Microsoft 365 Copilot Risks for Education & Research
- As Microsoft prepares to broadly release its AI-powered assistant, Copilot, to Education and Research institutions, a leading cybersecurity organization is urging caution.
- Currently, data processed by Microsoft 365 Copilot is routed thru Microsoft's global infrastructure, meaning it may not remain within the European Economic Area (EEA).
- The warning emphasizes that educational and research institutions have limited control over where their data is processed when using Copilot.
Microsoft 365 Copilot: A Cautionary Note for Education and research
Table of Contents
As Microsoft prepares to broadly release its AI-powered assistant, Copilot, to Education and Research institutions, a leading cybersecurity organization is urging caution. the Security and Research Foundation (SURF), based in the Netherlands, issued a warning on September 14, 2024, highlighting potential risks associated with the tool’s data handling practices within these sensitive environments.
Data Residency Concerns
SURF’s primary concern centers around data residency. Currently, data processed by Microsoft 365 Copilot is routed thru Microsoft’s global infrastructure, meaning it may not remain within the European Economic Area (EEA). This poses a challenge for organizations bound by strict data protection regulations, such as the General Data Protection Regulation (GDPR). Specifically, research data and student information could be subject to laws outside the EEA, potentially compromising privacy and compliance.
limited Control for Institutions
The warning emphasizes that educational and research institutions have limited control over where their data is processed when using Copilot. While Microsoft offers assurances regarding data security, SURF points out that the lack of clarity regarding data location hinders an organization’s ability to fully assess and mitigate risks. this is notably critical for institutions handling sensitive research data or personally identifiable information of students and staff.
specific Microsoft 365 Copilot Settings at Issue
SURF’s analysis focuses on the settings within Microsoft 365 Copilot that govern data usage. The organization notes that the default configurations may not align with the data governance policies of many educational and research institutions.Institutions need to carefully review and potentially modify these settings to ensure compliance with relevant regulations and internal policies.
Recommendations for a Safe Rollout
SURF recommends that organizations thoroughly evaluate the implications of using Copilot before deployment. This includes a detailed assessment of data flows, a review of Microsoft’s data processing agreements, and a clear understanding of the tool’s settings. Institutions should also consider implementing additional security measures and data loss prevention strategies to protect sensitive information.
Looking ahead
Microsoft has indicated plans to offer more control over data residency in the future, potentially including options for processing data within the EEA. However, the timeline for these changes remains uncertain. Until then, SURF advises caution and careful planning for any organization considering adopting microsoft 365 copilot within education or research settings. The organization’s warning serves as a crucial reminder that the benefits of AI tools must be weighed against potential risks to data privacy and security.
