Claude in Microsoft Copilot: What UK Businesses Should Be Aware Of 

Photo Credit: Thaspol Sangsee / Shutterstock.com

Executive Summary 

Microsoft is expanding Microsoft 365 Copilot beyond OpenAI’s ChatGPT models by introducing Anthropic’s Claude models into parts of the Copilot ecosystem. 

For many businesses, this sounds like a simple technology update. In reality, it raises some important questions around data processing, compliance, governance and AI strategy. 

The biggest issue for UK organisations is that Anthropic operates as a Microsoft subprocessor when Claude is used within Microsoft 365 Copilot. Microsoft has also confirmed that Anthropic-powered services are currently excluded from certain data residency commitments, including the EU Data Boundary. 

For SMEs already using Copilot, or considering wider AI adoption, this means it’s worth understanding exactly where your data may be processed, who may process it, and what controls are available before enabling new AI capabilities. 

The good news is that Microsoft has built these services within its enterprise framework rather than simply connecting users directly to a public AI tool. However, businesses should still review their AI governance, compliance requirements and internal policies before making changes. 

Introduction 

Over the past year, many businesses have become familiar with Microsoft Copilot as Microsoft’s AI assistant for Word, Excel, Outlook, Teams and the wider Microsoft 365 platform. 

Most people assume Copilot is powered entirely by OpenAI, the company behind ChatGPT. 

That is no longer the case. 

Microsoft has been steadily expanding its AI ecosystem and is now integrating Anthropic’s Claude models into various Copilot experiences. In some scenarios, users may even be able to choose between different AI models depending on the task they are performing. 

For business leaders, this development is less about which AI model writes better emails and more about understanding what happens to company data behind the scenes. 

Let’s look at what this means in practice. 

What Is Claude? 

Claude is a generative AI model developed by Anthropic, an AI company founded by former OpenAI researchers. 

Like ChatGPT, Claude can: 

  • Draft documents 
  • Summarise information 
  • Analyse data 
  • Answer questions 
  • Generate content 
  • Assist with research 

Claude has developed a reputation for strong reasoning capabilities, long-document analysis and structured writing. 

Microsoft has recognised these strengths and is increasingly making Claude available within parts of the Microsoft 365 ecosystem. 

This reflects a broader shift in Microsoft’s AI strategy. Rather than relying on a single AI provider, Microsoft is building a multi-model platform that allows different AI technologies to be used for different tasks. 

Where Is Claude Being Used in Microsoft Copilot? 

The rollout has been gradual, but Claude is now appearing across several Microsoft AI services. 

Examples include: 

  • Microsoft 365 Copilot 
  • Copilot Chat 
  • Researcher 
  • Copilot Studio 
  • Agent Mode in Excel 
  • Word, Excel and PowerPoint AI agents 

Microsoft’s goal is to give organisations access to multiple leading AI models while maintaining the security and compliance framework already associated with Microsoft 365. 

For users, the experience may feel seamless. 

For IT teams and business decision-makers, however, there are important governance considerations. 

Anthropic Is a Microsoft Subprocessor 

One of the most significant changes is that Anthropic is now being introduced as a Microsoft subprocessor for certain AI-powered services. 

In simple terms, a subprocessor is a third-party organisation that processes data on Microsoft’s behalf in order to deliver a service. 

Many businesses already work with subprocessors across cloud services. The concept itself is not unusual. 

What matters is understanding: 

  • Which services use the subprocessor 
  • What data may be processed 
  • Where processing takes place 
  • Whether this aligns with your compliance requirements 

When Claude is being used within Microsoft 365 Copilot, Anthropic may process data as part of delivering that service under Microsoft’s contractual framework. 

For many organisations this may be entirely acceptable. 

For regulated sectors, organisations with strict customer contracts, or businesses with specific data residency obligations, it deserves closer examination. 

The Data Residency Question 

This is the area that has attracted the most attention. 

Microsoft has stated that Anthropic-powered services are currently excluded from its EU Data Boundary commitments. This also affects UK organisations that rely on regional processing expectations. 

In practical terms, this means data associated with Claude-powered processing may not remain within the same geographic boundaries that some organisations expect from other Microsoft cloud services. 

Where personal data is involved, organisations should also consider whether a Data Protection Impact Assessment (DPIA) or wider privacy review is needed before enabling these features more broadly. 

This does not automatically mean the service is non-compliant. 

However, it does mean organisations should understand: 

  • Where data is processed 
  • Which regulatory requirements apply 
  • Whether contractual obligations require specific data locations 
  • Whether customers or partners have imposed residency restrictions 

For many SMEs this may not create a problem. 

For sectors such as legal, financial services, healthcare and professional services, it is likely to become an important discussion point. 

Why UK Businesses Should Pay Particular Attention 

Microsoft has taken a cautious approach with UK and EU customers. 

Anthropic models are currently disabled by default for many UK and EU tenants and require administrative approval before they become available. 

That tells us something important. 

Microsoft recognises that data processing requirements in these regions deserve additional consideration. 

It is also a good point to confirm whether internal governance, privacy or compliance stakeholders need to review the change before wider rollout. 

