Microsoft says OpenAI-operated models became available as an OpenAI subprocessor on 9 July 2026. The same Microsoft Learn page says that, starting 24 July, these models will be enabled for all users at eligible commercial customers unless an administrator selects 'No users' in the Microsoft 365 admin centre. This is a provider-operation boundary, not a claim that Microsoft 365 Copilot suddenly abandons enterprise controls. It is also not something an executive should discover from a model label after the default changes.
The right response is a documented tenant decision. Identify eligibility, current setting, intended user group, model need, data classes, geography, audit controls and rollback owner. Then preserve evidence of the decision and test it with non-sensitive content before broad access.
> The short answer: Before 24 July, eligible Microsoft 365 administrators should explicitly choose the allowed user scope for OpenAI-operated models, record the legal and security review, and verify downstream Power Platform controls.
The evidence boundary
Microsoft distinguishes OpenAI models operated by OpenAI from OpenAI models operated by Microsoft through Azure OpenAI. The subprocessor page states that Product Terms and the Microsoft Data Protection Addendum apply, subject to listed exclusions, and says OpenAI-operated models are included in the EU Data Boundary except where that documentation notes otherwise. Government and sovereign clouds are not currently eligible. Organisations still need their own assessment of data categories, permissions and contractual obligations.
At-a-glance decision matrix
| Check | Current signal | Decision use |
|---|---|---|
| Eligibility and current state | Commercial, government or sovereign tenant; present admin setting | Establish before change |
| User scope | All, selected or no users | Use least necessary population |
| Provider distinction | OpenAI-operated versus Microsoft-operated OpenAI model | Show in training and logs |
| Data classes | Public, internal, confidential, regulated and client-controlled | Set allowed inputs |
| Geography and contract | EU Data Boundary, DPA, Product Terms and exclusions | Legal review with dated sources |
| Power Platform controls | Copilot Studio and Power Platform model settings | Check downstream surfaces |
| Audit and rollback | Logs, pilot test, owner and disable procedure | Prove reversibility |
The matrix is deliberately asymmetric: a hard failure in identity, safety, compatibility or policy wording cannot be cancelled by several attractive features. Work from the controlling source to the practical test, and date every fact that can change.
Eligibility and current state
Read the Microsoft page in the tenant's region and capture the setting with timestamp and administrator identity. Do not assume that a colleague's tenant has the same eligibility or default. Government and sovereign exclusions are material.
Decision: Establish before change. Evidence to retain: Commercial, government or sovereign tenant; present admin setting.
User scope
Map the business workflows that require OpenAI-operated models. A selected security group is easier to observe and reverse than broad enablement. Define join and removal criteria rather than turning a pilot into permanent access by inertia.
Decision: Use least necessary population. Evidence to retain: All, selected or no users.
Provider distinction
Users may see similar model names while the operational path differs. Documentation, support and audit review should use the precise provider wording. Avoid collapsing all GPT use into one architectural statement.
Decision: Show in training and logs. Evidence to retain: OpenAI-operated versus Microsoft-operated OpenAI model.
Data classes
Enterprise protections do not replace data minimisation. Define examples that may and may not be submitted, including attachments and grounded Microsoft 365 content. Apply existing sensitivity labels and access controls, then test whether overshared repositories are exposed to authorised users through Copilot.
Decision: Set allowed inputs. Evidence to retain: Public, internal, confidential, regulated and client-controlled.
Geography and contract
Record which terms and boundary documents govern the tenant on the decision date. Do not paraphrase 'EU Data Boundary' as a universal promise about every processing event. Link the exact Microsoft pages in the change record.
Decision: Legal review with dated sources. Evidence to retain: EU Data Boundary, DPA, Product Terms and exclusions.
Power Platform controls
Microsoft notes that additional controls become available after enablement. An organisation that governs Microsoft 365 but ignores agents built in Power Platform has an incomplete boundary. Inventory existing agents and owners before activation.
Decision: Check downstream surfaces. Evidence to retain: Copilot Studio and Power Platform model settings.
Audit and rollback
Run synthetic prompts that exercise retrieval, file access and model selection, then confirm the interaction appears in the expected audit surface. Write the rollback steps and communication route before expanding access. Preserve screenshots without sensitive prompt content.
Decision: Prove reversibility. Evidence to retain: Logs, pilot test, owner and disable procedure.
