The short answer
Ungoverned Copilot is Copilot switched on. Governed Copilot is Copilot set up.
Both run on the same Microsoft license, in the same Word, Excel, Outlook and Teams. Switched on, Copilot keeps Microsoft's defaults: it reads everything each person can open and can use every AI provider Microsoft turns on. Once it is set up, someone has chosen those settings for your firm and kept a dated record of each choice. Ask whoever runs your Microsoft 365 the five questions below, and get the answers in writing. If they cannot answer two or more, do the permission review before anyone else gets a license.
First, what Copilot actually is
If you are new to this, start here.
§Copilot, in plain terms
+
Copilot is Microsoft's AI assistant for work. It sits inside the tools your staff already use. It drafts in Word, works through a spreadsheet in Excel, summarizes a long thread in Outlook, and catches someone up on a Teams meeting. It also has a chat window of its own. Staff can build small assistants on top of it, called agents.
The name changed this summer. The work version is now called Microsoft Copilot. Until recently it was Microsoft 365 Copilot. The same Copilot app now serves personal accounts too. So the name alone no longer tells you which rules apply. The account a person signs in with does. Microsoft says a firm's "security, privacy, compliance, and administrative controls continue to apply when you use Copilot with your work or school account." A staff member signed in with a personal account is outside those controls.
Copilot answers from what the person can already open. Microsoft says Copilot presents "only data that each individual can access." It does not reach past a person's permissions.
That last point is usually offered as reassurance. It is also why governance matters, as the next section explains.
What "ungoverned" means
"Ungoverned" is not an accusation. It does not mean anyone did something wrong. It means Copilot is running on the settings it arrived with. Microsoft wrote those settings for every business in the world, not for a firm that holds tax returns, client matters or account numbers.
§What the defaults look like today
+
It reads everything each person can open. In many small firms, nobody ever set those permissions on purpose. They built up over years: a server moved to the cloud with its folders intact, links shared with "anyone," access given to a whole folder when someone needed one file. Copilot does not create those gaps. It makes them easy to find with a plain question. Our brief Copilot Does Not Leak. It Reveals. walks through where they come from.
It can use AI providers the firm never chose. Copilot's AI now comes from three sources. The first is GPT models Microsoft runs itself. The second is GPT models OpenAI runs as a Microsoft subprocessor, meaning a company Microsoft hires to do part of the work. They have been on by default for eligible commercial customers since July 24, 2026. The third is Claude models Anthropic runs as a Microsoft subprocessor. They are on by default for most commercial customers outside the EU, EFTA and UK. Both outside providers are excluded from Microsoft's in-country processing commitments, its promises to run the AI inside a given country.
Nothing knows which files are sensitive. Microsoft's labels and data-loss rules exist. Out of the box, none of them know which folder holds client returns.
Staff can build their own agents. Agent Builder comes with the Copilot license unless an administrator limits it.
There is no record. Your firm can search and keep Copilot activity, but only once someone sets that up. Until then, the firm has no record of what anyone decided, or when.
None of this is a flaw in Microsoft's product. It is how a product built for every business arrives, before anyone sets it up for yours.
The two, side by side
The same license, the same apps. Every row below is a setting someone either chose or left alone.
| Question | Ungoverned | Governed | What it means |
|---|---|---|---|
| What it can read | Everything each person can open, overshared folders included | What a permission review leaves open | The partner compensation file stops turning up in answers |
| Sensitive client files | Treated like any other file | Labeled, and kept out of Copilot where the work does not need them | Returns, matters and payroll get a rule, not just a folder name |
| Sensitive numbers in prompts | No rule | A rule that stops Copilot answering when a prompt holds a Social Security number (preview) | A slip gets caught before it becomes an answer |
| Which AI models | Microsoft's own, plus OpenAI's and Anthropic's, both on by default for most commercial customers | Chosen for each group of staff, and dated | The firm decides who uses which provider |
| Outside AI apps | Whatever an administrator has approved, whenever they approved it | A written decision on each one, including Claude's Microsoft 365 connector | One administrator consent can open your whole Microsoft 365: decide on purpose |
| Agents | Agent Builder comes with the license unless an administrator limits it | Reviewed agents that read one library and hand the decision back to a person | An agent that cannot wander cannot wander into a client file |
| The record | None by default | Retention turned on, searched once to prove it works, every setting dated | The firm can answer "show me" |
| When Microsoft changes something | Nobody notices | Checked every quarter | This July alone, a new provider was switched on by default |
Five things that change
Five things that change
Governance sounds abstract. In practice it comes down to five things, each with a before and an after.
