If your organisation uses Microsoft 365 Copilot, a quiet but significant change has already landed in how your users' prompts and data can be processed, and Microsoft described it in two separate Message Center posts that don't tell quite the same story.
OpenAI has been added as an official subprocessor for Microsoft 365 Copilot. That's a new development: until now, OpenAI's models running inside Copilot were hosted entirely within Microsoft's own Azure environment, with OpenAI itself outside Microsoft's customer data processing boundary. That's no longer the only path. Under the new model, OpenAI can operate the infrastructure directly, with Microsoft providing contractual oversight rather than hosting the workload.
Subprocessor Addition: Microsoft added OpenAI as a direct M365 Copilot subprocessor alongside Azure OpenAI models
Conflicting Communication: MC1422074 announced auto-enablement on 24 July 2026, while MC1421915 framed the feature as opt-in
OpenAI as a subprocessor means OpenAI can now host and process Microsoft 365 Copilot prompts on its own infrastructure under contractual oversight from Microsoft.
Microsoft has always used OpenAI's models, so that isn't new. What is new is how those can be delivered.
Until this change, every OpenAI model used in Copilot ran as Azure OpenAI: Microsoft-operated infrastructure, inside Microsoft's own Azure environment. OpenAI itself sat outside Microsoft's customer data processing boundary entirely; it wasn't a subprocessor, because it never touched customer data.
With OpenAI as a subprocessor, Microsoft is introducing a second delivery path. OpenAI now operates some of the model infrastructure directly, under Microsoft oversight, contractual safeguards, and the same Microsoft Product Terms and Data Protection Addendum (DPA) that already govern Microsoft's Online Services, except where explicitly excluded (more on that below). OpenAI was added to the Microsoft Online Services Subprocessors List on 23 June 2026, with the capability available for use from 9 July 2026.
The first model delivered this way is GPT-5.6, which OpenAI has positioned as its preferred model for Microsoft 365 Copilot experiences including Word, Excel, PowerPoint, Cowork, and Copilot Chat. Functionally, users see the same GPT-based Copilot experience they already have. The change is in the infrastructure and governance model behind it, not the interface.
This mirrors the pattern Microsoft already established with Anthropic, which was onboarded as a Copilot subprocessor earlier in 2026. OpenAI is now the second non-Microsoft-operated AI subprocessor added to Copilot in the same year, and the assumption that "Copilot only ever uses Microsoft's own AI stack" is no longer safe to make.
| Feature / Commitment | Azure OpenAI (Microsoft-Operated) | OpenAI Subprocessor (Open-AI Operated) |
| Infrastructure Host | Microsoft Azure Environment | OpenAI Infrastructure |
| Default Tenant State | Active by default | Auto-enabled on 24 July 2026 (MC1422074) |
| SOC 1 Type 2 & HITRUST | Supported | Excluded |
| FedRAMP High / PCI DSS | Supported | Excluded |
| EU Data Boundary | Included | Included (with regional processing exceptions) |
| In-Country Data Residency | Guaranteed where available | Excluded (data may leave region) |
Microsoft issued two separate Message Center notifications, MC1421915 and MC1422074, because Microsoft targets updates based on tenant-specific attributes like seat count, enterprise licensing, or geographic region.
If you read tech commentary online or consult peers at other organisations, you may find conflicting advice on whether this feature is opt-in or auto-enabled. The discrepancy stems from how Microsoft segments its customer communications across two distinct Message Center IDs:
Relying on external summaries or third-party blog posts can create compliance risk. If an administrator acts on advice based on MC1421915 (opt-in) while their tenant is actually governed by MC1422074 (auto-enabled), OpenAI-operated models may already be active in their environment without their knowledge.
Key Takeaway: Do not assume which Message Center policy applies to your organisation. IT administrators must check their specific Microsoft 365 Admin Center portal to verify the live status of their tenant.
For a visual breakdown of how Microsoft 365 Copilot handles data processing and integration across productivity apps, check out this overview: Microsoft 365 Copilot: AI Built for Work.
Expanding Copilot capabilities often default to "enabled," forcing IT administrators to proactively manage external providers and agent access rather than opting in.
A prime example is how Copilot handles dedicated agents. Since Copilot gained the ability to call dedicated agents, including third-party ones built outside Microsoft, all agent types (Microsoft, organizational, and external) are available to every user by default.
That creates a distinct governance contrast:
To check and configure agent defaults in your tenant:
Go to Microsoft 365 admin center → Agents → Settings → Allowed agent types, then select Microsoft only, external publishers, or certified external publishers only.
The core lesson: Don't assume Copilot's expanding capabilities default to your organisation's security posture. Audit model subprocessors and agent permissions together.
OpenAI-operated subprocessor infrastructure is explicitly excluded from several core compliance frameworks, including FedRAMP High, SOC 1, PCI DSS, HITRUST, and local in-country processing guarantees.
