Published: 25 July 2026. Source: MC1422074: OpenAI models will soon be available as a subprocessor in Microsoft 365 Copilot
The deadline passed yesterday. Unless your organisation explicitly selected "No users" before July 24, 2026, OpenAI-operated models including GPT-5.6 are now active as a subprocessor in your Microsoft 365 Copilot deployment. This change happened automatically, without a separate admin confirmation. Admins reviewing the change now need to decide whether the current setting matches their governance requirements.
What changed on July 24, 2026
Microsoft added the OpenAI subprocessor setting to the Microsoft 365 admin center on July 9, 2026, initially in a disabled state. Organisations had fifteen days to review and opt out. On July 24, 2026, Microsoft automatically enabled the setting for any tenant that had not explicitly configured it, giving all licensed users access to OpenAI-operated models within Microsoft 365 Copilot.
| Before July 24, 2026 | After July 24, 2026 |
|---|---|
| OpenAI subprocessor setting visible in admin center but disabled by default | Setting auto-enabled for all users in tenants that did not opt out |
| M365 Copilot queries processed through Microsoft Azure OpenAI only | Some queries may route through OpenAI-operated models (GPT-5.6 and later versions) |
| No OpenAI subprocessor relationship in effect | OpenAI is a formal subprocessor under Microsoft Product Terms and the Data Protection Addendum |
What "subprocessor" means for your data
A subprocessor is a third-party organisation that Microsoft contracts to process customer data on its behalf. Adding OpenAI to that list means query data sent to certain Copilot features may be processed by OpenAI's infrastructure rather than exclusively by Microsoft's Azure OpenAI service.
Microsoft states the arrangement is governed by the same Product Terms and Data Protection Addendum that applies to the rest of Microsoft 365 services. Enterprise-grade security, compliance, and data residency commitments carry over, with exceptions documented on Microsoft Learn. Organisations operating under GDPR, the Australian Privacy Act, ISO 27001, or sector-specific frameworks should verify that the OpenAI subprocessor relationship is disclosed in their records of processing activities and is consistent with their existing data processing agreements.
Which workloads are affected
MC1422074 applies to three service areas: Microsoft 365 Copilot, Copilot in Microsoft 365 apps (Word, Excel, PowerPoint, Outlook, Teams), and Microsoft Copilot Studio.
SharePoint Online is not directly named in the MC, but Copilot in SharePoint runs on top of Microsoft 365 Copilot infrastructure. Content summarisation, question-and-answer over library content, and AI-generated pages within SharePoint all route through M365 Copilot. Admins who have enabled Copilot features in SharePoint should treat this change as directly applicable to their SharePoint Copilot deployment.
Organisations with SharePoint content that is governed by Restricted Access Control or sensitivity labels should review whether those controls are correctly scoped before Copilot begins processing that content. The SharePoint Copilot readiness use case covers the permission and content hygiene steps that reduce data exposure before expanding Copilot access.
What admins should do right now
If you missed the opt-out window and the setting is now enabled, you can still change it. Open the Microsoft 365 admin center, navigate to Copilot settings, and locate the OpenAI-operated models control. Setting it to "No users" disables the feature immediately, though some Copilot capabilities may become limited.
If you opted out before July 24, confirm the setting still shows "No users" to verify the opt-out was recorded correctly. No other action is required.
If you are keeping the feature enabled, update your internal processing register to note OpenAI as a subprocessor and review the Microsoft Learn subprocessor documentation for the specific data handling disclosures that apply. Notify your data protection officer or legal team if required by your sector's compliance framework.
Regardless of which option you choose, now is a good time to verify that SharePoint permissions are correctly scoped across your tenant. Copilot surfaces content based on what users can access, so overly broad permissions amplify the reach of any AI-generated response. The SharePoint permissions audit guide covers the steps to identify and remediate permission gaps before further expanding Copilot access.
Frequently Asked Questions
What is an OpenAI subprocessor in Microsoft 365 Copilot?
A subprocessor is a third party Microsoft engages to process customer data on its behalf. Enabling OpenAI allows M365 Copilot to route some queries through OpenAI-operated models such as GPT-5.6, governed by Microsoft's Product Terms and DPA.
Was MC1422074 opt-in or opt-out?
It was effectively opt-out. The setting appeared in the admin center on July 9 in a disabled state. Tenants that did not act before July 24 had it automatically enabled for all users. Admins who selected "No users" before that date remained opted out.
Can admins still disable OpenAI models in Microsoft 365 Copilot after July 24?
Yes. The setting can be adjusted at any time in the Microsoft 365 admin center under Copilot settings. Setting it to "No users" disables access to OpenAI-operated models. Microsoft notes that some Copilot features may become unavailable as a result.