As reported by The Sydney Morning Herald, AFL participation manager Gabrielle Boyle resigned on June 26, three days before the league switched on Copilot on June 29, after asking to opt out. The newspaper says AFL HR told her in writing that she did not have a right to prevent her work from being accessed by the organisation’s AI systems, and warned that non-compliance with its policy could lead to performance management.
Boyle’s wider objections to generative AI — including its energy use, effects on work and claimed existential risks — are personal political views, not a technical case against Microsoft 365 Copilot. But the AFL dispute is still useful for IT leaders because it separates two questions that are too often bundled together: whether Copilot creates a new external data exposure, and whether an employer has adequately explained the operational consequences of introducing it.
Microsoft’s own documentation supports part of the AFL’s technical explanation. Microsoft 365 Copilot uses Microsoft Graph and is designed to retrieve only content the signed-in user can already access; prompts, responses and Graph-grounded organisational data are not used to train Microsoft’s foundation models. In that narrow sense, deploying the service does not give an employee a new key to colleagues’ restricted SharePoint files, Teams chats or mailboxes.
But “it respects existing permissions” is a security property, not a complete change-management plan.
Copilot Does Not Create Permissions, but It Can Expose Bad Ones
The immediate concern for a Microsoft 365 tenant is rarely that Copilot breaks SharePoint or Exchange access control. It is that Copilot makes overly broad access more visible and easier to exploit.
A document buried in an old SharePoint site may already be accessible to hundreds of staff through a legacy group, an “Everyone except external users” setting, an inherited permission or a folder shared years ago for a project that ended. Before Copilot, finding it might require knowing that it exists, navigating to the right site and using search terms that match the file. With Copilot, a natural-language prompt can turn that same content into an answer, summary or draft.
Microsoft has been explicit that the service honors the organisation’s identity model, permissions, sensitivity labels, retention rules and administrative controls. That is precisely why the AFL’s reported claim — that Copilot could access only files and emails Boyle could already open — is plausible. Yet it also means a Copilot deployment is a practical audit of everything a worker can already reach.
For an AFL staff member working with community football programs, that could include participant records, internal planning material, team communications and reports containing data from other systems. The Herald reported that Boyle had raised a separate concern in March about a trainee potentially running a list of youth participants through an AI tool. The AFL’s reported AI policy subsequently barred staff from uploading personal or confidential information to unapproved tools.
That policy distinction is important. Microsoft 365 Copilot operating within a properly configured Microsoft 365 tenant is not equivalent to an employee pasting data into a consumer chatbot. But an organisation cannot rely on that distinction if staff do not understand which Copilot product they are using, what data source is being accessed, whether web grounding is enabled, what is logged, and which third-party tools are approved.
The AFL’s reported policy lists a broad set of endorsed products: ChatGPT, Microsoft 365 Copilot, Salesforce Agentforce, Cursor and Claude Code. Those services do not share one data boundary, one administrator console or one contractual privacy model. A policy that treats them as a single category called “AI” risks obscuring the controls administrators must actually configure.
The Missing Detail Is the Rollout Design
The Herald reports that AFL staff received less than two weeks’ notice before the Copilot rollout. The newspaper also reports that about 35 percent of staff had said in an earlier internal survey that they were uncomfortable with workplace AI adoption.
Neither figure establishes that the AFL’s implementation was unlawful, and the AFL has not publicly released the full deployment plan, policy, licence scope or risk assessment. That absence matters. The account leaves unanswered whether the AFL enabled paid Microsoft 365 Copilot licences, Microsoft 365 Copilot Chat with enterprise data protection, Copilot features within particular apps, or some combination of those services.
Those are materially different deployments. A Microsoft 365 Copilot licence can ground answers in a user’s work data through Microsoft Graph. Copilot Chat can have narrower capabilities depending on tenant configuration and licensing. Web search, agents, plugins, connectors, meeting transcription, Teams recording policies and sensitivity-label settings can all alter what users can ask and what content is processed.
The AFL’s reported assurance that its information remained “on AFL systems” is also imprecise if taken literally. Microsoft 365 Copilot is a Microsoft-hosted cloud service and processes data within Microsoft’s commercial-service boundary under the customer’s contractual and compliance commitments. The more accurate assurance, based on Microsoft’s published documentation, is that customer prompts, responses and Graph data are protected under those commercial terms and are not used to train foundation models.
That is a meaningful assurance. It is not the same as saying AI interaction data does not exist.
Microsoft states that Copilot interaction content — prompts, responses and cited grounding material — is stored as part of Copilot activity history and processed under the customer’s Microsoft 365 commitments. Organisations can use Microsoft Purview and audit capabilities to govern and investigate that content. For compliance teams, this may be a benefit. For employees worried that their daily work will be captured, reviewed or judged in new ways, it is a change that deserves a plain-language explanation.
