Copilot Can See Your Screen. The Share Picker Is the First Control., practitioner guidance from TheAICommand
← AI News
AI Security

Copilot Can See Your Screen. The Share Picker Is the First Control.

Microsoft 365 Copilot Vision lets a licensed user share an entire screen, a specific window or a mobile camera view during a voice conversation. For regulated Australian teams, the share picker now needs a purpose, a boundary and a stop condition before anyone starts talking.

·TheAICommand

Quick answer

Microsoft 365 Copilot Vision, rolling out from July 2026, turns a shared screen, window or mobile camera view into model input during a voice conversation. Before enabling it, approve a Visual Input Boundary: permitted share mode, prohibited information classes, preparation steps, a stop-share trigger and a named human reviewer, and keep media handling separate from transcript retention.

Microsoft 365 Copilot Vision turns an entire screen, a specific window or a mobile camera view into model input. For regulated teams, the share picker now needs a purpose, a boundary and a stop condition before anyone starts talking.*

The next Copilot prompt may begin before you speak. Microsoft 365 Copilot Vision lets a licensed user share an entire desktop screen, a specific window or a mobile camera during a voice conversation. Copilot can combine that visual input with available Microsoft 365 work data to answer questions aloud (Microsoft Support).

Microsoft announced on 30 June that Vision would roll out in July, after an administrative control for Vision rolled out in June (Microsoft's June update). Do not assume every tenant has it. Microsoft's voice FAQ still says Vision features are not currently available for any commercial customers, and that there is no feature-specific toggle for administrators to turn off voice features (Microsoft voice FAQ). Prefer the June rollout notice and the dedicated Vision pages, then verify your tenant, Message Centre notice and admin setting.

The practical verdict is simpler. The visual boundary needs approval before the prompt. A polished prompt cannot repair an over-broad screen share, an exposed notification or a camera view that includes another person's information.

What does Copilot Vision actually receive?

Vision is not a single screenshot attached to a chat. Microsoft says shared screen or camera content is processed as a series of images. It converts what appears in that stream into data it can analyse, including text, images, charts and on-screen interfaces, then grounds its response in available work data such as documents, emails, meetings and earlier discussions (Microsoft: how Vision works).

On desktop, the user can choose an entire screen or a specific window. On mobile, the input comes from the camera. Selecting Stop sharing ends the visual share but does not end the voice conversation (Microsoft: use Vision). That last distinction belongs in training. A person who intends to end all input can otherwise leave the microphone session running.

The capability also has useful limits. Vision currently works only through voice chat. It cannot read videos or animated GIFs, cannot take action or directly manipulate the screen, and does not reuse screen or camera input from an earlier session. Microsoft also warns that switching windows too quickly can lead to an answer based on the wrong screen content (Microsoft: how Vision works).

Do not turn those limits into broader claims. No long-term visual recall does not mean nothing is stored. No direct screen manipulation does not mean the answer is safe to use. A session-bound image stream can still expose customer, employee, claims, health, transaction or authentication information while the session is active. If your organisation already governs AI workplace monitoring, the same discipline applies to what a shared screen reveals about the people in it.

This is why the control surface is the share picker. The user chooses the visual aperture before the model interprets anything. In a financial-services workflow, that choice can be the difference between showing one approved dashboard and exposing the surrounding inbox, browser tabs, customer identifiers or other applications.

Why does the share picker need its own approval?

Treat each approved Vision use case as having a Visual Input Boundary. This is narrower than a generic AI use policy and more operational than a reminder to be careful. It states what may enter the image stream, what must remain outside it and exactly when sharing stops.

The boundary should contain seven fields:

  • the permitted business purpose and user group
  • whether a specific window, whole screen or mobile camera is allowed
  • permitted and prohibited information classes
  • the required preparation, including masking fields, closing unrelated applications and suppressing notifications
  • the permitted navigation path while sharing remains active
  • the stop-share trigger and unexpected-exposure route
  • the human reviewer who verifies any output before it is recorded or used

This is a proposed control, not a Microsoft feature or a regulator-prescribed form. It converts a fleeting user action into something a team can teach, test and evidence.

Where a frame contains personal information and the organisation is an APP entity, the current compilation of the Privacy Act 1988 provides the binding legal framework. The OAIC's commercially available AI guidance is guidance on applying privacy obligations, not legislation. It says personal information may appear in both AI inputs and outputs, recommends due diligence and embedded human oversight, and tells organisations to minimise the amount of personal information entered into an AI product (OAIC AI privacy guidance). Whether a particular image is personal or sensitive information depends on its content and whether a person is identified or reasonably identifiable.

