Skip to content
Cirran

By Michał Puchała · 2026-09-08 · 9 min read

Copilot Can Now Leave the EU Data Boundary at Peak Load. What 'Data Stays in Europe' Actually Covers

Since April, Microsoft 365 Copilot can process prompts in the US, Canada or Australia when European capacity runs short. The setting is on by default for new tenants. What this shows about 'data stays in Europe' promises, and the questions to ask any cloud vendor before you rely on one.

For three years, Microsoft's EU Data Boundary has been the standard answer to a standard question: does our Microsoft 365 data stay in Europe? In April 2026 the answer acquired a footnote. A new feature called flex routing lets Copilot send prompts, responses and the documents behind them to data centres in the United States, Canada or Australia whenever European capacity is under strain. For many tenants, it arrived switched on.

This article explains what flex routing does, why the difference between storing data in Europe and processing it in Europe matters, and why the way Microsoft rolled it out is the most instructive part of the story. It closes with the questions we suggest asking any vendor whose sovereignty claim you are about to rely on, and the steps to take in your own tenant this week.

What Microsoft changed in April

Flex routing is documented plainly on Microsoft Learn. It "lets customers in the European Union and the European Free Trade Association allow large language model inferencing to occur outside the EU Data Boundary during periods of peak demand". Inferencing is the step where the AI model reads your prompt and produces an answer. When flex routing is allowed, that step "may occur in the United States, Canada, or Australia".

Microsoft's EU Data Boundary documentation lists flex routing among the optional capabilities that move data out of the boundary, and it is specific about what travels: Copilot prompts, responses and grounding data. Grounding data is the material Copilot pulls in to answer a question, which in practice means the emails, files and chat messages the user has access to. Data at rest stays in Europe, with an exception for "limited pseudonymized data" kept outside the boundary for security and operations.

The rollout came with two Message Center notices published on 3 April, a fortnight before the 17 April activation date. As Office 365 for IT Pros documented, notice MC1269223 said flex routing would be enabled by default for existing EU and EFTA tenants, while a second notice, MC1269219, told a different set of tenants it would be off by default. Microsoft later confirmed to the Dutch outlet Tweakers, as ITdaily reported on 13 April, that large enterprise, education and public-sector tenants would get the opt-in version. Everyone else got opt-out.

The Microsoft Learn page settles one thing without ambiguity. Any eligible tenant created after 25 March 2026 has flex routing on by default. Tenants that existed before that date are told to check the Message Center to find out which default they received.

Storing and processing are different promises

The EU Data Boundary was designed as a commitment about storage and processing together. Microsoft's own definition says that for covered services, customer data and pseudonymised personal data are "stored and processed" in data centres in the EU or EFTA. That is the promise most European organisations have in mind when they tell an auditor or a board that their Microsoft data stays in Europe.

Flex routing separates the two halves. Storage stays in Europe, while processing, for the most sensitive step in a generative AI workflow, can leave. Under the GDPR, sending personal data to a third country for processing is a transfer, however brief the processing is and however quickly the data is deleted afterwards. The location where a copy of the data rests at the end of the day is a separate question.

The German privacy consultancy FIRST PRIVACY set out the consequences in a May 2026 analysis. A transfer to the United States relies on the EU-US Data Privacy Framework, while transfers to Canada and Australia rely on standard contractual clauses and, in principle, a transfer impact assessment. Organisations that allow flex routing need to reflect it in their records of processing and in any data protection impact assessment that covers Copilot. Those that assumed their earlier assessment still held may find it no longer describes what the service does.

To be clear, none of this makes flex routing unlawful. The GDPR does not prohibit processing outside the EU; it requires a valid legal basis for the transfer and documentation on the controller's side. The United States is covered by the Data Privacy Framework adequacy decision, which the EU General Court upheld in September 2025, Canada has held an adequacy decision for commercial organisations since 2001, and Australia is covered by the standard contractual clauses in Microsoft's data protection addendum.

Two points keep the question open. First, the General Court ruling is under appeal at the Court of Justice, and if the framework falls, the US leg of flex routing reverts to contractual clauses and a far harder impact assessment, as happened after Schrems II in 2020. Second, Article 25 of the GDPR requires data protection by default, and an on-by-default transfer sits uneasily with it, although that article binds controllers, so the argument does not make Microsoft's feature illegal. An unreviewed default is a gap in your own compliance file.

For a regulated mid-sized company, the practical effect is that a statement made in good faith to an auditor in 2025 may need revisiting. That is a manageable task once you know about it. The difficulty is that many organisations do not.

Why the default matters more than the setting

Microsoft did not hide flex routing. The setting is one click in the admin centre, under Copilot, then Settings, then "Flex routing during peak load periods". Selecting "Do not allow flex routing" keeps all inferencing inside the boundary, and Microsoft states that all existing data residency commitments then continue to apply. As a control, it is adequate.

