For most of Microsoft 365 Copilot's life, the answer to "where does our data go when staff use it?" was simple: to Microsoft, processed on Microsoft-operated infrastructure. Over 2026 that answer has become more layered. Copilot is now model-diverse by design, Anthropic's Claude models are selectable inside everyday experiences like editing in Word, and Microsoft has onboarded external AI providers as subprocessors, meaning some processing now happens on the model provider's infrastructure under Microsoft's contractual oversight rather than inside Microsoft's own services.
None of this is hidden; it is documented across Microsoft Learn, the Copilot release notes and admin centre settings. But it changes what a supplier-risk register, a privacy assessment and a board paper should say about Copilot, and in Australian tenants some of it is enabled by default. This guide separates what is verifiable in Microsoft's own documentation from what is so far reported only through admin channels, and finishes with what to document.
What has verifiably changed
- Model choice in the apps: per the Microsoft 365 Copilot release notes, since 11 August 2026 users editing a Word document with Copilot on the web can select Anthropic models alongside OpenAI models from a model menu. On 25 August 2026 the notes added Sonnet 5, one of Anthropic's Claude models, to the Word models menu as the default for higher-reasoning drafting and edits.
- Anthropic as a Microsoft subprocessor: Microsoft's documentation states Anthropic has onboarded as a subprocessor, with Claude available across Microsoft Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps. Microsoft's Product Terms and Data Protection Addendum apply, as does the Customer Copyright Commitment, except for separately flagged preview models.
- Default-on in Australia: Microsoft enables Anthropic models by default for most commercial cloud customers, with the EU, EFTA and the UK as the opt-in exceptions. Australian tenants sit in the default-on group. An organisation that has taken no action already has Claude models available to its users.
- A data boundary exclusion: Microsoft states that Anthropic models in these offerings are currently excluded from the EU Data Boundary and, where applicable, in-country processing commitments. For Australian organisations the practical reading is that model processing should be assumed to occur on the provider's infrastructure, not within a committed local boundary.
The OpenAI subprocessor change, as reported
A parallel change concerns OpenAI. Microsoft 365 admin community coverage of the message-centre notice reports that Microsoft has onboarded OpenAI as a subprocessor for Microsoft 365 Copilot and Copilot Studio, providing access to OpenAI-operated models running on OpenAI's own infrastructure, beginning with GPT-5.6. This is distinct from the Azure OpenAI Service arrangement Copilot has always used, where OpenAI's models run entirely inside Microsoft-operated infrastructure. Per the same reports, the admin setting appeared on 9 July 2026 switched off, and was automatically enabled for all users on 24 July 2026 in tenants where no administrator had adjusted it.
Frontrow has not located a public Microsoft Learn page documenting the OpenAI auto-enablement in the way the Anthropic arrangement is documented, so the dates above are attributed to admin reporting rather than to Microsoft directly. The action it implies does not depend on the reporting being precise: check the current state of the setting in your own tenant, because that is a fact you can verify in minutes.
Where the controls live
Microsoft has given tenants a genuine control surface for all of this, which is the customer-helpful part of the story and the part governance teams should use:
- 1In the Microsoft 365 admin centre, go to Copilot, then Settings, then View all, then select AI providers operating as Microsoft subprocessors. Each provider can be enabled or disabled, and access can be scoped to specific users or Microsoft Entra ID security groups rather than the whole tenant.
- 2Changing these settings requires the AI Administrator or Global Administrator role. The AI Administrator role is worth assigning deliberately: it is a governance chokepoint, and knowing who holds it is itself an audit item.
- 3Preview models with data retention are controlled separately and are default-off everywhere, even where standard Anthropic models are on by default. For those specific models, Anthropic acts as an independent processor under its own terms and retains most inputs and outputs for up to 30 days, so enabling them is a materially different decision from enabling the subprocessor models.
- 4Copilot Studio and Power Platform have an additional layer: once providers are enabled in the Microsoft 365 admin centre, the Power Platform admin centre controls whether external models can be used for generative responses there.
What this means for supplier risk, in Australian terms
For most organisations this is a change to record, not a reason for alarm: the subprocessor structure keeps Microsoft's DPA and Product Terms in force, and Microsoft states customer data is not used to train these models without permission. But "record" is doing real work in that sentence, and for some sectors the obligations are specific.
- APRA-regulated entities: CPS 234 makes information security obligations follow information assets managed by third parties, and CPS 230, in force since July 2025, expects material service providers and their supply chains to be actively managed. A change in which companies process staff prompts and document content is squarely the kind of fourth-party change those frameworks expect an entity to notice, assess and minute.
- Privacy Act obligations: where Copilot interactions can include personal information, processing on a provider's offshore infrastructure engages APP 8's cross-border disclosure considerations. The EU Data Boundary exclusion noted in Microsoft's documentation is the signal to reassess rather than assume prior conclusions still hold.
- Supplier registers and DPIAs: any privacy impact assessment or vendor assessment written for Copilot before mid-2026 described a single-provider processing chain. It is now out of date, whichever way the organisation decides to set the toggles.
The documentation pass to run this quarter
- 1Record the current state of the AI providers setting in your tenant: which providers are enabled, for which users or groups, and whether that state was chosen or defaulted.
- 2Record who holds AI Administrator and Global Administrator, and confirm changes to subprocessor settings would be visible to whoever owns supplier risk.
- 3Make the enable-or-restrict decision deliberately and minute it, whichever way it goes. A default accepted knowingly is a governance position; a default nobody noticed is a finding.
- 4Update the Copilot entry in the supplier register and any DPIA to reflect the multi-provider processing chain, the DPA coverage, and the data boundary exclusions.
- 5Subscribe someone to Microsoft's subprocessor list on the Service Trust Portal and to message-centre governance notices, with a standing review cadence. This change arrived with weeks of notice; the next one will too, but only for organisations that are watching.
- 6If preview models with data retention are ever requested, treat that as a separate assessment with Anthropic's own terms and retention practices in scope, not an extension of the existing approval.