Here’s an uncomfortable possibility. Right now, your organisation’s Copilot prompts and the company data Copilot pulls in to answer them may be flowing through OpenAI’s own infrastructure, not Microsoft’s.
And it may have happened automatically, without anyone on your team ticking a box to allow it.
That’s the reality of a quiet but significant change. OpenAI is now a subprocessor for Microsoft 365 Copilot. For most admins, it slipped by in a routine message centre notice.
For anyone responsible for data protection, it’s a question that deserves a proper answer. Here’s what changed, why it matters, and exactly what to check.
What Actually Changed?
Until 2026, Copilot ran on OpenAI models hosted within Microsoft’s Azure OpenAI Service. Microsoft controlled that infrastructure end-to-end, and most Copilot data protection assessments were written around that setup.
That’s no longer the only path. On 23 June 2026, Microsoft added OpenAI to its subprocessor list. From 9 July, a new admin setting allowed OpenAI’s infrastructure, running outside Azure, to handle Copilot requests directly. This is how GPT-5.6 and OpenAI’s newest models reach Copilot quickly.
The crucial detail is what happened next. The setting was disabled by default on 9 July, but on 24 July 2026 it was auto-enabled for all users at eligible commercial tenants unless an admin had first selected “No users”.
Read that again, because it’s the whole story. For many organisations, this switched on by itself.
Subprocessor, Azure OpenAI Whats the Difference?
These trips people up, so let’s be precise. There are now two ways an OpenAI model can serve your Copilot, and they are not the same.
- Azure OpenAI (Microsoft-operated): the model runs on Microsoft’s Azure infrastructure under Microsoft’s end-to-end control. This is the long-standing setup and is governed separately.
- OpenAI as a subprocessor (OpenAI-operated): the model runs on OpenAI’s own infrastructure under Microsoft’s oversight and contract, but no longer within Azure.
The important point: this new subprocessor toggle affects only OpenAI-operated models. It does not affect Azure OpenAI models, which continue to be governed as before. To the end user, the Copilot experience looks identical.
The change is entirely in the infrastructure and governance behind the scenes, which is exactly why it’s easy to miss and important not to.
Why This Matters for Compliance
For most commercial businesses, Microsoft’s assurances will be sufficient. The models are governed by the Microsoft Product Terms and the Data Protection Addendum, which include the enterprise-grade protections you already rely on.
But “for most” isn’t “for all”, and the detail is where the risk lies.
Microsoft’s own documentation is specific: OpenAI-operated models are included in the EU Data Boundary “except as otherwise noted” and are currently excluded from in-country processing commitments where those apply. For an organisation whose GDPR assessment maps its exact processing chain, adding OpenAI as a new subprocessor, on its own infrastructure, is a change that must be documented and evaluated, not assumed away.
It’s also worth understanding that this sits within a bigger shift. The same model choice that brings you GPT-5.6 also brings Claude and other models into Copilot, each with its own subprocessor implications, which we cover in our guide on multi-model AI in Copilot.
Model flexibility is a genuine advantage, but every provider you enable is another link in your data chain to account for.
This is precisely the kind of decision our AI Enablement Programme exists to get right, and as an ISO 27001–certified Microsoft partner, it’s the sort of thing we check before it becomes a finding in someone else’s audit.
The Setting Every Admin Should Check Today
Whatever you decide, the worst position is not knowing your current state. So check it. It takes minutes.
In the Microsoft 365 admin centre, go to Copilot > Settings > View all > AI providers operating as Microsoft subprocessors. From there, you can:
- Enable for all users if you’re happy with the OpenAI subprocessor arrangement
- Restrict to specific users or groups for a controlled rollout
- Select “No users” to block OpenAI-operated models entirely
One caveat to plan for. Selecting “No users” prevents OpenAI-operated models from running on OpenAI infrastructure, and as a result, some Copilot features may become unavailable, since certain capabilities now depend on the newest models.
It’s a genuine trade-off between the latest AI and the tightest control, and only you can make that call for your organisation.
What Your Business Should Actually Do
This isn’t a reason to panic, and it certainly isn’t a reason to switch Copilot off. It’s a reason to be deliberate. A short, clear process covers it.
- Confirm your current state, including whether OpenAI-operated models are already enabled in your tenant
- Check your obligations, particularly any data residency, EU Data Boundary or sector rules you are subject to
- Make a conscious decision to enable, restrict or block, rather than live with a default someone else chose
- Update your records so your data processing documentation reflects the subprocessor chain as it stands
- Revisit it periodically, because Microsoft has extended this same subprocessor model to Anthropic too, and the pattern will continue
Do that, and a change that caught many organisations off guard becomes just another well-governed decision.
Final Thoughts
The arrival of OpenAI as a subprocessor is a small toggle with big implications. It changed where your Copilot data can be processed, and for many organisations it did so quietly, by default.
That’s not a scandal; it’s simply how fast this space moves now, and it’s a reminder that AI governance is an active job, not a one-off setup.
The organisations that handle this well are the ones that check their settings, understand their obligations, and choose deliberately rather than drift.
If you’d like help reviewing your Copilot configuration against your compliance needs, that’s exactly what we do. Book a free assessment, and we’ll make sure your AI is set up the way your organisation requires- honest advice, no hard sell.
Frequently Asked Questions
What does it mean that OpenAI is a subprocessor for Microsoft 365 Copilot?
It means OpenAI can now process Copilot requests on its own infrastructure, outside Microsoft’s Azure environment, under Microsoft’s contractual oversight. It’s a new way to quickly deliver OpenAI models such as GPT-5.6.
Was this enabled automatically?
Yes. The setting was disabled by default on 9 July 2026 but was auto-enabled for all users at eligible commercial tenants on 24 July 2026, unless an admin had previously selected “No users”.
How is this different from Azure OpenAI?
Azure OpenAI models run on Microsoft’s infrastructure under Microsoft’s full control. The subprocessor arrangement uses OpenAI’s infrastructure. The new toggle affects only OpenAI-operated models, not Azure OpenAI.
Does this affect GDPR or data residency?
It can. OpenAI-operated models are excluded from in-country processing commitments where applicable and are subject to EU Data Boundary caveats, so organisations with strict residency rules should review and document the change.
How do I disable OpenAI-operated models?
Go to the Microsoft 365 admin centre, then to Copilot > Settings > View all > AI providers operating as Microsoft subprocessors and select “No users”. Note that some Copilot features may then be unavailable.