August 18, 2026
Note
- The information in this article only applies to the use of Microsoft Copilot by individuals that are signed in with a Microsoft account, such as a personal email address.
- For information about the use of Microsoft Copilot in organizations where users are signed in with their work or school account, see Application card: Microsoft Copilot (for organizations).
What is a Transparency Note?
An AI system includes not only the technology, but also the people who will use it, the people who will be affected by it, and the environment in which it is deployed. Microsoft's Transparency Notes are intended to help you understand how the AI technology behind Copilot works, the choices we made that influence the system's performance and behavior, and the importance of thinking about the whole system, so that users of Copilot can take control of their own experiences and understand the steps we are taking to provide a safe and secure product.
Microsoft's Transparency Notes are part of a broader effort at Microsoft to put our AI Principles into practice. To find out more, see the Microsoft AI Principles.
The basics of Microsoft Copilot
Introduction
Microsoft Copilot helps you move from idea to finished work, all in one place. Copilot is integrated into Word, Excel, PowerPoint, Outlook, Teams, and more, bringing the files and information you use into one experience. Copilot can help you create polished documents, presentations, and spreadsheets, draft emails, organize your day, and get answers grounded in the work you’re doing. With Cowork, Copilot can also help with bigger, multi-step tasks and deliver completed to-dos. You can also choose between leading AI models for different kinds of work. Specific features vary by subscription.
At Microsoft, we take our commitment to responsible AI seriously. Copilot has been developed in line with Microsoft's AI Principles, Microsoft's Responsible AI Standard, and in partnership with responsible AI experts across the company, including Microsoft's Office of Responsible AI, our engineering teams, Microsoft Research, and Aether. You can learn more at Responsible AI at Microsoft.
In this document, we describe our approach to responsible AI for Copilot. Ahead of release, we leveraged Microsoft's state-of-the-art methods to map, measure, and manage potential risks and misuse of the system and to secure its benefits for users. As we have continued to evolve Copilot, we have also continued to learn and improve our responsible AI efforts. This document will be updated periodically to communicate our evolving processes and methods.
Key terms
Classifiers Machine learning models that help to sort data into labelled classes or categories of information. In Copilot, one way in which we use classifiers is to help detect potentially harmful content submitted by users or generated by the system to mitigate generation of that content and misuse or abuse of the system.
Grounding For certain conversations where users seek information, Copilot is grounded in web search results. This means that Copilot centers its response on high-ranking content from the web and provides hyperlinked citations following generated text responses or in conversation transcripts in voice mode.
Large language models (LLMs) Large language models (LLMs) in this context are AI models that are trained on large amounts of text data to predict words in sequences. LLMs can perform a variety of tasks, such as text generation, summarization, translation, classification, and more.
Mitigation A method or combination of methods designed to reduce potential risks that may arise from using the AI features within Copilot.
Multi-modal models (MMMs) Multi-modal models (MMMs) are AI models that are trained on different types of data, such as text, images, or audio. These models can perform a variety of tasks, such as writing text, describing images, recognizing speech, and finding information across different types of data.
Prompts Inputs in the form of text, images, and/or audio that a user sends to Copilot to interact with the AI features within Copilot.
Red teaming Techniques used by experts to assess the limitations and vulnerabilities of a system and to test the effectiveness of planned mitigations. Red team testing includes testers adopting both benign and adversarial personas to identify potential risks and are distinct from systematic measurement of risks.
Responses Text, images, or audio that Copilot outputs in response to a prompt or as part of the back and forth with the user. Synonyms for "response" include "completion," "generation, and "answer."
Small language models (SLMs) Small language models (SLMs) in this context are AI models that are trained on smaller, more focused amounts of data compared to large language models. Despite their smaller size, SLMs can perform a variety of tasks, such as text generation, summarization, translation, and classification. While they may not match the extensive capabilities of LLMs, SLMs are often more resource efficient and can be highly effective for specific, targeted applications.
System Message The system message (sometimes referred to as a "metaprompt") is a program that serves to guide the system's behavior. Parts of the system message help align system behavior with Microsoft’s AI Principles and user expectations. For example, a system message may include a line such as "do not provide information or create content that could cause physical, emotional, or financial harm."
