Microsoft Copilot ranked as the most privacy-invasive of 13 popular AI platforms in an Incogni study highlighted by PCMag on August 20, but that result needs an important qualification for Windows and enterprise users: it describes the consumer Copilot experience and Microsoft’s wider consumer data practices, not Microsoft 365 Copilot under enterprise data protection.

Incogni’s analysis, conducted from June 15 through July 6, assessed ChatGPT, Claude, Copilot, DeepSeek, Gemini, Grok, Kimi, Meta AI, Perplexity, Pi, Qwen, Vibe, and Z.ai across 11 privacy criteria. Its weighted demerits covered training on prompts, the availability and clarity of opt-outs, third-party sharing, policy transparency, profiling, and mobile-app collection. Lower scores meant fewer privacy concerns.

PCMag reports that Vibe and ChatGPT had the fewest privacy demerits, while Copilot placed last, narrowly behind Meta AI and Kimi. The result is a useful warning for people who use Microsoft’s public-facing chatbot with a personal account. It is a poor shorthand for whether an organization can safely deploy Copilot in Microsoft 365, where Microsoft applies different contractual, technical, and training rules.

The practical takeaway is narrower but more valuable: a Copilot prompt has different privacy consequences depending on which Copilot a person is using, which account signs them in, and where the chat is embedded. IT departments need to teach that distinction before “Copilot” becomes the catch-all answer to employees’ questions about AI privacy.

Split-screen illustration of AI-powered collaboration and secure cloud-based business systems.Incogni’s ranking measures policy exposure, not a breach​

The Incogni study is principally a policy and product-controls comparison. It does not establish that Microsoft exposed Copilot chats to other users, that a data breach occurred, or that every prompt from every Copilot surface is used for training. Its ranking is instead a judgment about the privacy terms, opt-out design, data-use disclosures, and profiling practices available during the study window.

That is still consequential. Privacy policy is often the only advance notice a consumer gets before entering personal health details, financial questions, family information, work notes, uploaded images, or sensitive documents into a chatbot. A system that permits broad use of conversation activity by default, retains it for a long period, or makes users hunt for controls creates a larger privacy exposure even without an incident.

The study placed Claude, DeepSeek, Gemini, Grok, Perplexity, Pi, Qwen, and Z.ai in its middle tier. Kimi reportedly received maximum demerits for how it handles data for training. Copilot’s poor showing was driven most sharply by the study’s assessment of personalized-data handling, while Meta AI and Copilot were identified as especially aggressive in the profiling-related test.

Those findings should be read as a snapshot. Incogni itself says its research was collected between June 15 and July 6, and policies can change quickly. A privacy ranking should therefore prompt users to inspect current controls; it should not become a permanent label attached to an entire vendor’s sprawling product line.

Consumer Copilot can use conversation activity for model training​

Microsoft’s current Copilot privacy FAQ confirms the core concern behind the ranking: for eligible people using the consumer Copilot service while signed in with a personal Microsoft account or another supported sign-in method, Microsoft may use conversation activity for generative-AI model training unless the user opts out.

Microsoft says the material can include voice and conversation activity, along with images or files uploaded during conversations. The company says it removes or de-identifies information such as names, phone numbers, email addresses, physical addresses, device identifiers, and sensitive personal data before training. De-identification reduces direct identity linkage; it does not make a detailed prompt suitable for casual disclosure.

Microsoft also says consumer Copilot conversations are stored for 18 months by default, although users can delete individual chats or their full history. Its policy notes that some conversations can be subject to automated and human review for product-improvement and digital-safety purposes. There is no general opt-out from human review when Microsoft is investigating a suspected violation of its code of conduct.

The training opt-out is forward-looking. Turning it off tells Microsoft not to use future eligible conversations to train its generative AI models. It does not retract information already incorporated into a training process, and it does not necessarily disable personalization. Microsoft says a user can opt out of training while retaining a personalized Copilot experience that remembers details from prior conversations.

This is the distinction users should internalize: deleting a chat, switching off model training, clearing history, and disabling personalization are related controls, but they are not the same action. Treating them as interchangeable is how people believe they have removed data when they have only stopped one future use.

