And for anyone who's like "PShh! no organization dealing with sensitive data is gonna allow machines that ship with this into their org's networking ecosystem!": You're wrong.
I *Just This Last Week* got a new laptop from my university and copilot was already enabled, and pressing the "copilot" (reskinned context menu) button overrides even the group policy editor-level fix to turn it off, immediately reactivating it and resetting the GPE toggle to default.
So. Yeah. Bad.
Sent a very angry, very detailed email to my University's Vice-Chancellor for IT/CIO; I mean what else can I fucking do about it right now?