AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·Enterprise AI8 read

GPT-5.6 Is in Your Copilot Tenant (Unless You Opted Out)

On 24 July 2026 Microsoft auto-enabled OpenAI-operated GPT-5.6 in commercial Copilot tenants unless an admin chose "No users". The model is the least interesting part — the subprocessor terms, the excluded attestations and what your audit log can't tell you are the story.

J
James Okafor
Field CISO
2026-08-21

If you administer a commercial Microsoft 365 tenant and did nothing in the second half of July, your users have been getting GPT-5.6 answers in Copilot since 24 July 2026 — served by OpenAI, not by Azure. That is not a rumour or a roadmap item. It is Microsoft's own documentation: "As of July 24, 2026, OpenAI operated models are enabled for all users for eligible commercial customers, unless you specifically disable the use of OpenAI operated models by selecting No users for the setting in the Microsoft 365 admin center."

The model upgrade is the least interesting part. The governance change is who is running the model, under what terms, and what that does to the compliance assumptions you made when you bought Copilot.

What actually changed

Until this summer, every OpenAI model behind Microsoft Copilot ran on Azure OpenAI — Microsoft's infrastructure, Microsoft's attestations, data never leaving Microsoft. On 23 June 2026 Microsoft added OpenAI to its Online Services Subprocessors List. On 9 July, the day GPT-5.6 went generally available in ChatGPT and the API, a new tenant setting appeared in the Microsoft 365 admin center, switched off. Message Center post MC1422074, published the same week, said what would happen next: "If no action is taken prior to July 24, 2026, the setting will be automatically enabled."

Microsoft's page on the arrangement draws the line precisely: "The information in this article only applies to OpenAI models operated by OpenAI (provided by OpenAI as a subprocessor). The information doesn't apply to OpenAI models operated by Microsoft (Azure OpenAI)." Azure-hosted GPT-5.5 is still there. GPT-5.6 — in its Sol, Terra and Luna variants — comes through OpenAI's own Responses API, with OpenAI acting under Microsoft's Data Protection Addendum as a subprocessor. The Cowork model picker now labels them plainly: "Provided by OpenAI as a subprocessor."

If that pattern sounds familiar, it is. Anthropic's models went through the same sequence — toggle in December 2025, default-on for most commercial tenants on 7 January 2026 — and became the default for Copilot in Excel and PowerPoint in May. Microsoft now has a standard way of adding a model provider to your tenant: announce, ship disabled, auto-enable on a date, leave you a "No users" option.

Why "operated by OpenAI" matters more than "GPT-5.6"

The same Microsoft page lists what does not come with the OpenAI-operated models, in its own words:

  • "OpenAI operated models available through Microsoft aren't FedRAMP High authorized."
  • "A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance (AOC) isn't available for OpenAI operated models."
  • "A Health Information Trust Alliance (HITRUST) Common Security Framework (CSF) Certification Letter isn't available for OpenAI operated models."
  • "A System and Organization Controls (SOC) 1 Type 2 report isn't available for OpenAI operated models."
  • "OpenAI models delivered through OpenAI as a subprocessor in Copilot experiences are currently excluded from in-country processing commitments when applicable."
  • "Access to OpenAI operated models isn't currently available for use in government clouds (GCC, GCC High, DoD) or sovereign clouds."

Read that list against the reasons your organisation approved Copilot. If the approval memo leaned on FedRAMP High, a PCI AOC, a HITRUST letter or a contractual in-country processing commitment, the default-on change moved part of your Copilot traffic outside those assurances on 24 July without anyone in your organisation deciding that it should.

Two things do carry over. Microsoft's Product Terms and DPA apply "except as otherwise disclosed in the Exclusions section", and the use is covered by Enterprise Data Protection. And on retention: "OpenAI offers Zero Data Retention for the Responses API used by Microsoft," subject to OpenAI's documented Responses API data controls.

The EU position is better than Anthropic's — with one footnote

For tenants in the EU Data Boundary, the two subprocessors are not symmetrical. Anthropic's models "are currently excluded from the EU Data Boundary" and are disabled by default for EU/EFTA and UK customers. OpenAI-operated models are included in the boundary, with a single disclosed transfer: "OpenAI processes and stores a pseudonymized user ID in the United States for troubleshooting, debugging, and security purposes. All other Customer Data and personal data is processed within the EU Data Boundary and is not stored by OpenAI."

The footnote that catches people is flex routing, a separate setting: "Flex routing is on by default for eligible tenants that were created after March 25, 2026," and when it is on, Copilot prompts, responses and grounding data "may be processed outside the EU Data Boundary for AI inferencing, including in the United States, Canada, and Australia" during peak demand. A newer EU tenant can therefore have three different data-location answers for three different Copilot requests, depending on the model that answered and the load at the time.

What your audit log will and won't tell you

Purview audit records for Copilot carry a ModelTransparencyDetails block. ModelProviderName is populated. ModelName and ModelVersion are, per the documentation, "Not available in Microsoft 365 Copilot scenarios." You can prove that OpenAI answered a given prompt; you cannot prove from the audit trail whether it was GPT-5.6 Sol, Terra or Luna — and in Word, users see only "Quick Response" and "Think Deeper", labels Microsoft has not mapped to model variants. If a regulator or a customer asks which model processed their data, the honest answer today is the provider, not the model.

