Frontrow Technology
← All insights & guides
Guide

Data & Governance

Copilot model choice and subprocessors: what to check

Anthropic's Claude models are selectable in Microsoft 365 Copilot and OpenAI has been onboarded as a subprocessor. The supplier-risk checks and admin settings Australian organisations should work through.

Sam Williams · 28 August 2026 · 11 min read

For most of Microsoft 365 Copilot's life, the answer to "where does our data go when staff use it?" was simple: to Microsoft, processed on Microsoft-operated infrastructure. Over 2026 that answer has become more layered. Copilot is now model-diverse by design, Anthropic's Claude models are selectable inside everyday experiences like editing in Word, and Microsoft has onboarded external AI providers as subprocessors, meaning some processing now happens on the model provider's infrastructure under Microsoft's contractual oversight rather than inside Microsoft's own services.

None of this is hidden; it is documented across Microsoft Learn, the Copilot release notes and admin centre settings. But it changes what a supplier-risk register, a privacy assessment and a board paper should say about Copilot, and in Australian tenants some of it is enabled by default. This guide separates what is verifiable in Microsoft's own documentation from what is so far reported only through admin channels, and finishes with what to document.

What has verifiably changed

  • Model choice in the apps: per the Microsoft 365 Copilot release notes, since 11 August 2026 users editing a Word document with Copilot on the web can select Anthropic models alongside OpenAI models from a model menu. On 25 August 2026 the notes added Sonnet 5, one of Anthropic's Claude models, to the Word models menu as the default for higher-reasoning drafting and edits.
  • Anthropic as a Microsoft subprocessor: Microsoft's documentation states Anthropic has onboarded as a subprocessor, with Claude available across Microsoft Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps. Microsoft's Product Terms and Data Protection Addendum apply, as does the Customer Copyright Commitment, except for separately flagged preview models.
  • Default-on in Australia: Microsoft enables Anthropic models by default for most commercial cloud customers, with the EU, EFTA and the UK as the opt-in exceptions. Australian tenants sit in the default-on group. An organisation that has taken no action already has Claude models available to its users.
  • A data boundary exclusion: Microsoft states that Anthropic models in these offerings are currently excluded from the EU Data Boundary and, where applicable, in-country processing commitments. For Australian organisations the practical reading is that model processing should be assumed to occur on the provider's infrastructure, not within a committed local boundary.

The OpenAI subprocessor change, as reported

A parallel change concerns OpenAI. Microsoft 365 admin community coverage of the message-centre notice reports that Microsoft has onboarded OpenAI as a subprocessor for Microsoft 365 Copilot and Copilot Studio, providing access to OpenAI-operated models running on OpenAI's own infrastructure, beginning with GPT-5.6. This is distinct from the Azure OpenAI Service arrangement Copilot has always used, where OpenAI's models run entirely inside Microsoft-operated infrastructure. Per the same reports, the admin setting appeared on 9 July 2026 switched off, and was automatically enabled for all users on 24 July 2026 in tenants where no administrator had adjusted it.

Frontrow has not located a public Microsoft Learn page documenting the OpenAI auto-enablement in the way the Anthropic arrangement is documented, so the dates above are attributed to admin reporting rather than to Microsoft directly. The action it implies does not depend on the reporting being precise: check the current state of the setting in your own tenant, because that is a fact you can verify in minutes.

Where the controls live

Microsoft has given tenants a genuine control surface for all of this, which is the customer-helpful part of the story and the part governance teams should use:

  1. 1In the Microsoft 365 admin centre, go to Copilot, then Settings, then View all, then select AI providers operating as Microsoft subprocessors. Each provider can be enabled or disabled, and access can be scoped to specific users or Microsoft Entra ID security groups rather than the whole tenant.
  2. 2Changing these settings requires the AI Administrator or Global Administrator role. The AI Administrator role is worth assigning deliberately: it is a governance chokepoint, and knowing who holds it is itself an audit item.
  3. 3Preview models with data retention are controlled separately and are default-off everywhere, even where standard Anthropic models are on by default. For those specific models, Anthropic acts as an independent processor under its own terms and retains most inputs and outputs for up to 30 days, so enabling them is a materially different decision from enabling the subprocessor models.
  4. 4Copilot Studio and Power Platform have an additional layer: once providers are enabled in the Microsoft 365 admin centre, the Power Platform admin centre controls whether external models can be used for generative responses there.

