Connecting an AI cybersecurity tool can give it access to business content, let it send prompts or searches to connected services, and create records of prompts, retrieved information, and responses. What it can see, whether data may be used for product improvement, how long records remain, and where processing occurs depend on the specific product, license, features, permissions, and settings. Review those details before connecting a tool—not after it has access.
What does “connecting” an AI tool actually allow?
A connection can involve more than the text an employee types. Depending on the product and its setup, the service may also retrieve information from connected sources to answer a prompt, return a response, and retain interaction records. An agent or third-party connector may introduce another recipient with its own permissions and privacy terms.
Plan for the data sources that could be in scope: for example, mail, documents, security alerts, endpoint telemetry, tickets, identity records, cloud resources, repositories, or files a user uploads. This is an inventory checklist, not a claim that every product accesses every category. The actual scope comes from the product’s documented features, enabled connectors, account and tenant configuration, and permissions.
What can the tool access under your permissions?
Two Microsoft products illustrate why product-specific review matters. They are examples, not a basis for assuming that other vendors work the same way.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
| Product | Documented data and access boundary |
|---|---|
| Microsoft Security Copilot | Microsoft Learn describes customer data as including submitted prompts, information retrieved to generate responses, responses, and pinned-item content. Queries run as the user and do not gain elevated privileges beyond that user’s permissions. (Microsoft Learn, Privacy and data security in Microsoft Security Copilot.) |
| Microsoft 365 Copilot | Microsoft Learn says it grounds responses in organizational content accessed through Microsoft Graph—including documents, email, calendars, chats, meetings, and contacts—and surfaces information the individual user has at least view permission to access. (Microsoft Learn, Data, Privacy, and Security for Microsoft 365 Copilot.) |
These boundaries do not repair overly broad access already granted to employees. If sensitive material is widely shared or inherited permissions are too loose, an AI feature that works within user permissions may still surface that material to people who can already access it. Review both the tool’s permissions and the organization’s underlying access controls.
Are prompts or company data used to train AI?
Separate foundation-model training from product improvement and other security-model training. Microsoft’s Microsoft 365 Copilot documentation says prompts, responses, and data accessed through Microsoft Graph are not used to train foundation large language models. For Security Copilot, Microsoft documents optional sharing of customer data for product improvement and training its security AI model, while saying that this does not permit training foundation models. The Security Copilot documentation says data sharing is on by default in the documented product and that administrators can change it.
Rank #2
Those are distinct product statements, not a general promise for AI tools. For the exact product and business plan you intend to use, locate the terms and administrative controls covering prompts, retrieved content, responses, feedback, product improvement, and each kind of model training. Confirm the defaults and who is allowed to change them.
How long are prompts and responses stored?
Retention is a separate question from training: data not used to train a model may still be kept as interaction history, subject to the product’s settings and policies. Microsoft 365 Copilot records interactions that include prompts and responses. Microsoft says administrators can use Content Search and Microsoft Purview to view and manage those records and apply retention policies; the cited documentation does not establish one universal retention duration for every organization.
Recommended Free Tools
For Security Copilot, Microsoft says data shared previously is retained for no more than 180 days after an administrator opts out of sharing. That is a product-specific limit tied to opting out—not a general retention period for all Security Copilot data or for other AI tools.
Before enabling a service, establish what gets logged, how long each record type is kept, how deletion works, and whether legal holds, e-discovery, backups, exports, or audit controls affect the lifecycle. Do not assume that disconnecting a connector deletes records already retained by the service.
Rank #4
Where is business data processed and stored?
Storage location and processing location are not necessarily the same. Microsoft’s Security Copilot documentation says evaluation may occur in the US, UK, or EU depending on capacity for some regions. It also describes a safeguard under which EU traffic may be sent to US Azure OpenAI for processing while customer data is not stored outside the EU. The applicable region and safeguard depend on the product’s documented arrangement.
Microsoft 365 Copilot documentation says calls may be routed to other regions during periods of high use. It also says Anthropic models provided as a subprocessor are currently outside the EU Data Boundary. These statements are feature- and model-specific; check current documentation and the terms for the model and features actually enabled before relying on a regional commitment.
Best Value
For any vendor, check both processing and storage locations, subprocessors and model providers, support access, and the contract’s exact residency or boundary commitment for your organization’s jurisdiction.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should you review connectors and agents?
A connected agent or third-party service may have its own access requests, privacy statement, and terms. Microsoft says Microsoft 365 administrators can inspect agent permissions, terms, and privacy statements and choose which agents are available. Use comparable controls where another platform provides them, and verify exactly what information each connector receives and whether an administrator can restrict or disable it.
Pre-connection checklist for a business
- Identify the exact offering. Record the product, edition, account type, tenant, enabled features, and contract. Do not apply consumer terms—or one Copilot product’s terms—to a different business product.
- Map the connected sources. List the services, repositories, files, and data categories that the tool or its agents can reach. Include user-uploaded content where applicable.
- Review identities and permissions. Inspect OAuth and API permissions, service accounts, roles, and user-scoped access. Remove unnecessary privileges and correct broad inherited sharing before connection.
- Check data-use settings and terms. Find the provisions and admin controls for prompts, retrieved data, responses, feedback, product improvement, and model training. Record each default and who can change it.
- Set retention and audit expectations. Confirm interaction-log duration, deletion procedures, legal-hold and e-discovery behavior, backup handling, and available export and audit tools.
- Verify regional and provider terms. Check processing and storage regions, subprocessors and model providers, support access, and relevant contractual commitments for your jurisdiction.
- Review every connector or agent separately. Read its requested permissions, privacy statement, and terms; identify its data recipients and the administrator’s options to restrict or disable it.
- Pilot with low-risk information. Test both expected access and access that should be denied, inspect available logs, document an owner, and define how to disconnect or roll back the integration.
What the Microsoft examples do—and do not—establish
The Microsoft documentation provides concrete examples of user-scoped access, interaction records, training distinctions, administrator controls, and regional handling. It does not establish how other AI cybersecurity vendors handle telemetry, third-party model providers, training, retention, or residency. For another product, use its current business terms, technical documentation, and administrative settings rather than inferring its behavior from these examples.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

