Skip to main content
io4 Technologies

AI & Copilot

Claude in Microsoft 365 Copilot: what model choice means for your data

Claude Opus 5 has been available across the full Microsoft 365 Copilot suite since July 24, 2026, and Anthropic is now a Microsoft subprocessor. Before letting your teams switch models, three questions matter: where your data goes, who decides, and how you keep control.

By Jordane Dours 2026-08-01 6 min read

Claude Opus 5 has been available across the full Microsoft 365 Copilot suite since July 24, 2026, and Anthropic is now a Microsoft subprocessor. Before letting your teams switch models, three questions matter: where your data goes, who decides, and how you keep control.

Claude in Copilot: what's actually new

Claude didn't land in Copilot last month. Microsoft has offered Anthropic's models since September 24, 2025, first in the Researcher agent and Copilot Studio, behind an explicit admin opt-in (Microsoft 365 Blog, September 24, 2025). Back then the trade-off was clear: enabling Claude meant sending your data to Anthropic, outside Microsoft-managed environments, under Anthropic's terms.

Two things have changed since. On July 24, 2026, Claude Opus 5 became available across the full suite: Word, Excel, PowerPoint, Copilot Chat, Cowork and Copilot Studio, under the same Copilot licence, alongside GPT-5.6 (Microsoft Tech Community, July 24, 2026). And above all, the contractual framework is no longer the same: Anthropic is now a Microsoft subprocessor. For your users, it's one more dropdown menu. For whoever is responsible for IT or privacy, it's a governance decision: the choice of model determines who processes your corporate data, and under what terms.

Anthropic becomes a Microsoft subprocessor: what that covers

Microsoft has onboarded Anthropic as a subprocessor of its online services. Concretely, using Claude models in Copilot remains covered by the Microsoft contractual framework your organization already knows: the Product Terms, the Data Protection Addendum (DPA) and Copilot's enterprise data protection. Microsoft's Customer Copyright Commitment also applies to Anthropic models in Microsoft 365 Copilot and Copilot Studio (Microsoft Learn, July 22, 2026).

In other words: no contract to sign with Anthropic, no new agreement to negotiate. Contractually, this is the cleanest possible way to introduce a second model provider.

The point to watch: the data processing boundary

The important nuance is elsewhere. Microsoft states that Anthropic models deployed in its offerings are excluded from the EU Data Boundary and, when applicable, from in-country processing commitments (Microsoft Learn, July 22, 2026). For a Quebec organization that relies on Canadian residency or processing commitments, a request sent to a Claude model may therefore be processed outside that perimeter.

Second thing to know: in commercial cloud, Anthropic models are enabled by default for most customers. Only the European Union, EFTA and the United Kingdom are off by default. If you do nothing, your users already have the option.

That's no reason to panic: processing remains governed by the DPA and enterprise data protection. But if your Law 25 analysis, your privacy impact assessments or your client commitments rest on processing in Canada, the decision to enable Anthropic models or not should be documented, not endured.

“Preview models with data retention”: one more notch of vigilance

Microsoft distinguishes a second family: Anthropic preview models with data retention, such as Claude Fable 5 and Claude Mythos 5. For those, Anthropic acts as an independent data processor, not a Microsoft subprocessor: Anthropic's commercial terms and data protection addendum apply, and Anthropic retains most inputs and outputs for up to 30 days (longer if flagged by its safety classifiers).

These models are off by default for all tenants, even when Anthropic is enabled as a subprocessor, and require a deliberate double opt-in from the administrator. The reasonable position for most organizations: keep them off until a specific business need justifies the analysis.

What your administrator should do this week

  • Check the setting: Microsoft 365 admin center → Copilot → Settings → “AI providers operating as Microsoft subprocessors”. The AI Administrator or Global Administrator role is required.
  • Decide and document: enable for everyone, restrict to Entra ID security groups, or disable. The setting applies to Microsoft 365 Copilot and Copilot Studio.
  • Cover Copilot Studio and Power Platform: additional controls exist in the Power Platform admin center for agents that use external models.
  • Confirm that preview models with data retention remain disabled, and add that check to your periodic governance review.
  • Inform users: the Copilot interface shows when a Claude model is in use; clear guidance prevents improvised choices on sensitive files.

Conclusion

Claude's arrival in Microsoft 365 Copilot is good news: more choice, a Microsoft contractual framework already in place, and competition that pulls quality upward. But a model choice is first a data path choice. The winning sequence is simple: check the default setting, decide knowingly, document the decision in your Law 25 file, then let teams use the best model for each task. To frame that decision and fold it into your Copilot governance, talk to an io4 expert.

Keywords:Claude Microsoft 365 CopilotAnthropic CopilotCopilot model choiceMicrosoft AI subprocessorCopilot data governanceCopilot Law 25

Want to talk it through?

Let's spend 30 minutes on your situation.

A free assessment with an io4 architect. No commitment, no pressure.

Book my assessment
Let's talk about your project

30 minutes to frame what matters.

A direct conversation with one of our experts. No commitment, no pressure. You leave with a clear, reasoned perspective on your situation.

Or call us directly:1 888 285 9583
Free assessment