Ungoverned (switched on)
- Reads everything each person can open
- Both outside AI providers on by default
- No record
Governed (set up)
- Reads only what the permission review leaves open
- Outside providers off for anyone who handles returns
- Every setting dated
01What it can read
+
Ungoverned: Copilot reads everything each person can open. In a small firm that is usually more than anyone intended.
Governed: Someone first reviews who can open what, against the people who work there this week rather than an old org chart. Copilot then reads only what that review leaves open.
This is the single biggest difference, and it has nothing to do with AI. The review would be worth doing even if Copilot did not exist.
02Labels and rules
+
Ungoverned: A client return and a lunch menu look the same to the system.
Governed: Client folders carry sensitivity labels, tags that mark a file as confidential. Microsoft Purview is where Microsoft 365 keeps its data protection settings. Purview then keeps Copilot away from labeled files where the work does not call for them. When a label encrypts a file, Microsoft says Copilot "honors the usage rights granted to the user." In plain terms, Copilot can do with that file only what the person is allowed to do. A second rule, still in preview, can stop Copilot from answering when a prompt contains a number such as a Social Security number.
A label built around your firm's actual work turns a folder name into a rule.
03Which AI models run, and for whom
+
Ungoverned: Copilot can send work to GPT models Microsoft runs, GPT models OpenAI runs, and Claude models Anthropic runs. For most U.S. commercial tenants (a tenant is a business's own Microsoft 365), both outside providers are on by default.
Governed: Your firm decides, group by group. Microsoft lets administrators set both providers for specific users or security groups, so the choice is not everyone or no one. A tax firm might keep everyone who handles return data on the models Microsoft runs itself. It might allow Claude for a named group that never touches returns.
Why it matters: Where the data is stored and where the AI runs are two questions, with different answers. Storage is settled. Microsoft stores the prompt and the response, at rest, in the default geography of your firm's Microsoft 365. Where that default geography is the United States, Microsoft commits to keeping them there. Where the model runs is the open question. Microsoft says its own models route requests "to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization periods." Microsoft expects to offer processing inside the United States for U.S. tenants by the end of 2026. It does not commit to it today. For a firm under IRC §7216, that is why Claremont's position is this. Until Microsoft commits to U.S.-only processing and the firm can show who reaches the data, client tax return information goes into Copilot only with each client's consent. Our brief Governed Copilot vs Claude covers this in full.
04Agents
+
Ungoverned: Agent Builder comes with every Copilot license unless an administrator limits it, so staff can build agents on whatever they can open.
Governed: Someone reviews each agent before anyone uses it. Each one reads one library and cites the document behind every line. It says "not found" instead of guessing, and hands the decision back to the professional. It does not, on its own, send anything it writes.
An assistant limited to one folder is a smaller risk than a general assistant that can read your whole Microsoft 365.
05The record
+
Ungoverned: If a client, an insurer or an examiner asks what the firm did before turning on AI, the honest answer is "we turned it on."
Governed: Every decision above carries a date and the role of the person who owns it. Microsoft Purview can search and retain Copilot interactions. In a governed setup, someone turns that retention on and tests it. Your firm can hand over a record rather than a promise.
