What is Microsoft 365 Copilot? Pricing, EU Data Residency, and Best Alternatives in 2026
Microsoft 365 Copilot is Microsoft's AI assistant inside Word, Excel, PowerPoint, Outlook and Teams, grounded in your own tenant content through Microsoft Graph. It lists at USD 30.00 per user per month, paid yearly (EUR 26.00 on the EU-served page), and Microsoft states that "A separate license for a qualifying Microsoft 365 plan is required."
The fact most published Copilot content has not caught up with: since 25 March 2026, EU customers' Copilot prompts, responses and grounding data may be processed in the United States, Canada or Australia by default. Microsoft calls it flex routing and documents it in its own EU Data Boundary exception register. An EU or EFTA admin can switch it off.
Last updated: 2026-09-06. Every price and quote on this page was read from the vendor's own page on 2026-09-06.
Quick Decision Guide
Microsoft 365 Copilot is the right choice for organisations already standardised on Microsoft 365 that want an assistant inside the apps their people already have open, and that have the administrative capacity to run a permissions review before switching it on. It is the wrong choice when you need a phone channel, when small EU languages matter, or when EU inferencing has to be a contractual guarantee rather than a tenant setting.
| If you need... | Copilot fits | Better alternative |
|---|---|---|
| AI inside Word, Excel, Outlook, Teams and SharePoint | Yes | - |
| Answers grounded in your own tenant content via Microsoft Graph | Yes | - |
| A published, checkable list price | Yes | - |
| EU inferencing without an admin changing a setting | No, since 25 March 2026 | Ainora |
| A published default retention period for AI interactions | No, none is published | - |
| Voice or phone-channel AI for inbound or outbound calls | No | Ainora |
| Small EU languages handled natively | Partial | Ainora |
| Live in days, without a tenant-wide permissions review first | No | Ainora |
| Knowledge search across many non-Microsoft SaaS tools | Partial | Glean |
How Microsoft 365 Copilot Rates
A five-axis scorecard, the same format used across our provider pages. Every rating below is defended in the sections that follow, with the vendor's own words.
| Axis | Rating | Notes |
|---|---|---|
| Features and breadth | Strong | Native across the whole Microsoft 365 estate. Nothing else in this field is embedded in the apps people already have open all day. |
| Pricing transparency | Strong | USD 30.00 per user per month paid yearly is published on the enterprise page, EUR 26.00 on the EU page, USD 21.00 for Copilot Business. Two of the nine vendors we reviewed publish no price at all. |
| Ease of setup | Mixed | The licence is immediate. The permission hygiene is not. Microsoft has shipped two successive controls to stop Copilot surfacing over-shared content, and calls both temporary. |
| Integration depth | Strong | Microsoft Graph reaches the whole tenant. That is the strength and, per Microsoft’s own admin documentation, also the risk. |
| EU compliance and data residency | Mixed | EU Data Boundary scope follows the tenant sign-up country, but flex routing sends inferencing to the US, Canada or Australia by default for eligible tenants created after 25 March 2026 unless an admin disables it. |
What is Microsoft 365 Copilot?
Microsoft 365 Copilot is an AI assistant that runs inside the Microsoft 365 applications and grounds its answers in the customer's own tenant data through Microsoft Graph: mail, files, chats, meetings, SharePoint sites. It is not a separate destination you visit. It is a pane inside the tools your team already uses, which is the single biggest reason it wins adoption battles against standalone assistants.
It is sold as an add-on, not as a standalone product. Microsoft's enterprise page states, verbatim, "A separate license for a qualifying Microsoft 365 plan is required." That sentence is the one buyers most often miss when they build a business case from the headline seat price.
There are now two commercial SKUs. The enterprise SKU has been generally available since 2023. Microsoft 365 Copilot Business, aimed at smaller organisations, reached general availability on 2 December 2025, with Microsoft's announcement stating "For just USD21 per user per month". From 1 July 2026 Microsoft additionally began selling bundled base-plus-Copilot SKUs, announced on 28 May 2026 as "new Microsoft 365 SKUs with Copilot built-in".
On training, Microsoft's position is unambiguous and, unusually in this field, requires no opt-out. From the Copilot privacy document: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." Optional customer feedback may be used to improve the product, and Microsoft states that feedback is not used to train the foundation models either.
Does Microsoft 365 Copilot keep EU data in the EU?
No, not by default, and this changed recently enough that most published content about Copilot and the EU Data Boundary is now wrong. The headline commitment is still on the privacy document: "EU traffic stays within the EU Data Boundary while worldwide traffic can be sent to the EU and other countries or regions for LLM processing." The exception is in a different document, and it is the one that governs.
