The Register Home Page

back to article Microsoft declares bring your Copilot to work day, usurping IT authority

Your job may not support BYOD, but how about BYOC? Microsoft has declared that people can bring their personal Microsoft 365 subscriptions to work to access various Copilot features at companies that fail to provide an AI fix. Redmond has done so unilaterally, effectively endorsing "shadow IT" – the practice of bringing …

  1. original_rwg
    Devil

    I smell desperation....

    1. Michael Hoffmann Silver badge
      Thumb Up

      Seeing as Ed Zitron just wrote that maybe around 2% of Office 365 subscribers also pay for Copilot, making it a money black hole for what MS has to pour into "AI", yeah, I'd call it desperation, even panic.

      1. Dan 55 Silver badge

        Customers will start paying for the Copilot version of Office 365 unless they opt out. That was announced some time ago so I'm sure that number is higher than 2% now and will only go up.

        1. Anonymous Coward
          Anonymous Coward

          So far as I recall the stats wich Ed Zitron quoted related to business subscriptions, not personal ones.

          As you say, Microsoft is automatically "upgrading" personal accounts to include it unless you opt out (they don't tell you about opting out and the process is not obvious - it only appears if you go to cancel the subscription).

          1. Anonymous Coward
            Anonymous Coward

            When I went to cancel the option didn't show. I just cancelled since I wasn't really locked in to the Office ecosystem.

        2. PCScreenOnly Silver badge

          Want that a time limited deal?

          I have a few years worth banked up of old family licenses, but somehow send copilot is enabled at no cost for me family for them all

          I keep asking how to remove and disable - nothing yet.

        3. Raphael

          They already did that a while ago under a "your subscription cost is increasing" message which was sneakily changing you over to the plan with co-pilot. I had to go to cancel my M365 Family subscription to get the option to stay on the plan without copilot (which was the original pricing as well).

    2. elDog Silver badge

      Or just the normal infiltration and probable exfiltration.

      1. Paul Hovnanian Silver badge

        This was my thought.

        IT often objects to BYOD policies due to exfiltration from secure internal networks. To top that off, the Economist has a good article on the "Lethal Trifecta" of LLMs. This overcomes the problem of access to private data (for Microsoft, that is). Once the data is "out" and incorporated into ChatGPT (or whatever), it becomes a simple sales pitch to offer that AI service back to your company instead of those whiny, expensive employees.

    3. Anonymous Coward
      Anonymous Coward

      As long as we (Microsoft) are cranking out bug-riddled products, we want to help our customers do the same. You're welcome.

    4. el_oscuro
      Black Helicopters

      Well I have two completely separate corporate accounts. And about a week ago, MSFT changed the office home page on both so ChatCPT Copilot is right in your face, with the chatbot having cursor focus. Anything you type or paste after accessing office.com goes straight to the mothership, no matter how sensitive. And of course sliced and diced, sold to anyone with a checkbook, etc.

      Both of these corporate accounts are controlled by restrictive group policies, but I guess MSFT ignores those.

  2. Doctor Syntax Silver badge

    "companies that fail to provide an AI fix"

    I think they mean companies who've sensibly and successfully managed to avoid it.

    1. Anonymous Coward
      Anonymous Coward

      We're a medium sized outfit owned for a lage chunk by a much larger fish, and that far larger fish has some damn good IT security management.

      None of the outfits associated with aformentioned large fish are allowed to go as much as *near* AI without big fish board level approval, and we're talking about a major MS customer. The reason for that is simple: the risk of information leakage and inadvertent misappropriation of IP require pretty in depth risk assessments.

      I have a sneaking suspicion there will be interesting conversations to be had with MS in the next few days about this blatant attempt of an end run around policy. TBH, I wish I could sit in because I suspect it ain't going to be subtle..

      1. Anonymous Coward
        Anonymous Coward

        We've had a diktat from upon high that we are expected to exfiltrate proprietary and private data into Copilot, but must not do so with any other AI.

        Which has caused some trouble, as Copilot is clearly the worst at the AI tasks we've tried across the various departments.

        Though not much, as they're all worse than useless at everything - except Python, strangely. I do wonder if anyone has done comparative studies of LLM code output in different languages.

