AI Data Security:

The Complete Guide to Copilot & Claude

We Do Your IT Support helps small and medium-sized businesses across Bristol, Bath, Cheltenham, Swindon, Gloucester, and the wider South West secure their data before and during AI adoption. Our AI Data Security Pack, delivered alongside We Do Your Cyber Security (part of We Do Your Group), covers both Microsoft Copilot and Claude, giving you the governance, access controls, and data classification your business needs to use generative AI safely. This page is a comprehensive guide to the security risks, safeguards, and practical steps involved. If you are ready to act, we have a dedicated AI Data Security Pack service page where you can book an assessment and see exactly what is included.

Is Copilot and Claude safe to use in your business?

The short answer to both is yes – provided your organisation has the right foundations in place. Neither Microsoft Copilot nor Claude automatically grants itself access to everything in your business. Both tools operate within the boundaries your existing permissions and connectors already define.

Microsoft Copilot

Works within the permissions you already set.

How does Copilot work with your data?

Microsoft 365 Copilot operates entirely within the Microsoft 365 service boundary. It uses Microsoft Graph to surface content (emails, files, chats, calendar entries) but only content the individual user already has permission to access. Copilot does not create new data access rights. If a member of staff cannot open a document in SharePoint today, Copilot cannot summarise it for them tomorrow.

Labels and encryption

Microsoft Copilot also respects sensitivity labels and encryption applied through Microsoft Purview Information Protection. Content labelled “Highly Confidential” with Azure Rights Management encryption requires explicit EXTRACT or VIEW rights before Copilot can process it. Without those access rights, the content stays out of Copilot’s responses.

Training

Importantly, Microsoft states that organisational data processed by Microsoft 365 Copilot is not used to train foundational AI models. Your emails, files, and chats remain your own. Users and administrators can also opt out of personalisation features.

Claude

Sees only what you connect and authorise.

How does Claude access your data?

Claude uses a connector model called MCP (Model Context Protocol) to integrate with external data sources – Google Drive, Microsoft 365, Slack, GitHub, and others. Claude access to your data is user-delegated through OAuth. This means Claude only sees what the connector and the authenticated user’s permissions allow – no elevated service account quietly reading everything in the background.

How it handles your files

The Microsoft 365 connector retrieves data on demand. It doesn’t cache file content, credentials are encrypted, and data remains in your tenant.

Training and retention

Claude doesn’t use your prompts, outputs or files for model training without your organisation’s express permission. Retention follows whatever policy your organisation sets.

Common Misconceptions

A widespread concern is that AI tools “index everything in the company” or “learn from all company data” by default. Neither is accurate. Data access is constrained by user rights, connector scopes, DLP policies, and admin controls. Training data usage is a separate matter entirely, and both platforms require explicit permission before any organisational data is used for that purpose.

That said, neither tool creates new security boundaries. They work within the ones you already have. The risk is not that they bypass your permissions – it is that your existing permissions may be wider than you realise. AI surfaces content through search and summarisation, which means poorly understood file access and erroneous access permissions become far more visible and far more dangerous once an AI tool is involved.

Related resources

What are the main AI data security risks?

Understanding the specific risks for each platform is essential before deploying Copilot or Claude. Some risks are shared; others are unique to how each tool connects to your data.

802k
files at risk per organisation, on average
Concentric AI, 2022

15% +

of business-critical files are overshared with unverified users
Concentric AI, 2022
61%

of security leaders name data exposure as their top AI concern

Cloud Security Alliance, 2026

75%
of financial firms are using some form of AI

Bank of England, 2024

Microsoft Copilot risks

The primary concern for most organisations. Permission sprawl — hidden external links, broken inheritance, mis-aligned groups — means users can access far more than intended. When Copilot surfaces that content, the exposure multiplies.

Without consistent sensitivity labels, Microsoft Purview cannot enforce DLP rules. Content that should be restricted – financial documents, customer data, HR records – can be processed and included in Copilot’s responses if it lacks appropriate classification. Inappropriate classification is just as dangerous as no classification at all.

Attackers may embed malicious instructions hidden in content that Copilot retrieves – emails, documents, web content. The “SearchLeak” exploit demonstrated how a crafted q-parameter in a URL could cause Copilot to search a user’s mail and exfiltrate data by embedding content in image URLs. Prompt injection attacks remain one of the most active threat vectors against large language models.