Put the framework into a real decision
A global investment firm has Microsoft 365 Copilot licences for 800 employees but only 60 people need the newest OpenAI-operated model. Leaving the default broad creates an unnecessary population; disabling everything may block a tested research workflow. The administrator creates a pilot group, excludes deal-room and regulated teams, checks Purview and audit coverage, tests with synthetic documents, records the change ticket and assigns a rollback owner. The decision is narrower than 'trust OpenAI' or 'ban AI': it controls who can invoke this provider path for which work.
Treat 24 July as a governance change window
Microsoft’s notice gives eligible commercial customers a concrete control point before default enablement. Start with scope. Identify tenants, users and workloads that are eligible, and record government or sovereign exclusions exactly as Microsoft describes them. Never extrapolate one tenant’s state to subsidiaries, development tenants or acquisitions.
Map authority next. Record who can change the setting, who owns the data-protection assessment, who represents legal or procurement, and who communicates to users. Capture the current state with timestamp, tenant identifier and documentation revision. If the organisation selects “No users”, record the reason and review date. If access is permitted, record the population, training material and escalation route.
Separate this decision from wider Copilot governance. Enterprise data protection, retention, sensitivity labels, DLP, audit, eDiscovery, connectors and agent permissions remain relevant. A processor setting does not repair excessive access to SharePoint or Teams. Test representative prompts with approved non-sensitive data and verify what administrators can observe. For globally mobile executives, include unmanaged devices, travel networks, assistants and cross-border collaboration.
The evidence pack should be reproducible without confidential content: tenant, control path, before-and-after state, approver, timestamp, source URLs, test identifiers and outcome. Store screenshots in the controlled repository. Recheck after 24 July to confirm production matches the decision. This is operational guidance, not a legal conclusion about processor roles or international transfers; qualified privacy and legal teams make those determinations.
Schedule a second check after the default date rather than treating approval as the finish line. Compare the observed tenant state with the signed decision, retain the audit evidence and open a controlled incident if they diverge. That makes the change reversible and reviewable.
Keep a dated decision record
A useful record for this specific decision contains the following fields: Eligibility and current state: Commercial, government or sovereign tenant; present admin setting; User scope: All, selected or no users; Provider distinction: OpenAI-operated versus Microsoft-operated OpenAI model; Data classes: Public, internal, confidential, regulated and client-controlled; Geography and contract: EU Data Boundary, DPA, Product Terms and exclusions; Power Platform controls: Copilot Studio and Power Platform model settings; Audit and rollback: Logs, pilot test, owner and disable procedure. Add the source URL, access date, market or account, person responsible for the check and the point at which the answer would change the decision. Do not overwrite an earlier observation when the facts move; append a new dated entry so the sequence remains visible.
Finish with one of four outcomes: proceed, wait, request evidence or decline. State the reason in one sentence and name the unresolved risk that remains. If another person must review the choice, they should be able to reconstruct it without relying on a screenshot detached from its source. This short record also makes later performance review more honest: the team can see whether the article's recommendation was based on facts available at publication or on information learned afterwards.
The useful outcome may be to wait, narrow the configuration, request written confirmation or decline the transaction. That is not indecision. It is the point of turning a volatile headline or complex ownership question into evidence that another person can review.
Action checklist
Confirm tenant eligibility.
Capture the current model-provider setting.
Choose the smallest justified user group.
Define prohibited data classes.
Review DPA, Product Terms and EU boundary notes.
Check Power Platform and Copilot Studio.
Test with synthetic documents.
Record audit evidence and rollback owner.
Complete the checklist before transferring money, erasing a device, changing a tenant-wide setting or exposing an irreplaceable object. Where a source is market-specific, repeat the check for the country, account and configuration that actually applies.
Related VERTU reading
These internal links answer adjacent decisions; they do not replace the current primary source for this article.
Sources and verification
Sources were accessed on 21 July 2026. Product availability, prices, software settings, weather guidance, insurance wording and event details can change. Recheck the live source before acting. Health, legal, insurance and emergency references are general information, not individual professional advice.
Final view
The 24 July change deserves an explicit tenant record, not panic or silent acceptance. Microsoft provides the provider distinction and admin controls; the customer must decide population, data classes, geography, downstream agent use and rollback. Start narrow, test with synthetic content and preserve the evidence. The strongest executive AI posture is one in which provider choice is visible, reversible and tied to a defined workflow.