The admin checklist

  1. Decide per provider, and scope it. Microsoft 365 admin center → Copilot → Settings → View all → AI providers operating as Microsoft subprocessors → OpenAI → choose All users, specific users and groups, or No users. Requires the AI Administrator or Global Administrator role. Scoping is "applied at the AI provider level, not the AI model level", and supports up to 999 combined user and group assignments per provider — enough to carve out regulated teams while leaving the rest on.
  2. Know what you lose if you turn it off. Microsoft's warning: "Some features or models are only available when OpenAI operated models are enabled. If you disable OpenAI as a subprocessor, certain features or models may no longer be accessible." Test with a pilot group before flipping the tenant.
  3. Re-check Anthropic while you are there. Same screen, different defaults: on for most commercial tenants, off in the EU/EFTA/UK, excluded from the EU Data Boundary. The preview models that retain data — Claude Fable 5 and Claude Mythos 5 — run under Anthropic as an independent processor, stay default-off, and involve Anthropic storing most inputs and outputs for up to 30 days. Leave those off unless someone has read the terms.
  4. Check flex routing if your tenant was created after 25 March 2026: Copilot → Settings → View all → Flex routing during peak load periods.
  5. Reconcile the compliance memo. If Copilot was approved on FedRAMP High, PCI AOC, HITRUST or in-country processing grounds, either scope OpenAI-operated models away from the workloads those assurances cover, or get the approval re-issued on the new facts.
  6. Copilot Studio and Power Platform. Microsoft documents additional controls in the Power Platform admin center for letting OpenAI-operated models into Copilot Studio agents; as of 21 August the relevant admin page still named only Anthropic, Mistral and xAI under external models, so check it rather than trusting a screenshot.
  7. Plan the Azure side separately. In Azure AI Foundry, gpt-5.6-sol, -terra and -luna went GA on 9 July 2026 with a retirement date of 11 January 2028. Older models are going: o1 and o3 retire on 21 October 2026 with gpt-5.6-sol as the replacement, and the May 2024 gpt-4o retires on 1 October 2026. Provisioned deployments are not auto-upgraded.
  8. Put the provider in your own telemetry. Since Microsoft's audit log stops at the provider, an inline inspection layer that records model provider, data classes in the prompt and the policy decision per interaction is the only way to answer "what went to OpenAI last quarter, and what was in it" — across Copilot and every other assistant in the estate.

The larger point

The enterprise AI control plane is turning into a set of provider switches that vendors flip on a schedule and invite you to flip back. That is a reasonable way to ship models quickly. It is a poor way to run a compliance programme, because every switch changes which attestations, data boundaries and retention terms apply to a slice of your traffic — and the defaults favour adoption over review. Treat the subprocessor screen as part of your change-control scope, read the Message Center posts that touch it, and keep your own record of which provider saw what. The next auto-enable date is already on someone's calendar.

FAQ

Is GPT-5.6 in Copilot running on Azure?

No. The GPT-5.6 models in Copilot are operated by OpenAI as a Microsoft subprocessor, through OpenAI's Responses API. Azure-hosted OpenAI models — GPT-5.5 in Copilot today — remain available and are unaffected by the setting.

When was it turned on, and can I turn it off?

The setting appeared disabled on 9 July 2026 and was automatically enabled for eligible commercial tenants on 24 July 2026 unless an admin had selected "No users". You can change it at any time under Copilot settings → AI providers operating as Microsoft subprocessors, and scope it to specific users and groups.

Does Microsoft's DPA cover OpenAI-operated models?

Yes, with documented exclusions: no FedRAMP High authorisation, no PCI DSS AOC, no HITRUST certification letter, no SOC 1 Type 2 report, exclusion from in-country processing commitments, and no availability in government or sovereign clouds. Microsoft's Enterprise Data Protection commitments apply, and OpenAI offers Zero Data Retention on the API Microsoft uses.

Is my EU data leaving the EU Data Boundary?

For OpenAI-operated models, Microsoft says no, except for a pseudonymized user ID stored in the United States for troubleshooting and security. Anthropic models are excluded from the boundary and off by default for EU tenants. Flex routing, on by default for tenants created after 25 March 2026, can route inference to the US, Canada or Australia at peak load regardless of model.

Can I see in the audit log which model answered?

You can see the provider (ModelProviderName). Model name and version are "Not available in Microsoft 365 Copilot scenarios" according to Microsoft's audit documentation.

Sources: Microsoft Learn, "OpenAI as a subprocessor in Microsoft Online Services" (article dated 5 Aug 2026) · Message Center MC1422074 (archive mirror) · Microsoft Learn, connecting to AI subprocessors (22 Jul 2026) · Microsoft Learn, per-provider user and group access (22 Apr 2026) · Microsoft Learn, EU Data Boundary ongoing partial transfers (9 Jul 2026) · Microsoft Learn, flex routing (27 Mar 2026) · Microsoft Learn, audit logs for Copilot (17 Jul 2026) · Microsoft Learn, Cowork models (19 Aug 2026) · Azure AI Foundry model retirement schedule (19 Aug 2026) · TechCrunch on OpenAI's "preferred model" announcement (9 Jul 2026).

Related: Microsoft Copilot data security · Is Purview Enough for AI Security? · Running Copilot and ChatGPT Enterprise Together: The 2026 Control Matrix.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security