Skip to content
OnPrem

Is Microsoft Copilot safe for Australian law firms?

The short version — Copilot is one of the better cloud AI options for firms, but the analysis is more specific than most vendors will tell you.

Published 26 July 2026

Microsoft 365 Copilot is the most commonly-adopted AI product in Australian professional services. It has become the default recommendation from managed service providers, and for good reason: it is a competent product from a competent vendor, with a genuine effort at enterprise-grade data handling. It is also treated as a blanket solution to the AI-confidentiality problem in a way it does not fully warrant.

This article walks through what Copilot actually does, where the design decisions are strong, and where the remaining risks sit for a firm that takes client confidentiality seriously.

What Copilot actually is

Copilot is a set of AI features integrated across the Microsoft 365 suite — inside Word, Outlook, Excel, PowerPoint, Teams and OneDrive, plus a standalone chat interface. Under the hood it uses large language models operated by Microsoft in partnership with OpenAI, augmented by “grounding” against your Microsoft 365 tenancy data.

The key architectural point: when a staff member asks Copilot to summarise a document or draft an email, Copilot can read your tenancy data (documents, emails, meetings) as context — subject to whatever permissions that user already has. This “grounding” is what makes Copilot more useful than a generic chatbot for firm work.

Where the design is genuinely strong

Microsoft has thought carefully about several things that lesser vendors have not.

Data residency and enterprise data protection. Microsoft offers a tier called “Enterprise Data Protection” that commits to processing user prompts and grounding data within specific geographic regions, including Australia. This is a real commitment from a company with real reputational and regulatory exposure if it is broken, and it removes a substantial part of the cross-border disclosure analysis under APP 8.

No training on your data. Under standard Enterprise terms, Microsoft commits not to use your prompts or grounding data to train foundation models. This is a meaningful commercial commitment.

Permissions are honoured. Copilot cannot read documents the requesting user does not already have access to. This sounds obvious; in practice it is the single most valuable data-handling feature Copilot offers, because it prevents a partner accidentally receiving a summary of an HR file they should not see.

Auditability. Copilot activity is logged in Microsoft Purview and can be reviewed by administrators. Compared to consumer chatbots — where staff use is effectively invisible to the firm — this is a large step forward.

Sensitivity labels. If your firm has deployed Microsoft Purview Sensitivity Labels, Copilot honours them. Documents labelled “Highly Confidential” can be excluded from Copilot’s grounding entirely.

Where the remaining risks sit

None of the above is oversold, and each is real. But three gaps remain even for firms who have done the Copilot deployment properly.

1. The Purview problem

Most of Copilot’s security story depends on Sensitivity Labels being properly deployed. Very few firms have actually done this at any depth.

Deploying Purview Sensitivity Labels at a level that meaningfully controls Copilot’s grounding is a substantial project — typically involving information architecture work, label taxonomy design, staff training, and ongoing governance. Firms that “have Purview” but have not deployed labels rigorously have Copilot behaving on a permissive default that will read essentially anything the user can read.

For a firm where partner mailboxes contain years of privileged correspondence and every associate has broad SharePoint access, this can mean Copilot happily includes material in its answers that nobody would have chosen to expose to an AI query.

The comparison “Copilot vs on-premise” only becomes fair once you have honestly assessed whether your Purview deployment actually constrains Copilot the way you assume it does.

2. Some features route data outside your region

Microsoft is explicit about this in their documentation: certain Copilot features may involve processing outside your primary data residency region. Which features, and when, is published — and does change as Microsoft evolves the product.

For a firm relying on “our data stays in Australia” as a compliance position, the honest picture is more nuanced: prompts and grounding for many Copilot interactions stay in-region, but not all interactions and not all features. If a specific client contract requires strict Australian processing, this is a conversation with Microsoft licensing, not an assumption.

3. Personal-device leakage does not stop

This is the risk that most obviously does not go away with any enterprise AI deployment.

A firm buys Copilot licences. The associate working at 9pm on a difficult brief has the free ChatGPT app on her phone, already logged in. She opens Copilot, but her session has timed out, she cannot remember whether it is single sign-on or a separate password, and she has to be at court in the morning. She uses the app on her phone.

Nothing about the Copilot deployment reaches this behaviour. And unlike the previous two risks, this one cannot be solved by better Copilot configuration; it can only be solved by making the sanctioned tool at least as easy and frictionless as the unsanctioned one.

When Copilot is the right answer

For many Australian firms, Copilot is genuinely the right recommendation. Specifically:

  • If your firm is already deep in the Microsoft ecosystem and would benefit substantially from native Office integration.
  • If you have (or are willing to invest in) proper Purview and Sensitivity Label governance.
  • If your work is not dominated by privileged or client-confidential material — for example, an internal legal function of a corporate that mostly deals with the business’s own documents.
  • If per-user monthly pricing does not create sufficient budget pressure to leave staff quietly using free tools instead.
  • If you accept Microsoft as a strategic AI vendor alongside its role as your productivity provider.

For those firms, Copilot is a competent, well-supported product and we would say so directly.

When it is not

The situations where the fit is weaker:

  • High-volume privileged and client-confidential work. Litigation firms, corporate M&A practices, family law and criminal defence — where the material Copilot would need to be useful is exactly the material you cannot afford transmitted anywhere.
  • Firms without effective Purview deployment. In practice, most mid-tier and boutique firms. The compliance story only holds up if the underlying information governance is actually in place.
  • Firms with client contracts prohibiting third-party disclosure. If a client contract requires all handling of their material to be within your infrastructure, Copilot does not clear that hurdle regardless of Microsoft’s own commitments.
  • Firms operating in remote locations. Cloud AI does not work without connectivity.
  • Firms where per-seat pricing across a full team would drive substantial ongoing cost. The economics of on-premise become more attractive as team size grows.

The hybrid position

The answer many firms end up at, and the one that is often best on the merits, is a hybrid:

Copilot for general work — internal communications, non-client documents, meeting summaries within Teams, admin correspondence. This is the majority of daily AI usage and Copilot handles it well.

On-premise for privileged and client-confidential work — matter files, discovery, drafting client-facing advice, working with the actual detail of client circumstances. This is the higher-consequence but lower-frequency use.

This split maps cleanly to how work is naturally sensitivity-classified, and it is what a competent AI policy would specify regardless of which vendor you buy the tools from.

The question worth asking your provider

If you are being sold Copilot as the answer to your AI-confidentiality problem, one question tells you whether the person selling it has actually thought about your context:

“If a staff member decides to use the free version of ChatGPT on their personal phone tonight, what specifically about our Copilot deployment prevents that or gives us visibility of it?”

The honest answer is “nothing” — because that is the truthful answer for any enterprise AI product. If your provider claims otherwise, they are either overstating what Copilot does or not thinking about the actual mechanism by which firms leak confidential data to AI services.

The value of a well-implemented Copilot deployment is real. It is not that value; it is a different value.

This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.

Want to know what your firm is actually exposing?

We will walk through where confidential material is most likely leaving, and tell you plainly whether an on-premise system is worth it for a firm your size.

Request an assessment