Skip to main
University-wide Navigation

How Copilot Uses Your Data 

At the University of Kentucky, Copilot can only access data you have access to. The type of information Copilot will access is based on the type of prompt you submit.

Work IQ (formerly Work Search): Your UK Microsoft 365 Content

When using Microsoft 365 Copilot, the tool can help you find and summarize information you already have permission to access within the University's Microsoft 365 environment. This may include: 

  • Email messages 
  • Teams chats and channel conversations 
  • Meeting notes and transcripts 
  • Documents stored in OneDrive 
  • SharePoint files and sites 
  • Other Microsoft 365 content you are authorized to view

Copilot does not give users access to content they would not normally be able to see. It honors the same security permissions and access controls already applied across Microsoft 365.

For example, if you can't open a document in SharePoint, Copilot can't retrieve information from that document on your behalf.

Web Search: Public Internet Information

Web search allows Copilot to supplement your organization's information with publicly available content from the internet.

Examples include: 

  • Current events and industry trends 
  • Product information and vendor documentation 
  • Research articles and publications 
  • Public websites and knowledge resources 
  • General informational questions

This capability helps Copilot provide more complete answers when the information needed is not available within Microsoft's work data sources alone.

Note that both Work IQ and web search can be toggled on or off depending on your preferences. (https://support.microsoft.com/en-us/microsoft-365-copilot/frequently-asked-questions-about-microsoft-365-copilot-chat)

How does UK protect its data?

To support the safe use of web search, UK has implemented Microsoft Purview Data Loss Prevention (DLP) protections for Microsoft 365 Copilot and Copilot Chat. Its purpose is to help prevent sensitive information from being shared inappropriately, not to review or monitor the content of routine work-related prompts. 

These protections monitor prompts 

for sensitive information types, including protected health information (PHI). If a user enters information matching one of these protected data categories, Copilot will notify the user that the prompt must be adjusted. The sensitive information remains within the University's Microsoft 365 service boundary and is not passed outside of it.  

What Does This Mean for Users? 

Most users will notice that Copilot with Work IQ enabled can answer questions and add additional information from the public web. However, new protections may ask users to revise their prompts to ensure data safety.

Best Practices When Using Copilot

Even with these protections in place, users should continue following established University policies and practices for handling data.

Before entering information into any AI tool: 

  • Consider whether the information is sensitive, confidential, regulated or restricted 
  • Avoid sharing protected information unless specifically authorized and supported by approved University processes. 
  • Follow applicable HIPAA, FERPA, research and institutional data handling requirements.

Copilot is designed to be a productivity assistant, but users remain responsible for ensuring that University information is handled appropriately.

For questions about Microsoft 365 Copilot or AI use at UK, visit https://catsai.uky.edu. To report technical issues in Microsoft 365, see the options at https://its.uky.edu/get-help.