ChangePilot Microsoft 365 Blog

OpenAI as a Copilot Subprocessor: What Changed & What to Check Now

Written by Ella-Louise Jain | 11 August 2026

If your organisation uses Microsoft 365 Copilot, a quiet but significant change has already landed in how your users' prompts and data can be processed,  and Microsoft described it in two separate Message Center posts that don't tell quite the same story.

OpenAI has been added as an official subprocessor for Microsoft 365 Copilot. That's a new development: until now, OpenAI's models running inside Copilot were hosted entirely within Microsoft's own Azure environment, with OpenAI itself outside Microsoft's customer data processing boundary. That's no longer the only path. Under the new model, OpenAI can operate the infrastructure directly, with Microsoft providing contractual oversight rather than hosting the workload.

Summary

  • Subprocessor Addition: Microsoft added OpenAI as a direct M365 Copilot subprocessor alongside Azure OpenAI models

  • Conflicting Communication: MC1422074 announced auto-enablement on 24 July 2026, while MC1421915 framed the feature as opt-in

  • Current Status: Unless admins explicitly selected "No users," OpenAI-operated models (including GPT-5.6) are active in eligible commercial tenants today
  • Compliance Exclusions: OpenAI subprocessor infrastructure lacks SOC 1 Type 2, FedRAMP High, PCI DSS AOC, and HITRUST CSF certifications, and is excluded from local in-country processing commitments.

  • Immediate Action: Audit AI providers operating as Microsoft subprocessors inside the M365 Admin Center today

 

What Does 'OpenAI as a Subprocessor' Actually Mean?

OpenAI as a subprocessor means OpenAI can now host and process Microsoft 365 Copilot prompts on its own infrastructure under contractual oversight from Microsoft.

Microsoft has always used OpenAI's models, so that isn't new. What is new is how those can be delivered.

Until this change, every OpenAI model used in Copilot ran as Azure OpenAI: Microsoft-operated infrastructure, inside Microsoft's own Azure environment. OpenAI itself sat outside Microsoft's customer data processing boundary entirely; it wasn't a subprocessor, because it never touched customer data.

With OpenAI as a subprocessor, Microsoft is introducing a second delivery path. OpenAI now operates some of the model infrastructure directly, under Microsoft oversight, contractual safeguards, and the same Microsoft Product Terms and Data Protection Addendum (DPA) that already govern Microsoft's Online Services, except where explicitly excluded (more on that below). OpenAI was added to the Microsoft Online Services Subprocessors List on 23 June 2026, with the capability available for use from 9 July 2026.

The first model delivered this way is GPT-5.6, which OpenAI has positioned as its preferred model for Microsoft 365 Copilot experiences including Word, Excel, PowerPoint, Cowork, and Copilot Chat. Functionally, users see the same GPT-based Copilot experience they already have. The change is in the infrastructure and governance model behind it, not the interface.

This mirrors the pattern Microsoft already established with Anthropic, which was onboarded as a Copilot subprocessor earlier in 2026. OpenAI is now the second non-Microsoft-operated AI subprocessor added to Copilot in the same year, and the assumption that "Copilot only ever uses Microsoft's own AI stack" is no longer safe to make.

 

Comparison: Azure OpenAI vs OpenAI as a Subprocessor in Copilot

Feature / Commitment Azure OpenAI (Microsoft-Operated) OpenAI Subprocessor (Open-AI Operated)
Infrastructure Host Microsoft Azure Environment OpenAI Infrastructure
Default Tenant State Active by default Auto-enabled on 24 July 2026 (MC1422074)
SOC 1 Type 2 & HITRUST Supported Excluded
FedRAMP High / PCI DSS Supported Excluded
EU Data Boundary Included Included (with regional processing exceptions)
In-Country Data Residency Guaranteed where available Excluded (data may leave region)

 

 

Why Are There Two Message Center Items (MC1421915 and MC1422074)?

Microsoft issued two separate Message Center notifications, MC1421915 and MC1422074, because Microsoft targets updates based on tenant-specific attributes like seat count, enterprise licensing, or geographic region.

If you read tech commentary online or consult peers at other organisations, you may find conflicting advice on whether this feature is opt-in or auto-enabled. The discrepancy stems from how Microsoft segments its customer communications across two distinct Message Center IDs:

  • MC1422074 (Auto-Enablement Schedule):
    • Target Audience: Primary commercial tenants and standard enterprise organizations.
    • Default Policy: Set to Disabled by default on 9 July 2026.
    • Auto-Enable Date: Automatically switched to Enabled for all users on 24 July 2026 unless an administrator explicitly selected "No users".

  • MC1421915 (Opt-In Requirement Schedule):
    • Target Audience: Specific customer cohorts, such as high-compliance environments, sovereign regions, or custom enterprise licensing agreements.
    • Default Policy: Set to Disabled by default.
    • Auto-Enable Date: Remains permanently Disabled until an administrator actively opts in by enabling the setting.