Capabilities
System behavior
With Copilot, we've developed an innovative approach to bring a more personalized AI experience to users for an engaging experience that can help users with a variety of tasks. This innovative approach leverages a variety of advanced technologies, such as language and multi-modal models from Microsoft, OpenAI, and other model developers. We worked on the implementation of safety techniques for the models underlying Copilot prior to public release to develop a customized set of capabilities and behaviors that provide an enhanced Copilot experience. In Copilot, users can send prompts in natural language text or voice. Responses are presented to users in several different formats, such as chat responses in text form (with traditional links to web content as necessary) and images (if an image request was made as part of the prompt). If users send prompts in natural language voice within the Copilot Voice mode, they will receive audio responses.
When a user enters a prompt in Copilot, the prompt, conversation history, and the system message are sent through several input classifiers to help filter out harmful or inappropriate content. This is a crucial first step for helping to improve model performance and mitigate situations in which users might attempt to prompt the model in a way that could be unsafe. Once the prompt passes through the input classifiers, a determination is made if the request requires grounding data from the web and which language model should respond to the request. All models generate a response using the user's prompt and recent conversation history to contextualize the request, the system message to align responses with Microsoft’s AI Principles and user expectations, and if appropriate, align responses with search results to ground responses in existing, high-ranking content from the web.
Responses are presented to users in several different formats, such as chat responses in text form, traditional links to web content, images, and audio responses. When responses are provided in the form of text—and the responses are grounded in data from the web—the output contains hyperlinked citations listed below the text so users can access the website(s) that were used to ground the response and learn more about the topic from there. Copilot can also run code to complete complex calculations and generate graphs. Copilot can store specific facts users request it to remember, allowing it to generate more relevant responses and suggestions based on that context. Copilot can also delete saved facts when users ask to forget them explicitly.
Copilot also helps users to create new stories, poems, song lyrics, and images. When Copilot detects user intent to generate creative content (such as a user prompt that begins with "write me a …"), the system will, in most cases, generate content responsive to the user's prompt. Similarly, when Copilot detects user intent to generate an image (such as a user prompt that begins with "draw me a …"), Copilot will, in most cases, generate an image responsive to the user's prompt. When Copilot detects user intent to modify an uploaded image (such as a user prompt that begins with "add a …"), Copilot will, in most cases, modify an image responsive to the user's prompt. Copilot may not respond with creative content when the user prompt contains certain terms that could result in problematic content.
Intended safety behavior
Our goal for Copilot is to be helpful to users, and, we implement safeguards to help reduce the likelihood of generating harmful content and increase the likelihood of a safe and positive user experience. While we have taken steps to mitigate risks, generative AI models like those behind Copilot are probabilistic and can make mistakes, meaning mitigations may occasionally fail to block harmful user prompts or AI-generated responses. If you encounter harmful or unexpected content while using Copilot, let us know by providing feedback so we can continue to improve the experience.
Use cases
Intended uses
Copilot is designed to help users answer questions, generate content, and complete tasks through natural language using text, images, and voice. To provide helpful and relevant responses, Copilot may retrieve, analyze, and summarize information from available sources. Some advanced features may be available only to users with eligible subscriptions. Examples of common use cases include the following:
Chat using text and get web-based summaries. Users can chat with Copilot via text and ask follow-up questions to find new information and receive support across a wide variety of topics. Copilot can perform web searches and will use the top web search results to generate a summary of the information to present to users. These summaries include citations to webpages to help users review the sources for search results that helped ground Copilot's summary. Users can click on these links to visit the website source to learn more or evaluate the reliability of the website.
Get help generating new ideas. Each time users interact with the Copilot experience they will see a set of cards that they can click to start chatting with Copilot about useful and interesting topics. If users have interacted with other Microsoft consumer services, the cards will be personalized, in line with our privacy policies. Over time, cards in Copilot may be personalized based on a user's chat history. Users can opt-out of personalization at any time in settings.
Generate creative content. When chatting with Copilot, users can create new poems, jokes, stories, images, and other content with help from Copilot. Copilot can also edit images uploaded by users if requested.
Assist with research. Copilot can carry out research tasks by surfacing in-depth resources, offering detailed breakdowns of topics, and linking to sources to help users go beyond quick answers for more complex queries. Copilot may proactively generate personalized research suggestions for users based on things like past research queries and Copilot memory. Users can opt-out of personalization or notifications at any time in settings.