Because this introduces a genuinely new subprocessor, several protections and certifications that customers may assume are blanket commitments don't automatically extend to OpenAI-operated models. Per Microsoft's own documentation, the following exclusions apply:
For organisations already navigating GDPR, NIS2, or sector-specific data governance requirements, these exclusions are the kind of detail that belongs in front of legal and compliance, not discovered after the fact.
You can audit and change OpenAI subprocessor permissions inside the Microsoft 365 admin center under Copilot AI Provider Settings.
Follow these steps to verify your tenant's posture:
Step 1: Check the current setting
You must be an AI Administrator or Global Administrator. Go to the Microsoft 365 admin center → Copilot → Settings → View all → AI providers operating as Microsoft subprocessors.
Step 2: Review the OpenAI entry
Under Available subprocessors for your organization, select OpenAI to see the current access configuration.
Step 3: Choose your access level
Under Choose which users can access OpenAI-operated models, select All users, restrict to specific users or Entra ID security groups, or select No users to disable it entirely — then Save.
Step 4: Check Copilot Studio and Power Platform separately
Additional admin controls for OpenAI-operated models in Copilot Studio and Power Platform agents live in the Power Platform admin center, under external LLM configuration. This is a separate control surface from the Microsoft 365 admin center setting.
Step 5: Document the decision
Whatever you choose, record the rationale alongside the Message Center ID logged in your tenant portal so future audit reviews have clear context.
Because key rollout dates have already passed, the focus is on verification:
MC1421915 or MC1422074 inside your admin portal to see which specific terms were issued to your organisationAI providers operating as Microsoft subprocessors screen to verify whether access is currently active, restricted, or disabledWhat is OpenAI as a subprocessor in Microsoft 365 Copilot?
It's a new delivery path that lets OpenAI operate some of the model infrastructure behind Copilot directly under Microsoft's contractual oversight, rather than every OpenAI model running exclusively inside Microsoft's own Azure environment. It was added to the Microsoft Online Services Subprocessors List on 23 June 2026 and became available on 9 July 2026.
How is this different from Azure OpenAI?
With Azure OpenAI (Microsoft-operated), OpenAI's models are hosted entirely within Microsoft's infrastructure and OpenAI has no access to customer data. With OpenAI as a subprocessor (OpenAI-operated), processing happens on OpenAI's own infrastructure, governed by the Microsoft Product Terms and DPA, subject to specific compliance exclusions disclosed by Microsoft.
Why are there different Message Center items (MC1421915 vs MC1422074) for this feature?
Microsoft customizes Message Center notices based on tenant attributes like seat count, licensing, or regional defaults. While MC1422074 communicated an auto-enable deadline of 24 July 2026 for eligible commercial tenants, MC1421915 communicated an opt-in model. It is vital to check which notification landed in your specific tenant portal.
Is OpenAI-operated Copilot on by default in my tenant right now?
It depends on your tenant's licensing profile and Message Center assignment. For commercial tenants under MC1422074, the setting auto-enabled on July 24, 2026, unless an admin actively opted out. Check the AI providers operating as Microsoft subprocessors setting in your admin center to confirm.
Does this affect the EU Data Boundary?
OpenAI-operated models are included in the EU Data Boundary, except as otherwise noted in Microsoft's EU Data Boundary documentation. However, they are currently excluded from in-country processing commitments where applicable, so data may leave a specific country even while remaining within the EU Data Boundary.
What if my organisation needs FedRAMP High, PCI DSS, HITRUST, or SOC 1 assurances?
Those certifications and attestations are not currently available for OpenAI-operated models. If your organisation requires any of them, review whether OpenAI as a subprocessor should be disabled or restricted for your tenant, and consult your authorising official where relevant.
How do I disable OpenAI as a subprocessor?
In the Microsoft 365 admin center, go to Copilot → Settings → View all → AI providers operating as Microsoft subprocessors → OpenAI, then set Choose which users can access OpenAI operated models to No users, and Save. You can re-enable it at any time.
Is this the same as the "Allowed agent types" setting for Copilot agents?
No, but the two are closely related and worth reviewing together. "AI providers operating as Microsoft subprocessors" controls which model provider processes your Copilot prompts — the subject of this article. "Allowed agent types" (Microsoft 365 admin center → Agents → Settings) controls which third-party Copilot agents your users can invoke, and it defaults to every agent type being available to everyone.
OpenAI as a subprocessor isn't a dramatic feature launch, which is exactly why it's easy to miss, and why checking your tenant's specific Message Center details matters so much.
Anthropic landed as a Copilot subprocessor earlier this year. OpenAI has now landed the same way. Neither shift changed what Copilot looks like to your users. Both changed where their prompts and data can be processed, under what commitments, and who's accountable for reviewing it. That pattern isn't going to stop.
ChangePilot surfaces every M365 change that matters, tailored specifically to your tenant profile, filtered by security, compliance, and operational impact, so your team doesn't have to guess which settings applied automatically.
Not on the Bulletin yet? Catch critical M365 Message Center updates tailored to your posture the week they land. Sign up here