For an APRA-regulated entity, this also belongs in existing prudential processes. CPS 234 requires information assets, including third-party-managed assets, to be classified by criticality and sensitivity and protected with controls proportionate to threats, lifecycle and consequences (APRA CPS 234). The current CPS 230 determination, in force from 1 July 2026, requires effective operational-risk controls, monitoring and service-provider risk management (APRA CPS 230). Neither standard names a Visual Input Boundary. The technique is a practical way to feed this change into controls that already exist.

Use this prompt to draft the boundary without exposing the source content. Privacy, security, records and the business owner must review it before the use case is enabled.

Prompt
Using only [USE_CASE_DESCRIPTION], [DATA_CLASSIFICATION_STANDARD],
[APPROVED_USER_GROUP] and [RECORDS_RULE], draft a Visual Input Boundary
for Microsoft 365 Copilot Vision or equivalent.

Return:
1. permitted purpose and users
2. allowed share mode: specific window, whole screen or camera
3. permitted and prohibited information classes
4. preparation steps before sharing
5. allowed navigation while sharing
6. stop-share and unexpected-exposure triggers
7. output verification and record owner
8. evidence gaps requiring human decision

Do not request, reproduce or infer any customer or employee information.
Do not decide whether the use case is approved.

The strongest default is a specific window, where supported, prepared before sharing begins. Close unrelated material. Mask fields not needed for the task. Suppress notification previews. For camera use, scan the physical background for people, badges, whiteboards, paper files and other screens. Stop sharing before changing systems, opening another record or moving the camera.

What record should a Vision session leave?

Do not put “deleted after 48 hours” in a control without naming the data. Microsoft's dedicated Vision page says shared content is processed as a series of images, audio and video data are temporarily stored to allow feedback and deleted after 48 hours, and text transcripts are stored and managed like text conversations in the Microsoft 365 Copilot app (Microsoft: how Vision works).

Microsoft's voice FAQ uses narrower wording. It says user and Copilot audio is not stored, but when feedback is turned on, conversation audio is stored temporarily and deleted after 48 hours (Microsoft voice FAQ). Those statements should not be blended into a promise that every part of every session disappears after two days. Confirm the signed terms, tenant configuration, feedback setting and Vision-specific treatment with Microsoft or your authorised provider.

Timeline of one Copilot Vision session separating the media path from the transcript path
The 48 hours applies to the stated media path, not the retained transcript

The transcript belongs on a separate retention path. Microsoft says admins can use Microsoft Purview to set retention policies for Copilot interaction data, and that prompts, responses and data accessed through Microsoft Graph are not used to train foundation models (Microsoft data, privacy and security). These are vendor and contractual claims, the same class of statement your team already verifies before relying on a vendor-operated agent platform. They do not decide which transcript or approved outcome your organisation must retain under its own obligations and schedules.

Create a Two-Trail Session Receipt:

TrailWhat the receipt records
Visual and audioApproved share mode, intended frame, session start and stop, unexpected exposure, feedback setting and the verified vendor handling statement
Text and useTranscript location, applicable retention rule, output used or rejected, source verification, human reviewer and any record placed in the system of record

The receipt should describe the boundary, not copy the sensitive content into another register. Keep the evidence proportionate. A low-risk training demonstration with synthetic data needs less detail than a session that assists an analyst to interpret a live operational dashboard.

Consider a fictional insurer using Vision to help an analyst understand a claims backlog dashboard. The approved test displays a synthetic window containing [REPORTID], [REPORTDATE] and aggregate queues only. Notification previews are off, no customer record is open, and the analyst is not permitted to switch windows while sharing.

Vision points out a change in one queue. The analyst stops the share, checks the figure against the source report and asks the operational owner why it moved. A human writes the final note. Copilot does not determine claim priority, customer treatment or staffing action. The session receipt records that the observation was accepted only after source verification. This is a fictional worked example.

Use this prompt to draft the receipt from approved metadata and a redacted transcript. The session user and records owner must verify it, while the accountable professional decides whether any outcome enters the official record.

Prompt
Using [APPROVED_SESSION_METADATA], [REDACTED_TRANSCRIPT],
[OUTPUT_STATUS] and [RECORDS_RULE], draft a Two-Trail Session Receipt.

Separate:
- visual and audio trail
- text transcript and retention trail
- output accepted, amended or rejected
- source checks completed by a human
- unexpected exposure or control failure
- official record created, with identifier only
- unresolved questions and accountable owner

Do not reproduce sensitive source content.
Do not infer that deletion occurred.
Do not make a customer, claim, employment or risk decision.

