The ‘silent’ advance of Claude
Microsoft 365 Copilot has been positioned in recent years as the AI assistant for the workplace. Consequently, organizations invested heavily in licensing and governance. Meanwhile, another reality is taking shape: employees are opening a tab with Claude.ai in addition to their Copilot window. The reason is simple: it gives them better answers for texts, code, complex analyses and longer documents.
We now see this behavior in almost every organization we visit. And it creates a creeping problem: The carefully designed Copilot governance applies only to the first window. It completely excludes the second tab.
“The Copilot policy is fine. But what happens to the data in that other AI window?”
Two tools, two very different data streams
To understand the risks, you first need to know how each tool handles your data. The architecture differs fundamentally.
Microsoft 365 Copilot
Copilot is deeply integrated into your organization’s Microsoft 365 tenant. Data remains within the Microsoft Cloud ecosystem, and for EU customers it falls within Microsoft’s EU Data Boundary program. That is, storage and processing remain within Europe, if configured correctly. Moreover, everything falls under your existing Microsoft DPA and commercial terms, and your data is not used for model training.
Claude.ai (consumer or pro)
If employees use claude.ai with a personal account, including a paid Pro account, the data is outside any company agreement. The infrastructure runs on AWS in the United States, with no EU data residency. In addition, Anthropic made a controversial change in October 2025: users who did not actively disable the new privacy choice give permission to keep their conversations for up to 5 years for model training.
| CRITICAL RISK
An employee who pastes a client contract, an HR document or an internal strategy report in claude.ai into their personal account is sending that data to U.S. servers and thus outside your GDPR processing agreement. With no guarantee of data residency, and possibly permission to use it as training data. |
Copilot vs. Claude: the facts side by side
The table below puts the two worlds side by side. The differences are at every level that matters to an organization.
Aspect |
Microsoft 365 Copilot |
Claude.ai (consumer) |
| DATA & PRIVACY | ||
| EU Data Residency | ✓ Yes – through EU Data Boundary | ✗ Not available (US/AWS only) |
| Model training on your dates | ✗ Not applicable | ⚠ Enabled by default unless self-disabled (Oct. 2025) |
| GDPR DPA available | ✓ Yes, fully | Partial: SCCs, limited scope |
| LEGAL & COMPLIANCE | ||
| Falls under company contract | ✓ Yes | ✗ No: personal account |
| Call retention period | Per tenant settings | 30 days (opt-out) or 5 years (opt-in) |
| ISO 27001 / SOC 2 | ✓ Yes | ✓ Yes, plus ISO 42001 |
| INTEGRATION & MANAGEMENT | ||
| Access to corporate data | SharePoint, Teams, Mail… | Only what users insert themselves |
| Admin management possible | ✓ Full control | ✗ No admin control possible |
Claude within Copilot: how does that work?
There is a second scenario that is much less well understood in our conversations: Claude as a model within Microsoft 365 Copilot itself. Microsoft introduced in September 2025 the ability for Researcher Agent users to choose the underlying language model, which thus includes Anthropic’s Claude models.
| IMPORTANT DIFFERENCE
Claude as a model in Copilot is something completely different from Claude.ai. Yet it is not automatically safe for EU organizations either: the compliance situation is more complex than it appears at first glance. |
What happens technically
When a user chooses Claude in the Copilot Researcher Agent, the query is processed through AWS in the United States (i.e., not through Microsoft’s EU infrastructure). This means concretely:
- Data leaves Microsoft’s EU Data Boundary program
- Processing falls outside Microsoft’s standard DPA and ADR licenses
- Anthropic was added as a subprocessor in January 2026, but EU Data Boundary commitments do not apply to this model
- Users had to accept Anthropics’ own data processing terms when it was introduced, a step that passes unnoticed in many organizations because people quickly click through.
| GDPR-IMPACT
The use of Claude through the Copilot Researcher Agent for tasks involving the processing of personal data is not compatible with GDPR for EU organizations in its current configuration. Processing outside the EU/EEA is not covered by the required safeguards. Your DPO should be aware of this. |
What admins can do
From the Microsoft 365 Admin Center, manage the Researcher Agent and model selection. The recommended action for EU organizations: disable or limit the option to select Claude as a model until Microsoft and Anthropic provide a compliant EU processing solution.
Can Claude be used EU-compliant?