AI agents can be manipulated through phishing or malicious content to reveal or forward sensitive information. As Copilot generates summaries and drafts from across Microsoft services, a single compromised input can influence what other users see.

AI models can produce incorrect or misleading content. If a summary misrepresents financial data or fabricates a quote, the reputational and legal consequences for a business can be serious.

Claude’s strength is its flexible connector model, but that flexibility is a risk if not governed. A connector for Google Drive, Slack, or Microsoft 365 might be granted overly broad scope – write permissions, wide-folder access, or sharing outside organisation boundaries. Without strict access controls, connectors can expose data well beyond what was intended.

Claude risks

Claude’s strength is its flexible connector model, but that flexibility is a risk if not governed. A connector for Google Drive, Slack, or Microsoft 365 might be granted overly broad scope – write permissions, wide-folder access, or sharing outside organisation boundaries. Without strict access controls, connectors can expose data well beyond what was intended.

If your organisation does not set custom retention policies, data – transcripts, projects, uploaded files – may be stored longer than needed. While Claude does not use this data for model training without permission, the data still exists and is still a target.

Similar to Copilot risks. Content arriving via a Slack channel, GitHub repository, or shared drive that contains malicious prompts can manipulate Claude’s behaviour and produce unintended outputs or leak sensitive information.

Once connectors are enabled, files may be shared through Claude in ways users are not fully aware of. Write permissions, if not explicitly restricted, could allow Claude to create or edit content in connected systems.

Real-world examples

These are not hypothetical risks. In early 2026, Microsoft confirmed a bug (CW1226324) that allowed Copilot Chat to summarise confidentially labelled emails in Sent and Draft folders, bypassing DLP and sensitivity labels. The issue affected many users before a fix was rolled out in February 2026.

 

The “Reprompt” exploit, discovered by Varonis and reported in January 2026, allowed attackers to use a crafted link to trick Copilot into exporting user data (files accessed, meeting details, conversation history) to an external server. Microsoft patched it by mid-January 2026.

 

In March 2025, the U.S. Congress banned Copilot use due to data security concerns – a clear signal of how seriously institutional bodies treat the risk of AI tools interacting with sensitive data.

These examples illustrate why data security teams and enterprise security teams need to treat AI deployment as a security event, not just a productivity upgrade. 58% of financial services firms added security controls specifically for Copilot deployment. Mismanaged permissions can lead to unintended data access across organisations of any size.

What security measures do you need before using AI tools?

If your business is not yet ready for Copilot or Claude, it is better to pause and prepare properly than to rush ahead and create vulnerabilities. Here are the security measures we recommend and deliver through our AI Data Security Pack.

01

AI Data Security Assessment Report

After completing an AI data security assessment, you receive a detailed report covering your current vulnerabilities, risk levels across both Microsoft Copilot and Claude, and a clear picture of where your data governance stands today.

02

Prioritised Action Plan

From there, we provide a prioritised action plan with a realistic timeline for implementing the security measures your business needs. This typically includes permissions cleanup, sensitivity label deployment, DLP policy configuration, and connector governance – phased so your team is not overwhelmed.

03

Phased Roadmap for Deployment

You also receive a phased roadmap for safe Copilot and Claude deployment, designed around your business’s actual readiness rather than a generic checklist. For some businesses, this means a pilot with a small team before a wider rollout. For others, it means pausing AI adoption entirely until foundational security work is complete.

04

Ongoing Support and Monitoring

Ongoing support options include managed security services, regular review schedules to maintain security as AI tools evolve and gain new capabilities, and a staff training programme covering both platforms. We also monitor for emerging threats – prompt injection techniques, connector vulnerabilities, platform updates – and adjust your defences accordingly.

05

Evolving Threat Landscape

AI systems can be vulnerable to data poisoning attacks, and malicious prompts can lead to data leakage. The threat landscape around AI is evolving rapidly. Having a partner who stays current with these developments is not a luxury for enterprise users alone – it is a practical necessity for any business using AI tools with access to sensitive data.

