Microsoft 365 Copilot Can Now Send Your Data Outside the EU, and Nobody Asked You

Microsoft 365 Copilot Can Now Send Your Data Outside the EU, and Nobody Asked You

· by IDE Solutions

Somewhere in your Microsoft 365 admin center is a setting that changed itself on July 24, 2026. Nobody clicked it. If you or your IT provider did not go in and turn it off first, it flipped on by default, and it changes where some of the text your staff type into Copilot actually gets processed. This is not a hypothetical risk story. It is a factual change to a system most small businesses in Germany and the rest of the EU already run every day.

The setting is called "AI providers operating as Microsoft subprocessors", and as of that date it lets OpenAI itself, not just Microsoft's Azure OpenAI setup, handle some of the requests your team sends through Microsoft 365 Copilot. That distinction sounds technical. For a business subject to the GDPR, it is not. It decides which company's infrastructure your prompts, and the company data Copilot pulls in to answer them, actually touch.

What actually changed on July 24

Until this year, Copilot in Microsoft 365 ran on OpenAI models hosted inside Microsoft's own Azure OpenAI Service. Microsoft controlled the infrastructure end to end, and that setup is what most GDPR assessments and data processing agreements written for Copilot were based on. In June 2026, Microsoft added OpenAI to its subprocessor list, and on July 9 it rolled out a new admin toggle that lets OpenAI's own infrastructure, running outside Azure, handle Copilot requests directly. Two weeks later, on July 24, that toggle switched to enabled for eligible commercial tenants that had not explicitly set it to "No users".

Microsoft's own documentation is specific about what this means in practice: OpenAI-operated models are covered by the EU Data Boundary "except as otherwise noted", and the note that follows matters. Copilot prompts, responses, and the grounding data Copilot pulls from your files can be processed outside the EU for AI inferencing, including in the United States, Canada, and Australia. A separate pseudonymized user identifier is also stored in the United States for troubleshooting and security purposes, regardless of where your tenant is set up. None of this requires an incident or a breach. It is simply how the feature now works by default.

Why this matters more than it sounds like it should

A lot of small businesses treat "it's still Microsoft" as the end of the risk assessment. That instinct made sense when Copilot only ran inside Azure, a system most companies already trust and already have a data processing agreement covering. It makes less sense once a second company, with its own infrastructure, its own incident history, and its own separate terms, is in the path by default. Microsoft's contractual position is that OpenAI operates under the same Microsoft Product Terms and Data Protection Addendum as any other subprocessor. That is a real contractual commitment, not marketing language, but it still adds a second party to a chain that your own GDPR documentation, if you have any, almost certainly still describes as ending at Microsoft.

For a business that handles client contracts, health data, financial records, or anything else where "where exactly does this data go" is a question your own customers might reasonably ask, that gap is the actual problem. It is not that OpenAI is unsafe. It is that a decision with real GDPR implications got made for you, silently, unless someone in your organization happened to read a Microsoft message center post in July. Most ten-person companies do not have anyone whose job is reading Microsoft message center posts.

Why Microsoft made the change at all

None of this is Microsoft acting maliciously. OpenAI develops newer models faster than Microsoft can rebuild and certify each one inside Azure, and running some requests directly on OpenAI's own infrastructure is how Microsoft keeps Copilot on the newest capability rather than a version several months behind. From Microsoft's side, adding a well-governed subprocessor under contract is a reasonable trade for staying current. The part that lands on your desk, not theirs, is that the trade changes your data flow, and the default was set to on rather than off.

That pattern is not new, and it will not be the last time it happens. Anthropic was added as a separate subprocessor under the same admin center section for certain Copilot features, and more providers are likely to follow as the market for underlying AI models keeps moving. A business that reviews this setting once and moves on will be back in the same position the next time Microsoft adds a provider, unless the review becomes a recurring item rather than a one-time fix.

The GDPR angle: this is still your obligation, not Microsoft's

Article 28 of the GDPR makes the data controller, meaning your company, responsible for knowing who processes personal data on its behalf and on what legal basis, even when a subprocessor is added by a vendor rather than chosen directly. A German data protection authority does not accept "Microsoft changed a setting without telling us" as an answer to "why did this data leave the EU". The obligation to know and document who touches personal data sits with the business collecting it, which in this case is whoever runs the Microsoft 365 tenant, not Microsoft and not OpenAI.