"To help maintain a consistent Copilot experience during periods of peak demand, Copilot prompts, responses, and grounding data may be processed outside the EU Data Boundary for AI inferencing, including in the United States, Canada, and Australia. Pseudonymous user IDs may be stored in those locations for security and operational purposes. This applies to tenants that allow flex routing as described in Flex routing (EU and EFTA)."
The default is stated on the flex routing page itself: "Flex routing is on by default for eligible tenants that were created after March 25, 2026." For older tenants Microsoft directs administrators to the Message Center for their tenant's setting. Same page: "If flex routing is enabled, LLM inferencing may occur in the United States, Canada, or Australia during times of peak demand."
The remedy is real and it is a single admin action. Microsoft: "EU and EFTA customers can disable flex routing in the Microsoft 365 admin center at any time", and "If you select this option, LLM inferencing will occur inside the EU Data Boundary, even during periods of peak demand." If EU inferencing matters to your organisation, that is the setting to check this week, and it is worth putting the check date in your records.
Two further carve-outs buyers should know about
Anthropic models. Microsoft documents that "Anthropic models deployed in Microsoft offerings such as Microsoft Copilot, Researcher, Copilot Studio, Power Platform, and Copilot in Microsoft 365 apps are currently excluded from the EU Data Boundary, and when applicable, in-country processing commitments." The second half of that same passage is the half most write-ups omit, and omitting it overstates the risk: "Customers within the EU Data Boundary and customers in the UK have Anthropic models disabled by default." Microsoft also warns that if an administrator enables the data-retaining variant, "data is stored by Anthropic and not subject to your Microsoft Customer Agreement including commitments in the Product Terms and DPA".
Multi-Geo. If your organisation bought Multi-Geo Capabilities, the boundary does not apply to you at all: "Customers who have purchased Multi-Geo Capabilities are not in scope for the EU Data Boundary even if their tenant is listed as being in a country or region in the EU or EFTA." Scope otherwise follows the tenant's sign-up country rather than the licence tier.
The wider field finding is worth stating plainly, because it is the context that makes Microsoft's position ordinary rather than exceptional. Across the nine internal-assistant vendors we checked on 2026-09-06, not one promises that AI inference happens inside the customer's chosen EU region. Microsoft is simply the one that documents its exception in the most detail, in a register anyone can read.
How long does Microsoft keep Copilot prompts and responses?
Microsoft publishes no default retention period for Copilot interaction data. That is a finding, not a shrug, and it is worth more to a buyer than a number would be, because it tells you exactly where the responsibility sits: retention exists once an administrator configures a Microsoft Purview policy, and not before.
| Circulating claim | What Microsoft actually publishes | Verdict |
|---|---|---|
| "Copilot data is retained indefinitely by default" | No default retention period appears on the Copilot privacy document or on the Purview retention, governance and audit pages. The only "forever" match describes an administrator-chosen option. | Unsupported. We do not publish it. |
| "Only the administrator controls retention" | "Admins can also use Microsoft Purview to set retention policies for the data related to chat interactions with Copilot." And: "Your users can delete their Copilot activity history ... by going to the My Account portal." | Wrong. Control is shared. |
| "Only the user controls their Copilot history" | The same two sentences, read the other way round. | Also wrong. Control is shared. |
| "Copilot audit logs are kept for 180 days" | The 180-day figure on the Purview audit page is written against non-Microsoft AI applications, in both places it appears. | Do not transfer it onto Copilot. |
Our method, so you can repeat it. On 2026-09-06 we opened the Copilot privacy document, Learn about retention for Copilot and AI apps, the Purview Copilot governance page and the Copilot audit page, and searched for: default, by default, indefinite, indefinitely, forever, without a retention policy, no policy, not configured, isn't configured, not retained, retention. No default period appears on any of them.
A user deletion is not proof of deletion
This is the operational detail that catches compliance teams out. Microsoft's Purview retention documentation states that "Data from generative AI messages is stored in a hidden folder in the mailbox of the user who runs the AI app", that "The timer job typically takes 1-7 days to run", and, most importantly:
"Messages visible in your AI apps are not an accurate reflection of whether they are retained or permanently deleted for compliance requirements."
If a data subject asks you to delete their Copilot interactions, the fact that the interface no longer shows them is not, on Microsoft's own account, an answer.
Can Copilot surface files employees were never meant to see?
