The Copilot Blind Spot: The Discoverable Records Your Legal Hold Does Not Reach

The Triality Report - Clarity Where It Counts. Support Where It Matters.

The Triality Report | Article 2 — By Sean Reddick, Partner, Triality

Ask any corporate counsel who rolled out Microsoft 365 Copilot last year what happens to Copilot data when a lawsuit arrives, and you will get some version of the same answer: “It’s in Microsoft 365 somewhere. The hold covers it.” Ask any IT director who watched adoption spread across the enterprise faster than the governance committee could meet, or any litigation partner staring at a hold notice template written in 2019, and the answer does not change.

Somewhere is doing a lot of work in that sentence.

In the first article of this series, we wrote about operational structured data, the business system records that live outside your review platform’s reach and get missed until it is too late. Copilot is the newest chapter of the same story, with a twist. This time the overlooked data source is not a legacy ERP system that predates your collection tools. It is the AI assistant your client deployed on purpose, to every knowledge worker, eighteen months ago. And it has been quietly writing records into at least six different storage locations ever since, most of which a standard custodial hold does not reach.

One Prompt, Four Records

Here is the concept that most legal teams, and frankly most IT teams, have not internalized yet: a single Copilot interaction does not create one record. It creates up to four, in four different places, each preserved or lost by a different mechanism.

The conversation itself, the prompt and the response, is captured as a compliance record in a hidden folder of the user’s Exchange Online mailbox. Users cannot browse it. Admins cannot browse it. But Purview eDiscovery can search it, and a hold on the mailbox reaches it. This is the good news, and it is genuinely good: once the mailbox is on hold, a custodian deleting their chat history does not defeat preservation. The compliance copy survives.

The work product is a different animal. When Copilot drafts three paragraphs into a Word document, that text simply becomes part of the file. Six months later, nothing on the face of the document tells you which sentences a human wrote and which ones the machine wrote. That distinction, and in a growing number of disputes it is a distinction that matters, lives only in version history and audit correlation. A collection that grabs current file versions and skips the version chain has quietly destroyed the authorship record.

The proof it happened lives in the audit log. Purview captures that an interaction occurred, who, when, in which application, and which documents Copilot consulted for grounding. What the audit record does not contain is the actual text of the prompt or response. And here is the part that catches teams off guard: audit records expire on the license clock, roughly six months on standard tiers, a year on premium. A litigation hold does not extend audit retention. Not by a day. In a matter that is two years old, the audit trail is already gone unless someone exported it early.

And then there are the exceptions. The records Copilot creates that live outside the mailbox entirely. This is where holds fail silently.

The Five Places Your Hold Does Not Reach

Copilot Pages and Notebooks. Pages are stored in user-owned SharePoint Embedded containers. Not the mailbox. A hold on your custodian’s mailbox does not touch their Pages, full stop. Reaching them means identifying the container and adding it to the hold as its own location, which means someone has to know the containers exist and go find them.

Copilot memory. Copilot builds memory about users from their interactions. As of this writing, memory items are not covered by retention policies or eDiscovery holds at all. They persist until someone deletes them. And deleting a conversation does not delete the memory derived from it, a detail that cuts in both directions depending on which side of the v you are sitting on.

Meetings that leave nothing behind. Teams meetings can run Copilot in an “only during the meeting” mode. Participants ask Copilot questions, Copilot answers from live speech-to-text, and when the meeting ends the data is discarded. Not retained, not searchable, no audit trail. A meeting conducted this way leaves essentially no Copilot record to preserve. Whether that is a feature or a liability depends entirely on the matter, but it is a policy choice your client is making today, probably without legal in the room. Microsoft also changed the defaults in late 2025 so that using Copilot in a meeting no longer automatically saves a transcript. Whether a given meeting produced a transcript now depends on which policy configuration the tenant was running on that date. That configuration is itself a fact you may need to prove.

The organizer’s OneDrive. Transcripts, recordings, and AI recap documents live in the meeting organizer’s OneDrive, not with the participants. The new transcript-free recap feature stores its summary there with a default lifespan of about four months, and the organizer can delete it. If your custodian list has the attendees but not the organizer, the meeting record is one departing employee away from gone.

Custom agents. Agents built in Copilot Studio store their conversation transcripts in Dataverse, over in the Power Platform. Different product family, different retention rules, entirely outside the reach of M365 mailbox and site holds. Every custom agent your client has built is its own preservation question in its own system, and most organizations cannot tell you how many agents they have.

The Part That Should Actually Worry You

None of the above is stable. Microsoft has materially changed Copilot’s storage architecture at least four times in eighteen months. Retention locations were split. Transcript defaults flipped. Memory shipped without compliance coverage. Pages moved onto a storage platform the hold tooling had not caught up with. Anything you learned about Copilot preservation in 2024 is partially wrong today, and anything in this article will be partially wrong by next year. The organizations that handle this well are not the ones with the perfect hold template. They are the ones that treat Copilot preservation as a living discipline, re-verified against the tenant every quarter and tested before a matter arrives, not during one.

A Starting Point: Copilot Questions for Your Next Hold

The checklist below is not exhaustive, and it is not a substitute for testing collection in your own tenant. But it will surface the issues before they become preservation failures.

Deployment and Configuration

  • Which Copilot experiences are enabled, and since when? Chat, in-app, meetings, agents?
  • What do the tenant’s meeting policies say about Copilot and transcription, and did those settings change during the relevant period?
  • What audit tier is the tenant on, and how far back do Copilot audit records currently go?

Preservation and Legal Hold

  • Do the custodial holds cover mailbox and OneDrive, and have the custodians’ SharePoint Embedded containers been identified and added?
  • Have Copilot audit records been exported before they age out?
  • Who are the organizers of the relevant meetings, and are their OneDrive accounts on hold?
  • Has anyone inventoried the Copilot Studio agents, and where do their Dataverse records live?

Deletion Pathways

  • Is there a written moratorium on admin purge tooling and privacy-request deletion of Copilot history for custodians on hold?
  • Do custodian notices actually mention Copilot chats, memory, Pages, and meeting recaps, or do they still just say “email and documents”?

Verification

  • Has a test collection been run to confirm that prompts, responses, referenced files, and a known Copilot Page actually appear where expected?
  • Does your client need Triality to assess the tenant, close the gaps, and document the methodology in a format that survives scrutiny?

Why This Cannot Wait for the Complaint

The Copilot preservation problem is solvable, but only prospectively. Audit records that expired were never exported. Meetings run in no-persistence mode never created anything to collect. Memory a custodian deleted before the hold reached it is gone, and no motion practice brings it back. The window for getting this right is before the matter, which is exactly when nobody is thinking about it.

Triality works alongside corporate legal departments, outside counsel, and IT teams to map the Copilot estate as it actually exists in your tenant, not as the marketing slide describes it. We identify where the records live, test whether the hold and collection mechanics actually reach them, close the gaps, and document the methodology. We speak Purview and we speak preservation obligation, and we keep the map current as Microsoft redraws it, because they will.

The firms that figure this out in peacetime will spend the first week of their next matter litigating the merits. The ones that do not will spend it explaining to a judge why the AI records are gone.


Sean Reddick is the Partner at Triality, a legal technology company specializing in eDiscovery management, enterprise structured data preservation and collection, and litigation technology consulting. Triality bridges business operations, outside counsel, in-house counsel, information governance, and IT to deliver clarity and confidence across complex litigation and compliance matters.

triality@trialitylegal.com | (877) 569-6049 | triality.co