
Start here
Someone turning on an AI assistant inside Word, Gmail or Sheets is not adding a chat window next to their work — they are giving a model a possible route into whatever the account already holds: emails, files and calendars. Microsoft and Google both document this directly, and the question worth asking is not 'does it use my data' but under which license it uses which data, automatically or only when asked.
What the documents say
Microsoft's Copilot documentation, retrieved 16 September 2026, distinguishes three license tiers. Copilot Chat (Basic) and Microsoft 365 Copilot (Basic) are 'grounded in web data' only; they cannot pull from Microsoft Graph, the index of a user's emails, files, meetings and calendars, unless the user manually uploads a file or works with content already open in Outlook or Teams. Microsoft 365 Copilot (Premium) is different: it 'uses both web and organizational data via Microsoft Graph... and pulls information automatically,' scoped by the user's own permissions. Microsoft's page on enterprise data protection states that Copilot prompts, responses and Graph data 'aren't used to train foundation models,' following the organization's own identity and sensitivity-label controls. Google's Workspace page for Gemini states the assistant is built into Gmail, Docs, Sheets, Meet, Chat and Vids, and that 'Gemini only retrieves relevant content in Workspace that the user has access to' and that 'your company data is not used for AI model training or ads.' Both vendors tie automatic access to a specific paid tier or admin setting rather than to simply installing the assistant.
Check this
A reader in a workplace can check which mode applies to them by looking at their own license, not the product's marketing name: does the assistant answer only from what is pasted or uploaded, or does it answer using files it was never shown? Microsoft's documentation implies a direct test — ask about a specific email or file never opened or referenced in the chat; a correct answer confirms Graph grounding is active.
What holds and what fails
The vendor statements about training exclusion and permission-scoping hold as stated, for the licensed product described, on the date each page was read; they do not extend to every AI feature from the same company, to connected third-party agents, or to older license tiers, and both vendors note that controls vary by plan. Whether 'not used to train models' and 'not used for ads' remain true as products change is not something a page can guarantee going forward; it is a current commitment, not a permanent one.
- Find out which Copilot or Gemini license applies to an account before assuming what it can read.
- Ask the assistant about a file it has not been shown, as a direct test of automatic access.
- Reread the vendor's data-use page periodically, since both note that controls vary by plan and may change.
The distinction that matters is not whether an office assistant can see into an account — it is which license switches that seeing on automatically, and whether a reader knows which one applies to them.
Sources & reading trail
States the three Copilot license tiers and which ones ground responses automatically in Microsoft Graph data.
Source published: Not established · Retrieved: 16 September 2026
States that Copilot prompts, responses and Graph data are not used to train foundation models, and that access follows tenant permissions.
Source published: Not established · Retrieved: 16 September 2026
States which Workspace apps Gemini is built into and that company data is not used for model training or ads.
Source published: Not established · Retrieved: 16 September 2026
Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.