This article maps out the data flows and explains the risks attached to them, along with best practices you can start applying today.
:focal())
The 'quiet' rise of Claude
In recent years, Microsoft 365 Copilot has been positioned as the AI assistant for the workplace. Organizations invested heavily in licenses and governance accordingly. Meanwhile, a different reality is taking shape: alongside their Copilot window, employees also open a tab with Claude.ai. The reason is simple: they get better answers there for texts, code, complex analyses and longer documents.
We now see this behavior in almost every organization we visit. And it creates a creeping problem: the carefully set up Copilot governance only applies to the first window. The second tab falls completely outside it.
"The Copilot policy is in order. But what happens to the data in that other AI window?"
Two tools, two very different data flows
To understand the risks, you first need to know how each tool handles your data. The architecture differs fundamentally.
Microsoft 365 Copilot
Copilot is deeply integrated into your organization's Microsoft 365 tenant. Data stays within the Microsoft Cloud ecosystem, and for EU customers this falls under Microsoft's EU Data Boundary program. That means: storage and processing remain within Europe, provided it's configured correctly. On top of that, everything falls under your existing Microsoft DPA and commercial terms, and your data isn't used for model training.
Claude.ai (consumer or pro)
If employees use claude.ai with a personal account, even a paid Pro account, the data falls outside any corporate agreement. The infrastructure runs on AWS in the United States, with no EU data residency. On top of that, Anthropic made a controversial change in October 2025: users who didn't actively opt out of the new privacy setting consent to having their conversations retained for up to 5 years for model training.
CRITICAL RISK An employee who pastes a customer contract, an HR document or an internal strategy report into claude.ai on a personal account sends that data to American servers and therefore outside your GDPR processing agreement. With no guarantee of data residency, and possibly with consent for its use as training data. |
Copilot vs. Claude: the facts side by side
The table below puts both worlds side by side. The differences show up at every level that matters to an organization.
Aspect | Microsoft 365 Copilot | Claude.ai (consumer) |
DATA & PRIVACY | ||
EU data residency | ✓ Yes — via EU Data Boundary | ✗ Not available (US/AWS only) |
Model training on your data | ✗ Not applicable | ⚠ On by default unless you switch it off (Oct. 2025) |
GDPR DPA available | ✓ Yes, in full | Partly: SCCs, limited scope |
LEGAL & COMPLIANCE | ||
Covered by a company contract | ✓ Yes | ✗ No: personal account |
Retention period for conversations | Per tenant settings | 30 days (opt-out) or |
ISO 27001 / SOC 2 | ✓ Yes | ✓ Yes, plus ISO 42001 |
INTEGRATION & MANAGEMENT | ||
Access to company data | SharePoint, Teams, Mail… | Only what the user pastes in |
Admin management possible | ✓ Full control | ✗ No admin control possible |
Claude inside Copilot: how does that actually work?
There's a second scenario that's much less well understood in our conversations: Claude as a model inside Microsoft 365 Copilot itself. In September 2025, Microsoft introduced the ability for users of the Researcher Agent to choose the underlying language model, including Anthropic's Claude models.
IMPORTANT DISTINCTION Claude as a model in Copilot is something completely different from Claude.ai. Even so, it is not automatically safe for EU organizations either: the compliance situation is more complex than it looks at first sight. |
What happens technically
When a user selects Claude in the Copilot Researcher Agent, the query is processed via AWS in the United States (so not through Microsoft's EU infrastructure). Concretely, this means:
The data leaves Microsoft's EU Data Boundary program
Processing falls outside Microsoft's standard DPA and ADR licenses
Anthropic was added as a sub-processor in January 2026, but the EU Data Boundary commitments don't apply to this model
At launch, users had to accept Anthropic's own data processing terms, a step that goes unnoticed in many organizations because people click through it quickly.
GDPR IMPACT Using Claude through the Copilot Researcher Agent for tasks that process personal data is, in the current configuration, not compatible with GDPR for EU organizations. Processing outside the EU/EEA is not covered by the required safeguards. Your DPO needs to be aware of this. |
What admins can do
You manage the Researcher Agent and model choice from the Microsoft 365 Admin Center. The recommended action for EU organizations: disable or restrict the option to select Claude as a model, until Microsoft and Anthropic offer a compliant EU processing solution.
Can Claude be deployed in an EU-compliant way?
