Enterprise Compliance, decided and defensible: Surfaces, Identity, Residency and Audit.
Governance Per Surface
Microsoft 365 Copilot, Copilot Studio and Microsoft Foundry are distinct surfaces, each with its own governance path. Enabling a model there does not automatically apply to the others, and each has its own admin controls.
Where Inference Happens
For EU-only inference there are three paths: Microsoft Foundry, AWS Bedrock in Frankfurt, Ireland or Paris, or Google Vertex AI. Each path brings its own agreement and its own check against the data protection record.
The Audit Record
Commercial plans exclude prompts from model training by default, without configuration and without opt-out. The plan tiers differ mainly on audit logs and SCIM, often the deciding factor for governance functions.
DPA Included
a Data Processing Agreement covers Enterprise and API use, ready before a data protection officer asks
Choice of Path
Microsoft Foundry, AWS Bedrock and Google Vertex AI each offer an inference path you check against the region your data protection record names
From Disabled by Default to a Decision an Auditor Can Read
Activation2 steps
01
The Default Is Off in Your Tenancy
In regulated tenancies (EU, EFTA, UK, government, sovereign), a newly available model stays disabled at the platform level until a tenant administrator explicitly enables it. That activation is not a configuration task: you establish which surfaces the model runs on, under which contract, and against which data protection record you justify the choice. The audit trail starts with the first model call, not the moment someone documents the decision.
02
Three Surfaces, One Governance Decision Each
Microsoft 365 Copilot, Copilot Studio and Microsoft Foundry are distinct surfaces with distinct governance paths. Enabling a model in one surface does not automatically apply to the others, and each surface has its own admin controls that have to be set individually.
Identity & Residency2 steps
03
Identity at Every Layer
Every model call in production carries an identity question: which principal authorised the call, which credential is in the request header, and what that credential's lifecycle looks like. On Copilot surfaces the answer follows from the tenant's Entra ID configuration, since Microsoft operates the identity plane there. For direct Foundry or API calls, you define the application identity and its permissions explicitly.
04
Where Inference Actually Happens
For a European organisation that requires EU-bound inference, three paths exist: Microsoft Foundry, which keeps the call inside the Microsoft infrastructure already governing the tenant; AWS Bedrock in Frankfurt, Ireland or Paris; or Google Vertex AI. Each carries its own subprocessor agreement and requires a separate assessment of whether it satisfies the clause in the data protection record naming the inference location. The choice is made once, at architecture time, and any later change in residency position requires reassessing every workload that assumed the original choice.
Data & Retention2 steps
05
Model Training Is Off by Default, Without Configuration
Commercial plans, including direct API access, exclude prompts from model training by default. This is not a setting the seat holder or the admin needs to turn on: it is the default position of the plan itself, and it cannot be changed from the seat or the tenant side. A data protection impact assessment recording the training position does not need to caveat an opt-out mechanism, because none exists and none is required.
06
Retention, Keys and the Data Record
Custom data retention periods make sure prompt and response history does not stay with a provider longer than the organisation's own data lifecycle policy allows. Customer-managed encryption keys keep the key material with the organisation rather than the provider. Together these two controls close the questions a data protection officer typically raises about inference data: how long it is retained, by whom, and under whose key.
Rollout & Audit1 steps
07
What an Audit Can Be Shown
A Compliance API with programmatic access to activity logs, chats, files and projects makes an audit independent of screenshots or manual exports: the record is queryable. OpenTelemetry export means the same traces that appear for engineering teams in an observability platform are available to a compliance function in its own tooling. Together they give the data protection record a live, queryable source.
Frequently Asked Questions
Does a model need to be enabled separately from the rest of Microsoft 365?
Yes, and the default depends on the tenancy type. It has been enabled by default in most commercial Microsoft tenancies since 2026-01-07, but remains disabled by default in EU, EFTA, UK, government and sovereign tenancies. There, a tenant administrator enables it explicitly. The distinction matters because an organisation in an affected tenancy that deploys it without that explicit enablement step is running it outside the platform's own governance path, which is the harder answer to give an auditor.
Where does inference happen if the organisation is in the EU?
EU-only inference runs through one of three hosted paths: Microsoft Foundry, which keeps the call inside the Microsoft DPA already governing the tenant; AWS Bedrock in Frankfurt, Ireland or Paris; or Google Vertex AI. Each carries its own subprocessor agreement. A Data Processing Agreement is available for Enterprise and API customers, and Standard Contractual Clauses cover EU-to-US transfers for direct API use. The residency path has to be selected before the first production call, not added to the architecture after a data protection officer raises it.
Are user prompts used to train the model?
No, for commercial plans. Direct API access excludes prompts from model training by default, just like the commercial plans themselves. This is not a per-user setting and cannot be changed from the seat or the tenant side: the exclusion is the default position of the plan itself. A data protection impact assessment recording the training position does not need to caveat an opt-out mechanism, because none exists and none is required. This applies equally to access through Microsoft Foundry, Copilot Studio and Microsoft 365 Copilot.
Contact
Privacy
Cookies & tracking
We set the cookies this site needs to work. Statistics and marketing only with your
consent. You can change or withdraw your choice at any time.
Privacy Policy
Privacy
Cookie settings
Choose which categories you allow. Necessary cookies are required to run the site and are
always active.
NecessaryAlways active
Core functions and storing the cookie choice you make here. The site does not work
without them.
Statistics
Reach measurement with Ahrefs Web Analytics and Google Analytics, so we can see which
pages are read and improve them.
Marketing
Advertising and remarketing pixels. We run none of them today. The switch stays here so
that nothing can load without your consent if that changes.