OpenAI is now a subprocessor inside Microsoft 365 Copilot: and the toggle was auto-enabled on 24 July 2026
GPT-5.6 runs under OpenAI as a subprocessor in M365 Copilot. The admin toggle auto-enabled 24 July 2026 unless you'd already said no.
If you are responsible for a Microsoft 365 tenant, this is the update that should have landed at the top of your inbox in July 2026. Via Message Center notification MC1422074, Microsoft confirmed that OpenAI is now an official subprocessor inside Microsoft 365 Copilot, starting with GPT-5.6. The setting that controls whether your users can access OpenAI-operated models was initially disabled on 9 July 2026. On 24 July 2026, it was automatically enabled for all eligible commercial tenants where an admin had not explicitly set it to “No users.” That means if you did not act, the switch was flipped for you.
MVP Tom Arbuthnot at empowering.cloud calls it “the biggest story of the month for anyone responsible for a tenant.” It is hard to argue with that.
What actually changed
Microsoft has been operating OpenAI models inside Copilot for some time, but always as the operator itself under Azure OpenAI Service. From 9 July 2026 onwards, a new arrangement exists: OpenAI operates certain models directly as a subprocessor. The first model in this category is GPT-5.6, which became the preferred model for Microsoft 365 Copilot on the same date and is available across Word, Excel, PowerPoint, and Cowork.
Under the subprocessor model, OpenAI processes data on Microsoft’s behalf, governed by the Microsoft Product Terms and Data Protection Addendum. Microsoft describes this as carrying “the same enterprise-grade security, compliance, and data protection commitments you already rely on.” That phrase, though, comes with a material qualifier: “except as otherwise disclosed in Microsoft Learn documentation.”
That qualifier matters. A lot.
The EU data boundary problem
For organisations in the European Union, the key sentence in Microsoft’s documentation reads: “OpenAI operated models are included in the EU Data Boundary, except as otherwise disclosed.” The exceptions are documented separately on Microsoft Learn, and they include the fact that OpenAI-operated models are currently excluded from in-country processing commitments. In plain terms, your data may leave your region even though Microsoft’s contractual protections still apply.
The comparison with Anthropic is instructive. Anthropic has been a subprocessor in Microsoft 365 Copilot for longer, and for EU and UK customers, Anthropic-powered features are disabled by default precisely because of the data boundary implications. OpenAI has not been given the same default-off treatment in most tenants.
The German data protection authority (DSK) has separately raised concerns that Microsoft’s standard mechanism for notifying customers of subprocessor changes, an email update with a 30-day objection window, does not give controllers meaningful control over AI subprocessors under GDPR. If your organisation operates under German or broader EU data protection obligations, that is worth flagging to your legal or compliance team now.
Government and sovereign cloud tenants
One clear-cut group: if your tenant runs in GCC, GCC High, DoD, or a sovereign cloud, OpenAI-operated models are not available in those environments. This particular change does not apply to you, though it is worth confirming your configuration regardless.
How to check and control the setting
The admin toggle is in the Microsoft 365 admin centre. The path is:
Copilot > Settings > View all > AI providers operating as Microsoft subprocessors > OpenAI
From there you can set access to “All users,” a specific set of users and groups, or “No users.” Selecting “No users” blocks OpenAI-operated models entirely, though Microsoft notes this may make some Copilot features unavailable.
If you set this to “No users” before 24 July 2026, nothing changed for your tenant automatically. If you did not, the setting was enabled for all users. Either way, go and check what it is set to now.
The setting is separate from the Azure OpenAI Service models that Microsoft itself operates. Changing this toggle does not affect those.
The broader governance pattern to watch
This is not an isolated incident. It reflects a deliberate product strategy: the “Auto” model routing that Microsoft uses across many Copilot scenarios is designed to let Microsoft swap underlying models without requiring admin action each time. The auto-enable on 24 July 2026 is the same logic applied to a significant infrastructure change, a new legal entity processing your data.
Empowering.cloud flags this as a governance theme worth watching: “defaults doing the work.” Impactful changes activate quietly through default-on toggles, and the window to intervene is short. MC1422074 gave admins from 9 July to 24 July 2026 to act before the default kicked in. Fifteen days is not a long runway for organisations with formal change management processes or data protection impact assessment requirements.
What this means for you
For all M365 Copilot admins: Check the toggle in the admin centre now, regardless of your organisation’s position on GPT-5.6. Knowing what state it is in is the minimum action.
For EU tenants: Review the “except as otherwise disclosed” documentation on Microsoft Learn and assess whether your data protection obligations require you to set this to “No users” until you have completed a data protection impact assessment. The Anthropic precedent suggests the data boundary implications are real, not theoretical.
For compliance and legal teams: The DSK’s position on subprocessor notification mechanisms adds urgency here. If your organisation has not reviewed its Microsoft 365 Copilot data processing documentation since 9 July 2026, this is the trigger to do so.
For everyone else: Microsoft 365 Copilot now has 30 million paid seats, and OpenAI is formally in the data processing chain. Understanding your organisation’s configuration is a basic piece of AI governance hygiene at this point, not an edge case.