Co-pilot Edge browser privacy issue

Tim 0 Reputation points
2026-07-15T14:46:29.6533333+00:00

I have recently realized that if I send a URL to Copilot using the Edge browser extension, Copilot cannot follow that URL unless I give it permission to view the page that I am currently on even if the page I am currently on has absolutely nothing to do with the request that I am sending to Copilot. They call it "context clues." This is an incredible violation of privacy. I might be accessing my bank account or medical information. Why does Copilot need to see that in order to answer a question related to a webpage about something else entirely? I've asked this question to Copilot and it agrees by saying, "your reaction makes complete sense. You’re not overreacting — you’re pointing out a real tension in how the permission system works."

This apparently only applies to the browser extension, not the stand-alone Copilot app.

What is going on here?

Microsoft Copilot | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-07-15T14:46:52.0833333+00:00

    What is happening is the difference between a normal Copilot query and a query that uses browsing context inside Microsoft Edge.

    In Edge, Microsoft states that it decides what data to send to Copilot based on the query and consent settings.

    • For prompts that do not need browsing context, Edge sends only:
      • the query
      • the URL
      • the page title
      • previous conversation history
    • For prompts that do need browsing context—such as summarizing a page or answering about what is open in the browser—Edge asks for permission to access page information.

    Microsoft defines browsing context as the URL and page content open in the active tab. It also defines page information as the content of the webpage or document open in the active tab.

    That means the Edge-integrated experience is designed around the current active tab, not an arbitrary URL pasted into the prompt. If the request is treated as needing browsing context, Edge asks for permission to use the active tab’s page information. That is why the permission prompt can appear unrelated to the URL mentioned in the request.

    Microsoft also states that for questions needing browsing context, Edge sends the full browsing context only for public pages that are on the Bing index. For page context-based conversations, Edge and Copilot do not store or train on the context used for grounding. Conversation history, however, stores Copilot queries and responses until deleted.

    If the goal is to prevent Copilot in Edge from reading the current page, the documented control is:

    • Settings > Copilot and sidebar > Copilot
    • turn off Allow Copilot to read context clues on the web

    For Actions in Edge, there is a separate permissions model under:

    • Settings > AI innovations

    That area controls whether Copilot can act on sites with Light, Balanced, or Strict permissions, and whether sites are allowed or blocked.

    So the behavior is not that Copilot needs unrelated bank or medical content to answer every URL question. The documented behavior is that the Edge integration uses the active tab as its context source when a request is classified as needing browsing context, and permission is required for that. The standalone Copilot experience differs because it is not tied to the active Edge tab in the same way.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.