Do this Monday

  1. Check deployment truth. Confirm whether Vision is present in your tenant, capture the Message Centre notice and record the current Vision admin setting.
  2. Choose two bounded trials. Start with synthetic or de-identified content, one specific window and no need to move between systems while sharing.
  3. Write the Visual Input Boundary. Name the allowed share mode, prohibited data, preparation steps, stop trigger, incident route and human reviewer.
  4. Separate the retention trails. Verify the media, feedback and transcript handling against signed terms and tenant controls, then map the transcript and approved outcome to existing records rules.
  5. Rehearse the stop. Test wrong-window switching, an unexpected notification, camera background spill and the difference between stopping visual sharing and ending voice chat.
  6. Review the evidence. Have privacy, security, records, risk and the business owner decide whether the control works before expanding access.

Bottom line

Copilot Vision makes the share picker a data-control decision, not a user-interface detail. Approve the visual aperture before the prompt, stop sharing before the frame changes and keep media handling separate from transcript retention. Use a Two-Trail Session Receipt to prove what was intended, what was verified and what a human chose to use. Roll out only when the tenant setting, contractual treatment and Australian control owners agree.

This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.

References

  1. Microsoft, “What's New in Microsoft 365 Copilot, June 2026”: https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/what-s-new-in-microsoft-365-copilot-june-2026/ba-p/4529572
  2. Microsoft Support, “How vision in Microsoft 365 Copilot works”: https://support.microsoft.com/en-us/microsoft-365-copilot/how-vision-microsoft-365-works
  3. Microsoft Support, “Use vision in Microsoft 365 Copilot”: https://support.microsoft.com/en-us/microsoft-365-copilot/use-vision-microsoft-365-copilot
  4. Microsoft Support, “Frequently asked questions about voice features in Microsoft 365 Copilot”: https://support.microsoft.com/en-us/microsoft-365-copilot/frequently-asked-questions-about-voice-features-in-microsoft-365-copilot
  5. Microsoft Learn, “Data, Privacy, and Security for Microsoft 365 Copilot”: https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy
  6. Federal Register of Legislation, “Privacy Act 1988, latest compilation”: https://www.legislation.gov.au/C2004A03712/latest/text
  7. Office of the Australian Information Commissioner, “Guidance on privacy and the use of commercially available AI products”: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
  8. APRA, “CPS 234 Information Security”: https://www.apra.gov.au/standards/cps-234
  9. APRA, “CPS 230 Operational Risk Management”: https://www.apra.gov.au/standards/cps-230

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What can Microsoft 365 Copilot Vision actually see?
A licensed user can share an entire desktop screen, a specific window or a mobile camera view during a voice conversation. Microsoft says the shared content is processed as a series of images, converted into analysable data including text, images, charts and on-screen interfaces, and grounded in available Microsoft 365 work data. Vision cannot read videos or animated GIFs, cannot take action on the screen, and does not reuse screen or camera input from an earlier session.
Does stopping the screen share end the Copilot session?
No. Microsoft's documentation says selecting Stop sharing ends the visual share but does not end the voice conversation. A person who intends to end all input can leave the microphone session running, which is why the difference between stopping visual sharing and ending voice chat belongs in training and in the stop-share rehearsal.
What does Microsoft retain after a Vision session?
Two different paths. Microsoft's Vision page says audio and video data are temporarily stored to allow feedback and deleted after 48 hours, while text transcripts are stored and managed like text conversations in the Microsoft 365 Copilot app, where admins can apply Microsoft Purview retention policies. The 48 hours applies to the stated media path, not the retained transcript, so the two trails need separate retention answers verified against your signed terms and tenant configuration.
Is there an admin control for Copilot Vision?
Microsoft's June 2026 update says an administrative control for Vision rolled out in June, ahead of the July rollout of Vision itself. At the same time, Microsoft's voice FAQ still says vision features are not currently available for any commercial customers. Verify your own tenant, the Message Centre notice and the current admin setting rather than assuming either statement describes your deployment.
Does APRA require a Visual Input Boundary?
No. Neither CPS 234 nor CPS 230 names a Visual Input Boundary; it is a proposed control, not a regulator-prescribed form. It is a practical way to feed screen-sharing AI into obligations that already exist, including CPS 234 classification of information assets by criticality and sensitivity and CPS 230 operational-risk and service-provider risk management.

Tags

Microsoft 365 CopilotMultimodal AIPrivacyInformation SecurityAustralian Financial Services
← Back to AI News