Sovereign AI

Microsoft Copilot Flex Routing: What It Means for the EU Data Boundary and How to Turn It Off

Flex routing lets Microsoft process EU and EFTA Copilot prompts outside the EU Data Boundary when demand peaks. What Microsoft's documentation says about the default, the admin setting that turns it off, and how it relates to the EU Data Boundary, Advanced Data Residency and Multi-Geo.

Copilot flex routing is a Microsoft 365 setting that lets large language model inferencing for EU and EFTA tenants run outside the EU Data Boundary, in the United States, Canada or Australia, during periods of peak demand. Microsoft documents it as on by default for eligible tenants created after 25 March 2026. Admins can turn it off in the Microsoft 365 admin center, keeping inferencing inside the boundary.

What Copilot flex routing is

Microsoft’s documentation on flex routing, last updated on 29 September 2026, describes it as a way for EU and EFTA customers to allow inferencing outside the EU Data Boundary when demand peaks, so the Copilot experience stays consistent. Inferencing is the step in which the model executes a prompt and produces the answer, such as a summary of a thread or a draft reply. Microsoft announced it to EU and EFTA tenants through the Microsoft 365 message center in April 2026, as Office 365 IT Pros reported at the time.

What moves, and what stays, when a tenant allows it:

  • Processed abroad at peak. Microsoft’s list of ongoing EU Data Boundary transfers says Copilot prompts, responses and grounding data may be processed outside the boundary for inferencing, including in the United States, Canada and Australia. Grounding data is the email, chat and file content Copilot retrieves to answer a prompt.
  • Stored abroad. Pseudonymous user IDs may be stored in those locations for security and operational purposes.
  • Stays in the boundary. Microsoft says data at rest remains inside the EU Data Boundary apart from that limited pseudonymised data, and that everything is encrypted in transit and at rest.

Two settings cover the product range. The one in the Microsoft 365 admin center applies to Microsoft Copilot and Copilot Chat. The one in the Power Platform admin center applies to the Copilot experiences in Dynamics 365, Power Platform and Copilot Studio. Microsoft has also renamed Microsoft 365 Copilot to Microsoft Copilot, so licences and admin screens may still show either name for a while.

Is flex routing on by default?

It depends on when the tenant was created. Microsoft Learn says, as of October 2026:

TenantWhat Microsoft’s documentation says
Eligible tenant created after 25 March 2026Flex routing is on by default
Eligible tenant that existed on or before 25 March 2026Administrators are encouraged to check the setting

For the older tenants, the message center was not consistent. Office 365 IT Pros reported on 7 April 2026 that post MC1269223 announced flex routing for EU and EFTA tenants from 17 April 2026, on by default for everyone not already covered by the new-tenant rule. Readers of that article then reported a second post, MC1269219, which told some tenants the setting was off by default. Given that history, nobody should assume the current state. Open the admin center and look.

Only tenants in scope for the EU Data Boundary see the setting. For Microsoft 365 that means a sign-up location in an EU or EFTA country. Tenants that have bought or used Multi-Geo are outside the EU Data Boundary even with an EU sign-up country, and the flex routing setting does not appear in their Microsoft 365 admin center.

How to turn off flex routing

Microsoft documents the steps as follows:

  1. Sign in to the Microsoft 365 admin center as an administrator with the AI Administrator role.
  2. Go to Copilot > Settings > View all > Flex routing during peak load periods.
  3. Select Do not allow flex routing. Inferencing then stays inside the EU Data Boundary even at peak demand, and Microsoft’s data processing and residency commitments for Microsoft 365 continue to apply.
  4. Check the Power Platform admin center. Its setting follows the Microsoft 365 choice unless its own value is more restrictive. When flex routing is not allowed in Microsoft 365, it is off in Power Platform and cannot be switched on there.
  5. Record the decision: who changed the setting, when, and why, in your record of processing activities or the DPIA for Copilot. An auditor should be able to see that someone chose the inference location deliberately.

The opposite option, Allow flex routing during periods of peak load, also permits the associated pseudonymised data to be stored outside the boundary. Microsoft notes that peak periods are typically limited in duration and do not run continuously.