        1. Phil O'Sophical Silver badge
          Coat

          they're all worse than useless at everything - except Python, strangely

          I suppose it frees you from the tedium of counting spaces.

        2. localzuk

          I find it amazing how Copilot is poor at creating good Powershell scripts, worse than its competitors, yet Microsoft should have the best LLM out there, with access to Github and their own development documentation and systems for everything you'd use Powershell for!

      2. Anonymous Coward
        Anonymous Coward

        If only

        I would love to have the backing to setup an IT company specialising in providing internally controlled IT systems to corporates. Enabling them to break away from the restrictive licensing and control. It would be a long journey with all the legacy and need multi-decade commitment to achieve so likely impossible. But I believe it could ultimately provide enhanced security, control and much reduced cost. They can have their own AI if they want it and decide how much and for which roles. These days you can count the organisations on one hand that can think multi-decade. In fact most of those are of nefarious intent; UN, WEF, CIA, MI6, Blackrock, BIS ...

        1. JimmyPage Silver badge
          Linux

          Re: providing internally controlled IT systems to corporates

          There is only one way to do that.

          Linux.

          However even if that were realised as the solution it's not too little, too late. Enterprises had 20 years to do this when it was possible. Now they've waited until it's impossible.

          A quick scan of the vacancies tells me all the hammers are MS shaped. Making all the problems nail shaped.

          1. Paul Hovnanian Silver badge

            Re: providing internally controlled IT systems to corporates

            If your only tool is an MS hammer, every problem looks like a thumb.

            1. Anonymous Coward
              Anonymous Coward

              Re: providing internally controlled IT systems to corporates

              If your only tool is an MS hammer, every problem looks like a thumb.

              Oooooh, I'm going to borrow that. Beautiful :)

  3. Alien Doctor 1.1

    Fecking hell

    This has to rank among the Most Stupid Microsoft Decisions Ever (tm). If anyone did this at my company they would be sacked for a serious breach of IT policy.

    Additionally it's fucking typical of ms to leave company IT staff to police it.

    The sooner the artificial irritant bubble bursts the better. I am fed up with the whole shit show.

    1. GNU Enjoyer
      Angel

      Re: Fecking hell

      As the sole reason for the problem is microsoft, why isn't using microsoft software a serious breach of IT policy?

      1. Alien Doctor 1.1

        Re: Fecking hell

        The majority of internal servers are linux. Gradually all staff machines are being switched to linux as the users are trained on the new os and libre office. As we move to a full FOSS workplace and have no shareholders, all staff have a profit share and I am increasing our donations to the FOSS developers which hopefully by this time next year will be 15% of profits.

    2. MyffyW Silver badge

      Re: Fecking hell

      "Admins have the ability to disallow personal Copilot usage on work documents using cloud policy controls."

      Well that's very kind of them, but surely that should be the default setting rather than having to turn it on after the fact?

      1. Patch Wombat
        Facepalm

        Re: Fecking hell

        As an admin, I have enough crap to deal with and Microsoft is not helping. Copilot is currently banned for security reasons on the advice of legal. Now I get to start my day checking to see if and how Microsoft has savagely rammed Copilot sideways up my backside again.

        Microsoft needs a #MeToo movement. NO means freaking NO!

      2. Woodnag

        Re: Fecking hell

        I repeatedly delete ai.exe and its friends to stop it running as a child under outlook, and MS keeps reinstalling it.

        1. HorseflySteve

          Re: Fecking hell

          Have you tried deleting it & making a read-only, undeletable dummy ai.exe?

          1. Anonymous Coward
            Anonymous Coward

            Re: Fecking hell

            The problem is that you don't actually have ultimate control, Microsoft does. I see them capable of coming up with an 'above administrator' level for themselves where they will just replace your dummy irrespective of permissions and re-install theirs. As a matter of fact, I think MS Defender would already do this because your ai.exe checksum won't match.

        2. original_rwg
          Thumb Up

          Re: Fecking hell

          In the folder where Micros~1 keeps reinstalling the file ai.exe, make a folder called ai.exe.

      3. Anonymous Coward
        Anonymous Coward

        Re: Fecking hell

        surely that should be the default setting rather than having to turn it on after the fact?

