NTNU piloted Microsoft 365 Copilot in spring 2024 inside Datatilsynet's sandbox; its exit report gave eight findings and concluded NTNU was not ready to deploy it organisation-wide.
Details
Promoter
Norwegian University of Science and Technology (NTNU) with Datatilsynet
Period
2024
Keywords
generative AI, data protection, DPIA, public university
Description
In spring 2024 the Norwegian University of Science and Technology (NTNU) tested Copilot for Microsoft 365 as part of the Norwegian Data Protection Authority's (Datatilsynet) regulatory sandbox, examining the tool through a data-protection lens and presenting eight main findings. The exit report found that a data protection impact assessment is generally required for generative AI tools like Copilot and that DPIAs must be carried out continuously because the tool changes frequently. It noted that Copilot sees the same information as the user, so weak access management and poor control of personal data are made visible and amplified. It also identified structural challenges for data minimisation and purpose limitation and left US surveillance-law exposure as an unresolved legal risk. NTNU concluded it was not ready to deploy Microsoft 365 Copilot across the whole organisation, partly because its own information governance was not orderly enough. The report was published openly, and the university's project documentation and a toolbox are public; the report also drew criticism in the Norwegian press. This is a cautionary, candid case: value is in transparent risk findings, not in measured productivity gains, which the pilot did not establish.
Read the full analysis: https://www.ntnu.no/adm/it/copilot
Implementation
Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.
Do you run this practice?
Claim it —
verified implementers get a public contact pathway and can propose corrections.
Data sources
Where this practice's information was retrieved from, and when.