Claude Sonnet 5 in Microsoft 365 Copilot: EU tenant guide
Microsoft switched on Anthropic's Claude Sonnet 5 inside Microsoft 365 Copilot yesterday, 2 July 2026, with the rollout beginning in Copilot Cowork and Copilot in PowerPoint. Microsoft describes Sonnet 5 as a frontier model built for agentic, multi-step work across documents, spreadsheets and presentations, and it joins the growing set of models available behind the Copilot surface. Admins manage access based on their organisation's policies and readiness.
For a tenant in the United States, this is a feature announcement. For a tenant in Sweden, it is a governance decision, because Anthropic models in Microsoft 365 Copilot run outside the Microsoft EU Data Boundary and are disabled by default for EU and UK customers. Model choice inside Copilot has stopped being a Microsoft implementation detail and become something your admin team, your data protection officer and your procurement function all have opinions about. The default OpenAI models stay inside Microsoft's boundary commitments; the Anthropic models do not. That asymmetry is the entire story, and it deserves a careful walk-through before anyone in your organisation flips the toggle.
What Microsoft shipped on 2 July
Claude Sonnet 5 becomes available in Microsoft 365 Copilot for licensed customers, with two surfaces first in line. Copilot Cowork is Microsoft's agentic Copilot experience, where users hand off multi-step background tasks rather than chat turn by turn, and it is a natural fit for a model tuned for long-horizon agentic work. Copilot in PowerPoint is the second surface, where Sonnet 5 can drive drafting and deck generation. Microsoft's documentation for the EU app-level setting lists Excel and PowerPoint as supported today, with Word support arriving during the summer.
This is not Anthropic's debut in Copilot. Microsoft first added Claude Sonnet 4 and Claude Opus 4.1 in September 2025, in the Researcher agent and in Copilot Studio, rolled out through the Frontier programme. What has changed since then is less about which model is newest and more about the legal plumbing underneath, which is where EU tenants need to pay attention.
From Anthropic's terms to Microsoft's DPA: the contractual shift
When Anthropic models first appeared in Copilot in 2025, Microsoft was unusually blunt about the arrangement: the models were hosted outside Microsoft-managed environments and subject to Anthropic's own Terms of Service. Your Microsoft DPA did not cover that processing. Tenant admins who opted in were effectively signing their users up to a second provider relationship in the middle of a Microsoft product.
That arrangement is gone. Anthropic has since onboarded as a Microsoft subprocessor, which changes the compliance picture substantially:
- September 2025: Anthropic models arrive in Researcher and Copilot Studio, hosted outside Microsoft-managed environments under Anthropic's Terms of Service, opt-in via the admin center.
- 25 March 2026: cut-off date that determines default settings for EU, EFTA and UK tenants (details below).
- 3 April 2026: Microsoft introduces a dedicated admin setting, Copilot in Microsoft 365 apps with Anthropic models, for EU, EFTA and UK tenants.
- 1 May 2026: the old Anthropic independent processor setting is decommissioned. If Anthropic is not enabled as a Microsoft subprocessor, access to Anthropic models is no longer available in the tenant.
- 2 July 2026: Claude Sonnet 5 begins rolling out in Copilot Cowork and Copilot in PowerPoint.
Under the subprocessor model, Anthropic operates with Microsoft oversight through contractual safeguards and technical and organisational measures. The Microsoft Product Terms and the Microsoft Data Protection Addendum apply to use of Anthropic models through Microsoft's enterprise Online Services, use is covered under Enterprise Data Protection, and the Microsoft Customer Copyright Commitment applies to Anthropic models used in covered products, including Copilot and Copilot Studio. For a DPO, this is a meaningful upgrade: one DPA, one subprocessor list, one accountability chain, instead of a side agreement with a second AI vendor.
Re-opt-in required. If your organisation is in the EU, EFTA or the UK and previously opted in to Anthropic models under Anthropic's separate commercial terms and data processing agreement, that consent did not carry over. The subprocessor toggle is set to Off by default and you need to opt in again. If your users had Claude in Researcher last winter and it quietly disappeared, this is why.
The EU Data Boundary exclusion, plainly stated
Microsoft's documentation is direct on the point that matters most to Swedish organisations: Anthropic models deployed in Microsoft offerings such as Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps are currently excluded from the EU Data Boundary and, where applicable, from in-country processing commitments. When a user in your tenant runs a prompt against Claude Sonnet 5, the data processing for that model call happens outside the EUDB. Customers within the EU Data Boundary and customers in the UK therefore have Anthropic models disabled by default, while most commercial-cloud customers elsewhere get them enabled by default.
Note what this does and does not mean. It does not mean your SharePoint content or Exchange mailboxes leave the boundary; it means the prompt and grounding data sent to the Anthropic model for a given request are processed outside it. It also does not mean the processing is uncontracted: the Microsoft DPA covers it, including Microsoft's standard transfer mechanisms. But an EUDB exclusion is exactly the kind of change that data-flow documentation, transfer impact assessments and DPIAs exist to capture. If your Copilot rollout was approved internally on the strength of the EU Data Boundary, that approval does not automatically extend to the Anthropic model path.
Two settings, and how they interact
EU tenant admins now juggle two related controls in the Microsoft 365 admin center, and confusing them is easy.
