1. What the document is: Microsoft's general consumer Services Agreement. Section 13(s), "AI Services," governs "services or features... that use Artificial Intelligence (AI) technologies, including any generative AI services" — covering Copilot among other Microsoft AI features.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
Independent reviews, where they had something to say
Microsoft Copilot – Acceptable Use Policy
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/Microsoft Copilot/Acceptable Use Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2026-03-06
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (competing model ban,feedback,ai disclosure). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.Document-scope note: This capture is the entire Microsoft Services Agreement (Xbox, Skype, Bing, Cortana, Microsoft 365, Rewards, etc.), not an AI-specific policy — only §13(s) “AI Services” and §13(r) “Copilot AI Experiences” are relevant to this wiki’s scope and analyzed below.
Overview
1. What the document is: Microsoft’s general consumer Services Agreement. Section 13(s), “AI Services,” governs “services or features… that use Artificial Intelligence (AI) technologies, including any generative AI services” — covering Copilot among other Microsoft AI features.
2. Input rights: Narrower in purpose than most providers: “Microsoft will process and store your inputs to the service as well as output from the service, for purposes of monitoring for and preventing abusive or harmful uses or outputs.” No general “improve services”/research catch-all is stated for AI Services specifically. On ownership: “Microsoft doesn’t claim ownership of any content you provide… including feedback and suggestions” — Feedback is explicitly folded into that no-ownership-claim, a more user-protective framing than most other providers’ Feedback clauses.
3. Output restrictions: A “Content credentials” (provenance/watermarking) anti-removal clause: you may not strip or obscure AI-content-provenance markers, or use the AI services “to generate content for the purpose of misleading others about whether content was generated by using the AI services.”
4. Non-explicit predatory clauses: Section 13(s)(iv) bans using “the AI services, or data from the AI services, to create, train or improve (directly or indirectly) any AI technology” — broader than most providers’ competing-model bans, since it isn’t limited to competing products, it covers improving any AI technology. Section 13(s)(iii) also bans web scraping/data extraction from the AI services.
5. Regulatory references: A genuine, named EU regulation citation does appear elsewhere in the document — the “European Accessibility Act (EAA)/Directive (EU) 2019/882” (§13(t), accessibility conformance to ETSI EN 301 549) — but no GDPR or EU AI Act citation appears anywhere, even though §13(s)(ix)‘s usage restrictions are a near-complete, itemized restatement of the EU AI Act’s Article 5 prohibited-practices list: subliminal/manipulative techniques, exploiting age/disability/socioeconomic vulnerability, social scoring, criminality-risk profiling, categorizing people by inferred biometric traits, untargeted facial-recognition-database scraping, real-time “in the wild” law-enforcement facial recognition, and emotion inference. This is the second provider in this dataset (after Meta AI) found adopting AI-Act-derived restrictions without naming the AI Act.
6. Regional variation: The EAA reference is itself EU-specific (accessibility conformance). No other explicit regional split is described for the AI Services section.
7. Key risk to users: Low-to-moderate overall. The narrow-purpose Input/Output processing and the no-ownership-claim on Feedback are both unusually user-protective compared to this dataset’s norm. The main risk is the broad “create, train, or improve any AI technology” restriction, which could be read to prohibit even unrelated AI development work that happens to reference Copilot outputs.
Flagged Keywords & Risks (LLM-assigned)
competing model ban— “You may not use the AI services, or data from the AI services, to create, train or improve (directly or indirectly) any AI technology.” Why it matters: broader than other providers’ competing-model bans — it’s not limited to competing products, it covers any AI technology.feedback— Feedback and suggestions are explicitly covered by Microsoft’s no-ownership-claim, rather than being granted to Microsoft under a broad usage license. Why it matters: this is the most user-protective Feedback framing found in this dataset so far.ai disclosure— You can’t remove “content credentials”/provenance signals, and can’t use the AI services “to generate content for the purpose of misleading others about whether content was generated” by them. Why it matters: this is a technical, watermarking-based approach to AI disclosure, distinct from the plain textual-disclosure requirements seen elsewhere in this dataset.
Regulatory & Research Context
Pandit et al. (2026), who manually coded Microsoft/Copilot’s terms directly, found that “all terms in our analysis contained language that explicitly discards assurances regarding the quality, availability and appropriateness of the service” — consistent with this page’s broad competing model ban (“create, train or improve… any AI technology”) functioning as a one-sided restriction with no reciprocal assurance to users. Davidson et al. (2026) did not study Microsoft directly, but their identification of “regulatory gray areas” in LLM Terms applies by analogy to this document’s AI-Act-aligned §13(s)(ix) usage restrictions, which — as flagged above — substantively restate the EU AI Act’s Article 5 prohibited-practices list without ever citing the Act by name, leaving the regulatory basis for these restrictions ambiguous to a reader.
Changes Summary
| Date | What changed |
|---|---|
| 2026-02-18 | Baseline version (“Published: 30 July 2025, Effective: 30 September 2025”). |
| 2026-03-06 | Cosmetic only: one unrelated services-list addition (“Xbox apps and websites”) elsewhere in the document; no change to the AI Services section. |
Version History
2026-02-18
- Explicit AI clause: YES
- Non-explicit predatory: YES
- Flagged keywords:
competing model ban,feedback,ai disclosure
Clause: competing model ban
Limits on use of data from the AI Services. You may not use the AI services, or data from the AI services, to create, train or improve (directly or indirectly) any AI technology.
Clause: feedback
Ownership of Content. Microsoft doesn’t claim ownership of any content you provide, post, input, or submit to or receive from the AI services (including feedback and suggestions).
Clause: ai disclosure
Content credentials. When you use the AI services to generate content, Microsoft may store information about the content and associate this information and the content with content credentials. You may not use the AI services or create content with the purpose of removing, altering, obscuring or hiding content credentials or other provenance methods, marks or signals, or otherwise use the AI services to generate content for the purpose of misleading others about whether content was generated by using the AI services.
Clause: AI-Act-aligned usage restrictions (not separately concept-tagged — no AI Act citation present)
You agree that you will not use the AI services… To deceive or intentionally misinform… or deploy subliminal techniques… with the intent to manipulate or distort the behaviour of a person in a way that causes harm; To exploit any of the vulnerabilities of a person due to their age, disability or a specific socio- or economic situation…; For social scoring or predictive profiling that would lead to discriminatory, unfair, biased, detrimental, unfavourable, or harmful treatment…; For the assessment of criminality risk of natural persons based solely on the profiling of a natural person…; Based on their biometric data, to categorise people or to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, or sex life or sexual orientation…; To create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage; For any real-time facial recognition technology on mobile cameras used by any law enforcement globally…; To attempt to infer people’s emotional states from their physical, physiological or behavioural characteristics…
2026-03-06
All flagged clauses unchanged from 2026-02-18 — this date’s only change was an unrelated Xbox-services-list addition.