Yes, and the strongest source for it is Microsoft's own administrator documentation. This is the material a buyer should read before a rollout, and it is the reason a Copilot deployment is a permissions project before it is an AI project.
The failure mode is structural rather than a vendor defect. An assistant grounded in your tenant guarantees you can see what you could already technically access. It does not guarantee you only see what you were meant to find. Before an assistant existed, an over-permissive site was protected by obscurity. Retrieval removes the obscurity and leaves the permission exactly as it was. Microsoft writes this out as a worked example:
"Most people don't know about this site, so the site owner hasn't set up proper permissions and hasn't followed correct data governance process. The site might be open to some users who aren't allowed to see it, such as Alex. When Alex asks Copilot for some budgeting information, Copilot gets information from the budgeting site."
Microsoft has now shipped two successive controls whose stated purpose is to stop Copilot surfacing content people can technically reach but were not meant to find, and it describes both as temporary.
Restricted SharePoint Search. Microsoft calls it "a short-term solution that gives your organization's administrators time to review and audit site and file permissions. It's not intended or scalable for long-term use." It caps at 100 sites, which Microsoft itself flags: "Restricted SharePoint Search limits to 100 sites, which isn't sustainable as your organization scales Copilot and agentic operations." It is also explicit about what the control is not: "it's important to note that Restricted SharePoint Search isn't a security boundary and doesn't change any permissions on SharePoint sites", and "Neither Copilot nor Restricted SharePoint Search prevents users from accessing content they own or previously accessed." The page now carries a retirement banner: "Restricted SharePoint Search is retiring. Starting July 31, 2026, new enablement is blocked."
Restricted Content Discovery. The replacement, and Microsoft describes it in the same terms: "a temporary governance control that gives organizations time to review and right-size access while continuing their Copilot deployment". It has a licence gate, "Customers who are licensed for Copilot and have SharePoint Advanced Management available to them can configure Restricted Content Discovery", and a warning that using it works against the thing you bought: "Excessive use can reduce the amount of content available to organization-wide search and Microsoft Copilot experiences, which can affect the completeness and relevance of search results and AI-generated responses."
Read together, those two pages are the most useful thing Microsoft publishes for a prospective Copilot buyer. The honest summary: the assistant is as well-governed as your SharePoint permissions were on the day you switched it on, and the tools Microsoft offers to buy you time are, by its own description, temporary and lossy.
Has Microsoft 365 Copilot had a disclosed vulnerability?
Yes, one, and Microsoft disclosed it against its own hosted service. Microsoft assigned itself a CVSS 9.3 information-disclosure CVE against Microsoft 365 Copilot in June 2025 for an AI command-injection flaw requiring no user interaction, and states it was fully mitigated and not exploited.
The record is CVE-2025-32711, published 2025-06-11, described at the National Vulnerability Database as "Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network." The 9.3 CVSS v3.1 score comes from Microsoft's own source record, with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N. NVD's own analyst score for the same CVE is 7.5. The UI:N and PR:N components mean no user interaction and no privileges were required.
The part that has to be said in the same breath. Microsoft's advisory metadata for the June 2025 release records Publicly Disclosed:No and Exploited:No, and the advisory text reads: "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency." This is a disclosed and patched vulnerability class, not a confirmed real-world breach, and no source we could verify shows customer data was leaked. Pages that imply otherwise are making a claim their sources do not support.
Microsoft 365 Copilot Pricing
Microsoft publishes its prices, which puts it ahead of several vendors in this field. Every figure below was read from a Microsoft page on 2026-09-06, with the currency and the page it came from named.
| SKU | Published price | Source page, fetched 2026-09-06 |
|---|---|---|
| Microsoft 365 Copilot (enterprise) | USD 30.00 user/month paid yearly, or USD 31.50 paid monthly on an annual commitment | microsoft.com/en-us/microsoft-365-copilot/enterprise |
| Microsoft 365 Copilot (enterprise), EU-served page | EUR 26.00 user/month paid yearly, or EUR 27.30 paid monthly. "Price does not include VAT." | microsoft.com/en-ie/microsoft-365-copilot/enterprise |
| Microsoft 365 Copilot Business | USD 21.00 user/month paid yearly. GA 2 December 2025. | microsoft.com/en-us/microsoft-365-copilot/business |
| Microsoft 365 Business Standard with Copilot | USD 23.50 user/month paid yearly | microsoft.com/en-us/microsoft-365-copilot/business |
| Microsoft 365 Business Premium with Copilot | USD 32.00 user/month paid yearly | microsoft.com/en-us/microsoft-365-copilot/business |
| Microsoft 365 Business Standard with Copilot, EEA (no Teams) | EUR 17.58 user/month paid yearly | microsoft.com/en-us/microsoft-365-copilot/business |
| Ainora | Individual pricing | ainora.lt/contact |
Two things to hold on to when you build the business case. First, the add-on is genuinely an add-on: "A separate license for a qualifying Microsoft 365 plan is required", so the Copilot seat price is on top of whatever you already pay per user for Microsoft 365. Second, Microsoft 365 Copilot Business is currently displaying a promotional price on its page that expires on 31 December 2026. We quote the list price of USD 21.00 rather than the promotional figure, because a promotional figure in a comparison table stops being true in a few months and then reads as a fabricated discount.
