Published
This assessment reflects my personal opinion (Daniel Rohregger) and is not a legally exhaustive analysis.
As of: June 2026 | Update: Flex Routing, mandatory TIA, new admin toggles, and what that really means
Ever since Anthropic became an official subprocessor for Microsoft 365 Copilot, the debate has been simmering in German IT departments. Rightly so – but not in the way most people think. What actually applies, what’s still open, and why most companies can act now.
What does “subprocessor” actually mean – and why is this not a minor detail?
A data processor under Art. 28 GDPR must be contractually bound, may only process data for a specified purpose, and remains under the controller’s oversight. That is exactly what happened with Anthropic’s subprocessor onboarding at Microsoft – officially since January 7, 2026. Microsoft is the contracting party. Anthropic operates under Microsoft’s oversight, contractual safeguards, and technical and organizational measures (TOMs).
That’s not a footnote. It means the GDPR requirements for data processing are met. The Microsoft Data Protection Addendum (DPA), the Product Terms, and the Enterprise Data Protection framework apply in full. Anyone who doubts that is, by the same logic, doubting every other Microsoft service – including Exchange Online, SharePoint, and Teams.
For completeness: the old “Anthropic Independent Processor” toggle, which allowed Anthropic to be used under its own terms, was permanently switched off on May 1, 2026. From that point on, only the subprocessor path under the Microsoft contract applies – or no access to Claude models at all. That’s a simplification, not a weakening.
What the subprocessor status concretely includes:
-
No use of customer data for model training – documented and binding
-
Processing solely for the inference task
-
Encryption in transit and at rest
-
The Microsoft Customer Copyright Commitment (CCC) also applies to Anthropic models in products such as Microsoft 365 Copilot and Copilot Studio
What still doesn’t apply today (but is nonetheless transparent)
The discussion around EU data processing isn’t entirely unfounded. Anthropic models are currently officially excluded from the EU Data Boundary. That means inference requests are processed on Anthropic’s own infrastructure outside the EU. Microsoft documents this explicitly.
This transparency is the opposite of a problem: Microsoft gives admins active control. For tenants in the EU/EFTA and UK, Anthropic is disabled by default – a deliberately privacy-conservative default. Activation is a conscious opt-in.
Since April 2026, there are two separate admin toggles that both need to be checked:
-
Global subprocessor toggle (M365 Admin Center → Copilot → Settings → AI providers operating as Microsoft subprocessors): controls whether Anthropic is active as a subprocessor at all.
-
Feature-specific toggle “Copilot in M365 apps with Anthropic models” (from April 3, 2026): controls the use of Claude in Word, Excel, and PowerPoint for EU/EFTA/UK tenants.
For tenants created after March 25, 2026, the second toggle is active by default. That’s not a privacy loophole – but it is a reason to actively check your own admin settings rather than trusting the defaults.
The Flex Routing issue: what many people overlook – and it’s not just about Anthropic
This is where it gets interesting, because it’s a topic almost completely ignored in the current Anthropic debate.
Since early 2026, EU/EFTA tenants have had what’s called Flex Routing. During capacity bottlenecks, Microsoft can temporarily process LLM inference outside the EU – in the US, Canada, or Australia. And this affects not just Claude models, but also the standard OpenAI/GPT path.
Microsoft documents that data stays encrypted, and data-at-rest remains within the EUDB, with the exception of pseudonymized operational data used for security purposes. Flex Routing is enabled by default for tenants created after March 25, 2026, and can be switched off in the M365 Admin Center.
What this means: anyone who rejects Anthropic on EU data-protection grounds but hasn’t checked Flex Routing may well have the same problem on the OpenAI path – just without knowing it. The pragmatic response isn’t to block both, but to consciously manage and document both.
The 10 strongest arguments for pragmatism
-
EU Standard Contractual Clauses (SCCs) are the recognized transfer mechanism. Transferring personal data to the US is generally permissible under GDPR if appropriate safeguards are in place. Microsoft relies on the EU Standard Contractual Clauses (SCCs, Art. 46 GDPR, Decision 2021/914/EC) – explicitly not on the EU-US Data Privacy Framework. The SCCs are recognized by the CJEU and confirmed by the Schrems II follow-up case law. Third-country transfers are therefore regulated – not prohibited. Part of that: a Transfer Impact Assessment (TIA) by the controller is legally required – but with infrastructure as extensively documented as Microsoft’s, it’s practically feasible.
-
Enterprise Data Protection offers more protection than many on-prem solutions.
No training on customer data, encryption in transit and at rest, tenant isolation, Purview integration, a complete audit trail. This substantially exceeds the protective effect of many internal IT environments.
-
The Copyright Commitment applies here too. The Microsoft Customer Copyright Commitment protects companies using Copilot features with Anthropic models – a genuine enterprise-grade promise that many alternatives don’t offer.
-
Admin control is complete – but it has to be actively used.
EU/EFTA admins can disable Anthropic models, enable them selectively for specific user groups, or block them entirely. Control rests with the company. Two separate toggles in the Admin Center, granular control via Entra ID security groups – that’s state of the art in enterprise governance.
-
The Yammer precedent: the world has already survived this.
For years, Yammer was hosted exclusively in US data centers – even when the M365 tenant was located in the EU. Many companies accepted that, because what counted was the contractual protection mechanisms, not the physical server location alone. Anthropic is following the same pattern: contractual safeguards first, geographic expansion second – just as Azure, Exchange, and Teams did before it.