Relying on external summaries or third-party blog posts can create compliance risk. If an administrator acts on advice based on MC1421915 (opt-in) while their tenant is actually governed by MC1422074 (auto-enabled), OpenAI-operated models may already be active in their environment without their knowledge.

 

Key Takeaway: Do not assume which Message Center policy applies to your organisation. IT administrators must check their specific Microsoft 365 Admin Center portal to verify the live status of their tenant.

For a visual breakdown of how Microsoft 365 Copilot handles data processing and integration across productivity apps, check out this overview: Microsoft 365 Copilot: AI Built for Work.

 

Why Is Copilot Default Governance Becoming an Industry Risk?

Expanding Copilot capabilities often default to "enabled," forcing IT administrators to proactively manage external providers and agent access rather than opting in.

A prime example is how Copilot handles dedicated agents. Since Copilot gained the ability to call dedicated agents, including third-party ones built outside Microsoft, all agent types (Microsoft, organizational, and external) are available to every user by default.

That creates a distinct governance contrast:

  • Third-Party Models (e.g., Claude, OpenAI): Access was initially restricted or kept off by default until brought under formal subprocessor agreements like Microsoft’s Enterprise Data Protection (EDP).

  • Third-Party Agents: Access defaulted to on for all users, shifting the burden onto IT teams to manually restrict external publishers.

To check and configure agent defaults in your tenant:

Go to Microsoft 365 admin center → Agents → Settings → Allowed agent types, then select Microsoft only, external publishers, or certified external publishers only.

The core lesson: Don't assume Copilot's expanding capabilities default to your organisation's security posture. Audit model subprocessors and agent permissions together.

 

Compliance Exclusions: How Does the OpenAI Subprocessor Affect Your Data?

OpenAI-operated subprocessor infrastructure is explicitly excluded from several core compliance frameworks, including FedRAMP High, SOC 1, PCI DSS, HITRUST, and local in-country processing guarantees.

Because this introduces a genuinely new subprocessor, several protections and certifications that customers may assume are blanket commitments don't automatically extend to OpenAI-operated models. Per Microsoft's own documentation, the following exclusions apply:

  • In-Country Processing: OpenAI-operated models are currently excluded from in-country processing commitments where applicable, meaning data may leave the region even though Microsoft's contractual protections still apply

  • Sovereign Clouds: Not currently available in government clouds (GCC, GCC High, DoD) or sovereign clouds

  • EU Data Boundary: Included in the EU Data Boundary, except as otherwise noted in Microsoft's EU Data Boundary documentation

  • FedRAMP High: No FedRAMP High authorisation - organisations requiring it should confirm with their authorising official before enabling

  • PCI DSS: No PCI DSS Attestation of Compliance (AOC) is available for OpenAI-operated models

  • HITRUST CSF: No HITRUST CSF Certification Letter is available

  • SOC 1 Type 2: No SOC 1 Type 2 report is available

  • Zero Data Retention: Microsoft incorporates OpenAI's Responses API into certain Copilot experiences; OpenAI offers Zero Data Retention for that API as used by Microsoft, subject to the limitations described in OpenAI's own data controls documentation.

For organisations already navigating GDPR, NIS2, or sector-specific data governance requirements, these exclusions are the kind of detail that belongs in front of legal and compliance, not discovered after the fact.

 

How to Check and Control the OpenAI Subprocessor Setting in Your Tenant

You can audit and change OpenAI subprocessor permissions inside the Microsoft 365 admin center under Copilot AI Provider Settings.

Follow these steps to verify your tenant's posture:

Step 1: Check the current setting

You must be an AI Administrator or Global Administrator. Go to the Microsoft 365 admin center → Copilot → Settings → View all → AI providers operating as Microsoft subprocessors.

 

Step 2: Review the OpenAI entry

Under Available subprocessors for your organization, select OpenAI to see the current access configuration.

 

Step 3: Choose your access level

Under Choose which users can access OpenAI-operated models, select All users, restrict to specific users or Entra ID security groups, or select No users to disable it entirely — then Save.

 

Step 4: Check Copilot Studio and Power Platform separately

Additional admin controls for OpenAI-operated models in Copilot Studio and Power Platform agents live in the Power Platform admin center, under external LLM configuration. This is a separate control surface from the Microsoft 365 admin center setting.

 

Step 5: Document the decision

Whatever you choose, record the rationale alongside the Message Center ID logged in your tenant portal so future audit reviews have clear context.

