Start here
The free tool below runs entirely in this browser — no account, nothing stored or transmitted. Redact anything you would not want kept before you type it.
Open the companion tool →Why three consents hide inside one sentence
'AI features are now available in your workspace' covers at least three different things: what the assistant can read (your documents, mail, messages, and everything they contain, including other people's data), what happens to that content afterwards (whether it is retained, logged, or used to improve or train a model), and who processes it (your employer's own tenant, or a third-party model vendor under a data-processing agreement). Each has a different answer and a different owner.
Asking separates them, and separation is what makes an answer checkable. 'Does the assistant read my files' produces a yes; 'is my content used to train models outside our tenant, and can I opt out' produces a policy citation. Those questions are also the ones a privacy officer expects, which is why asking them in writing is normal rather than confrontational.
The protocol
- Save the rollout notice, the admin setting name, and the date. If the feature was enabled silently, note the first date you saw it.
- Find the scope: what the assistant can read (files, mail, chat, meetings), whether it reads content you did not open yourself, and whether colleagues' data is inside that scope.
- Ask what is retained: are prompts, responses, or searched content logged, for how long, and who inside the organization can read those logs.
- Ask about training and improvement: is your content used to train or improve models, is that inside your employer's tenant or at a vendor, and is there an opt-out.
- Ask who the vendor is, whether a data-processing agreement exists, and whether content leaves your employer's region or tenant.
- Ask what you can control yourself: can the feature be disabled per person, per folder, or per mailbox, and is there a label or sensitivity setting that excludes certain content.
- Send the questions in writing to the privacy, IT, or security contact, and keep the answers with dates. Re-ask after any major update, because these settings change without a new notice.
What the tool does
Turn a workplace AI rollout notice into a consent brief: what it grants, which three consents it bundles, the questions to ask in writing, and the opt-out or scope request to send. It stores nothing and sends nothing.
Limit first: This is a terms-reading and question-preparation aid, not legal advice, and it cannot tell you what your employer's systems actually do. Employee data rights differ by country, state, contract, and collective agreement.
Open the companion tool →One human next step
Send the questions to your organization's privacy or data-protection officer, or to IT or security if there is no named officer. In the EU and UK, a subject access request and a question about automated processing are formal routes; in the US, ask under your state's employee-privacy or consumer-privacy law where one applies, and involve a union representative or works council if you have one. If the answer is that content leaves your employer's control for training and there is no opt-out, that is worth raising formally in writing.
Research log and safety checks
AI-assist path: not applicable. The brief reads the employer's own notice and the answers it gives; a model's guess about a tenant's configuration would be unverifiable and would hide its basis (§1.2 UIC-10, §0.5d). §6.9 disclosed: no assist path — the artifact is the reader's written record of an employer's answers. §6.10: not a frontier-pace topic; the entry names no company's safety commitments, cites no capability-acceleration claim, and takes no position on whether employers should deploy these features — only on what an employee may ask.
§0.5 protection result: category is informed-consent-literacy; crisis-adjacent: no; fear/urgency/scarcity toolkit used: no. The protective function is free and the paid feature is convenience only.