Back to Blog
implementation

Claude inside Microsoft 365 Copilot: the UK tenant setting most admins have not checked

By Jay MatharuPublished Last reviewed
An IT administrator pausing over a laptop while reading a printed page, with the City of London skyline behind

Microsoft has made Anthropic's Claude models available inside Microsoft 365 Copilot, and has been explicit that when they are used, processing happens outside the Microsoft EU Data Boundary. For UK organisations this is an administrator decision rather than a background change, and it is one that touches your data protection impact assessment and your record of processing activities.

There is a complication that most coverage has missed. There are two different settings, they behave in opposite ways, and they interact. A UK administrator who reads the headline coverage and concludes their tenant is safe by default may be wrong, depending on which setting is in play and when the tenant was created.

This article is written for the person who has to make and defend that decision: the IT director, the data protection lead, or the managing partner who signs off supplier changes. It is not a walkthrough of where the toggle lives, which Microsoft documents perfectly well. It is about what you are consenting to when you enable it.

The two settings, and why they conflict

The first is the global subprocessor setting, covering AI providers operating as Microsoft subprocessors. Microsoft's position on this one is unambiguous for the UK: Anthropic models in Microsoft 365 Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps "are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments. Customers within the EU Data Boundary and customers in the UK have Anthropic models disabled by default." For these regions the setting appears but defaults to no users.

The second is a narrower, apps-level setting covering Copilot in Microsoft 365 apps with Anthropic models. This one behaves the opposite way: Microsoft states it is on by default for tenants in the EU, EFTA and the UK created after 25 March 2026. Tenants that existed before that date are directed to the Message Center.

So the correct answer to "are we opted in by default?" is: it depends which setting you mean and when your tenant was created. Stated without that qualification, either version is wrong.

The two also interact in a way that can trap an administrator mid-configuration. Microsoft notes that when the global subprocessor setting is scoped to all users, or to specific users and groups, the apps-level Anthropic setting becomes unavailable and cannot be changed. Configure in the wrong order and a control you expected to have disappears.

There is one more item for organisations that believe they have already handled this. UK, EU and EFTA organisations that previously opted in under Anthropic's own separate commercial terms must opt in again, because the newer toggle defaults to off. The Anthropic independent processor setting was decommissioned on 1 May 2026, and without the subprocessor setting enabled, access to Anthropic models is no longer available. A prior decision does not carry forward.

The UK is not inside the EU Data Boundary

This is the point that most UK commentary gets wrong, usually by treating "UK and EU" as a single bucket.

The EU Data Boundary stores and processes customer data in EU and EFTA datacentres. The United Kingdom is not in it. What the UK has instead is a separate in-country data processing commitment: Microsoft announced in-country processing for Microsoft 365 Copilot across fifteen countries including the United Kingdom, published in November 2025 and updated in April 2026.

That commitment is precisely what enabling Anthropic models sets aside. Microsoft states that when Anthropic models are used in Copilot experiences in Word, Excel or PowerPoint, data processing occurs outside the EU Data Boundary, with coverage currently Excel and PowerPoint and Word support due in summer 2026. Its main Copilot privacy page repeats the position plainly: models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary.

So a UK firm enabling this is not making a marginal adjustment to an EU arrangement it was never inside. It is switching off a UK-specific commitment it did hold.

Two different contractual positions, and one that catches people out

Where Anthropic operates as a Microsoft subprocessor, your contractual position stays inside the Microsoft estate. The Microsoft Product Terms, the Microsoft Data Protection Addendum, Enterprise Data Protection and the Microsoft Customer Copyright Commitment all apply. Your counterparty remains Microsoft.

Preview models with data retention are a different matter entirely, and this is the item most likely to be missed in a governance review. Microsoft names Claude Fable 5 and Claude Mythos 5 in this category and states that for them, Anthropic acts as an independent data processor rather than a Microsoft subprocessor, subject to Anthropic's own commercial terms and Data Processing Addendum, with data stored by Anthropic and not subject to your Microsoft Customer Agreement including the commitments in the Product Terms and DPA.

Enabling those preview models therefore changes who you are contracting with. They are off by default everywhere, including in tenants where Anthropic is otherwise enabled, which is the right default and worth leaving alone unless someone can articulate why not.

Microsoft publishes retention figures for that category which are directly usable in a DPIA: Anthropic stores most inputs and outputs for up to 30 days, may retain content flagged by trust and safety classifiers for up to two years and classification scores for up to seven years, and does not use retained data for training without express permission. Cite those to Microsoft. Anthropic's own retention page confirms the 30-day baseline for covered Mythos-class models but does not state the two-year or seven-year figures.

Does enabling this create a restricted transfer?

This is where the two routes diverge, and where a UK organisation should take the question seriously rather than assuming the answer.

The ICO published updated international transfers guidance in January 2026 introducing a three-step test: does UK GDPR apply to the processing; are you initiating the transfer to an organisation outside the UK; and is the recipient a separate legal entity. Every restricted transfer needs a safeguard or an exception, and where a safeguard is relied on, a completed transfer risk assessment is required.

The second step is the one that matters here, because it turns on who initiated the transfer. Under the subprocessor route, Microsoft appointed Anthropic; your contractual relationship remains with Microsoft, and the transfer analysis follows that structure. Under the preview-models route, your tenant is directly appointing an overseas independent processor under Anthropic's own DPA, which looks materially more like a controller-initiated restricted transfer requiring an IDTA or Addendum plus a transfer risk assessment.

Legal commentary on the ICO update suggests the practical rule of thumb is to follow the contractual relationships and identify the party that designed the transfer structure or first chose the recipient, and notes this analysis is particularly important in cloud, SaaS, managed service, processor and sub-processor arrangements. The same commentary notes that the Data (Use and Access) Act 2025 has introduced material UK and EU divergence, so a single transfer analysis may no longer satisfy both regimes.

