The headline of the past few months is that Microsoft turned Anthropic models on by default in Microsoft 365 Copilot. That is true, and it does not apply to your company: the documentation itself says they are enabled "for most customers in commercial cloud (excluding EU/EFTA and UK)". If your tenant was signed up in Spain, the global setting ships set to "No users" by default. This is where most IT managers close the tab. And that is precisely the mistake, because that is not the only switch.
There are three separate settings governing the same thing — which artificial intelligence model processes what your people write in Word, Excel and PowerPoint — and all three have different defaults. One of them does not depend on your country, or your licence plan, or on a decision made by anyone in your company: it depends on the date your tenant was created. And to find out which default you got, Microsoft's documentation does not tell you: it sends you to check the Message Center.
Switch one: Anthropic as a subprocessor
This is the one that made the news. Anthropic has been onboarded as a Microsoft subprocessor, which means its use inside Microsoft 365 Copilot falls under Microsoft's Product Terms and Data Protection Addendum rather than under a separate agreement with Anthropic. Contractually that is an improvement: you go from having to read two agreements to reading one.
And it comes with a warning Microsoft prints in bold on its own page: Anthropic models deployed in Microsoft 365 Copilot, Researcher, Copilot Studio and Power Platform "are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments". That is why the default in the EU, EFTA and the UK is No users: it is not a rollout oversight: it follows directly from that exclusion. The setting is called "AI providers operating as Microsoft subprocessors" and it lives in the admin center, under Copilot → Settings → View all.
There is a detail that is going to catch people out, and it is split across the two pages. If your company enabled Claude back when it ran under Anthropic's own commercial terms, that no longer exists: Microsoft documents that the "independent processor" setting was decommissioned on 1 May 2026, and consent has to be given again, this time as a subprocessor. The subprocessor page says it plainly: "you need to opt in again. The toggle is set to Off by default". In other words, there were companies that made a decision, wrote it down, and the decision has evaporated with nobody looking.
Switch two: the one a date decided
On 3 April 2026 Microsoft added a second setting to the admin center, exclusive to the EU, EFTA and the UK: "Copilot in M365 apps with Anthropic models". It makes Copilot use Anthropic models by default when generating or refining content inside Excel and PowerPoint (Word was announced for this summer in the page's latest revision). And here is what matters: the documentation states that it "is separate from the global Anthropic subprocessor setting in Microsoft 365" and that "changes to this setting do not modify global subprocessor configurations".
Its default is the sentence this whole article is about, and it deserves reading twice:
"This setting is on by default for tenants in the EU, EFTA, and UK that were created after March 25, 2026. For tenants in the EU, EFTA and UK that existed before March 25, 2026, check the Message Center for details on your tenant's default setting."
Two companies on the same street, same plan, same headcount, same advisor, end up with different configurations because one set up its tenant in February and the other in April. The sign-up date ended up deciding how a setting that governs where content gets processed arrived configured. Nobody in the company took part in that. And the second sentence is even more telling: for a large part of the estate — predictably the majority: a tenant created after March 2026 is the exception — Microsoft does not publish what the default is. It tells you where to go and look. The same page encourages, quite reasonably, all tenant administrators to check that setting to make sure it matches their company's requirements.
The same page explains what having it on means, in a section headed "Data processing and the EU Data Boundary": "When Anthropic models are used in Copilot experiences in Word, Excel, or PowerPoint, data processing for these models occurs outside of the Microsoft EU Data Boundary (EUDB)". There is no fine print to interpret. It is written by the vendor, in its own official documentation, and it is one of the few times a vendor tells you that plainly where your content stops being covered.
This is as far as the sources go
This is where a lot of articles take the leap and run a headline saying your documents are already leaving Europe. We are not going to claim that, because it does not follow from the sources. The two settings coexist, and the same page that decommissions the independent processor adds that "if Anthropic is not enabled as a Microsoft subprocessor, access to Anthropic models and related features is no longer available". Read strictly, the global switch appears to govern the app-level one. What Microsoft does not publish, tenant by tenant, is which value each of the two settings arrived with in an older European tenant — and that absence is precisely why its own documentation asks every administrator to go and check.
There is also a documented interaction that breaks the intuition that these are two parallel levers: "when the setting is enabled for All users or Specific users and groups, the Anthropic model use in supported apps setting is unavailable and can't be changed". Translated: depending on how you leave the first one, the second is greyed out and locked. Anyone who has ever tried to reconstruct after the fact what was enabled in a tenant knows what that means — today's screenshot does not explain last week's state.
Switch three: the models that do keep what you type
The third is the least known and the one that worries us most, even though it is paradoxically the best configured: preview models with data retention (the documentation names Claude Fable 5 and Claude Mythos 5) are off by default in every scenario, including in regions where the rest of the Anthropic models ship enabled. Nobody uses them until an administrator goes in and deliberately turns them on.
What changes when you enable them is not model quality, it is the contract. There, Anthropic stops being a Microsoft subprocessor and acts as an independent data processor, and whatever gets typed stops being covered by your Microsoft Customer Agreement. Retention, as Microsoft summarises it from Anthropic's policy:
- →Up to 30 days. Anthropic — not Microsoft — stores most inputs and outputs before deleting them.
- →Up to two years of content, inputs and outputs included, if its trust and safety classifiers flag a potential breach of its usage policy.