 

Timeline: OpenAI M365 Copilot Subprocessor Rollout Dates

  • 23 June 2026: OpenAI added to the Microsoft Online Services Subprocessors List

  • 9 July 2026: OpenAI as a subprocessor becomes available for use; Message Center posts published

  • 14 July 2026: MC1422074 updated

  • 24 July 2026: Auto-enable date for commercial tenants under MC1422074 (OpenAI-operated models enabled unless opted out)

What to Do Now

Because key rollout dates have already passed, the focus is on verification:

  • Check your specific Message Center item: Look up MC1421915 or MC1422074 inside your admin portal to see which specific terms were issued to your organisation

  • Audit the setting today: Open the AI providers operating as Microsoft subprocessors screen to verify whether access is currently active, restricted, or disabled

  • Confirm user scope: Identify which specific users or groups currently have access to OpenAI-operated models

  • Inform compliance teams: Flag the new subprocessor, and its compliance exclusions, to security, legal, and compliance, particularly if you operate under FedRAMP High, PCI DSS, HITRUST, SOC 1, or in-country data residency obligations

  • Update internal policies: Update internal AI acceptable-use policies and admin documentation to explicitly name OpenAI as a subprocessor, distinct from Azure OpenAI

  • Brief support desk: Brief helpdesk and support teams. Some users may notice model/branding differences and ask questions

  • Establish a continuous audit process: Treat this as a repeatable process, not a one-off check: Anthropic landed earlier this year, OpenAI has now landed as a subprocessor too, and Microsoft is clearly continuing to expand third-party model options inside Copilot.

Frequently Asked Questions

What is OpenAI as a subprocessor in Microsoft 365 Copilot?
It's a new delivery path that lets OpenAI operate some of the model infrastructure behind Copilot directly under Microsoft's contractual oversight, rather than every OpenAI model running exclusively inside Microsoft's own Azure environment. It was added to the Microsoft Online Services Subprocessors List on 23 June 2026 and became available on 9 July 2026.

How is this different from Azure OpenAI?
With Azure OpenAI (Microsoft-operated), OpenAI's models are hosted entirely within Microsoft's infrastructure and OpenAI has no access to customer data. With OpenAI as a subprocessor (OpenAI-operated), processing happens on OpenAI's own infrastructure, governed by the Microsoft Product Terms and DPA, subject to specific compliance exclusions disclosed by Microsoft.

Why are there different Message Center items (MC1421915 vs MC1422074) for this feature?
Microsoft customizes Message Center notices based on tenant attributes like seat count, licensing, or regional defaults. While MC1422074 communicated an auto-enable deadline of 24 July 2026 for eligible commercial tenants, MC1421915 communicated an opt-in model. It is vital to check which notification landed in your specific tenant portal.

Is OpenAI-operated Copilot on by default in my tenant right now?
It depends on your tenant's licensing profile and Message Center assignment. For commercial tenants under MC1422074, the setting auto-enabled on July 24, 2026, unless an admin actively opted out. Check the AI providers operating as Microsoft subprocessors setting in your admin center to confirm.

Does this affect the EU Data Boundary?
OpenAI-operated models are included in the EU Data Boundary, except as otherwise noted in Microsoft's EU Data Boundary documentation. However, they are currently excluded from in-country processing commitments where applicable, so data may leave a specific country even while remaining within the EU Data Boundary.

What if my organisation needs FedRAMP High, PCI DSS, HITRUST, or SOC 1 assurances?
Those certifications and attestations are not currently available for OpenAI-operated models. If your organisation requires any of them, review whether OpenAI as a subprocessor should be disabled or restricted for your tenant, and consult your authorising official where relevant.

How do I disable OpenAI as a subprocessor?
In the Microsoft 365 admin center, go to Copilot → Settings → View all → AI providers operating as Microsoft subprocessors → OpenAI, then set Choose which users can access OpenAI operated models to No users, and Save. You can re-enable it at any time.

Is this the same as the "Allowed agent types" setting for Copilot agents?
No, but the two are closely related and worth reviewing together. "AI providers operating as Microsoft subprocessors" controls which model provider processes your Copilot prompts — the subject of this article. "Allowed agent types" (Microsoft 365 admin center → Agents → Settings) controls which third-party Copilot agents your users can invoke, and it defaults to every agent type being available to everyone.

 

Closing

OpenAI as a subprocessor isn't a dramatic feature launch, which is exactly why it's easy to miss, and why checking your tenant's specific Message Center details matters so much.

Anthropic landed as a Copilot subprocessor earlier this year. OpenAI has now landed the same way. Neither shift changed what Copilot looks like to your users. Both changed where their prompts and data can be processed, under what commitments, and who's accountable for reviewing it. That pattern isn't going to stop.

ChangePilot surfaces every M365 change that matters, tailored specifically to your tenant profile, filtered by security, compliance, and operational impact, so your team doesn't have to guess which settings applied automatically.

Not on the Bulletin yet? Catch critical M365 Message Center updates tailored to your posture the week they land. Sign up here