The short answer

For a regulated firm, governed Copilot is the stronger choice.

Copilot can already run Claude in Microsoft 365, so the real choice is the terms and settings that come with it. Governed means your firm has limited what Copilot can read and kept staff who handle returns on Microsoft's models. Microsoft does not yet commit to running the AI only in the U.S., so for now return information needs each client's consent. Claude on its own gets Anthropic's newest features first, but it adds a second vendor, and Microsoft's labels and rules do not reach its app. Either way, your administrator has three jobs: limit who can open which files, set each group's AI models, and note when each was set.

The comparison

Three columns, because "Copilot" means two different things: the product as it arrives, and the same product once someone has set it up.

Governed Copilot has the edge on 8 of 12 questions. Claude alone has it on 1, Copilot either way on 1, and 2 are ties.

QuestionCopilot (as it arrives)Copilot (governed)Claude aloneEdge
What it can readEverything the user can open, overshared files includedOnly what the permission review leaves openEverything the user can open, through the connectorGoverned
Which AI modelsMicrosoft's, OpenAI's and Anthropic's. The last two are on by default for most commercial customersMicrosoft's only for staff who handle returns, set group by group, with the date recordedClaudeGoverned
Where prompts are processedNearest region, others at peak load. Outside providers have no in-country commitmentMicrosoft's regions, outside providers off. U.S.-only processing is expected by the end of 2026, not committed todayNo U.S.-only setting documented for Team or EnterpriseGoverned
ContractMicrosoft's terms, except opt-in "Data Retention" modelsMicrosoft's terms, with a dated record of allowed modelsAnthropic's terms, a second vendorGoverned
Record of AI activityAvailable in Purview, once set upRetention switched on, then searched once to prove it worksCompliance API on the Enterprise planGoverned
Labels and rulesAvailable, but not set to the firm's filesLabels on the client folders, and rules that keep Copilot off them, testedNot covered by Copilot's Purview rulesGoverned
Proof for an examiner or insurerNone by defaultA dated record of every safeguardWhatever the firm writes downGoverned
Training on firm dataNot used for trainingNot used for trainingNot used by defaultTie
AgentsAgent Builder, included with the licenseAgents reviewed before use, each reading one libraryProjects and skillsGoverned
Where people use itWord, Excel, Outlook, Teams, PowerPoint and Copilot ChatWord, Excel, Outlook, Teams, PowerPoint and Copilot ChatAnthropic's app, reaching Microsoft 365 through a connectorBoth Copilots
Writing and analysisStrong, on any of the three model sourcesStrong. Staff who handle returns use Microsoft’s models, everyone else can use Claude if the firm allows itStrong, on Claude modelsTie
Anthropic's newest featuresOn Microsoft's scheduleOn Microsoft's scheduleAs Anthropic releases themClaude
Checked against Microsoft's and Anthropic's own documentation. The detail and every source are further down the page.

Where a prompt goes

Copilot (as it arrives)

  • Reads everything each person can open
  • Both outside AI providers on by default
  • No record
Copilot as it arrivesCopilot reads everything the person can open, including labeled and overshared files, and can send work to GPT models run by Microsoft, GPT models run by OpenAI, and Claude models run by Anthropic, with both outside providers on by default. There is no record.ReadsModelsEverything thisperson can openCopilot(as it arrives)GPTrun by OpenAIGPTrun by MicrosoftClauderun by AnthropicOutside providerson by defaultRecordNone

Copilot (governed)

  • Reads only what the permission review leaves open
  • Outside providers off for anyone who handles returns
  • Every setting dated
Governed CopilotCopilot reads only what the permission review leaves open, labeled client files are kept out, the two outside model providers are switched off for anyone who handles return data, and every setting is recorded with a date.ReadsModelsWhat the permissionreview leaves openCopilot(governed)GPTrun by OpenAIGPTrun by MicrosoftClauderun by AnthropicOutside providersoff for anyone whohandles return dataRecordDatedevery setting, every review

Before the next license

Before your firm assigns another Copilot license, it should be able to answer five questions in writing, for every AI tool it uses.

  1. What can it read?
  2. Which models run, and for whom?
  3. Where is the data processed?
  4. Under which contract?
  5. Where is the record of what the AI did, and when did someone last check it works?

If any answer is "we are not sure," that is the gap a governed setup closes.

The detail

The detail, in five parts

01

Your firm may already be using Claude

+

Most comparisons of Copilot and Claude compare the models: which one writes better, reasons longer, or handles a workbook more cleanly. For a firm that holds client data, that is no longer the choice. Copilot can already run Claude, and for most commercial customers outside the EU, EFTA and UK, Microsoft turns it on by default.

Since July 9, 2026, models that OpenAI runs itself can also power Copilot's GPT-based features. Since July 24 those models have been on by default for eligible commercial customers. So the question worth asking is not which model. It is whether anyone at your firm decided what the AI can read and which models it may use. And if they did, where is that written down?