EU Data Boundary, ADR and Multi-Geo: what each one covers

Four Microsoft mechanisms get mixed up in residency discussions. They answer different questions.

MechanismWhat it governsDoes it fix where inference runs?
EU Data BoundaryMicrosoft’s commitment to store and process Customer Data and personal data for its enterprise online services in the EU and EFTA, with documented exceptions. For EU customers, Copilot is an EU Data Boundary serviceYes, subject to flex routing and the other exceptions
Flex routingA tenant setting that allows an exception for model inferencing at peak demandIt is the switch for that exception
Advanced Data Residency (ADR)An add-on that commits data at rest to a local country region. For Copilot that means the content of interactions and the related semantic index. It requires ADR licences for every eligible paid seatNo, it is a data-at-rest commitment
Multi-GeoStores each user’s Copilot content of interactions at rest in that user’s preferred data locationNo, and Multi-Geo tenants fall outside the EU Data Boundary

Microsoft’s privacy documentation adds the history: Copilot became a covered workload in the data residency commitments of the Product Terms on 1 March 2024, and ADR and Multi-Geo have included Copilot since the same date. The same page says Copilot calls to the model go to the closest data centres in the region but can reach other regions with spare capacity during high utilisation, with EU traffic kept inside the boundary. Read that line together with the flex routing page, which carves out the exception for tenants that allow it.

The short version: ADR and Multi-Geo decide where Copilot content is stored, while the EU Data Boundary and the flex routing setting decide where it is processed. A tenant that needs both has to manage both.

Other Copilot paths that leave the EU Data Boundary

Flex routing is not the only route out of the boundary:

  • Anthropic models. Microsoft states that Anthropic models in Copilot, Researcher, Copilot Studio, Power Platform and Copilot in Microsoft 365 apps are currently excluded from the EU Data Boundary and, where applicable, in-country processing commitments. They are off by default for customers in the EU Data Boundary and the UK, and admins can opt in for named users or groups. Models labelled “Anthropic models with Data Retention” go further: Anthropic, not Microsoft, stores most inputs and outputs for up to 30 days, outside Microsoft’s product terms and data protection addendum, and these models stay off until an admin explicitly enables them.
  • Web search. When Copilot grounds an answer on the web, it sends a generated query to Bing with user and tenant identifiers removed. Microsoft says its data protection addendum and the EU Data Boundary do not apply to those queries, and that it acts as a data controller for them. Admins control web search with the Allow web search in Copilot policy in the Cloud Policy service.
  • Agents and connectors. Third-party agents carry their own privacy statements and terms of use, which Microsoft tells admins to review in the Integrated apps section of the admin center before allowing them.

Settings like these are one layer of the Copilot governance gap: they decide where data goes, while which workflows and agents should exist at all remains a separate decision.

What flex routing means for GDPR and residency mandates

Under the GDPR, inferencing in the United States, Canada or Australia is processing outside the EEA, so Article 44 requires it to rest on a Chapter V transfer mechanism under your agreement with Microsoft. Microsoft keeps the data encrypted and stores it at rest inside the boundary, but the prompts and the grounding content behind them are still processed abroad during those periods. Whether that is acceptable is a decision for you as controller. Write it into the DPIA and the record of processing, and make sure your data protection officer has seen it.

The episode also shows what residency controls can and cannot do. Copilot processes data in Microsoft’s cloud. Residency settings change which Microsoft region does the processing; they do not keep the data inside your own infrastructure, and a default or a tenant setting can change the region. For many organisations that trade-off is acceptable under contract. For an organisation whose policy says certain data never leaves its own systems, no region setting meets the requirement, which is the distinction between data sovereignty and data residency. Our GDPR checklist for AI tools applies the same questions to other vendors.

