standalone service or as included in an Office 365 or Microsoft 365-branded plan or suite: Customer Lockbox, Exchange Online Archiving, Exchange Online Protection, Exchange Online, Microsoft Bookings, Microsoft Forms, Microsoft Planner, Microsoft Stream (Classic), Microsoft Teams,  Microsoft To-Do, Microsoft Defender for Office 365, Office for the web, OneDrive for work or school, Project, SharePoint, Sway, Viva Insights, Whiteboard, Viva Engage, and Microsoft 365 Copilot.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“In the event of any conflict or inconsistency between the DPA and any other terms in Customer’s licensing agreement (including these terms), the DPA shall prevail.”
Vendor publishedMicrosoft Product Terms ↗retrieved Oct 5, 2026
“The Data Protection Addendum does not apply to Bing Search Services or to any use of Bing within a Product. For any component of a Product that is powered by Bing, as disclosed in the product documentation, the Microsoft Privacy Statement ( https://privacy.microsoft.com/privacystatement ) applies.”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Have Customer data treatment disclosures independently corroboratedData 65 → 80
+3Have Governance & accountability disclosures independently corroboratedOrganisation 60 → 75
+3Publish Change management evidenceAI System 27 → 47
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 65 → 85
+3Verify CSA STAR Level 2 scope covers this assessmentIndependent Assurance 59 → 81

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 52 → up to 77 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSMicrosoftMicrosoftMicrosoft 365 CopilotMicrosoft 365 CopilotMicrosoft 365 Copilot ChatMicrosoft 365 Copilot ChatMicrosoft Dragon CopilotMicrosoft Dragon CopilotAzure OpenAIAzure OpenAIBing Search ServicesBing Search ServicesOpenAIOpenAI
View as list
Azure OpenAI Uses AI Service OpenAI

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 7 — registry checks and verification ladders, click to view
SSAE 18 SOC 1 Type IIVendor claimed only

Stated in the Product Terms for Office 365 Services, which are defined to include Microsoft 365 Copilot. Auditor and report period not in the stashed documents.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

SSAE 18 SOC 2 Type IIVendor claimed only

Stated in the Product Terms for Office 365 Services, which are defined to include Microsoft 365 Copilot. Auditor, trust services criteria and report period not in the stashed documents.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27018Vendor claimed only

Organisation-wide commercial cloud statement on the Privacy Principles page; certificate scope, issuer and validity not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001Claimed, scope unclear

Inferred from the Product Terms' reference to the DPA's statement of compliance with ISO 27001; the DPA itself, the certificate scope and the issuer are not in the stashed documents.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Oct 5, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Oct 5, 2026: Verified on the registry

Sources 14 — click to view
Responsible AI: Ethical policies and practices | Microsoft AI
AI Documentation · Vendor · retrieved Oct 5, 2026
Microsoft Trust Center | Data Security, Privacy, and Compliance
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Microsoft Product Terms
DPA · Vendor · retrieved Oct 5, 2026
Trust Portal
Subprocessor List · Vendor · retrieved Oct 5, 2026
Microsoft Privacy Principles | Microsoft Trust Center
Privacy Notice · Vendor · retrieved Oct 5, 2026
Managing Cloud Compliance | Microsoft Trust Center
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
https://trust.microsoft.com/assets/DocumentationCommandBar-CblJq2wZ.js
Product Documentation · Vendor · retrieved Oct 5, 2026
Legal Resources from Microsoft | Microsoft Legal
Terms · Vendor · retrieved Oct 5, 2026
Responsible AI Principles and Approach | Microsoft AI
AI Documentation · Vendor · retrieved Oct 5, 2026
Cloud Data Integrity at its Finest | Microsoft Trust Center
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Microsoft Accessibility | Microsoft Trust Center
DPA · Vendor · retrieved Oct 5, 2026
Sign in to your account
Subprocessor List · Vendor · retrieved Oct 5, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.