Discover, compare, and buy products. Copilot Shopping can help you find products, compare options, and streamline purchases. Except where identified, Microsoft doesn't receive commissions or other compensation for product suggestions or search results provided in Copilot.
Study smarter with Copilot Learn. Copilot Learn can create quizzes and practice tests, generate flashcards, and is designed to help enhance responses with images to make complex concepts easier to understand.
Get help with daily tasks. Copilot Cowork carries out tasks on your behalf. You describe what you need in natural language, and Cowork does the work, creating documents, drafting and sending email, scheduling meetings, and managing files. You review and approve sensitive actions before it happens.
Analyze and edit files. File upload in Copilot allows users to upload images or certain supported file types directly into their chat sessions. Once uploaded, Copilot can analyze and extract information from these files to provide relevant insights, answer questions, or assist with specific tasks. Copilot can also reference files in your connected online storage providers like OneDrive and Google Drive, with your permission.
See and understand. Use Vision to analyze images, get insights from photos, and search visually. Copilot reviews uploaded images to help you understand what you're seeing.
Use your voice. Talk naturally with Copilot using voice chat. Brainstorm ideas, write content, or get quick answers, completely hands-free.
Connects to other apps. Bring in the apps and information you choose, like email, calendars, files, contacts, and other services.
Considerations when choosing other use cases
We encourage users to review all content before making decisions or acting based on Copilot's responses, as AI can make mistakes and may not be suitable for certain use cases. Additionally, there are certain scenarios that we recommend avoiding or that go against our Terms of Use. For example, Microsoft does not allow Copilot to be used in connection with illegal activities or for any purpose intended to promote illegal activity.
Limitations
The language, image, and audio models that underly the Copilot experience may include training data that can reflect societal biases, which in turn can potentially cause Copilot to behave in ways that are perceived as unfair, unreliable, or offensive. Despite our intensive model training and safety fine-tuning, as well as the implementation of the responsible AI controls and safety systems that we place on training data, user prompts, and model outputs, AI-driven services are fallible and probabilistic. This makes it challenging to comprehensively block all inappropriate content, leading to risks that potential biases, stereotypes, ungroundedness, or other types of harm that could appear in AI-generated content. Some of the ways those limitations might manifest in the Copilot experience are listed here.
Stereotyping: The Copilot experience could potentially reinforce stereotypes. For example, when translating "He is a nurse" and "She is a doctor" into a genderless language such as Turkish and then back into English, Copilot might inadvertently yield the stereotypical (and incorrect) results of "She is a nurse" and "He is a doctor." Another example is when generating an image based on the prompt "Fatherless children," the system could generate images of children from only one race or ethnicity, reinforcing harmful stereotypes that might exist in publicly available images used to train the underlying models. Copilot might also reinforce stereotypes based on the contents in the user's input image by relying on components of the image and making assumptions that might not be true. We have implemented mitigations to reduce the risk of content that contains offensive stereotypes, including input and output classifiers, fine-tuned models, and system messages.
Overrepresentation and underrepresentation: Copilot could potentially over- or under-represent groups of people, or even not represent them at all, in its responses. For example, if text prompts that contain the word "gay" are detected as potentially harmful or offensive, this could lead to the underrepresentation of legitimate generations about the LGBTQIA+ community. In addition to including input and output classifiers, fine-tuned models, as well as system messages, we use prompt enrichment in Designer as one of several mitigations to reduce the risk of content that over- or under-represents groups of people.
Inappropriate or offensive content: The Copilot experience can potentially produce other types of inappropriate or offensive content. Examples include the ability to generate content in one modality (for example, audio) that is inappropriate in the context of its prompt or when compared to the same output in a different modality (for example, text). Other examples include AI-generated images that potentially contain harmful artifacts such as hate symbols, content that relates to contested, controversial, or ideologically polarizing topics, and sexually charged content that evades sexual-related content filters. We have put in place mitigations to reduce the risk of generations that contain inappropriate or offensive content, such as input and output classifiers, fine-tuned models, and system messages.
Information reliability: While Copilot aims to respond with reliable sources where grounding information is sought, AI can make mistakes. It could potentially generate nonsensical content or fabricate content that might sound reasonable but is factually inaccurate. Even when drawing responses from high-authority web data, responses might misrepresent that content in a way that might not be completely accurate, up to date, or reliable. We remind users through the user interface and in documentation like this that Copilot can make mistakes. We also continue to educate users on the limitations of AI, such as encouraging them to double-check facts before making decisions or acting based on Copilot's responses. When users are interacting with Copilot via text, it will attempt to ground itself in high-quality web data to reduce the risk that generations are ungrounded.