The answer is yes, but only via specific deployment paths. The direct route via claude.ai or the Anthropic API does not guarantee EU data residency. However, there are two configurations that do offer this:
Deploymentpad |
EU Residency |
Requirements |
| Claude via AWS Bedrock (EU inference profiles) | ✓ Available (eu-central-1, eu-west-1…) | AWS account + Bedrock configuration + EU region setting |
| Claude via Google Vertex AI (EU regional endpoints) | ✓ Available (europe-west1, europe-west4…) | Google Cloud account + Vertex AI + EU endpoint configuration |
| Claude Enterprise (directly at Anthropic) | ✗ Standard on US infrastructure. | Only via Bedrock or Vertex AI if EU required |
| Claude.ai (Pro/Consumer) | ✗ Never possible | Never suitable for personal data in EU context |
If you want to use Claude structurally, for document analysis or customer communications, for example, the way through AWS Bedrock or Google Vertex AI with a properly configured EU region is the only GDPR-compliant option outside the Microsoft ecosystem.
Mapping the concrete risks
So what does this mean specifically for your organization? These are the scenarios we encounter most often in practice, ranked by impact.
| HIGH RISK
Personal data to US HR data, customer lists or medical records pasted into claude.ai leave the EU without appropriate safeguards. |
HIGH RISK
Training dates without permission Employees who missed the October 2025 opt-out allow company interviews to be kept for 5 years for model training. |
HIGH RISK
Shadow AI outside governance IT has no visibility into what data is being processed through personal AI accounts. Audit trails are completely lacking. |
| MEDIUM RISK
Claude in Copilot without checking Employees choose Claude as Copilot model without realizing that the processing takes place outside the EU. |
MEDIUM RISK
Confidential documents Strategic plans, M&A documents or patent applications that inadvertently end up in a consumer platform. |
LOW RISK
Reputational damage A data breach or compliance violation found by a regulator also has reputational consequences in addition to financial ones. |
Best practices for your organization
The reality is that employees continue to use AI tools and bans rarely work. The key is policies that are realistic and offer safe alternatives. Here are the eight steps we recommend organizations take.
- For an AI inventory from
Map what AI tools your employees are effectively using, not just what IT has approved. Anonymous surveys yield more honest results than log tool analyses. - Classify your data and link it to allowed tools
Clearly define which data categories (public, internal, confidential, secret) may be processed in which tools. Personal data and confidential information: never in consumer platforms. - Offer an approved Claude alternative.
If employees prefer Claude to Copilot, give them an EU-compliant version via AWS Bedrock or Vertex AI, with a corporate account, DPA and Zero Data Retention if necessary. Banning without an alternative doesn’t work. - Disable Claude as a model in Copilot for EU tenants
Go to the Microsoft 365 Admin Center and restrict model selection in the Researcher Agent. Actively communicate this to users and explain why: a temporary measure until compliance is guaranteed, not a ban. - Check opt-in status for all employees with claude.ai
Employees who used claude.ai before October 2025 and did not consciously answer the pop-up may be allowing their conversations to be used for training. Instruct them to turn this off via Settings > Privacy > ‘Improve Claude for everyone’. - Conduct a DPIA for any AI use involving personal data
A Data Protection Impact Assessment is required by law for high-risk processing operations. AI tools that process personal data usually qualify. Complete this before deployment, not after the fact.
Conclusion: strong AI with weak governance is a ticking time bomb
Claude is an excellent AI assistant. The quality of responses is real, and employees who prefer the tool over Copilot for certain tasks do so for valid reasons. But quality and compliance are two different dimensions.
The current situation in many organizations is that of a split reality: formal governance around Copilot and an informal free zone for everything outside it. That policy gap is growing as AI becomes more established.
Structuring works better than prohibiting. Give employees the tools they want to use and configure them so that your company data stays in Europe, under your control and within a legal framework that’s right. This is perfectly technically feasible today. It just requires a conscious decision.
Xylos helps you securely structure AI usage
At Xylos, we guide organizations in drawing up an AI policy that works in practice. We map out actual AI use, link your data classification to permitted tools and set up a secure, EU-compliant configuration for the AI assistants your employees want to use effectively. That’s how you combine the productivity gains of AI with the control your DPO expects.
Want to know where your organization stands today? Contact us for a free consultation with our experts.
About the author