Can I use Microsoft Copilot, Slack GPT, or similar embedded AI features at work?

Answered

Only after you understand architecture, vendor mitigations, and what organisational data the service can see and how it is processed or transmitted. Check departmental guidance for what each tool can handle; speak with your security team first.

From the guidance

Primary (how) AI Insights: Generative AI

Before enabling a service, you must understand what data is visible to integrated AI services, and how that data is consumed, processed, and potentially transmitted or communicated externally.

Section: Integrated generative AI applications

Read this in AI Insights: Generative AI (opens in new tab)

Secondary (normative) AI Playbook for the UK Government

Before adopting any of these products it’s important to understand the underlying architecture of the solution, and what mitigations the vendor has put in place for the inherent risks associated with AI.

Secondary (normative) AI Knowledge Hub: Using AI at work

paid versions of tools (such as, Copilot Enterprise, or Gemini Pro) have data protection agreements. This means they can often handle personal and sensitive information safely. Check your department's guidance to understand what each tool can handle.

Related questions