Next steps: book a Copilot security review

Your staff are already using ai tools. The only question is whether they are doing it safely. Putting a simple ai usage policy and basic ai governance in place is now essential, not optional. The goal is safe, productive use of ai, not banning artificial intelligence altogether.

 

Download the free AI Policy Template for UK SMEs and spend 30 to 45 minutes tailoring it to your business with your leadership team. It covers everything from approved tools to ethical use to incident response and regular audits.

 

Then contact We Do Your IT Support to book a Copilot security review. We will assess your current ai usage, Copilot readiness, GDPR risks and technical controls including ThreatLocker Web Control, and help you put a policy in place that staff will actually follow.

 

Call us on 0117 911 8808 or visit our website to schedule a consultation. No pressure, no strings attached. Just clear, practical guidance on getting ai governance right for your business.

Senior, happy man and call center with headphones in customer service, support or telemarketing at office. Mature businessman

FAQs

Is Microsoft Copilot safe to use at work?

Yes, provided your organisation has proper governance in place. Microsoft 365 Copilot only surfaces data a user already has permission to access. It respects sensitivity labels and DLP policies configured through Microsoft Purview. However, the CW1226324 bug in early 2026 – where Copilot summarised confidentially labelled emails despite protections – shows that even well-configured environments can be affected by software vulnerabilities. Regular auditing and monitoring are essential. Copilot can access all sensitive data users can access, which is why permission cleanup matters so much.

Yes, with the right safeguards. Claude uses user-delegated connectors and does not cache file content when connecting to Microsoft 365. It does not use organisational data for model training without explicit permission. However, safe usage depends on restricting connector scopes, applying retention policies, controlling write permissions, and maintaining audit practices. Is Claude AI safe? It is, but only as safe as the governance around it.

Yes. Conversation content, uploads, and files users interact with are stored. Default retention can be up to 18 months for conversation history. Users and administrators have controls for deletion and adjusting retention policies through Purview.

Claude stores chat, project, and file content following your organisation’s set retention policy. It does not use prompts or outputs for model training without express consent, and data storage is minimal, based on feature needs. If your organisation does not configure a custom retention policy, defaults will apply.

Microsoft processes and stores your data – prompts, files, responses – within its cloud services. For purposes such as bug monitoring and compliance, internal access exists. Microsoft states that organisational data is not used to train foundational AI models unless explicitly allowed. Data sharing with third parties is governed by Microsoft’s Data Protection Addendum and existing privacy policies. Data privacy and security in AI is a legitimate concern, and organisations should review these agreements carefully.

It can be, if that information is correctly classified with sensitivity labels, DLP is configured to block or exclude processing of labelled content, permissions are limited, and encryption is enforced. The CW1226324 bug demonstrated that even when labels are correctly applied, code-level issues can bypass protections. Defence in depth – multiple layers of control – is the right approach for confidential data and financial documents.

With the same caveats. If the source data (SharePoint, OneDrive, Google Drive) uses appropriate permissions and controls, and connectors are carefully configured with read-only access and restricted write permissions, then yes. Credential storage, SSL, and scope of access must all be audited. Is Claude safe for sensitive data? Only if the environment around it is properly secured.

They are entirely different products. Microsoft 365 Copilot is a productivity tool embedded in apps like Word, Excel, Outlook, and Teams – it helps with drafting, summarising, and analyzing data across your Microsoft 365 environment. Microsoft Security Copilot is a separate product designed for cybersecurity analysts and SOC teams, focused on threat investigation and incident response. This page covers Microsoft 365 Copilot only.

Microsoft Purview Information Protection enables data classification, sensitivity labelling, encryption, and rights management. It integrates directly with Copilot to enforce access controls – sensitivity labels prevent Copilot from processing, summarising, or generating content from protected sources unless the right users have the appropriate rights. Purview also supports DLP policies, auditing, retention policies, and eDiscovery, making it foundational for any AI data security strategy. Microsoft Purview data governance capabilities extend across the full data estate.

Classified data allows policy rules to distinguish between public, internal, and confidential information. This enables DLP to block or warn when sensitive data is used in prompts, prevents sensitive files and emails from being processed by AI, and ensures appropriate encryption. Without data classification, control simply cannot be applied – AI tools will treat all accessible content equally, regardless of how sensitive it actually is.