If your organisation uses Microsoft 365 Copilot, it is worth checking: 

  • Whether Claude functionality is available in your tenant 
  • Whether it has been enabled 
  • Which users can access it 
  • Whether your compliance team has reviewed the implications 

Many businesses may not even realise new AI models have become available within their Microsoft environment. 

Does This Change Microsoft’s Enterprise Security Protections? 

The answer is largely no. 

Microsoft states that Enterprise Data Protection continues to apply when Claude is used within Microsoft 365 Copilot. Anthropic operates within Microsoft’s existing contractual and compliance framework for these services. 

That means organisations are not simply sending information to a public AI chatbot in the same way they might if an employee independently pasted company information into a consumer AI tool. 

This is an important distinction. 

Microsoft has invested heavily in providing enterprise-grade controls around: 

  • Identity management 
  • Access control 
  • Audit logging 
  • Compliance management 
  • Data governance 

Those protections remain an important advantage of using AI through Microsoft 365 rather than through unmanaged consumer AI services. 

However, businesses should not assume that all AI models are identical from a governance perspective. 

The addition of new providers means governance reviews become increasingly important. 

What Should SMEs Do Now? 

For most SMEs, there is no reason to panic. The introduction of Claude is not, in itself, a security incident or compliance failure. It is simply another example of how quickly the AI landscape is evolving. 

The sensible approach is to treat this as a governance, privacy and risk management exercise before enabling wider use. 

Review your Microsoft Copilot settings 

Check which AI models and providers are available in your tenant, whether they are enabled, and which users or groups can access them. Organisations should verify the current setting rather than assume the default is correct for their environment. 

Assess whether a DPIA or privacy review is needed 

If staff may use Copilot with personal data, customer information, commercially sensitive information, HR records, or other regulated data, it is sensible to assess the privacy impact before rollout. In higher-risk cases, that should include a formal Data Protection Impact Assessment. 

Review contracts, compliance obligations and data residency requirements 

Check whether customer contracts, sector regulations, or internal governance requirements place limits on where data may be processed or which subprocessors can be used. This is particularly important where organisations have committed to UK-only or EU-based handling expectations, or where sensitive client data is involved. 

Review data classification, permissions and oversharing risk 

Microsoft 365 Copilot works within existing Microsoft 365 permissions, which means it can surface information users already have access to, including content that may be overshared. Before enabling broader AI use, organisations should review SharePoint, OneDrive and Exchange permissions, strengthen data classification, and consider sensitivity labels, data loss prevention and other governance controls where appropriate. 

Update AI policies and user guidance 

Many organisations wrote AI policies when staff were primarily using ChatGPT or the earlier Microsoft Copilot experience. Those assumptions may no longer be complete. Policies should reflect that multiple model providers may now sit behind Microsoft services, and should give clear guidance on what staff can and cannot upload, paste, summarise or analyse using AI tools. 

Use a phased rollout rather than enabling everything at once 

A pilot group can help identify practical issues around data access, user behaviour, output quality and governance before the feature is made more widely available. This is often the safest approach for SMEs that want the benefits of Copilot without introducing unnecessary compliance or security risk. 

Work with your IT provider or internal compliance lead 

An experienced IT partner or internal compliance lead can help assess tenant settings, privacy implications, data governance controls, licensing and rollout approach. The key point is not to assume that a new AI capability should simply be switched on without review. 

Final Thoughts 

Microsoft’s decision to bring Anthropic’s Claude into Microsoft 365 Copilot is part of a much bigger shift towards a multi-model AI future. 

For users, this may lead to better results, greater flexibility and more powerful AI capabilities. 

For businesses, it introduces an additional layer of governance that cannot be ignored. 

The key issue is not whether Claude is good or bad. 

The key issue is understanding where your business data goes, who processes it, and whether those arrangements align with your compliance and security requirements. 

As AI becomes embedded into everyday business tools, organisations that take the time to understand these details will be in a much stronger position than those that simply switch new features on without review. 

Need Help Assessing AI Risks in Microsoft 365? 

If your business is using Microsoft 365 Copilot or considering wider AI adoption, Get Support can help. 

We work with SMEs across the UK to review Microsoft 365 environments, assess security and compliance risks, implement governance controls and ensure AI technologies are being used safely and effectively. 

Whether you need advice on Copilot, data protection, Microsoft licensing or AI policy development, our team can help you make informed decisions with confidence. 

Contact Get Support to discuss your Microsoft 365 and AI strategy. 

FAQs 

Yes. Microsoft continues to use OpenAI models extensively within Copilot. The introduction of Claude adds additional AI model options rather than replacing OpenAI entirely. 

When Claude-powered features are used, Anthropic may process data as a Microsoft subprocessor as part of delivering the service. Organisations should review Microsoft’s documentation and assess whether this aligns with their requirements. 

No. Availability varies by service, licensing and region. Microsoft has disabled Anthropic models by default for many UK and EU organisations. 

Not necessarily. Microsoft’s enterprise security protections continue to apply. However, organisations should review governance, compliance and data processing implications before enabling new AI providers. 

We can help assess your Microsoft 365 environment, review AI settings, identify compliance considerations, develop AI usage policies and ensure your organisation adopts AI safely and effectively.