        You must be new here. If you need a hint, have a look at Microsoft's approach to security over, oh, let's say the last few DECADES.

        Same sh*t, different day.

    3. ponga

      Re: Fecking hell

      And what a way to get off to a roaring start with the EU NIS2 Act!

      I wonder if any of the potentially massive fines could be passed on to Microsoft? Probably not, given the way they write their corporate contracts.

      1. Anonymous Coward
        Anonymous Coward

        Re: Fecking hell

        As far as I can tell from the lack of checks on their behaviour they appear to have bribed/dined/sponsored/lobbied their way into being considered 'critical' so I don't see that happen.

        Yes, I am a cynic. How did you know?

  4. MeeDeeCee

    DLP be damned!!!

  5. may_i Silver badge

    "AI" buttons popping up everywhere!

    My corporate O365 has CoPilot buttons obtrusively popping up, the same with the Atlassian products we use. And in Visual Studio. I've no idea if it is IT sanctioned or not - I leave the buttons well alone.

    1. Anonymous Coward
      Anonymous Coward

      Re: "AI" buttons popping up everywhere!

      Using of the Atlassian one is explicitly prohibited by our IT policy, yet they seem powerless to remove the buttons.

      Or to block the weekly Atlassian spam exhorting us all to use it. I've taken to reporting it as phishing, as it arguably is.

      1. Raphael

        Re: "AI" buttons popping up everywhere!

        Atlassian is probably hoping for atleast on person to click on it so they can start billing for it.

    2. PCScreenOnly Silver badge

      Re: "AI" buttons popping up everywhere!

      Remove it from teams and every day you still get a prompt for it with just "ok" or "maybe later"

      And again tomorrow.

      Not even just a callout as per those annoying boxes in office (registry entries can sort most of those)

    3. Scene it all

      Re: "AI" buttons popping up everywhere!

      It is all over Github as well. I think if I ignore it, it will not mess with my projects.

      1. Steve Davies 3 Silver badge

        Re: It is all over Github as well

        Doh! Stop using the cesspit that Github has become. Anything that they (MS) touch gets worse from day 1.

        There are plenty of alternatives to Github.

  6. DM2012

    MS attempting to drive up sales for Purview?

    1. ComputerSays_noAbsolutelyNo Silver badge

      Yeah, introduce the paid-for anti-feature along with the (as of now) free-to-use "feature".

      That's good business

  7. Sudosu Silver badge

    Common

    MS only wants to injest your companies IP

    If you won't do it they will send your staff to do it

    1. MyffyW Silver badge

      Re: Common

      Your biological and technological distinctiveness will be added to the collective.

      Now, how about we get some skin moisturiser to take the sting out of those nano-probes?

    2. Anonymous Coward
      Anonymous Coward

      Re: Common

      If you won't do it they will send your staff to do it

      They send in 'consultants' who wil 'improve your use of Microsoft products'. MS even pays for them, which is as clear a hint as you'll get that this is absolutely not for YOUR benefit. It may not come as a surprise that for this project to "deliver the most benefit', the designated Microsoft spies need access to your entire infrastructure.

      Ergo, they get to spy on what you do, have a good sniff around at your IP and on top of that will then come up with means by which you'll have to pay more.

      IMHO, that's also why their products need TBs worth of patches every month: "nice infrastructure you have there, shame if you missed some patches and someone broke in like they have at a gazillion other places, no?"

      Personally I think they're making enough money to have some proper liability lobbed at them.

  8. LosD

    In Denmark, a Microsoft-backed think tank ("Digital Dogma") is pressuring women to use more AI "so they don't fall behind the curve".

    https://ing.dk/artikel/advarer-kvinder-mod-ignorere-ai-i-risikerer-blive-haegtet-af-arbejdsmarkedet (in danish and paywalled unfortunately. Just wanted to link my source. It's a pretty useless article anyway, they're just parroting Digital Dogma)

    1. ComputerSays_noAbsolutelyNo Silver badge

      I smell AI-splaining.

      Wouldn't it be better to actually train women instead of replacing man-splaining men breathing down their necks by AI-splaining Clippy?