The default is the problem. A feature that is off until someone turns it on requires a decision, while a feature that is on until someone turns it off requires awareness, and awareness is unevenly distributed. In a 200-person company, the person who holds the AI Administrator role in Microsoft 365 may be an outsourced managed-service partner who receives several hundred Message Center notices a year. The person accountable for the sovereignty commitment to the board is someone else entirely, and probably has no idea the notice existed.

There is a second, quieter lesson in the two notices. Microsoft made a judgement about which customers would object: large enterprises, universities and public bodies were given opt-in, and everyone else was given opt-out. If your company has 50 to 500 employees, you were almost certainly in the second group, whether or not you handle patient records or client financial data. A vendor's assessment of who cares about sovereignty is a commercial one, and it will not always match your regulatory position.

The boundary has a list of exceptions, and it is growing

Flex routing is one entry on a longer list. Microsoft publishes a page of optional capabilities that move data out of the EU Data Boundary, and reading it is a useful exercise for anyone who signs off on a sovereignty statement.

Azure AI Foundry, the platform many companies use to build their own AI features, offers "Global" deployment types. Choose one and your prompts and completions "may be processed in any Azure AI Foundry Models region globally, including outside the EU", even when the resource was created in a European region. An EU-only "data zone" option exists, but it is a choice the engineer makes at deployment time. Microsoft Security Copilot has a data-sharing feature that lets prompts and responses be stored outside the boundary, and it is, in Microsoft's words, "turned on by default".

Multi-factor authentication by phone or push notification can be processed outside Europe because it rides on global telecoms and device-vendor networks. Teams shared channels temporarily store guest email addresses in the United States. None of these is a scandal, and each is documented with a control. Together they describe a boundary that holds by default for the core storage promise and depends on configuration for a widening set of features, with generative AI now the largest of them.

This is the position of every hyperscaler with global infrastructure and a European commitment layered on top. The commercial pressure to use global capacity is real, and flex routing exists because European GPU capacity was short of demand. A European provider whose infrastructure is entirely inside the EU has a simpler story to tell, because there is nowhere else for the processing to go. That is a structural difference worth understanding when you compare options, whichever way you eventually decide.

Three questions to ask any vendor

Sovereignty claims are increasingly common in cloud marketing, and most of them are true in the narrow sense their authors intended. The useful skill is knowing which questions turn a marketing claim into a fact you can defend to an auditor. We suggest three.

First, does the promise cover processing as well as storage, and does it cover every step of the workflow? Ask specifically about AI inference, support access, telemetry and security analytics, because these are where exceptions cluster.

Second, which of these commitments depend on a setting, and who controls it? Ask for the list of tenant-level or subscription-level options that change where data goes, and whether the vendor can change the default without your consent. Microsoft can and did, with two weeks of notice through a channel most executives never read.

Third, what is the vendor's documented list of exceptions? A serious provider publishes one. Read it before signing, and again at every renewal, because the list changes. Microsoft's flex routing page was created in March 2026 and updated in August.

If a vendor cannot answer these questions in writing, the claim belongs in the marketing folder and out of the compliance file.

What to do in your own tenant this week

For a CTO or head of IT with Microsoft 365 Copilot in use, the first step takes ten minutes. Sign in to the admin centre with the AI Administrator role, open Copilot settings, check the flex routing status, and record what you find and the date. If your tenant was created after 25 March, expect it to be on. If you use Copilot in Dynamics 365 or Power Platform, check the Power Platform admin centre as well, since it inherits the Microsoft 365 setting unless set more strictly.

Then decide deliberately. Some organisations will accept flex routing because the trade-off between response times and processing location is one they are comfortable with, and the transfer mechanisms Microsoft relies on are lawful today. Others, particularly in healthcare and financial services, will switch it off and note the decision. Either answer is defensible, and an undocumented default is not.

Finally, bring the finding to whoever owns the sovereignty commitment on the business side. The most useful outcome of the flex routing episode is a shared understanding between the technical and executive sides of a company that "our data stays in Europe" is a statement about configuration, and configuration needs an owner. Cirran works with European companies on exactly this kind of question, as a partner that maps where data actually goes before anyone decides whether it should move.

Thinking about migration? Book a free consultation to discuss your situation.

See the European equivalent for your stack. Compare AWS, Azure, and GCP services side by side with OVHcloud, Scaleway, STACKIT, IONOS, and Hetzner.

Open the service mapping

Thinking about migration?

Book a free consultation to discuss your situation.

Copilot Can Now Leave the EU Data Boundary at Peak Load. What 'Data Stays in Europe' Actually Covers | Cirran