The answer is yes, but only through specific deployment paths. The direct route via claude.ai or the Anthropic API does not guarantee EU data residency. There are, however, two configurations that do offer this:
Deployment path | EU residency | Requirements |
Claude via AWS Bedrock (EU inference profiles) | ✓ Available (eu-central-1, eu-west-1…) | AWS account + Bedrock configuration + EU region setting |
Claude via Google Vertex AI (EU regional endpoints) | ✓ Available (europe-west1, europe-west4…) | Google Cloud account + Vertex AI + EU endpoint configuration |
Claude Enterprise (directly with Anthropic) | ✗ US infrastructure by default | Only via Bedrock or Vertex AI when the EU is a requirement |
Claude.ai (Pro/consumer) | ✗ Never possible | Never suitable for personal data in an EU context |
If you want to deploy Claude structurally, for document analysis or customer communication for example, going through AWS Bedrock or Google Vertex AI with a correctly configured EU region is the only GDPR-compliant option outside the Microsoft ecosystem.
Mapping the concrete risks
What does this concretely mean for your organization? These are the scenarios we encounter most often in practice, ranked by impact.
HIGH RISK Personal data to the US HR data, customer lists or medical records pasted into claude.ai leave the EU without appropriate safeguards. | HIGH RISK Training data without consent Employees who missed the opt-out of October 2025 allow company conversations to be kept for 5 years for model training. | HIGH RISK Shadow AI outside governance IT has no view of which data is processed through personal AI accounts. Audit trails are missing entirely. |
MEDIUM RISK Claude in Copilot without control Employees pick Claude as their Copilot model without realising the processing takes place outside the EU. | MEDIUM RISK Confidential documents Strategic plans, M&A documents or patent applications that unintentionally end up in a consumer platform. | LOW RISK Reputational damage A data breach or compliance violation found by a regulator has reputational consequences on top of the financial ones. |
Best practices for your organization
The reality is that employees will keep using AI tools, and a ban rarely works. The key is a policy that's realistic and offers safe alternatives. These are the eight steps we recommend to organizations.
Carry out an AI inventory
Map which AI tools your employees actually use, not only what IT has approved. Anonymous surveys give more honest results than log tool analyses.Classify your data and link it to permitted tools
Set out clearly which data categories (public, internal, confidential, secret) may be processed in which tools. Personal data and confidential information: never in consumer platforms.Offer an approved Claude alternative
If employees prefer Claude over Copilot, give them an EU-compliant version via AWS Bedrock or Vertex AI, with a company account, a DPA and Zero Data Retention where needed. A ban without an alternative does not work.Switch off Claude as a model in Copilot for EU tenants
Go to the Microsoft 365 Admin Center and limit the model choice in the Researcher Agent. Communicate this actively to users and explain why: a temporary measure until compliance is guaranteed, not a ban.Check the opt-in status for every employee using claude.ai
Employees who used claude.ai before October 2025 and did not consciously answer the pop-up may be allowing their conversations to be used for training. Instruct them to switch this off via Settings > Privacy > 'Improve Claude for everyone'.Run a DPIA for every AI use involving personal data
A Data Protection Impact Assessment is legally required for high-risk processing. AI tools that process personal data usually qualify. Complete this before the roll-out, not afterwards.
Conclusion: strong AI with weak governance is a ticking time bomb
Claude is an excellent AI assistant. The quality of its answers is real, and employees who prefer the tool over Copilot for certain tasks do so for good reason. But quality and compliance are two different dimensions.
The current situation in many organizations is a split reality: formal governance around Copilot, and an informal free zone for everything outside it. That policy gap grows as AI becomes further embedded in everyday work.
Structuring works better than banning. Give employees the tools they want to use and configure them so your company data stays in Europe, under your control, and within a legal framework that holds up. That's perfectly achievable technically today. It just takes a deliberate choice.
Xylos helps you structure your AI use securely
Xylos guides organizations in mapping out an AI policy that works in practice. We map out actual AI usage, link your data classification to approved tools, and set up a secure, EU-compliant configuration for the AI assistants your employees actually want to use. That way, you combine the productivity gains of AI with the control your DPO expects.
Want to know where your organization stands today? Get in touch for a no-obligation conversation with our experts.
About the author
Peter Verrykt is Business Unit Lead Data & AI at Xylos and helps organizations turn data into concrete business value. He helps companies look beyond technical implementations and uses data and AI as a foundation for better decisions, greater agility and sustainable growth.