      1. MyffyW Silver badge

        Are you assuming us women aren't perfectly well trained already?

        [In the olden days I would have inserted a Paris icon at this point. Please can we have Ada Lovelace or Rosalind Franklin?]

        1. Excused Boots Silver badge

          It’s a tough call, but if push comes to shove then I have to go for Ada Lovelace.

          1. xyz Silver badge

            can't we ask for a Tilly Norwood making the sign of the wanker?

        2. tiggity Silver badge

          How about Jocelyn Bell (Burnell)

          A woman who also should have got a Nobel given her male colleagues did (like Franklin)

          .. and unlike Franklin & Lovelace (fairly obviously given their dates of death), someone I have met

  9. Anonymous Coward
    Anonymous Coward

    Maybe good

    It may be a good idea to setup your services device and ideally OS independent, securing it by whatever client is used for ultimate flexibility with control. But I suspect this is not the reason. Whatever Microsoft's purpose I can see other corporates using it as a way to reduce overhead from them to employees. "Yes, we'll be offering you the job but you'll need a £3000 machine with large monitor to be effective. What? you aren't willing to spend that? Well doesn't look like you have the sort of commitment we require".

    What next, bring your own software licences?

    1. MyffyW Silver badge

      Re: Maybe good

      As a neophyte PC support analyst back in the mid-90s that is pretty much what my users did.

      Or sometimes just the installation disks that they'd got off a bloke they knew down the pub.

      1. Anonymous Coward
        Anonymous Coward

        Re: Maybe good

        That was more or less my first ever experience with a virus. Some idiot had removed the read-only tab cover from the 5 1/4" floppy of XCOPY (I made original disks read-only by default) "because the computer said so", and lo, we had to order a new copy and had to run virus scans everywhere where this [censored] had 'helped' people install it by accessing the disk library which he wasn't supposed to access. Buy hey, he knew better. This was before the days of FAST, but licence management mattered and we ran a straight ship (appropriately, as it was a marine consultancy with a fair percentage of management properly certified captains. But I digress).

        As a result, he had quite an interesting session with the IT Director, who used his maths professor mode (he genuinely was) to deliver a lecture you would not want to be on the receiving end of. Honestly, it was art. If we had had asocial media in those days this would have gone viral the moment he finished talking.

        Aforementioned chap never dared take his aura anywhere beyond userland since.

  10. JimmyPage Silver badge
    Childcatcher

    GDPR ?

    If your works IT is used with your personal accounts (data) then how are the company protecting it from a GDPR perspective ?

    How does this genius idea square with the myriad data protection regimes of the world ?

    1. Anonymous Coward
      Anonymous Coward

      Re: GDPR ?

      They managed to wine and dine enough officials to acquire 'essential' status in the EU so nobody will touch them even when reported.

      I know of gov financial departments that have been repeatedly warned of security, privacy and performance problems if they go the Microsoft route, but those lower ranked voices have been told to shut up or had their lives made miserable in the hope they would resign.

      1. Doctor Syntax Silver badge

        Re: GDPR ?

        "those lower ranked voices have been told to shut up or had their lives made miserable"

        I hope they've secured their paper/email trains.

        1. MyffyW Silver badge

          Re: GDPR ?

          And printed the T-shirts with "We told you so" written on them...

        2. Anonymous Coward
          Anonymous Coward

          Re: GDPR ?

          I need to get one of them to write up all the challenges they had trying to make things work with Excel's approach to CSVs and how incredibly slow it made everything. By now he could write a book about it, and he should.

  11. Jason Hindle

    Terrible idea

    IT departments across all businesses provide varying degrees of leeway regarding how the equipment and software they provide is used. Still, one thing is universal: their sovereignty over the equipment and software they provide is everything!

  12. illuminatus

    Opportunities for creativity

    There are really only so many ways you can say "fuck right off" to stuff like this, but I'll continue trying to find creative ones to manage it.

  13. JWLong Silver badge

    Hey MIcrosoft

    What's the matter, no one buying in on your crap fuck fest AI? You've been shoving this shit up everybodies ass since day one and your actions are a big indicator that you made a major investment in a pile of shit!

    I'm going to name this the "Nancy Reagan" effect, "Just Say No" to AI.

