Is M365 Copilot sending some prompts to Anthropic?
Microsoft made in-country Copilot processing available in Australia in late 2025. Most mid-market organisations heard the headline and updated their privacy register accordingly. Anthropic opened its Sydney office on 10…
Microsoft made in-country Copilot processing available in Australia in late 2025. Most mid-market organisations heard the headline and updated their privacy register accordingly. Anthropic opened its Sydney office on 10 March 2026, the fourth in Asia-Pacific, and named data residency as the single most common request from Australian enterprises. Both moves point in the same direction. Neither closes the gap that opens the moment you switch a Copilot session to Claude. The Microsoft Foundry page on Claude is unusually clear about it. “Anthropic (not Microsoft) is the processor of the data,” the documentation reads. Prompts and outputs may be processed outside the customer’s region. Claude inside M365 Copilot is explicitly out of scope for the EU Data Boundary, and the equivalent Australian assurance does not yet exist either. For a buyer who tested Copilot under the Microsoft sovereignty story and then enabled Claude under the same brand, that is the sentence the procurement deck should have flagged. What changed under the M365 banner The integration is real and useful. Anthropic became a Microsoft sub-processor in January 2026, the Foundry catalogue now lists Claude Opus 4.6 alongside Microsoft’s first-party models, and enterprise buyers can route specific Copilot tasks to Claude without leaving their tenant interface. For Australian organisations standing up multi-model deployments, this is a credible buying option. What changed quietly is the data path. IDM Magazine’s coverage sets out the practical implication. Standard M365 Copilot interactions can be processed and stored within Australian borders. Any request routed through Claude falls outside that commitment. The host tenant looks unchanged. The data flow has moved. Anthropic’s own regional compliance page lists Microsoft Foundry in Europe as “Coming 2026”. Australia is not yet on that page at all. The Q&A thread on the Microsoft Foundry forum from April 2026 makes the practical position explicit: even where the customer selects an EU region today, inference execution does not occur fully inside Azure-operated data centres. The same is true for Australia, with the additional fact that there is no Australian-region commitment to point to. Attribute Microsoft-managed Copilot path Anthropic-routed Copilot path Processor of record Microsoft Anthropic (under Microsoft sub-processor terms) Australian in-country processing Available since late 2025 Not currently committed EU Data Boundary in scope Yes Explicitly out of scope Region selection guaranteed inside that region Yes for standard Copilot interactions No, may be processed in US, Europe, Asia, or Australia Default storage region Australian data centres for in-scope Copilot data United States The Microsoft-managed and Anthropic-routed paths inside M365 Copilot, contrasted on the five sovereignty attributes that change the most under audit. Sources: Microsoft Foundry data privacy documentation, Anthropic privacy centre, Anthropic regional compliance page. Why the gap matters now, not next year For three groups of Australian buyers, the gap is not abstract. The first is APRA-regulated entities. APRA’s 30 April 2026 letter to industry names supplier risk as one of four AI observation areas. It tells boards to map material, third-party and fourth-party dependencies in full. A Copilot deployment that silently routes prompts through Anthropic, processed offshore, sits inside that supply chain. It rarely appears in the supplier register the way the regulator now expects. The second is government and SOCI-regulated entities. The Department of Industry, Science and Resources Expectations for data centres and AI infrastructure developers, published 23 March 2026, frame sovereign hosting and IRAP-aligned procurement as a default. Claude inside Foundry, processed outside Australia, does not meet that bar today. For Protected-classification workloads it cannot. The third is professional services firms handling material non-public client data. The exposure here is contractual, not regulatory. Most engagement letters and managed-service deals signed in the last 18 months name Copilot as the tool and assume the data stays in Australia. The Claude path inside M365 changes that, and the client will not know unless you tell them. What the supplier deck quietly skips Most vendor briefings on M365 Copilot lead with the EU Data Boundary story and the Australian in-country processing commitment. Both are real and durable. Neither extends automatically to Anthropic. The deck almost always shows the boundary diagram for Microsoft-managed inference and lets the buyer infer the rest. If we were sitting in the next vendor meeting, the four questions we would put on the table are these: Which Copilot features and policies route prompts to Anthropic, and what fraction of our tenant traffic does that represent today? The answer is rarely zero, and most buyers cannot tell from inside the admin centre. What is the residency commitment for the Anthropic path specifically, not the Microsoft-managed path? The honest answer for Australia is currently “data may be processed in the US, Europe, Asia or Australia, and stored in the US”. Anthropic’s own privacy page is explicit on this. Which configurations in Foundry and Copilot let us disable, route, or default-deny the Anthropic path for sensitive classifications? The configuration exists. It is rarely on by default. What is the timeline and contractual commitment for Anthropic to deliver Australian-region processing, and what evidence will be produced once it ships? “Coming 2026” is on the website. It is not a contractual commitment. Asking these in order, in writing, produces the audit trail a board will need when the next supplier review opens. Where That Robot lands on this Multi-model Copilot is a sound architectural pattern. Claude is a strong production model. Anthropic’s Sydney office and exploration of local compute are the right direction of travel for the Australian market. None of that is in dispute. What is in dispute is the idea that the Microsoft sovereignty boundary covers every model under the M365 surface. It does not. The gap is narrow and fixable, but only by the buyer. Suppliers will not raise it on their own. They have been asked to sell the integration, not to map its edge cases. For organisations that already think hard about sovereignty under SOCI and NIST AI RMF, the action list is short. Audit the routes today. Restrict the Anthropic path for sensitive classifications by configuration, not policy. Add the missing supplier register entries before the next APRA, OAIC, or ASIC engagement. Build the contractual commitment your supplier will agree to once you ask the question, rather than waiting for a regional product update. For organisations that signed off on Copilot on the sovereignty story alone, the action list is shorter. Stop. Map the routes. Decide which workloads can sit on the Anthropic path today, and which cannot, before someone else makes the decision for you. The EU GPAI Code of Practice signals the same direction for cross-border buyers. The local equivalent is on its way. The Claude path inside M365 is the most useful test case Australian buyers have had in two years for the question of where their data actually goes. The answer is not the answer the supplier deck implies. The fix is straightforward once the question is asked. We have mapped Copilot, Foundry and Claude data flows inside Australian regulated businesses and produced the supplier questionnaire, technical control map, and evidence pack required to defend the architecture under audit. See how we build for sovereignty and we will walk you through which configurations close the gap inside the week, and which need a written commitment from your supplier before they close at all.