In June 2025, researchers disclosed the first zero-click exploit against a production enterprise AI assistant. A single markdown email, never opened by the user, was enough to make Microsoft 365 Copilot hand over data from prior chats and files to an attacker. No malware. No phishing click. Just Copilot doing its job on content it was authorized to read.
That’s the uncomfortable shape of the question landing on CISO desks: Microsoft Copilot is now integrated across Microsoft 365, reading the same files, mail, and chats its users can already access. The board wants a straight answer on whether it’s safe to deploy at enterprise scale, and the honest answer starts with your tenant, not Microsoft’s platform.
Copilot’s safety depends on how your enterprise governs it. Tenant configuration is foundational, but visibility, runtime controls, and AI governance ultimately determine enterprise risk. Microsoft has built substantial platform-level protections, but they don’t extend to the variable that drives much of the Copilot exposure: the state of your own tenant. Permissions accumulated over a decade and unconfigured data controls decide what Copilot can reach. Fast-multiplying agents widen that surface further.
The difference between a productivity engine and a discovery engine for content nobody locked down sits in the tenant, and this article walks through how to close that gap, from Microsoft’s shared-responsibility boundary to the runtime controls that make deployment defensible.
Key takeaways
- Copilot can be safe at enterprise scale only when tenant permissions, data controls, and agent access are properly governed.
- Microsoft’s platform protects model infrastructure, tenant isolation, encryption, and covered enterprise data, while customers remain responsible for access governance, usage policy, output review, and legal compliance.
- Overshared content, indirect prompt injection, and rapidly multiplying agents are the principal risks, as Copilot can retrieve authorized data and act via delegated access.
- A defensible rollout combines staged permission remediation with AI-specific visibility, intent-aware inspection, runtime enforcement, audit evidence, impact assessments, and human oversight.
Is Copilot safe out of the box? Microsoft’s commitments and their boundary
Microsoft’s platform commitments are extensive, though narrower than many buyers assume. Microsoft states that prompts, responses, and data accessed through Microsoft Graph aren’t used to train the foundation models used by Microsoft 365 Copilot. Its enterprise commitments also cover data isolation between tenants and encryption at rest and in transit. They include an AI management system certified to ISO/IEC 42001:2023.
Those commitments come with documented caveats. Anthropic models are currently excluded from the EU Data Boundary, and web search queries are excluded as well. A Dutch privacy assessment found that privacy risks remain “orange” despite improvements.
More important is what stays on your organization’s side of the line. Customer-configured data controls shape the protection available. These controls include data loss prevention and detailed interaction capture. Industry shared-responsibility guidance places the enterprise application owner in a distinct accountability tier, a role that needs clear ownership and enough staff to enforce governance. Your organization remains responsible for reviewing outputs and validating decisions. You must also ensure compliance with applicable laws.
Microsoft secures the model and infrastructure. Your organization owns enterprise data governance and AI usage policy, along with oversight. Most Copilot exposure comes from controls your organization manages.
You Can’t Secure What You Can’t See
WitnessAI gives you network-level visibility into every AI interaction across employees, models, apps, and agents. One platform. No blind spots.
Explore the PlatformWhere enterprise controls strengthen Copilot safety
In practice, most Copilot exposure comes from the organization’s side of the responsibility model. Three patterns consistently emerge across enterprise deployments: content that was overshared long before Copilot existed, prompt-injection attacks targeting the AI layer rather than the code, and a growing population of agents operating with delegated access. Each one needs a different control, and the sections below walk through what to look for and how to close the gap.
1. Making oversharing visible
Copilot reduces the protection that security through obscurity once provided. By pulling from across the tenant on demand, Copilot makes widely over-shared documents far more accessible than the underlying permissions ever suggested.
This amplifies gaps such as over-permissioned sites and missing sensitivity-label protections. A salary file shared too broadly years ago was once merely hard to find; semantic search makes it retrievable in a chat window.
Oversharing is one issue organizations can address during a pilot. Gartner’s global rollout data don’t explain why deployments remain limited, but they show that 94% of organizations report measurable benefits while only 6% have completed global rollouts. Another 72% remain in pilots as they establish deployment controls.
2. Managing AI prompt injection at the AI layer
Many attacks against Copilot target the AI runtime rather than the underlying application code. EchoLeak attack analysis documents CVE-2025-32711, a CVSS 9.3 zero-click prompt injection attack on a production enterprise AI assistant. Instructions hidden in a Markdown email caused Microsoft 365 Copilot to collect data from prior chats and files. Copilot then sent it to an attacker-controlled server.
Indirect prompt injection hides instructions inside documents, emails, or web content that Copilot retrieves and obeys. Security researchers treat this as a structural risk for RAG-based systems like Copilot rather than a bug to be patched, because the model is doing exactly what it was designed to do: read retrieved content and act on it. Without appropriate controls, that same behavior can exfiltrate data or spread disinformation.
3. Identity governance for AI agent sprawl
Copilot Studio has made agent creation low-code, and enterprise tenants are accumulating agents faster than their identity infrastructure can govern them. Most organizations don’t yet have a clear inventory of which agents exist, who owns them, what data they can reach, or what actions they can take on a user’s behalf.