Options for EU organisations with a strict residency mandate

  1. Turn off flex routing in the Microsoft 365 admin center, then confirm that the Power Platform admin center follows it.
  2. Keep Anthropic models off, or limit them to groups whose work is cleared for processing outside the boundary.
  3. Decide on web search. Disable it with the Cloud Policy setting, or allow it only for groups whose prompts and open documents will not feed personal or confidential terms into the generated queries.
  4. Add a data-at-rest commitment where eligible. ADR commits stored Copilot content to a local country region if the tenant’s default geography is on Microsoft’s list and ADR licences cover every eligible paid seat. It does not change where inference runs.
  5. Protect the most sensitive files at the source. Copilot honours the usage rights that Microsoft Purview encryption grants each user, so encrypting sensitivity labels limit what it can work with.
  6. Move the most sensitive workloads onto infrastructure you control. For data that may not leave your environment at all, run models on-premises or in your own private cloud, so the inference location is a property of your network rather than a vendor setting. The on-prem Copilot replacement playbook maps that path, the Copilot replacement readiness check helps decide which workloads should move, and VDF AI and Copilot Studio compared covers the agent side.

How VDF AI fits

VDF AI runs assistants and agents on-premises, in your private cloud or air-gapped. In those deployments, inference, embeddings, private retrieval, logs and orchestration stay in your environment, and production use needs no third-party model API sub-processor. Egress can be disabled entirely. The model router enforces model policy by domain, sensitivity level and residency requirement, so your policy decides which model serves a sensitive workload, however busy anyone else’s data centre gets.

It can run alongside Microsoft 365 rather than replace it: Copilot for general productivity, VDF AI for the workloads whose data may not leave. The Microsoft integration can reach the OneDrive, SharePoint and Outlook content a user’s account already has access to. On-premises, staff sign in through native Microsoft Entra ID single sign-on, with Entra security groups mapped to VDF AI roles, and role-based access control decides who can use which agents and tools.

Sources

Frequently asked questions

What is Copilot flex routing?

Flex routing is a tenant setting for Microsoft customers in the EU and EFTA. When it is allowed, Microsoft can run the large language model inferencing behind Microsoft Copilot, Copilot Chat and the Copilot experiences in Dynamics 365, Power Platform and Copilot Studio outside the EU Data Boundary during peak demand, in the United States, Canada or Australia. Prompts, responses and grounding data are processed there. Data at rest stays inside the boundary, apart from pseudonymous user IDs that Microsoft may keep there for security and operations.

Is Copilot flex routing on by default?

Microsoft's documentation says it is on by default for eligible tenants created after 25 March 2026, and asks administrators of tenants that existed on or before that date to check their setting. The message center posts that reached older tenants in April 2026 did not agree with each other: one announced the setting as on by default from 17 April, while readers reported a second post describing it as off. The only safe assumption is to open the admin center and look.

How do I turn off flex routing in Microsoft 365?

Sign in to the Microsoft 365 admin center with the AI Administrator role, go to Copilot, then Settings, View all, and Flex routing during peak load periods, and select Do not allow flex routing. Inferencing then stays inside the EU Data Boundary even at peak demand. The Power Platform admin center follows that choice unless its own setting is stricter, so Copilot Studio, Power Platform and Dynamics 365 inherit it. Record who made the change and when.

Does Advanced Data Residency stop flex routing?

No. Advanced Data Residency is a commitment about where data is stored at rest, such as the content of Copilot interactions and the semantic index, in a local country region. Flex routing concerns where inferencing happens, so an EU tenant with Advanced Data Residency still needs to check the flex routing setting. Multi-Geo is a separate case: Microsoft says tenants that bought or used it are not in scope for the EU Data Boundary and do not see the flex routing setting at all.

Does Copilot web search stay inside the EU Data Boundary?

No. When web search is on, Copilot sends a short generated query to Bing, with user and tenant identifiers removed. Microsoft says its data protection addendum and the EU Data Boundary do not apply to those queries and that it acts as a data controller for them. The query can draw on a document the user has open or names in the prompt. Admins can switch web search off, or limit it, with the Allow web search in Copilot policy in the Cloud Policy service.

Does flex routing break GDPR compliance?

Not automatically. Microsoft keeps the data encrypted and keeps data at rest inside the EU Data Boundary, and processing outside the EEA can rest on a valid transfer mechanism. It does change the facts your DPIA and record of processing describe, because prompts and grounding data may be processed in three countries outside the EU. If your own policy, a client contract or a sector rule requires processing inside the EU, turn the setting off and document that decision.

Filed under
Microsoft Copilotdata residencydata sovereigntyGDPRsovereign AIAI governance
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading