The model picker is a data control, not a quality dial
AI-generated audio discussion of this module — same content, spoken.
Overview
Your corporate assistant has a model picker, and you almost certainly read it as a speed-and-depth choice. The products encourage that: Microsoft’s Cowork guidance says to leave it on Auto, because Auto “picks the model best suited to the task you describe.”
It is also a routing decision. Which entry you choose can decide which company processes your prompt, whether that company keeps it, and which parts of your employer’s contract travel with it. Every assistant offering models from more than one lab is making that call on someone’s behalf, every message.
Both vendors below answer that question in public. Neither answers it where you’re choosing.
What you’ll do differently: read the picker as a routing decision, and go and find the page where your vendor actually answers it.
The content
Three questions travel between tools: who processes this, do they keep it, and does your employer’s agreement follow it there? What follows is those three questions answered in two different filing systems.
Microsoft answers them per model, in a page written for administrators, sorting models into three kinds whose differences are contractual rather than technical. Models hosted and operated by Microsoft are “hosted on Azure and provided to customers directly by Microsoft”, and that description ends with a five-word sentence: “Data does not leave Microsoft.” An AI Subprocessor is “a third-party AI provider that handles data on Microsoft’s behalf and under Microsoft’s” DPA, Product Terms and enterprise safeguards — different company, same paperwork. An AI Independent Processor “processes data under its own data processing commitments, privacy, compliance, and enterprise terms. As a result, this data handling occurs outside of Microsoft’s Data Protection Addendum, Product Terms, and enterprise safeguards.”
The phrase to carry away is processor tier, because that third one isn’t hypothetical. Anthropic’s Preview models with Data Retention are the live example: for those, “Anthropic acts as an independent data processor, not a Microsoft subprocessor”, and data “is stored by Anthropic and not subject to your Microsoft Customer Agreement including commitments in the Product Terms and DPA.” Anthropic holds most inputs and outputs for up to 30 days, and content flagged by its classifiers for up to two years.
Two things stop that being a scare story. Anthropic “doesn’t use retained data for model training without your express permission.” And those models are default-off for every tenant, even where Anthropic is otherwise enabled — an administrator has to switch them on and choose who gets them. If one is in your picker, that was a decision.
Documentation also ages faster than the product. Microsoft’s Cowork model page was last updated on 17 July 2026. Seven days later OpenAI-operated models were “enabled for all users for eligible commercial customers, unless you specifically disable” them, and the page announcing that says those models “serve the same GPT-based Copilot experiences your users already have.” Be careful what that establishes: the same page states it “doesn’t apply to OpenAI models operated by Microsoft (Azure OpenAI)”, so it is not evidence that the Cowork row changed hands. What it does show is that a delivery path can move under a familiar product name while the page describing it is a week behind.
Now the other filing system, because most readers aren’t in Copilot. Glean answers the three questions once for the whole list: it “manages contracts, capacity, and upgrades with providers such as OpenAI, Azure OpenAI, Vertex AI, and Amazon Bedrock”, and “Providers are configured with zero-retention commitments, so customer data is not stored or used for training by the model vendors.” Admins “decide which models are available for their users in Glean Chat.”
On retention that is simpler than Microsoft’s — one commitment rather than a table with exceptions to hunt for. Note its scope, though: the sentence is about what the model vendors store, and the absence of per-model exceptions is a property of the documentation rather than something you can check model by model from it. The provider-to-model mapping does exist, on Glean’s admin-facing Supported LLMs page, updated 24 July 2026, which lists OpenAI as served “via Azure or OpenAI”, Google Gemini “via Google Vertex AI”, and Anthropic “via Google Vertex AI or Amazon Bedrock”.
So the answer is published in both tools. In neither is it beside the dropdown — and Glean’s picker page links to the mapping rather than showing it. That is the pattern worth carrying between tools: the disclosure is real, it is written for whoever configured your tenant, and finding it is a job you do once.
Be careful with the conclusion either way, because the tempting version is wrong. None of this says your data is unprotected. Where OpenAI operates as a subprocessor the Product Terms and DPA apply, “except as otherwise disclosed in the Exclusions section” — and four of that section’s five items turn out to be missing artefacts: a FedRAMP High authorisation, a PCI DSS Attestation of Compliance, a HITRUST certification letter, a SOC 1 Type 2 report. That is a gap in the paperwork an auditor asks for, not an absence of protection. The distinction is the difference between being useful in a meeting and being wrong in one.