- →Up to seven years for those classification scores. And one sentence worth quoting in full because it cuts the other way: Anthropic "doesn't use retained data for model training without your express permission".
None of this is a scandal: it is a published retention policy, reasonable for a preview product, and that is exactly why it ships disabled. The problem is the usual one. A checkbox an administrator can tick in twenty seconds moves the company out of the contractual framework it signed and into a different one, and in most organisations there is no control that notices. The rule we apply is simple: when ticking a box changes who answers for your data, that box needs an owner and a date before anyone touches it.
What the Data Boundary promises and what it does not
It is worth being clear about what is under discussion. The EU Data Boundary is a contractual and architectural commitment by Microsoft to store and process Customer Data and personal data for its enterprise services inside the EU and EFTA. It is not a law, it is not the same as GDPR compliance, and it is not absolute: the documentation itself warns that the commitments are "subject to limited circumstances where Customer Data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary".
And there is a scoping trap almost nobody checks. For Microsoft 365, customers whose sign-up location is in an EU or EFTA country are in scope for the Data Boundary. But the documentation adds, in as many words, that "customers who have purchased Multi-Geo Capabilities are not in scope for the EU Data Boundary even if their tenant is listed as being in a country or region in the EU or EFTA". If Multi-Geo was ever bought for a subsidiary abroad, this Anthropic discussion is second on your list, not first.
Why we are not going to tell you to switch it off
The industry reflex when news like this lands is to switch everything off and call it prudence. We do not recommend that by default, and the reason is in the same documentation: "some features are only available when Anthropic models are enabled. If you turn off Anthropic as a subprocessor, certain features may no longer be accessible". Turning it off has a cost, that cost is paid by the people using Copilot every day, and nobody measures it because it shows up on no dashboard.
What is more, the current framework is better than what came before: with Anthropic as a subprocessor, Microsoft's Product Terms, Data Protection Addendum and Customer Copyright Commitment all apply. The difference between a vendor inside your contract and one sitting next to it shows up the day there is something to claim. We have nothing against Claude or against Copilot; we have written fairly sceptically about enterprise AI projects precisely because we want the ones that do go ahead to work.
What we do not defend is the most common state today: three switches, no decision, and nobody able to say from memory how they are set. It is the same pattern we saw with a feature that lets someone outside act on mail inside your tenant: the change arrives through the vendor's channel, not yours, and it arrives just the same if nobody reads it.
The twenty-minute review
- →Check the global setting. Microsoft 365 admin center →
Copilot→Settings→View all→ AI providers operating as Microsoft subprocessors. Write down the value and, if it is not "No users", which users or security groups it covers: the permission applies at provider level and propagates to Copilot Studio. - →Find out when your tenant was created and compare it with 25 March 2026. If it predates that — it almost certainly does — search the Message Center for the notification about the Copilot in apps with Anthropic models setting. That notice is today the only source that tells you how yours arrived configured.
- →Check the preview models with data retention. They ship off; what you need to verify is that nobody switched them on "just to try" three months ago. If they are active, your privacy notice and your record of processing activities need to list Anthropic as an independent processor.
- →Check who can touch this. It takes the AI Administrator or the Global Administrator role. If in your tenant five people hold the latter and nobody is identified as the former, what you have is five people who can change it without telling anyone, and no control.
- →Write the decision down somewhere you can show it. What each setting is set to, who decided, and on what date. With the obligations of the European AI regulation already in force, you will be asked for a decision with a date and a signature, and a screenshot is not that.
What is missing lives in the calendar
A company can have all three switches set exactly where we would want them and still have nothing. Because the next change will arrive anyway: a new model, a new region, another cut-off date, another notice in the Message Center. What separates the organisations that find out from the ones that do not is that somebody has it written down, by name, that reviewing those notices is their job — plus an hour a month in the calendar to do it. It is boring and it appears in no digital transformation deck, but it is the only part of this that does not depend on what the vendor decides.
Sources: on-by-default in commercial cloud excluding EU/EFTA and the UK, exclusion from the EU Data Boundary, the "No users" default, preview models with data retention (Claude Fable 5 and Claude Mythos 5) and their 30-day, two-year and seven-year windows, the AI Administrator and Global Administrator roles, and the warning about features becoming unavailable — "Anthropic models in Microsoft Online Services", Microsoft Learn (revision of 22 July 2026). The Copilot in M365 apps with Anthropic models setting, its 3 April 2026 date, the decommissioning of the independent processor setting on 1 May 2026, the default that depends on tenant creation before or after 25 March 2026, the referral to the Message Center, processing outside the Data Boundary and the setting being locked when the global one is enabled — "Copilot in Microsoft 365 apps with Anthropic models", Microsoft Learn. Scope and limits of the Data Boundary and the Multi-Geo exclusion — "What is the EU Data Boundary?", Microsoft Learn. Header image: Korensko Sedlo border crossing, photo by David Edgar (Wikimedia Commons, CC BY-SA 3.0), cropped. We have not independently verified the state of any particular tenant: everything above is what the vendor publishes.
Do you know how all three are set in your tenant?
At everyWAN we run automation and AI with the same criteria as everything else: what gets enabled, who decides, and where it is written down. We do it alongside Microsoft 365 deployment and security and our compliance and continuity work. We are not resellers of any particular platform: if the right answer for you is to leave it switched off, we will tell you so.
Talk to everyWAN