What this means for supplier risk, in Australian terms

For most organisations this is a change to record, not a reason for alarm: the subprocessor structure keeps Microsoft's DPA and Product Terms in force, and Microsoft states customer data is not used to train these models without permission. But "record" is doing real work in that sentence, and for some sectors the obligations are specific.

  • APRA-regulated entities: CPS 234 makes information security obligations follow information assets managed by third parties, and CPS 230, in force since July 2025, expects material service providers and their supply chains to be actively managed. A change in which companies process staff prompts and document content is squarely the kind of fourth-party change those frameworks expect an entity to notice, assess and minute.
  • Privacy Act obligations: where Copilot interactions can include personal information, processing on a provider's offshore infrastructure engages APP 8's cross-border disclosure considerations. The EU Data Boundary exclusion noted in Microsoft's documentation is the signal to reassess rather than assume prior conclusions still hold.
  • Supplier registers and DPIAs: any privacy impact assessment or vendor assessment written for Copilot before mid-2026 described a single-provider processing chain. It is now out of date, whichever way the organisation decides to set the toggles.

The documentation pass to run this quarter

  1. 1Record the current state of the AI providers setting in your tenant: which providers are enabled, for which users or groups, and whether that state was chosen or defaulted.
  2. 2Record who holds AI Administrator and Global Administrator, and confirm changes to subprocessor settings would be visible to whoever owns supplier risk.
  3. 3Make the enable-or-restrict decision deliberately and minute it, whichever way it goes. A default accepted knowingly is a governance position; a default nobody noticed is a finding.
  4. 4Update the Copilot entry in the supplier register and any DPIA to reflect the multi-provider processing chain, the DPA coverage, and the data boundary exclusions.
  5. 5Subscribe someone to Microsoft's subprocessor list on the Service Trust Portal and to message-centre governance notices, with a standing review cadence. This change arrived with weeks of notice; the next one will too, but only for organisations that are watching.
  6. 6If preview models with data retention are ever requested, treat that as a separate assessment with Anthropic's own terms and retention practices in scope, not an extension of the existing approval.

Common questions

Frequently asked

Which Microsoft 365 Copilot features can use Anthropic's Claude models?
Microsoft's documentation lists Claude availability across Microsoft Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps. In practice users see it as a model menu, for example when editing with Copilot in Word on the web, where Anthropic models have been selectable alongside OpenAI models since 11 August 2026. In Copilot Studio, makers choose the model when creating an agent.
Are Anthropic models on by default for Australian tenants?
Yes. Microsoft enables Anthropic models by default for most commercial cloud customers, with the EU, EFTA and the UK as the opt-in exceptions where the default is no users. Australia is in the default-on group, so an Australian tenant that has taken no admin action already has Claude models available, which is exactly why the setting state should be captured and the decision minuted.
What changed with OpenAI as a Copilot subprocessor?
Admin community reporting of the message-centre notice says Microsoft onboarded OpenAI as a subprocessor so Copilot and Copilot Studio can access OpenAI-operated models, beginning with GPT-5.6, running on OpenAI's infrastructure rather than Microsoft's Azure OpenAI Service. The reports state the setting appeared on 9 July 2026 disabled and was auto-enabled on 24 July 2026 where admins had not adjusted it. Frontrow has not found this documented on Microsoft Learn, so verify the setting state directly in your own tenant.
Where is the admin control, and who can change it?
In the Microsoft 365 admin centre under Copilot, Settings, View all, AI providers operating as Microsoft subprocessors. Each provider can be disabled or scoped to specific users and security groups. Changes require the AI Administrator or Global Administrator role, and Copilot Studio and Power Platform have an additional control in the Power Platform admin centre.
Does Microsoft's Data Protection Addendum still apply when Claude processes our data?
For the standard subprocessor arrangement, yes: Microsoft states its Product Terms and DPA apply to Anthropic models used through Microsoft's enterprise services, with the Customer Copyright Commitment also covering supported products. The exception is preview models with data retention, where Anthropic acts as an independent processor under its own terms and retains most inputs and outputs for up to 30 days; those are default-off and need a separate, deliberate decision.
What should an APRA-regulated organisation do about this change?
Treat it as a material change in a critical supplier's processing chain: capture the current setting state, make and minute a deliberate enable-or-restrict decision, update the supplier register and any DPIA to reflect multi-provider processing and the data boundary exclusions, and map the assessment to CPS 234's third-party information security obligations and CPS 230's service provider management expectations. None of that requires turning anything off; it requires being able to show the decision was made.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.