1. The global subprocessor setting
Under Copilot, then Settings, then View all, the page called AI providers operating as Microsoft subprocessors is the master switch. For EU, EFTA and UK tenants it defaults to No users. An admin holding the AI Administrator or Global Administrator role can enable Anthropic there and choose who gets access: all users, or specific users and Entra ID security groups. Those assignments are applied at the provider level and enforced across Copilot and Copilot Studio experiences, which makes group scoping the natural mechanism for a controlled pilot.
2. The app-level setting for Word, Excel and PowerPoint
Introduced on 3 April 2026 specifically for EU, EFTA and UK tenants, the setting called Copilot in Microsoft 365 apps with Anthropic models allows Copilot in the Office apps to use Anthropic models by default when generating or refining content. Two behaviours are worth internalising. First, for tenants created after 25 March 2026 this setting is on by default; older tenants should check the Message Center for their tenant's default. Second, when the global subprocessor setting is scoped to All users or to specific users and groups, the app-level setting becomes unavailable and cannot be changed, because the provider-level assignment takes precedence.
There is a third layer for makers: once Anthropic is enabled in the Microsoft 365 admin center, Copilot Studio and Power Platform have additional controls in the Power Platform admin center governing whether external large language models can be used for generative responses. If you run Copilot Studio agents in production, that PPAC setting belongs in the same change request as the tenant toggle.
Should you enable Claude in your tenant? A decision framework
The engineering upside is real. Model diversity inside Copilot means a task can run on the model that suits it, and Sonnet 5's agentic profile is a credible fit for Cowork-style background work. The question is whether the upside justifies adding a processing path outside the EUDB. Work through it in order:
- 1. Classify the data Copilot can reach. Copilot grounds prompts in whatever the user can access. If your tenant holds patient data, financial records under sectoral rules, or public-sector case files, the EUDB exclusion is a materially different risk than it is for a consultancy's proposal library.
- 2. Check what your internal approvals actually said. If the Copilot DPIA or rollout decision references the EU Data Boundary as a control, enabling Anthropic models invalidates that assumption for the Anthropic path and the DPIA needs a delta assessment before, not after, the toggle flips.
- 3. Decide scope before mechanism. A pilot group of power users in Cowork and PowerPoint is a defensible first step. Scope the global subprocessor setting to a security group, document who is in it and why, and expand from evidence.
- 4. Confirm which setting governs your scenario. Provider-level scoping overrides the app-level toggle. If you want Anthropic in Copilot Studio but not as a default drafting model in Office apps, map the combination deliberately rather than discovering it in production.
- 5. Verify the default you inherited. Tenants created after 25 March 2026 have the app-level setting on by default. A new subsidiary tenant spun up this spring may already be in a different posture than your main tenant. Audit both.
- 6. Set a review date. Microsoft's documentation says Anthropic models are currently excluded from the EUDB. If that changes, your risk calculus changes with it, so treat the exclusion as a fact to re-verify quarterly, not a permanent property.
The Swedish angle: DPIA, records and procurement
DPIA and transfer assessment. For organisations that maintain a GDPR Article 35 DPIA for Copilot, and most Swedish enterprises that deployed it at scale do, the Anthropic option introduces a new subprocessor and a new processing location in one change. That is a textbook trigger for a DPIA update: document the data categories that can flow to the model, the transfer mechanism Microsoft applies under the DPA, and the mitigations you choose, such as group scoping and app-level restrictions. Your transfer impact assessment should treat the Anthropic path explicitly rather than folding it into the general Microsoft 365 analysis, precisely because Microsoft itself carves it out of the EUDB.
Article 30 records and the subprocessor list. Anthropic now appears in Microsoft's subprocessor disclosures via the Service Trust Portal. Your records of processing should reflect that Copilot has two model families with different processing footprints, and your DPA-mandated subprocessor change monitoring should have caught the notice. If it did not, that is a process finding worth fixing regardless of what you decide about Claude.
Procurement and upphandling. Public-sector buyers and regulated enterprises in Sweden routinely bind suppliers to EU processing commitments in framework agreements. A supplier delivering services on your tenant, or building Copilot Studio agents for you, may now be able to route prompts through a model outside the EUDB if your tenant permits it. Contract language written in 2024 about "Microsoft 365 within the EU Data Boundary" did not anticipate per-model carve-outs. Review supplier clauses and your own bid commitments, and state explicitly in new agreements whether Anthropic-model processing is permitted.
The quiet default problem. The most likely failure mode for a Swedish organisation is not a considered decision that goes wrong but an unconsidered default: a tenant created after 25 March with the app setting on, an admin who enables the subprocessor to unlock a Copilot Studio feature without realising it flows through to Office apps, or a pilot group that never gets reviewed. The controls are adequate. The discipline of using them is the actual work.
What to do this week
- Check the AI providers operating as Microsoft subprocessors page in your admin center and record the current state, including user and group assignments.
- Check the Copilot in Microsoft 365 apps with Anthropic models setting, especially on any tenant created after 25 March 2026, and reconcile it against your intended policy.
- Search your Message Center history for the Anthropic default-setting notices that apply to your tenant.
- If Anthropic was enabled under the old independent-processor arrangement, confirm whether anyone re-opted in after 1 May and whether that decision went through change control.
- Brief your DPO on the EUDB exclusion and schedule the DPIA delta before opening access beyond a pilot group.
- If you use Copilot Studio, review the Power Platform admin center setting for external LLMs in the same pass.
- Decide your Sonnet 5 pilot posture now, because users will start asking for it as soon as they see it in Cowork and PowerPoint.