Multilingual performance: There could be variations in performance across languages, with English performing best at the time of releasing Copilot. Improving performance across languages is a key investment area, and recent models have led to improved performance.
Audio limitations: Audio models might introduce other limitations. Broadly speaking, the acoustic quality of the speech input, non-speech noise, vocabulary, accents, and insertion errors might also affect whether Copilot processes and responds to a user's audio input in a satisfactory way.
AI is not a replacement for professional help: AI can be a useful tool for problem-solving and can seen empathetic, but it is not a replacement for seeking professional help. If you are experiencing depression, thoughts of suicide or self-harm, or other mental health issues, please seek professional help. Copilot can also be used to find crisis or mental health resources near you.
Dependence on Internet connectivity: Copilot relies on Internet connectivity to function. Disruptions in connectivity can have an impact on the availability and performance of the service.
Exercise caution when creating or using agents: Users should exercise caution when creating their own agents or using agents provided by others, especially if the actions taken by the agents could have significant consequences,be irreversible, or have potential to share sensitive personal information (such as passwords, logins, or personal data). Because agents may not work well for all use cases, and may make mistakes, misinterpret instructions, or be deceived by malicious hidden instructions, users should monitor results closely and review important details Users may be restricted from certain use cases, such as visiting harmful websites or creating inappropriate content. Additional precautions should also be taken when creating autonomous agentic AI as described further in the Code of Conduct section in the Microsoft Services Agreement.
System performance
In many AI systems, performance is often defined in relation to accuracy (that is, how often the AI system offers a correct prediction or output). With Copilot, we're focused on Copilot as an AI-powered assistant that reflects the user's preferences. Therefore, two different users might look at the same output and have different opinions of how useful or relevant it is to their unique situation and expectations, which means that performance for these systems must be defined more flexibly. We broadly consider performance to mean that the application performs as users expect.
Best practices for improving system performance
Interact with the interface using natural, conversational language. Interacting with Copilot in a way that is comfortable for the user is key to getting better outcomes through the experience. Similar to adopting techniques to help people communicate effectively in their day-to-day lives, interacting with Copilot as an AI-powered assistant either through text or speech that is familiar to the user may help elicit better results.
User experience and adoption. Effective use of Copilot requires users to understand its capabilities and limitations. There might be a learning curve, and users might wish to reference various Copilot resources (for example, this document and Microsoft Copilot help & learning) to effectively interact with and benefit from the service.
Mapping, measuring, and managing risks
Like other transformational technologies, harnessing the benefits of AI is not risk-free, and a core part of Microsoft's Responsible AI program is designed to identify and map potential risks, measure those risks, and manage them by building mitigations and continually improving Copilot over time. In the sections below we describe our iterative approach to map, measure, and manage potential risks.
Map: Careful planning and pre-deployment adversarial testing, such as red teaming, helps us map potential risks. The underlying models that power the Copilot experience went through red team testing from testers who represent multidisciplinary perspectives across relevant topic areas. This testing was designed to assess how the latest technology would work both with and without any additional safeguards applied to it. The intention of these exercises at the model level is to produce harmful responses, surface potential avenues for misuse, and identify capabilities and limitations.
Application-level testing before release. Before making Copilot publicly available, we conducted application-level red teaming to identify shortcomings and vulnerabilities. This testing helped us understand how a wide range of users might use Copilot and informed improvements to our mitigations.
Ongoing testing. We also test new features and technical updates, as appropriate, when updating Copilot. This continuing process helps us identify emerging risks and refine our mitigations over time.
Measure: In addition to evaluating Copilot against our existing safety evaluations, the use of red teaming described above helped us to develop evaluations and responsible AI metrics corresponding to identified potential risks, such as jailbreaks, harmful content, and ungrounded content.