Copilot now uses models from three places. What sets them apart is who runs the model, not which company trained it.

GPT models Microsoft runs. OpenAI builds them, and Microsoft runs them in its own cloud under your firm's Microsoft agreement. This is what most people picture when they picture Copilot.

GPT models OpenAI runs. Microsoft now also offers OpenAI models that OpenAI runs itself. Here OpenAI is a Microsoft subprocessor: a company Microsoft hires to do part of the work. Microsoft says these models "serve the same GPT-based Copilot experiences your users already have." As of July 24, 2026, they are on for all users at eligible commercial customers, unless an administrator turns them off.

Claude models Anthropic runs. Anthropic is a Microsoft subprocessor too. Microsoft enables its models "on by default for most customers in commercial cloud (excluding EU/EFTA and UK)." That covers Copilot, Researcher, Copilot Studio, Power Platform and Copilot in the Microsoft 365 apps. Copilot Cowork has been generally available since June 16, 2026. It runs on Anthropic models, and it stays off until an administrator turns it on.

Your administrator controls both outside providers in one place: the Microsoft 365 admin center, under Copilot, then Settings, then View all, then AI providers operating as Microsoft subprocessors. The administrator can apply the setting to specific users or security groups, so the choice is not everyone or no one.

One group of Claude models needs a decision of its own. Microsoft's Product Terms and Data Protection Addendum cover Anthropic models in Copilot, unless the models are labeled "Anthropic models with Data Retention." Microsoft keeps those models off until an administrator opts in. Once they are on, Anthropic acts as an independent processor under its own Commercial Terms of Service and Data Protection Addendum. Microsoft says Anthropic "(not Microsoft) stores most inputs and outputs for up to 30 days before deleting them." Content flagged by Anthropic's safety classifiers can be kept for up to two years. If your firm opts in, record who decided and when.

A note on names. Microsoft now calls its product for work accounts Microsoft Copilot. Until recently it was Microsoft 365 Copilot. The same Copilot app now serves personal accounts too, so the name alone no longer tells you which terms apply. The account does. Microsoft says the organization's controls "continue to apply when you use Copilot with your work or school account."

And Copilot is not ChatGPT. ChatGPT is OpenAI's own app, with its own accounts and its own terms. Take two staff members and the same return. One pastes it into a personal ChatGPT account, and the other asks Copilot about it. The second works under your firm's Microsoft agreement. The first does not, even when the model family is the same.

02

What it can read

+

Copilot works inside the tools your firm already uses: drafting in Word, working through a workbook in Excel, summarizing a thread in Outlook, catching someone up on a Teams meeting. Claude on its own works in Anthropic's app. It reaches your firm's files through Anthropic's Microsoft 365 connector, which reads SharePoint, OneDrive, Outlook and Teams.

Here is the part most comparisons miss. Both read what the user can already open. Microsoft says Copilot presents "only data that each individual can access." Anthropic says its connector works through delegated permissions: it acts as the signed-in person, inside that person's existing Microsoft 365 access.

That sounds safe until you ask who set the permissions in a small firm. Usually nobody did. They piled up. Take a compensation file in a folder eleven people can open. The only thing protecting it was that nobody knew where it was. Either assistant finds it with one plain question. We covered where those permissions come from in Copilot Does Not Leak. It Reveals.

So the permission review, a check of who can open which files, is not only for Copilot. It is the first step for any AI that reads your firm's files, Claude included. Microsoft Entra is where Microsoft 365 keeps its sign-in and access settings. Anthropic's setup asks a Microsoft Entra Global Administrator to grant consent for the connector once, for your firm's whole Microsoft 365. That consent is a firm decision. Record which role gave it, and when.

03

Labels, rules and the record

+

Microsoft 365 has protections that Anthropic's app does not reach. Microsoft ships some default settings, but none of them know which folder holds your firm's returns.

Sensitivity labels. These are Microsoft's tags that mark how sensitive a file is. A label such as Client Confidential can encrypt a file. Microsoft says that when content is encrypted this way, Copilot "honors the usage rights granted to the user." In other words, Copilot can do with the file only what that person is allowed to do. A label built around your firm's work puts that protection on the file itself. A folder name is only a name.

Rules for Copilot. Microsoft Purview, the data protection settings in Microsoft 365, can keep Copilot from using files and emails that carry sensitivity labels. It can also stop Copilot from answering when a prompt contains a sensitive number, such as a Social Security number. Microsoft still marks that second rule as preview.

A record of AI activity. Purview can search and keep Copilot prompts and responses. Anthropic's Enterprise plan offers a Compliance API, which lets your systems pull activity feeds, chat data and audit log events. Neither one is a record until your administrator sets it up and checks that it runs.

This is where governed Copilot pulls ahead. The labels and rules sit in the same system as the files they protect. One administrator sets all of them.