Residency rewards the same care. Footnote 3 of Microsoft’s enterprise data protection page says “Anthropic models are currently excluded from the EU Data Boundary and when applicable, in-country processing commitments”, which is why EU, EFTA and UK tenants have Anthropic off by default. OpenAI-operated models are included, with narrower carve-outs. On the boundary itself the vendor that arrived most recently is the better-contained one, and you would not guess that from the names.
Which brings us to the part that changes your morning, and it holds in both tools here. The default is automatic selection, so most of the time nobody at your desk is choosing anything. Cowork’s answer is one easily-skimmed line: it “shows a model badge in the conversation so you can see which model produced a response.” Glean’s model-choice page doesn’t say whether the user can see which model answered. When selection is automatic, whatever your tool prints on the response is the record you can actually see of the route it took.
Try it
Two minutes, in whichever assistant your organisation gives you. No admin rights, nothing changed.
- Open the picker and read the labels, not the names. You’re hunting four words: a hosting location, a provider name that isn’t your vendor’s, preview, and retention.
- Go and find the page where your vendor answers it — this is the step that matters. In both tools above the answer is published and neither puts it beside the dropdown, so expect a search rather than a link. Try your tool’s name plus “model choice”, “supported models” or “subprocessor”.
- Send one throwaway prompt on the default and look for a model badge on the response. Whatever it names answers “who processed that”. If nothing anywhere names it, that’s your finding for today.
- Name one recurring task you’d want kept closest to home — the client matter, the unreleased numbers, the personnel note — and decide now which entry you’ll choose for it, rather than in the moment you’re in a hurry.
Where this breaks. The picker describes the arrangement; it knows nothing about your material. Nothing in Microsoft’s documentation describes a sensitivity label blocking your selection of a retention model, and the banner shown while one is selected is a notice, not a block. A short picker isn’t a safe picker either — the list only shows what your organisation has allowed. And disclosure is uneven even within one vendor: Microsoft documents a badge and a Notes column for Cowork, while for Microsoft 365 Copilot on web, desktop and mobile the documented indicator is narrower — “UI indicators show when Claude models are in use.”
If you can’t find the page, that’s the thing worth taking upward, and it’s a use question rather than a procurement one: which of the models in my picker are hosted by us, which are third parties, are any of them retaining what I send, and can I tell which one answered? Somebody had to read those answers to switch the tool on. You’re asking where they wrote them down.
Additional reading
- Understanding AI functionality and models in Microsoft Online Services — June 2026. The three-tier definition, including “occurs outside of Microsoft’s Data Protection Addendum, Product Terms, and enterprise safeguards”. The vocabulary is Microsoft’s; the distinction sits behind any multi-provider picker.
- Model choice (30 June 2026) and Supported LLMs (24 July 2026) — Glean, and you need both: the first carries the zero-retention commitment covering a picker that spans OpenAI, Azure OpenAI, Vertex AI and Amazon Bedrock, the second is where the provider-by-model mapping actually lives.
- Anthropic models in Microsoft Online Services — 22 July 2026. Preview models with Data Retention as “an independent data processor, not a Microsoft subprocessor”, the retention periods, and the default-off controls.
- Choose a model for Copilot Cowork — last updated 17 July 2026. The picker table, the model badge, the retention note and banner. Check the date before trusting the model list.
- Enterprise data protection in Microsoft 365 Copilot and Services that transfer a subset of Customer Data out of the EU Data Boundary — May and July 2026. Footnote 3 carries the Anthropic exclusion; the second states the OpenAI carve-out precisely, with all other Customer Data and personal data “processed within the EU Data Boundary and is not stored by OpenAI”.
- OpenAI as a subprocessor in Microsoft Online Services — 24 July 2026. The default-on change, the “No users” control, and the exclusions — worth reading for how narrow four of the five are against how they get repeated. The scope line at the top matters: none of it applies to OpenAI models operated by Microsoft as Azure OpenAI.
Editor’s note
For almost everyone, this is a matter of trusting your employer and calling it a day. That’s mostly fine, and the check in this module is a once-off, not a habit. It is aimed at people who want to know the material ways providers are engaged differently, so that knowledge is portable when something changes. Low risk on any given day. Worth the two minutes once.
// three assertions against what you just read · results stay in this browser
The module says three questions travel between tools whatever your organisation runs. What are they?
Both vendors in the module publish the answers. What does the module say they have in common about WHERE those answers live?
What limits does the module put on the picker itself?
Was this useful for your daily work?