Microsoft 365 Copilot can be a reasonable choice for client work at a law or accounting firm, with two conditions. First, you have to use it through your firm's work accounts, where Microsoft's enterprise data protection applies: prompts and responses stay under the same terms as your email and SharePoint files, and aren't used to train Microsoft's foundation models. Second, and this is where most firms get caught, you have to clean up who can see what in SharePoint, OneDrive and Teams before you turn it on. Copilot only shows people what they already have access to, but it makes overshared files much easier to find. Your professional duties still apply too, so check your bar or professional body's guidance.

This article explains what Microsoft documents. It isn't legal advice, and you should confirm the details for your own firm and jurisdiction.

What Microsoft commits to

When someone uses Microsoft 365 Copilot or Copilot Chat signed in with a work account, Microsoft's enterprise data protection applies. According to Microsoft's documentation:

  • Same terms as your email and files. Prompts and responses are covered by the same contractual terms as email in Exchange and files in SharePoint, including Microsoft's Data Protection Addendum.
  • No training on your data. Prompts, responses and the data Copilot reads through Microsoft 365 aren't used to train foundation models.
  • Your permissions and labels carry over. Copilot respects each person's existing permissions, inherits sensitivity labels, applies your retention policies and supports auditing of interactions.
  • Compliance commitments. Microsoft lists GDPR, the EU Data Boundary, ISO/IEC 27018 and HIPAA (for properly configured setups) among the commitments that apply.

One limit to know about: when Copilot searches the web, those web queries go to Bing, which runs separately from Microsoft 365 and has different data-handling practices. Microsoft removes user and tenant identifiers first. If you don't want client details going into web searches, your admin can control web grounding.

The real risk: oversharing

Copilot doesn't give anyone access they didn't already have. The problem is that most firms have more access than they think. A folder shared with "everyone in the organization" years ago, a Teams channel that the whole office joined, a client file sent as a company-wide link: nobody found those before because nobody went looking. Copilot goes looking for them every time someone asks a question.

Microsoft's own guidance puts it plainly: SharePoint's default sharing settings are the most permissive option, and preventing oversharing means fixing permissions before Copilot reads your content.

For a law firm, that could mean a paralegal asking Copilot about a matter and getting a summary pulled from a conflict-walled client's file. For an accounting firm, it could mean an associate seeing payroll or another client's return. That's not a Copilot breach. It's a permissions problem that Copilot exposes.

What to set up before you turn it on

  1. Review sharing settings. In the SharePoint admin center, go to Policies, then Sharing. Tighten the default link type so new links go to specific people, not everyone in the organization.
  2. Find what's already overshared. Look for sites and files shared with "Everyone except external users" or with organization-wide links. Microsoft's data access governance reports find these for you, but they need SharePoint Advanced Management, an add-on. Without it, you can review your main client sites by hand.
  3. Lock down client and matter sites. Restrict each client or matter site to the people who work on it. For conflict walls, make sure the wall is enforced by permissions, not just policy.
  4. Hide sensitive sites from Copilot where needed. Restricted Content Discovery (part of SharePoint Advanced Management) keeps a site out of Copilot and organization-wide search even for people who have access.
  5. Use sensitivity labels on the most sensitive documents, so protection travels with the file.
  6. Roll out in stages. Start with a small group, check what Copilot surfaces for them, fix what you find, then expand.

Professional duties still apply

The tool being secure doesn't settle your professional obligations.

Law firms. The American Bar Association's Formal Opinion 512 (July 2024) says lawyers using generative AI must keep client information confidential, understand the benefits and risks of the tools they use, review AI output, and bill reasonably for AI-assisted work. It also discusses when client consent is needed before putting client information into certain AI tools. Many state bars have issued their own guidance, so check yours.

Accounting and tax firms. Tax preparers should look at how IRS Section 7216 rules on disclosing and using tax return information apply to AI tools, and how their state board and the AICPA treat it. Practitioners don't all agree yet on how these rules apply to AI, so a conservative approach (clear client consent language, business-grade tools only, human review of every output) is sensible until the guidance settles.

For both: write down which tools are approved, what data can go in them, and who reviews the results. Our AI usage policy template is a starting point.

What about ChatGPT or Claude instead?

The same logic applies. Business plans (ChatGPT Business, Claude Team) don't train on your data by default, and personal accounts are where the risk sits. The difference is that Claude and ChatGPT don't automatically read your whole Microsoft 365 tenant, so the oversharing risk is smaller, but people have to upload or connect files deliberately. We compare all three in Claude vs ChatGPT vs Copilot for a small business.

When to call someone

You can do the sharing review yourself if your firm is small and your SharePoint is tidy. It's worth getting help if you've never reviewed permissions, if you have conflict walls or regulated data, if you're not sure which Microsoft 365 plan and add-ons you need, or if you want Copilot rolled out with training so people use it safely from day one.

Our AI advisory covers exactly this: a privacy and permissions review, the right plan and settings, a written policy, and training for your team, at a fixed price.

Sources: Microsoft Learn, Enterprise data protection in Microsoft 365 Copilot and Copilot Chat, Microsoft 365 Copilot best practices with SharePoint, Restricted Content Discovery; American Bar Association, Formal Opinion 512.

Written by Tapestries Bot, the AI writing assistant at Tapestries Group.