-
Bing Web Grounding already leaves the EU boundary today – without anyone noticing.
Web search queries that Copilot sends to Bing are explicitly not covered by the DPA or the EU Data Boundary. Microsoft acts as an independent controller there. That has always been the case. Anyone who rejects Anthropic but has Web Grounding enabled is practicing selective data protection.
-
Selective outrage isn’t a legal strategy.
Amazon S3, Salesforce, Google Workspace, GitHub Copilot, ServiceNow – practically every enterprise SaaS tool processes data on US infrastructure. Anyone who only raises an eyebrow at Anthropic should review their entire software stack.
-
The competitive loss is real and measurable.
Researcher, Agent Mode in Excel, Word/PowerPoint Agents, Copilot Cowork – these features use Anthropic models. With Anthropic disabled, agents automatically fall back to OpenAI GPT-4o – with reduced capabilities. Companies that block across the board miss out on productivity gains that competitors in other markets are already capturing.
-
The legal risk is hypothetical for most companies – the obligations are not.
Without a sector-specific rule, there’s no legal obligation for EU-only processing. The fear is cultural – not legal. But here’s what isn’t hypothetical: a TIA and a DPIA are mandatory for high-risk processing involving third-country transfers. These obligations aren’t a blocker, they’re documentation tasks – and with Microsoft’s infrastructure and existing compliance documentation, they’re practically manageable.
-
Transparency beats silence.
Microsoft documents every aspect of the data flow, every exception, every boundary – publicly and verifiably. In November 2025, after intensive negotiations with Microsoft, the HBDI (Hessian Commissioner for Data Protection and Freedom of Information) classified M365 as fundamentally operable in a data-protection-compliant way. That assessment applies to Microsoft’s internal path (OpenAI/Azure) – but it shows that GDPR-compliant use of M365 in Germany is possible and recognized. Comparable statements for the Anthropic path are still pending, which makes documenting your own risk assessment all the more important.
What a “documented risk assessment” actually means
The first step isn’t a checkbox – it’s two concrete obligations, both of which are manageable:
Transfer Impact Assessment (TIA, Art. 46 GDPR): a mandatory component of any SCC-based third-country transfer. It assesses whether US law (FISA 702, CLOUD Act) undermines the SCCs’ protective effect. Microsoft provides extensive documentation for this. In most cases, the outcome is: transfer is justifiable with supplementary measures (encryption, data minimization).
Data Protection Impact Assessment (DPIA, Art. 35 GDPR): in many cases mandatory for AI systems with access to emails, documents, and communications combined with a third-country transfer. Not to be understood as a brake, but as evidence of a deliberate decision.
Anyone who documents both is in a substantially stronger position with data protection authorities than companies that do nothing – regardless of which direction they ultimately take.
Who genuinely needs EU-only – and who doesn’t
The decisive question isn’t “Are data allowed to leave the EU?” – it’s: “Is there a legal or regulatory rule that prohibits this for my company specifically?”
Genuinely need to act:
-
Hospitals and medical practices (§ 203 of the German Criminal Code, KHZG, social data protection under SGB V/X)
-
BaFin-regulated financial institutions with explicit requirements
-
Public administration handling VS-NfD classified data (BSI approval required)
-
Tier-1 critical infrastructure operators (NIS2 implementation, KRITIS umbrella act)
-
Defense contractors with relevant classification levels
-
Companies with applicable works council agreements that mandate EU-only processing
Can take a pragmatic approach:
-
Mid-sized companies without sector-specific regulation
-
Marketing, sales, HR, operations
-
Service providers without special confidentiality requirements
-
Companies already making heavy use of US SaaS
-
Anyone who already has Bing Web Grounding enabled in Copilot
The path forward: a conscious opt-in or opt-out, a documented TIA, a DPIA where needed – no blind activation, but no reflexive blocking either.
What the future holds
Microsoft has clearly signaled that EU Data Boundary integration for Anthropic models is on the roadmap long-term. For Microsoft Foundry (the developer API access), EU-native inference is listed as “Coming 2026” – for M365 Copilot, there’s no concrete timeline yet.
Once that integration lands, most of the open questions disappear: EU data residency for Claude would then be a given, and the third-country debate would be history. Until then, control rests with the admins – with a complete audit trail via Microsoft Purview.
Anyone who makes an informed, documented decision now has a clear compliance advantage over companies that simply do nothing.
Bottom line
Anthropic as a Microsoft subprocessor is legally sound, fully backed by contract, and technically controllable. There are open points – above all the missing EU Data Boundary integration and a retention commitment for the Claude path that isn’t yet explicitly documented. These are communicated transparently and controllable via admin settings.
Anyone who genuinely needs EU-only already knows it from their sector-specific regulation. Everyone else doesn’t have a legal problem – they have a documentation task. And that doesn’t call for a compliance brake, but for a deliberate decision, a TIA, and clean governance documentation.
And if you think you can sidestep the issue by doing nothing: Flex Routing does the exact same thing on the OpenAI path – and that’s already been active for a long time.
Sources: Microsoft Learn (connect-to-ai-subprocessor, copilot-anthropic-apps, copilot-flex-routing, microsoft-365-copilot-privacy), Microsoft EU Data Boundary documentation, HBDI report November 2025, GDPR Art. 28 / 35 / 44 et seq., German Works Constitution Act (BetrVG) § 87 (1) No. 6
Putting this into practice
The guidance and context are fully contained in this article. If you want to carry it over to your own specific environment, the right starting point is Coaching for IT and Admins.