Why regulated firms feel the difference
For a firm without client data, ungoverned Copilot is mostly an efficiency question. For a regulated firm, the rules already ask for the things governance produces.
§What the rules already ask for
+
The FTC Safeguards Rule. For the firms it covers, tax preparers among them, it asks that each person can reach only what their job needs. It also asks that someone reviews that access periodically.
16 CFR 314.4(c)(1)(ii)
Limit authorized users' access only to customer information that they need to perform their duties and functions, or, in the case of customers, to access their own information;
16 CFR 314.4(c)(1)(ii)It also asks firms to "monitor and log the activity of authorized users," under 16 CFR 314.4(c)(8). Ungoverned Copilot reads everything each person can open. In a firm where nobody has reviewed who can open what, that works directly against the access rule. A firm with no record of its settings cannot show the monitoring and logging.
IRC §7216. For tax firms, the question is whether return information is disclosed outside preparation. The answer depends on facts such as which AI provider handles a prompt, and where. Governance does not answer the legal question. It gives counsel the facts to answer it with. The full treatment is in Governed Copilot vs Claude.
Clients and insurers. They increasingly ask how a firm uses AI. "We use Microsoft" is not an answer to that question. A dated record is.
What governed does not mean
A few misunderstandings come up often enough to address directly.
§Four things it is not
+
It does not mean blocking AI. The point is to give staff a governed tool that beats the personal accounts they would otherwise reach for. It is not to take tools away.
It does not mean Copilot runs inside your firm. Copilot works within Microsoft's service, under your firm's agreement with Microsoft. The models run in Microsoft's cloud, or with the outside providers Microsoft uses. Governance decides which ones, and for which staff.
It does not make a firm compliant on its own. No software does. Governance produces the settings and a dated record of them. Whether they satisfy a given rule is a judgment for your firm and its advisers.
It is not a one-time project. Microsoft changes Copilot often. In one week this July, it switched on OpenAI's own models by default. It also added a setting that lets non-federal customers in GCC, Microsoft's government cloud, use Anthropic models. A governed setup is checked again every quarter.
How to tell which one you have
Ask whoever runs your Microsoft 365 these five questions, and ask for the answers in writing.
- When did someone last review who can open which files, and is there a record of it?
- Which AI providers can Copilot use in our Microsoft 365, and for which people?
- Are our client folders labeled, and does anything keep Copilot away from them?
- Who can build or share Copilot agents here, and has anyone reviewed the ones that exist?
- If a client or an insurer asked tomorrow how we govern AI, what would we hand them?
If two or more answers are "not sure," you have ungoverned Copilot. That is common, and it can be fixed. Order matters more than speed. Do the permission review before anyone else gets a license.
Sources
§Sources+
Microsoft
- Microsoft Learn: data, privacy and security for Copilot page updated 2026-08-18
- Microsoft Learn: Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat page updated 2026-08-18
- Microsoft Support: Copilot app updates for personal, work, and school accounts posted 2026-09-16
- Microsoft Learn: Anthropic models in Microsoft Online Services page updated 2026-09-18
- Microsoft Learn: OpenAI as a subprocessor in Microsoft Online Services page updated 2026-08-18
- Microsoft Learn: Microsoft Purview DLP for Microsoft 365 Copilot and Copilot Chat page updated 2026-09-17
- Microsoft Learn: Agent Builder in Microsoft 365 Copilot page updated 2026-07-23
- Microsoft 365 blog: in-country data processing for Copilot posted 2025-11-04, editor's note 2026-04-03
Regulation
- 16 CFR 314.4, Safeguards Rule elements eCFR current as of 2026-09-17
Claremont Security sets up governed Microsoft Copilot for regulated firms: the permission review, the labels, the model settings, the agents, and the dated record. To see where your firm stands before anyone calls, try the AI Readiness Check. It is free and needs no account: claremontsecurity.com/readiness
claremontsecurity.com/insights/governed-vs-ungoverned-copilot