Microsoft 365 Copilot is governed by a separate data boundary​

The Incogni result becomes misleading if it is applied directly to Microsoft 365 Copilot, Copilot Chat with enterprise data protection, Security Copilot, or other commercial services signed in through an organization’s Microsoft Entra ID account.

Microsoft’s enterprise documentation states that prompts and responses in Microsoft 365 Copilot Chat are processed within the Microsoft 365 service boundary and are not used to train underlying foundation models. The same policy separation applies to organizational Entra ID users in Microsoft’s consumer Copilot documentation. Microsoft also excludes Copilot conversations integrated into Word, Excel, PowerPoint, and Outlook for Microsoft 365 Personal and Family subscribers from model training.

That does not mean an enterprise administrator can stop thinking about data handling. Microsoft 365 Copilot can process prompts, generated answers, attached files, citations, and Copilot activity history as part of its service. Depending on the feature enabled, Copilot Chat can use a file that the user uploads, a document deliberately selected through ContextIQ, content open in Word, Excel, or PowerPoint, or work data available through Outlook and licensed Microsoft 365 Copilot capabilities.

Microsoft says its commercial services enforce existing user permissions and use tenant isolation, encryption in transit and at rest, and the organization’s compliance commitments. But the service can only respect permissions that the tenant already has. If SharePoint sites are broadly shared, sensitivity labels are absent, external sharing is uncontrolled, or users can attach sensitive material to unapproved agents, Copilot can reveal longstanding information-governance failures more quickly and more conversationally.

The privacy risk in a commercial tenant is therefore less about consumer-model training and more about oversharing, retention, logging, connected agents, and poor access governance. Those are different problems, requiring different controls.


What users and administrators should change now​

For personal Copilot users, the immediate step is to open Microsoft Copilot’s privacy settings and disable the control that allows conversation activity to be used for generative-AI model training. Do not assume that using the service through Edge, Windows, a mobile app, or a Microsoft account changes the underlying consumer policy in your favor. Confirm the signed-in account and the product surface.

Personal users should also remove chats that no longer need to remain in history, review personalization settings separately, and avoid pasting content that would be damaging if retained or reviewed: credentials, recovery codes, unredacted medical information, legal documents, customer records, source code, confidential financial data, or internal incident details. The same restraint applies to attachments. A “summarize this PDF” prompt can disclose much more than the user notices in the moment.

For organizations, the work is administrative rather than merely advisory:

  • Confirm whether employees are using consumer Copilot accounts, Microsoft 365 Copilot Chat with enterprise data protection, browser sidebars, third-party AI tools, or a mix of all four.
  • Define which AI services are approved for internal content, and ensure employees have a clear route for sensitive work that does not force them toward personal accounts.
  • Review SharePoint, OneDrive, Teams, and Outlook permissions before expanding Microsoft 365 Copilot access, because Copilot honors existing access rather than repairing excessive sharing.
  • Audit agents, connectors, browser permissions, and web-grounding settings, since each can create additional paths for a prompt or organizational content to be processed.
  • Apply sensitivity labels, data-loss-prevention rules, retention policies, and audit logging before treating Copilot deployment as a productivity-only project.

The ranking’s real warning is the product name​

PCMag is right to flag the opacity surrounding chatbot privacy. Tom’s Guide reached a similar conclusion in a July comparison of major assistants: there is no industry-standard privacy model, and controls vary sharply between providers. ChatGPT’s consumer toggle may be easier to find, Gemini’s activity setting can affect history and personalization, and Claude’s policy includes its own safety-related exceptions.

But the sharper finding for Windows users is that “Copilot” no longer identifies one privacy posture. The public consumer chatbot, Copilot in Microsoft 365 apps, Copilot Chat under enterprise data protection, and specialized products such as Security Copilot operate under different rules and use different data sources.

Incogni’s last-place ranking is a reason to turn off consumer training where eligible and to reconsider what belongs in a personal Copilot prompt. For IT administrators, it is also a reason to stop using vendor names as privacy classifications. Inventory the exact Copilot experience, account type, license, data connection, and retention path in use. That is where the meaningful answer begins.