Those agents join the human and digital workforce with delegated access to enterprise data. As agent populations grow, you’ll benefit from governing identities, permissions, tools, and actions with the same discipline applied to human users.
Blocking AI Isn’t a Strategy. Governing It Is.
WitnessAI enforces intent-based policies, routes prompts to the right models, and redacts sensitive data in real time so your teams keep moving while your data stays protected.
Explore ControlThe controls that make Copilot deployment defensible
Closing these gaps requires controls beyond policy documents because Copilot controls must act at the moment of interaction. A written policy can’t intercept a prompt or reshape an output; only a runtime layer can.
Governance and compliance establish the foundation. Layered AI runtime enforcement adds continuous inspection, policy enforcement, and protection as AI interactions occur.
Four capabilities make that approach practical:
- Network-level visibility: Network-level visibility extends beyond browsers to native applications, embedded AI, enterprise copilots, AI agents, and shadow AI, providing complete visibility into enterprise AI interactions. Much AI usage occurs through unmanaged personal accounts, leaving organizations with limited visibility into who uses which tools and where data flows.
- Intent-based Policy Enforcement: Gartner’s AI-readiness guidance distinguishes AI-specific governance, runtime inspection, and enforcement from existing security tooling. An M&A summary or drug-research upload may contain few obvious flagged terms, even when its purpose and context make it sensitive. Conversational AI therefore benefits from controls that account for purpose and context.
- Enforcement options: Enforcement can offer more choices than allow or block. Without a practical sanctioned path for AI use, employees may turn to personal accounts or other unmanaged tools. Controls can warn users or route sensitive prompts to approved internal models. They can also tokenize data to preserve productivity while protecting the enterprise.
- Audit evidence: Runtime guardrails need supporting audit evidence, and regulators increasingly expect controllers to demonstrate compliance with evidence rather than assert it. The legal exposure has precedent. An Air Canada ruling ordered the airline to pay C$812.02 after its chatbot misstated a fare policy. The tribunal rejected the argument that the chatbot was a separate legal entity.
Your security team handles visibility and runtime defense, while legal and compliance own audit evidence and DPIAs. HR sets sensitive-content boundaries. This division makes Copilot adoption easier to govern.
Runtime AI Threats Need Runtime Defense.
WitnessAI’s enterprise AI firewall delivers bidirectional runtime defense, blocking prompt injections, jailbreaks, and data exfiltration before they reach your models or your customers.
Explore ProtectHow WitnessAI secures Copilot across employees and agents
WitnessAI applies these controls through its Secure AI Enablement Platform across employee AI usage, enterprise copilots, custom AI applications, and AI agents. Our capabilities address the embedded, native-app AI footprint and growing agent population that Copilot creates. Traditional security tools were designed to monitor traffic and access. They track data movement, but they weren’t designed around this AI-specific context.
We organize that protection across three core modules:
- Observe: Our network-level discovery, delivered through Observe, surfaces Copilot in Word and Visual Studio Code without endpoint clients or browser extensions. This Microsoft Copilot support includes Microsoft 365 Copilot and GitHub Copilot within Visual Studio Code. Discovery spans more than 4,000 AI applications. It surfaces Shadow AI alongside sanctioned Copilot and makes agent connections to external MCP servers visible at the network layer.
- Control: Proprietary drug-research content may contain no obvious flagged keywords, so intent-based policy classifies it by purpose instead. With the Control module, we offer four responses: allow, warn, block, or route sensitive prompts to approved internal models. Real-time data tokenization replaces PII and credentials before a prompt reaches a third-party model, then rehydrates the original values so that sensitive data stays within enterprise control.
- Protect: Protect delivers bidirectional runtime protection against prompt injection, jailbreaks, sensitive data exposure, and harmful responses while maintaining comprehensive audit evidence. Our audit trails cover AI interactions captured through the platform, from prompt through response and policy outcome. Through bidirectional runtime defense, the Protect module detects and blocks prompt injection and jailbreak attempts in traffic routed through the platform before it reaches models. The same scoped layer filters harmful outputs before they reach users.
At the network level, our coverage includes AI-scale data from more than 4,000 AI applications, more than 40 countries, and millions of daily AI interactions. An anonymized WitnessAI customer quotation from an airline VP of cybersecurity describes the outcome directly: “The ability to see every AI interaction across our global workforce has transformed our security posture.”
Moving from Copilot hesitation to Copilot confidence
Copilot can be safe for enterprise use when the enterprise supplies the layer the platform leaves to the customer. If you’re under pressure to move Copilot from pilot to production, this is the layer that unblocks the board conversation.
That layer provides visibility into how AI is used and intent-aware control over where data flows. It also adds runtime defense against AI-native attacks and audit evidence for regulators and boards. A defensible control framework can speed deployment and give stalled pilots a clearer path to production.
Our Secure AI Enablement Platform provides the shared governance layer that allows security and AI teams to accelerate AI adoption while maintaining security, compliance, and control. We combine intent-based policies and bidirectional runtime defense with guardrails for employees and agents. Schedule a demo to see how we govern Microsoft Copilot in your environment.