04

Where the data is stored, and where it is processed

+

These are two questions, and the answers are different. Where the data is stored is settled, and you can check it. Microsoft stores each Copilot prompt and response in the user’s own Exchange Online mailbox. That mailbox sits in your firm’s default geography, the region your Microsoft 365 is set up in. Under the Product Terms, Microsoft commits to keeping that stored content there when the default geography is the United States, or one of fourteen other countries. That commitment is why Purview can search and retain it. Where the data is processed, meaning where the AI runs, is the open question.

This is the part most comparisons skip, and for a tax firm it matters most.

For the models Microsoft runs itself, Microsoft routes Copilot requests "to the closest data centers in the region, but also can call into other regions where capacity is available during high utilization periods." Microsoft has announced in-country processing for Copilot. It expects to offer that for the United States by the end of 2026. Today it is not a commitment for U.S. tenants.

The two outside providers are further from those commitments. Microsoft says Anthropic models "are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments." It says OpenAI's own models "are currently excluded from in-country processing commitments when applicable." Claude on its own is not simpler. For its API, the service software developers build on, Anthropic documents a U.S.-only setting for where the AI runs. But the default there is global routing, which may run the AI in any available geography. On that platform, stored data is held in the United States. Anthropic does not describe either setting for its Team and Enterprise plans.

Why a tax firm should care. 26 U.S.C. §7216(a) covers anyone in the business of preparing returns, or providing services in connection with preparing them. It makes it a misdemeanor for them to knowingly or recklessly disclose information furnished for a return, or to use it for any purpose other than preparing the return. The exception in 26 CFR 301.7216-2(d)(1) lets a preparer share return information with another preparer without the client's consent, including a preparer providing auxiliary services. That exception reaches only a recipient located in the United States.

26 CFR 301.7216-2(d)(1)

Except as limited in paragraph (d)(2) of this section, an officer, employee, or member of a tax return preparer may disclose tax return information of a taxpayer to another tax return preparer (other than an officer, employee, or member of the same tax return preparer) located in the United States (including any territory or possession of the United States) for the purpose of preparing or assisting in preparing a tax return, or obtaining or providing auxiliary services in connection with the preparation of any tax return, so long as the services provided are not substantive determinations or advice affecting the tax liability reported by taxpayers.

26 CFR 301.7216-2(d)(1), first sentence

The same paragraph closes by requiring the client's consent before return information goes to another preparer for substantive determinations. That is one reason Claremont's agents report what does not match and leave the judgment to the professional.

Located means where the people are. The regulation's own example treats a contractor's employee abroad who only views return information held on a U.S. server as a disclosure outside the United States. So what counts is where the people who receive or view the information are, not where the provider is headquartered.

Microsoft commits to store Microsoft 365 Copilot prompts and responses at rest in the United States for U.S. tenants. Its data protection terms let it process data in the United States or any other country where Microsoft or its subprocessors operate. U.S.-only processing for Copilot is expected by the end of 2026, not committed.

Until Microsoft commits to U.S.-only processing, and your firm can show who reaches the data, Claremont's position is this. Client tax return information goes into Microsoft 365 Copilot only with each client's consent under 26 CFR 301.7216-3. For Form 1040 clients that consent follows Rev. Proc. 2013-14, and the Social Security number stays out even with consent. Whether a particular disclosure needs consent is a conclusion for your firm's counsel.

One point is still open. Whether automated processing on a server abroad, with no person viewing it, is a disclosure has not been decided. Claremont does not build on the argument that it is not. For everyone who handles return data, the settings step is the same either way: keep them on the models Microsoft runs itself, turn the outside providers off, and record the date.

Patient data is its own case. Microsoft's page on Anthropic models in Copilot says nothing about HIPAA. Anthropic offers a business associate agreement (BAA) on its HIPAA-ready Enterprise plan. The agreement covers chat. Anthropic also says its own Cowork product "isn't an Eligible Service under the BAA in any configuration." Anthropic's page does not address Microsoft's Copilot Cowork. A practice should keep patient information out of both until coverage is confirmed in writing.

05

When Claude on its own fits

+

Governed Copilot is not the answer for every firm.

The firm does not run on Microsoft 365. Copilot's advantages come from working where your files already are. A firm on another platform starts from a different place.

A team works without client data. Marketing, recruiting or firm administration may want Anthropic's newest features as they ship. That can be a sound choice, if it comes with a written policy, its own record, and no way into client files.

Many firms land in between: Copilot for everyone, with Claude inside Copilot allowed for a named group that never handles return data. The same five questions apply to every option. What can it read? Which models run? Where is the data processed? Under which contract? Where is the record of what the AI did?

Sources

§Sources16 sources · Microsoft 9 · Anthropic 5 · statute and regulation 2+

Claremont Security sets up governed Microsoft Copilot for regulated firms: the permission review, the model settings, and the dated record. To see where a prompt goes before and after, try the AI Exposure Check. It is free and needs no account: claremontsecurity.com/ai-exposure