Your Data Is in Your Tenant. But Where Does It Go?
Security is not the same as data sovereignty. Before rolling out AI, organisations should ask where their data is stored, processed, and who has access to it, especially when handling government or confidential information.
One question I think every organisation should be asking before rolling out AI:
Where does our data actually go?
I've been thinking about this a lot recently, particularly with organisations adopting tools like Microsoft Copilot.
Microsoft has been quite clear about its position. Copilot operates within the Microsoft 365 service boundary, respects existing permissions and security controls, and Microsoft states that prompts, responses and Microsoft Graph data aren't used to train foundation LLMs.
That's important.
But I think there is another question we need to ask.
Security is not the same as data sovereignty.
Your data can remain protected within a cloud provider's security boundary while still raising questions about where that data is processed, which services process it, which jurisdictions apply and who ultimately has access to it.
And this becomes much more important when we're talking about government agencies, critical infrastructure and organisations dealing with confidential or sensitive information.
Microsoft's own documentation shows that Copilot is not one single processing environment. Different Copilot capabilities can involve different services, agents, models and subprocessors. Microsoft also documents scenarios where data can move across regions depending on the configuration and service being used.
So before putting sensitive organisational information into an AI environment, I think we should be asking:
Where is the data stored?
Where is it processed?
Which models are processing it?
Are any third parties or subprocessors involved?
What jurisdiction does that processing fall under?
What happens when we introduce an AI agent or connector?
Can we see and audit what information the AI accessed?
And perhaps most importantly:
Do our contractual and governance controls actually match the sensitivity of the data we're putting into these systems?
This isn't an argument against Copilot or AI.
Quite the opposite.
AI has enormous potential for government and industry.
But the Australian Government is already treating sovereignty, privacy and security as important considerations when selecting hosting arrangements for sensitive government information. The Hosting Certification Framework specifically exists to help government identify hosting services that meet enhanced privacy, sovereignty and security requirements.
The Protective Security Policy Framework also makes it clear that government information needs to be appropriately protected throughout its lifecycle, including when it is stored, processed or transmitted.
And in 2026, the PSPF has gone a step further with specific guidance around the risks of frontier AI.
So perhaps we need to move beyond asking:
"Is this AI secure?"
And start asking:
"Can we prove what happens to our data when AI uses it?"
For me, that's where AI governance, data governance and data sovereignty come together.
The organisations that get this right won't be the ones that avoid AI.
They'll be the ones that understand their data well enough to use AI confidently.
That's a conversation I'm particularly interested in exploring through Arivu.
#AI #AIGovernance #DataGovernance #DataSovereignty #CyberSecurity #AustralianGovernment #GovTech #ResponsibleAI #MicrosoftCopilot
Sources / further reading:
• Microsoft, Data, Privacy, and Security for Microsoft 365 Copilot (https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy?utm_source=chatgpt.com) • Microsoft, Microsoft Copilot Data Protection Architecture (https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-architecture-data-protection-auditing?utm_source=chatgpt.com) • Australian Government Architecture, Hosting Certification Framework (https://architecture.digital.gov.au/standard/hosting-certification-framework?utm_source=chatgpt.com) • Australian Government, Protective Security Policy Framework 2026 PSPF Release 2026 (https://www.protectivesecurity.gov.au/publications-library/pspf-annual-release-2026?utm_source=chatgpt.com) • Australian Government, PSPF Policy Advisory 001-2026: Cyber Security Readiness in the Frontier AI Era (https://www.protectivesecurity.gov.au/protective-security-directions-under-pspf/protective-security-policy-advisories?utm_source=chatgpt.com)
// Want to talk?
If you have questions, concerns, or you're simply curious, get in touch with us.
Get in touch