The Australian Services Union made that point to the Herald, arguing that the question is not exhausted by whether a tool stays inside a worker’s existing access rights. The practical issue is whether the system changes how output is captured and assessed. The AFL has reportedly said it supports responsible AI use and respects differing views on new technology, but it has not publicly explained what accommodation, if any, was available for workers who did not want to use Copilot.
Consultation Is Not a Veto, but It Is Not Optional in Every Case
The AFL dispute should not be read as a general right for employees to reject software on an employer-owned device. Australian privacy law includes an employee-records exemption for private-sector employers handling records directly related to current or former employment. The Office of the Australian Information Commissioner also notes that the exemption is limited; it does not cover every piece of data an employer may possess, nor does it automatically govern data held by outside service providers.
Likewise, consultation obligations do not mean individual staff can block a technology deployment. Fair Work Ombudsman guidance says consultation clauses in awards and enterprise agreements generally apply where an employer makes a definite decision to introduce major changes in technology that are likely to have significant effects on employees. Employers must notify affected workers, provide relevant information, invite feedback and genuinely consider it. They retain the final management decision.
Whether a Copilot rollout meets that threshold depends on the applicable enterprise agreement or award, the roles involved and the actual effect of the deployment. Requiring a new assistant to be available on a laptop is one thing. Rewriting job expectations around AI-generated output, requiring workers to use it, retraining staff, changing performance measures or reducing roles is another.
The Herald reports that Boyle was told the AFL expected policy compliance from all staff. But public reporting has not established whether using Copilot itself was mandatory, whether particular tasks had to be completed with it, whether her role was covered by a consultation clause, or whether the AFL conducted a documented impact assessment. Those facts would determine far more than the headline dispute over an opt-out.
NSW’s New Digital Work System Law Is Relevant, but Not a Copilot Ban
New South Wales has moved faster than most Australian jurisdictions in treating digital systems as workplace safety issues. The Work Health and Safety Amendment (Digital Work Systems) Act 2026 defines a digital work system broadly enough to include algorithms, artificial intelligence, automation and online platforms.
SafeWork NSW says the legislation clarifies that existing employer duties apply to managing risks arising from digital work systems. It also adds a duty relating to health and safety risks from the allocation of work by those systems, while providing a framework for work health and safety entry permit holders to seek assistance accessing and inspecting relevant systems where a suspected breach exists.
That legislation does not create a general employee right to refuse Microsoft Copilot. Nor does it establish that a general-purpose productivity assistant is inherently unsafe. Its relevance is more practical: employers cannot treat AI deployment as a procurement task that ends once identity, licensing and data-loss-prevention settings are configured.
If an AI system creates unreasonable monitoring, intensifies workloads, changes task allocation, contributes to psychosocial harm or drives opaque performance decisions, workplace safety duties may become relevant. SafeWork NSW has said further provisions and guidelines require commencement steps, so the operational reach of the new inspection powers is still developing. The AFL case illustrates why that detail matters: the alleged harm is not a data breach or a technical fault, but distress arising from a compulsory workplace change.
What Microsoft 365 Administrators Should Take From the AFL Dispute
The operational lesson is not to offer a blanket individual opt-out whenever Microsoft introduces a Copilot feature. That could be unworkable, particularly where an organisation needs consistent records, security controls or supported collaboration tools. The lesson is to make rollout choices legible before turning the service on.
A defensible deployment should establish, in writing, which Copilot product is being enabled; which users are licensed; whether web grounding and external connectors are permitted; where prompts and responses are retained; how audit data may be used; and whether employees are expected, encouraged or merely permitted to use the service.
It should also include a permissions remediation program rather than treating Copilot’s permission inheritance as proof that the tenant is ready. Review broad SharePoint sharing, stale Microsoft 365 groups, old project sites, confidential-data labels, Teams meeting policies and Purview controls before promising staff that the assistant can see only what it should.
Finally, administrators need to distinguish a policy against pasting confidential information into public AI tools from governance of enterprise AI. The first is a necessary prohibition. The second requires product-specific controls, approved-use cases, manager training, incident reporting, retention decisions and an answer to a question employees will reasonably ask: Will my Copilot prompts or AI-assisted output be used to assess me?
Boyle’s resignation, as reported by The Sydney Morning Herald, is an extreme individual response to a workplace technology rollout. It does not establish a legal right to veto Copilot. It does show that an organisation can have a technically accurate security explanation and still fail to persuade the people expected to work under the new system.