    I can't wait until this bubble pops like the big used condom it is!

  14. Paul Hovnanian Silver badge
    Devil

    So ...

    ... does Microsoft have a "Bring Gemini to work" day?

  15. Gnisho

    Considering how many places where there's a legal requirement for data confidentiality, it isn't just irresponsible, immoral, and idiotic of Microsoft to make the suggestion, it may well venture into inducement of illegal activity as well.

  16. A. Coatsworth
    Windows

    This is proper good news!

    Hopefully MS has finally something stupid enough to actually annoy their corporate customers.

    We know they don't give a flying fuck about domestic users, having done whatever they want with "our" computers for decades. But on the corporate front they have been somewhat more cautious.

    Now their callousness or desperation perhaps made them cross a line that may make corpos to reconsider their relationship.

    We can only wait and hope

  17. M.V. Lipvig Silver badge

    Mmmmm

    How about...

    ...noooo...

  18. Locomotion69

    In my company...

    BYOD: no

    BYOC: don't you dare....

    Most applications used to share data are forbidden.

    Still Office365 and Onedrive (although mine is empty).

    Sorry M$.

  19. sabroni Silver badge
    Facepalm

    From the article: Copilot's level of access "is strictly governed by the user’s work account permissions, ensuring enterprise data remains protected."

    So if an employee can see it MS can see it. Yeah, that's super fucking secure.

  20. Anonymous Coward
    Anonymous Coward

    All your base are belong to us

    Absolutely barking mad MS this this is acceptable practice from a supplier

  21. Will Godfrey Silver badge
    Facepalm

    From the 'you couldn't make it up' dept.

    Against man's Microsoft's stupidity, the gods themselves contend in vain.

  22. FirstTangoInParis Silver badge

    Mad and illegal

    so you’d like me to run personal software on my work computer? And get me arrested under the Computer Misuse Act, be put on a major disciplinary for contravening company security policy leading potentially to dismissal? And this will also apply in Microsoft’s offices in this country.

    This should have not got past the grown ups in the building it was thought up in, let alone made it to the outside world.

    Just say no. See also https://scarfolk.blogspot.com/2013/05/the-dont-campaign-and-kak-1973.html

    1. WorBlux

      Re: Mad and illegal

      It's worse that that even. You'll also be paying legal fees and indemnifying Microsoft when your employer sues them for the data breach.

  23. cookiecutter Silver badge

    is nadella running ransomware gangs?

    At this point that's the only thing that can explain things like this, Recall, key loggers built into Win 11 & sharing between home & corporate OneDrive!

    On my mac somehow MS have worked out how to pop Sharepoint on the startup even though i don't have sharepoint (it seems to be embedded into ObeDrive) so even if I turn it off as a login item, it pops back up on reboot... i've removed OneDrive now & will transition to apple drive or wasabi.

    1. Anonymous Coward
      Anonymous Coward

      Re: is nadella running ransomware gangs?

      Business Onedrive is just a function of Sharepoint (although they make it look different).

      1. cookiecutter Silver badge

        Re: is nadella running ransomware gangs?

        still shouldn't be installing itself without my permission. removed it and looking at how to get my data off before cancelling my m365 subscription

  24. Anonymous Coward
    Anonymous Coward

    Encouraging employees to breach corporate policies?

    My understanding is that many corporations do not allow employees to use LLMs for anything relating to work, other than something company approved e.g. an enterprise version of ChatGPT, where OpenAI promises not to ring fence your data.

    Surely this will encourage people to ignore these policies, why else would you open up Copilot at work? Won't these same employees then get into trouble when their prompts are revealed to their employers?

    Muddying the waters like this smacks of desperation. Why doesn't MS just give Copilot away for free for a while, and when employees/employers fall in love with it (ahem), then start charging?

  25. bigtreeman

    Laugh

    I've got a belly laugh building up,

    when AI fails in a really big way I'm just going to let it out.

    A 'told you so' moment is coming.

  26. Dronius

    ...... other Reg headline;

    "AI Devs close to scraping the bottom of data barrel" https://www.theregister.com/2025/10/03/ai_training_requires_more_data/

    ..... well lookee here what we found. We done struck a new lode.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like