Microsoft has shipped at least seven products named Copilot. Some come bundled with a Microsoft 365 subscription at no extra charge. Others cost $30 per user per month. Some can access your organization’s data. Some cannot. The naming is not going to simplify. Microsoft is building toward a single AI platform, and the product family will keep growing. For a mid-market buyer making a purchasing decision today, that confusion carries real financial risk: you can spend money on the wrong product, or assume data protections you do not actually have.

Here is what each product actually is.

The Copilot brand covers several distinct products

Microsoft 365 Copilot is the AI assistant that connects to your organization’s data through Microsoft Graph, including emails, Teams conversations, SharePoint files, OneDrive content, calendar, and meeting transcripts. It surfaces answers, summaries, and drafts grounded in your company’s actual content. This is the product most buyers mean when they say “Copilot for business,” and it requires a paid license in addition to your base Microsoft 365 subscription.

Copilot Chat is different. It is a web-grounded AI assistant included with Microsoft 365 commercial plans at no extra charge. Copilot Chat can draft, summarize, and answer questions using public internet content, but it does not access anything inside your organization’s tenant. It is the free on-ramp, not the full product.

Beyond those two, the Copilot brand also covers the general Microsoft Copilot consumer app (no commercial data protections by default), Copilot Pro (a personal subscription for individuals who want AI inside their own Office apps), Copilot in Windows (a system-level assistant built into Windows 11), and GitHub Copilot (a developer coding tool with no connection to the Microsoft 365 ecosystem). Each is a separate product with different data handling rules, different pricing, and a different appropriate use case.

The full Copilot SKU map, side by side

The table below maps every current Copilot product as of June 2026. The “data the model can see” column refers to what information is available during a session, not storage or retention policies, which are governed separately by your Microsoft 365 tenant configuration.

Microsoft Copilot product comparison, June 2026
ProductData the model can seePrice tierPrimary audience
Microsoft Copilot (consumer)Public web only. No commercial data protection when accessed outside a work account.FreePersonal and consumer tasks
Copilot Chat (M365 commercial)Public web. Commercial data protection applies. No org data access.Included with M365 commercial plansBusiness users needing general AI assistance
Microsoft 365 CopilotOrg data via Microsoft Graph (email, Teams, SharePoint, OneDrive, Calendar). Commercial data protection.Add-on to M365 E3 or E5. Bundled in M365 E7.Business users needing org-data context
Microsoft 365 E7 (bundled)Same as M365 Copilot, plus advanced compliance and security controls.New premium tier (launched May 2026)Enterprise buyers with high Copilot adoption
Copilot ProPersonal Office apps and web. No org data protection.$20 per user per month (personal only)Individuals with personal Microsoft 365
Copilot in WindowsPublic web and system settings. No org data.Included with Windows 11Windows users for system and general tasks
GitHub CopilotCode in developer’s active repository and IDE context. No M365 data.Free (2,000 completions/month); Pro $10/user/month; Business and Enterprise: customSoftware developers and engineering teams

Two distinctions matter most for mid-market buyers. The consumer Copilot and Copilot in Windows are not appropriate for confidential work without additional controls. And GitHub Copilot, despite sharing the name, belongs on a completely separate evaluation track from any Microsoft 365 adoption decision.

The data question most buyers get wrong

The most common mistake in Copilot evaluations is treating data handling as an afterthought. It is not. The data question determines which product belongs in your environment and what preparation your environment needs before any user touches it.

For commercial Copilot products, Microsoft’s Copilot documentation states that prompts, inputs, and responses are not used to train the underlying models. Your employees’ queries stay within your tenant boundary, governed by the same sensitivity labels and access controls already configured in Microsoft 365. This applies to both Copilot Chat and the paid Microsoft 365 Copilot add-on.

The consumer Copilot app does not carry those protections unless the user is signed in with a Microsoft Entra work account. This matters when employees access Copilot through a personal browser or device outside your managed environment. The company may believe it has commercial data protection across the board. Individual sessions may not.

The deeper governance question is about access scope. Microsoft 365 Copilot honors your existing data permissions. If your SharePoint environment has permissive access settings that have drifted over time, Copilot will surface that content to any user who technically has access. An AI readiness assessment typically surfaces these gaps before they become rollout failures.

What this actually costs at 200 seats

For a 200-seat Microsoft 365 E3 shop, the math works like this. E3 runs roughly $36 per user per month, or about $86,400 per year at full headcount. Adding the Microsoft 365 Copilot license brings the per-seat cost to approximately $66 per month. Rolled across all 200 seats, that is $158,400 per year for the Copilot layer alone, before any change management, training, or integration work.

That figure is worth taking seriously. Most mid-market buyers who run a quick calculation assume the ROI case writes itself. It often does not, at least not at full rollout from day one. A 100-seat rollout costs roughly $79,200 per year on the Copilot add-on, which is a more defensible starting point for a CFO conversation.

The May 2026 launch of Microsoft 365 E7 changes the calculus for organizations planning broad adoption. E7 bundles Copilot with advanced compliance, security, and Purview capabilities at a single premium price. If your organization is already paying E3 plus Copilot add-on for more than half your seats, E7 is worth modeling before your next Microsoft renewal.

The standard recommendation for mid-market buyers: start with 50 to 75 power users across two or three high-volume workflows. Measure actual time savings over 60 days before committing the full budget.

Which Copilot fits a Microsoft 365 shop

The starting point for any Microsoft 365 shop is Copilot Chat. It is already included with your commercial subscription. Turn it on, point 10 or 20 users at it, and watch which workflows they reach for it. That feedback tells you more than any vendor presentation.

If users consistently want to pull email threads, SharePoint content, or meeting notes into a session, that is the signal to evaluate the Microsoft 365 Copilot add-on. The use cases that drive real return tend to cluster around meeting summarization, long-document review, and cross-system search. If those are not among your top workflows, the add-on may not pencil out at full-seat rollout.

GitHub Copilot belongs on a separate track entirely. If your organization has a software development team, evaluate it independently of any Microsoft 365 decision. The two products share a name but serve completely different audiences and solve different problems.

For organizations still working out where to start, an AI advisory conversation can compress weeks of internal debate into a clear next step. Heartwood is an AI advisory panel for mid-market executives who need on-demand technology strategy guidance without a full engagement.

How to evaluate Copilot in four weeks

Four weeks is enough time to know whether Microsoft 365 Copilot belongs in your environment at scale, if the evaluation is structured correctly.

Week one is infrastructure only. Audit your SharePoint permissions, sensitivity labels, and guest access before any user touches Copilot. Overpermissioned SharePoint environments are the most common source of rollout failures. If users can see files they should not, Copilot will surface them. Fixing that takes longer than a week, so flag it now.

Week two is use case selection. Choose three to five workflows, not eight. Meeting summarization, email triage, and long-document review are the most common starting points because they have measurable baseline times. Identify 15 to 20 users who do those workflows daily.

Weeks three and four are the pilot. Have participants log time before and after for each workflow. Ask one question at the end of each week: did this change how you worked, or did you use it once and forget about it? Adoption patterns at two weeks predict deployment success far better than satisfaction scores.

At the end of week four you should have a per-workflow time delta, an adoption rate, and a defensible number for the CFO. If you do not have all three, extend the pilot by two weeks before expanding seats.