Should my business use Microsoft Copilot or ChatGPT?

Short answer

Both are defensible on their business plans: Microsoft says Copilot prompts, responses and Microsoft Graph data are not used to train foundation models, and OpenAI says it does not train on ChatGPT Business, Enterprise or API data by default. Copilot fits companies already standardized on Microsoft 365 because it inherits existing permissions and labels; ChatGPT is a separate platform you must govern.

A note on names

Microsoft has renamed Microsoft 365 Copilot to Microsoft Copilot and Microsoft 365 Copilot Chat to Microsoft Copilot Chat; Microsoft says the security, compliance and privacy terms did not change. On the OpenAI side, the business tiers are ChatGPT Business, ChatGPT Enterprise and ChatGPT Edu, plus the API for developers.

How Microsoft Copilot handles your data

According to Microsoft Learn:

  • Prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs.
  • Copilot only surfaces organizational data the user already has at least view permission to.
  • It honors Microsoft Purview sensitivity labels and encryption, applies retention policies, and supports audit of interactions.
  • Use by organizations is covered by the Microsoft Products and Services Data Protection Addendum and Product Terms, with Microsoft acting as a data processor.
  • Web search queries sent to Bing are handled separately under the Microsoft Services Agreement and are not covered by the DPA or the HIPAA Business Associate Agreement.

How ChatGPT business plans handle your data

OpenAI states that by default it does not use inputs or outputs from ChatGPT Business, Enterprise, Edu or the API to improve its models. For the API, abuse-monitoring logs are retained for up to 30 days by default, and OpenAI offers additional retention controls to approved customers.

ChatGPT does not sit inside your Microsoft 365 permission model. Files reach it when users upload them or when you enable connectors, so governance depends on your admin settings and your policy.

How to decide

Choose Copilot first if your documents, email and Teams already live in Microsoft 365 and you want AI that respects existing access controls. Be aware that this also exposes over-shared SharePoint sites: Copilot will surface anything a user can technically open, so fix permissions before rollout.

Choose ChatGPT when the work is less about your internal files and more about drafting, analysis, coding or building on the API. Many companies license both, with a policy that says which data goes where.

Whichever you choose, the deciding work is the same: clean up permissions, label sensitive content, turn on audit logging, require company sign-in, and train staff on what each tool may see. The licensing decision is easier than the governance work, and the governance work is what protects you.

Common follow-up questions

Does Copilot read every file in our company?

No. Microsoft states Copilot only surfaces organizational data that the individual user already has at least view permission to. The practical risk is over-sharing: if a sensitive folder is open to everyone, Copilot can find it for anyone who asks.

Is Microsoft Copilot HIPAA compliant?

Microsoft says Copilot and Copilot Chat support HIPAA compliance for properly configured implementations, but web search queries are not covered by the DPA or Business Associate Agreement. Configuration, the BAA and your own policies determine whether your use is compliant.

Can we use both Copilot and ChatGPT?

Yes, and many companies do. The key is a written policy that names both tools, ties each to company-managed accounts, and states which data classes are allowed in each, so employees are not guessing.

Need help with this?

LAN Service Group assesses Microsoft 365 permissions and sensitivity labeling before a Copilot rollout, configures ChatGPT business workspaces, and writes the policy that tells employees which tool to use for which data.

Talk to LAN Service Group (888) 281-7243

Sources