We would not tell you the answer for your organisation in an article. We would tell you that the two routes are not equivalent and should not be assessed together, and that if your DPIA treats them as one thing it is probably wrong.

What this means for your DPIA and ROPA

Three practical consequences follow, and none of them is satisfied by flipping a switch.

Your record of processing activities needs to reflect Anthropic processing outside the EU Data Boundary, because a new processor in a new location is exactly what a ROPA exists to record. Your DPIA needs revisiting rather than reusing, since the tool it assessed is not the tool you are now running. And your scope is wider than Copilot chat: a single subprocessor decision affects Microsoft 365 Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps, with Copilot Studio and Power Platform requiring a second set of controls in the Power Platform admin centre.

The middle option is the one most firms should look at first. Access can be scoped to specific users or Microsoft Entra ID security groups rather than enabled tenant-wide, applied at provider level and enforced across Copilot and Copilot Studio. For a firm with mixed data sensitivity, where a marketing team's use case and a client-confidential matter are not the same risk, that is usually the proportionate answer.

If you have not yet produced a DPIA for your assistant rollout at all, our guide to whether you need a DPIA before rolling out Claude or Copilot sets out the screening test.

What to do, and what not to do

  • Check both settings, not one. Confirm the global subprocessor setting and the apps-level setting separately, and note your tenant creation date, because the defaults differ.
  • Re-check if you opted in previously. The independent processor setting was decommissioned on 1 May 2026 and prior opt-ins do not carry forward.
  • Decide scope before you decide on or off. Specific users and groups is a real option and is usually the proportionate one.
  • Leave preview models with data retention alone unless someone can explain why the change of contracting party is acceptable.
  • Update the ROPA and revisit the DPIA as part of the change, not afterwards.
  • Do not assume the UK is covered by EU Data Boundary commentary. It is not inside the boundary and its protection is a separate commitment.
  • Do not treat the two routes as one for transfer purposes. Who initiated the transfer differs, and so does the analysis.

Where The AI Consultancy fits

Working out which settings are live in your tenant, what the change does to your existing documentation, and whether scoped access is the proportionate answer is the kind of review our Claude implementation engagements open with. Where the question is broader than one toggle, the AI readiness assessment covers the governance position as a whole. Our guide to whether Claude is GDPR compliant covers Anthropic's own retention and training position, and Claude data residency for UK organisations covers what can and cannot be kept in region on the direct routes.

Verified on 31 July 2026 against Microsoft Learn documentation for the AI subprocessor setting and the Anthropic apps setting, Microsoft's Copilot privacy and EU Data Boundary pages, Anthropic's data retention documentation and the ICO's international transfers guidance. This admin surface changed in April, May and July 2026 and is expected to keep moving; confirm the current position in your own tenant before acting. This article is general information, not legal advice.

Frequently asked questions

Are Anthropic's Claude models enabled by default in a UK Microsoft 365 Copilot tenant?
It depends which setting you mean, and the two differ. At the global AI subprocessor setting, Microsoft states that customers in the UK and within the EU Data Boundary have Anthropic models disabled by default. At the narrower Copilot in Microsoft 365 apps setting, Microsoft states the opposite: it is on by default for tenants in the EU, EFTA and the UK created after 25 March 2026, with earlier tenants directed to the Message Center. Check both settings and note your tenant creation date rather than relying on either default in isolation.
Does enabling Claude in Copilot take our data outside the UK?
Microsoft states that when Anthropic models are used in Copilot experiences in Word, Excel or PowerPoint, data processing occurs outside the Microsoft EU Data Boundary. The UK is not inside that boundary in any case; its protection is a separate in-country data processing commitment that Microsoft announced across fifteen countries including the United Kingdom. Enabling Anthropic models sets that commitment aside for the affected experiences, which is why the decision belongs in your ROPA and your DPIA rather than being treated as a routine feature toggle.
Who are we contracting with when Claude runs inside Copilot?
It depends on the route. Where Anthropic operates as a Microsoft subprocessor, your counterparty remains Microsoft and the Microsoft Product Terms, Data Protection Addendum, Enterprise Data Protection and Customer Copyright Commitment all apply. For preview models with data retention, Microsoft states that Anthropic acts as an independent data processor subject to its own commercial terms and DPA, with data stored by Anthropic and not subject to your Microsoft Customer Agreement. That is a different contracting party and a different risk position, and those models are off by default everywhere.
Do we need to update our DPIA before enabling Anthropic models?
You should revisit it rather than reuse it, because the tool your existing DPIA assessed is not the tool you would be running. A new processor in a new location also belongs in your record of processing activities. Note that the scope is wider than Copilot chat: a single subprocessor decision affects Microsoft 365 Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps, and Copilot Studio and Power Platform require a second set of controls in the Power Platform admin centre.
Can we enable Claude for some staff but not others?
Yes, and for most organisations that is the proportionate answer. Microsoft allows access to be scoped to specific users or to Microsoft Entra ID security groups rather than enabled tenant-wide, applied at provider level and enforced across Microsoft 365 Copilot and Copilot Studio. Where a firm has mixed data sensitivity, for example a marketing function and a client-confidential practice area, scoped access lets the lower-risk use case proceed without extending the change to material where it would be harder to justify.

Related Articles

implementation

Why Your AI-Built App Works in Preview But Fails in Production

implementation

Fix, Refactor or Rebuild? A Decision Matrix for AI-Built Apps

implementation

Security Vulnerabilities in AI-Generated Apps, A UK Guide

Ready to explore AI for your business?

Book a free 20-minute consultation. No obligation, no jargon.