In practice that means the five-minute check below is not optional housekeeping. If your business processes any personal data through Copilot, customer names in a summarized email thread, HR notes in a Teams recap, client details in a drafted proposal, this setting is now part of what your record of processing activities needs to reflect accurately.

Azure OpenAI versus the OpenAI subprocessor path

Question Azure OpenAI Service (original setup) OpenAI subprocessor (new default)
Who runs the infrastructureMicrosoft, inside AzureOpenAI, outside Azure
Covered by the EU Data BoundaryYes, without the exception clauseYes, with a documented exception for AI inferencing
Can data leave the EU for processingNot for this workloadYes, to the US, Canada, or Australia
Enabled by default since July 24, 2026Was already the defaultYes, unless disabled by an admin
Where to control itn/aAdmin center > Copilot > Settings > AI providers operating as Microsoft subprocessors

How to check what your own tenant is doing right now

This takes about five minutes and does not need a specialist, though it is worth doing as part of a proper review rather than a one-off click.

  • Sign in to the Microsoft 365 admin center with a Global Administrator account.
  • Go to Copilot > Settings > View all, then open "AI providers operating as Microsoft subprocessors".
  • Check whether OpenAI is set to all users, specific groups, or no users. If nobody has touched this setting, it is very likely set to all users by default.
  • Decide deliberately, rather than by inheritance. Restricting it to "No users" turns off the OpenAI-direct path; Microsoft notes some newer Copilot features may then be unavailable, which is a real trade-off to weigh, not a reason to skip the decision.
  • Write down what you decided and why. If a client or auditor ever asks where their data went, "we reviewed it on this date and set it to X" is a very different answer than silence.

Should you actually turn it off?

Not automatically. For a business with no regulated data, no client contracts that specify data location, and staff who mostly use Copilot for drafting emails and summarizing meetings, the practical risk is genuinely low, and turning the setting off may just mean losing access to newer model capabilities for no real benefit. The calculation changes fast for a business handling health records, legal case files, financial data subject to retention rules, or any contract that names a processing location. In those cases, the decision belongs with whoever is accountable for your GDPR compliance, documented, not defaulted.

This is the exact kind of question our Microsoft 365 security assessment is built to catch, because Microsoft ships changes like this through admin center notices that most businesses never read in time. A governance review puts a documented answer behind every setting like this one, so the next Microsoft change does not sit unnoticed for weeks either. And where a business is actually planning to use Copilot or another AI tool for real, not just experimenting, our AI advisory work covers exactly this kind of subprocessor and data flow decision before rollout, not after a client asks an awkward question.

Quick answers

Did this happen to every Microsoft 365 tenant?

It applies to eligible commercial tenants with Copilot licensed. If nobody in your organization set the "AI providers operating as Microsoft subprocessors" setting to "No users" before July 24, 2026, it is very likely enabled in your tenant now.

Does this break our existing GDPR documentation?

Not automatically, but it likely makes it inaccurate. If your data processing agreement or record of processing activities describes Copilot as running solely on Microsoft's Azure infrastructure, that description no longer matches how the tenant is actually configured unless the setting has been reviewed and set deliberately.

Is Anthropic involved in the same way?

Anthropic is a separate Microsoft subprocessor for certain Copilot features, controlled under the same admin center section and subject to the same Product Terms and Data Protection Addendum. It is worth checking alongside OpenAI, not instead of it.

Will turning it off remove features our staff already rely on?

Possibly. Microsoft states that some newer Copilot capabilities depend on OpenAI-operated models specifically, so disabling the setting is a genuine trade-off between data location control and feature access, worth deciding with the actual risk in mind rather than by default in either direction.

We check what your tenant actually sends, and where

Microsoft changes settings like this several times a year, usually through an admin center notice nobody has time to read closely. Our security assessment reviews exactly this kind of subprocessor and data residency setting across your tenant, not just the headline security controls.

Where the answer needs a documented decision rather than a default, we put one in place, sized to what your business actually handles.

More Articles