We collected conversational data targeting these risks, using a combination of human participants and an automated conversation generation pipeline. Each evaluation is then scored by either a pool of trained human annotators or an automated annotation pipeline. Each time the product changes, existing mitigations are updated, or new mitigations are proposed, we update our evaluation pipelines to assess both product performance and the responsible AI metrics. These automated evaluation context pipelines are a combination of collected conversations with human evaluators and synthetic conversations generated with LLMs prompted to test policies in an adversarial fashion. Each of these safety evaluations is automatically scored with LLMs. For the newly developed evaluations, each evaluation is initially scored by human labelers who read the text content or listen to the audio output, and then converted to automatic LLM-based evaluations.
The intended behavior of our models in combination with our evaluation pipelines—both human and automated—enable us to rapidly perform measurement for potential risks at scale. As we identify new issues over time, we continue to expand the measurement sets to assess additional risks.
Manage: As we identified potential risks and misuse through red teaming and measured them with the approaches described above, we developed additional mitigations that are specific to the Copilot experience. Below, we describe some of those mitigations. We will continue monitoring the Copilot experience to improve product performance and our risk mitigation approach.
Phased release plans and continual evaluation. We are committed to learning and improving our responsible AI approach continuously as our technologies and user behavior evolve. Our incremental release strategy has been a core part of how we move our technology safely from the lab into the world, and we're committed to a deliberate, thoughtful process to secure the benefits of the Copilot experience. We are making changes to Copilot regularly to improve product performance and existing mitigations and implement new mitigations in response to our learnings.
Leveraging classifiers and the system message to mitigate potential risks or misuse. In response to user prompts, LLMs may produce problematic content. We discussed types of content that we try to limit in the System Behavior and Limitations sections above. Classifiers and the system message are two examples of mitigations that have been implemented in Copilot to help reduce the risk of these types of content. Classifiers classify text to flag potentially harmful content in user prompts or generated responses. We also utilize existing best practices for leveraging the system message, which involves giving instructions to the model to align its behavior with Microsoft's AI principles and with user expectations.
Uploading images to Copilot Vision. The first time a user uploads an image to Copilot Vision, they will be provided with information on how their image is processed by Copilot. If a user does not continue with the upload, the image won't be sent to Copilot. All images are deleted within 30 days after the conversation ends.
AI disclosure. Copilot is also designed to inform people that they are interacting with an AI system. As users engage with Copilot, we offer various touchpoints designed to help them understand the capabilities of the system, disclose to them that Copilot is powered by AI, and communicate limitations. The experience is designed in this way to help users get the most out of Copilot and minimize the risk of overreliance. Disclosures also help users better understand Copilot and their interactions with it.
Media provenance. For all images created with Copilot, we have implemented content credentials, provenance based on the C2PA standard, to help people identify whether images were edited or generated with AI. Provenance metadata can be viewed on the Content Credentials site.
Automated content detection. When users upload images as part of their chat prompt, Copilot deploys tools to detect child sexual exploitation and abuse imagery (CSEAI). Microsoft reports all apparent CSEAI to the National Center for Missing and Exploited Children (NCMEC), as required by US law. When users upload files to analyze or process, Copilot deploys automated scanning to detect content that could lead to risks or misuse, such as text that could relate to illegal activities or malicious code.
Terms of Use and Code of Conduct. Users should abide by Copilot's applicable Terms of Use and Code of Conduct, Microsoft Services Agreement, and the Microsoft Privacy Statement, which, among other things, inform them of permissible and impermissible uses and the consequences of violating the terms. The Terms of Use also provides additional disclosures for users and serves as a reference for users to learn about Copilot. Users that commit serious or repeated violations may be temporarily or permanently suspended from the service.
Feedback, monitoring, and oversight. The Copilot experience includes tooling that allows users to submit feedback, which are reviewed by Microsoft's operations teams. Furthermore, our approach to mapping, measuring, and managing risks will continue to evolve as we learn more, and we are already making improvements based on feedback gathered during preview periods.
Detecting and Responding to Suicide and Self-Harm Risks. Copilot uses machine learning classifiers trained to recognize language patterns that may indicate suicide or self-harm intent from the user. When such content is detected, the system disengages from the conversation and instead provides crisis support resources (for example, the Suicide and Crisis Lifeline at 988 in the United States), encouraging users to seek professional help. Copilot does not provide counseling; its role is limited to detection and referral to ensure user safety.
Extended usage notification. Copilot may remind users to take a break if they’ve been engaging in continuous conversation for an extended period of time. Users are also regularly informed that AI is not human and can make mistakes.