For context on how unusual published pricing is in this field: of the nine internal-assistant vendors we checked on 2026-09-06, two publish no price at all. Glean has published none since January 2023, which we verified from a live 301 redirect on its pricing URL, the absence of any pricing URL in its sitemap, and a Wayback capture history that stops in that month.
Microsoft 365 Copilot and Ainora, side by side
An honest comparison is more useful than a flattering one, so this table shows where Microsoft is straightforwardly ahead of us. Certifications are the clearest case: Microsoft holds them, we do not, and we will not imply otherwise by leaving a cell ambiguous.
| Dimension | Microsoft 365 Copilot | Ainora |
|---|---|---|
| SOC 2 | Yes, Microsoft holds it | No. Ainora holds no SOC 2 report of any type. |
| ISO 27001 | Yes, named in the Copilot privacy document | No. Ainora holds no ISO certification. |
| ISO 42001 (AI management systems) | Yes, named in the same sentence | No. Ainora holds no ISO certification. |
| Published list price | Yes, USD 30.00 user/month paid yearly | Individual pricing |
| EU inferencing | Flex routing to the US, Canada or Australia is on by default for eligible tenants created after 25 March 2026; an admin can disable it | EU-native by design |
| Phone and voice channel | No | Yes, inbound and outbound calls |
| Small EU languages | Partial | Multilingual, including small EU languages |
| Time to live | Licence is immediate; the permissions review is the real timeline | Days |
| Published uptime figure | Not assessed in this review | 99.9% |
Microsoft's certification claim is Copilot-scoped and verbatim: "Microsoft Copilot provides broad compliance offerings and certifications, including GDPR, ISO 27001, HIPAA, and the ISO 42001 standard for AI management systems."
Microsoft 365 Copilot Pros and Cons
Pros
- Embedded where work already happens. No new destination for employees to remember.
- Published, checkable pricing in both USD and EUR, which two of nine vendors in this field do not offer.
- Training is off with no opt-out required: prompts, responses and Graph data are not used to train the foundation models.
- Strong, Copilot-scoped compliance position including ISO 27001 and ISO 42001.
- Unusually candid administrator documentation. Microsoft writes down its own oversharing failure mode and its own CVE.
- Shared retention control: administrators set Purview policy, users can delete their own activity history.
Cons
- Since 25 March 2026, EU inferencing is a tenant setting rather than a default. Flex routing is on by default for eligible tenants created after that date.
- No published default retention period for Copilot interaction data. Retention begins when an admin writes a Purview policy.
- Deletion is not observable from the interface: Microsoft states that what you see in the AI app is not an accurate reflection of what is retained.
- Rollout is a permissions project. Both mitigations Microsoft offers are described by Microsoft as temporary, and the newer one is licence-gated and degrades answer quality when overused.
- The seat price sits on top of a qualifying Microsoft 365 licence.
- No phone or voice channel, and the value is concentrated inside the Microsoft estate.
Verdict: Who Should Use Microsoft 365 Copilot?
If your organisation lives in Microsoft 365, Copilot is the default answer and the burden of proof is on anything else. Nothing else in this field is inside Outlook and Teams the way it is. Buy it with two eyes open: send an administrator to the Microsoft 365 admin center to check the flex routing setting before you decide anything about EU data flows, and treat the rollout as a SharePoint permissions review with an AI deadline attached, because that is what Microsoft's own documentation says it is. Copilot is the wrong tool if the job is a phone call, if your customers speak a small EU language, or if your compliance position needs EU inferencing to be a commitment rather than a checkbox. In those cases look at an EU-native, multi-channel alternative such as Ainora.
Best Microsoft 365 Copilot Alternatives in 2026
1. Ainora
"Copilot answers inside your documents. Ainora answers the phone, in your customer's language, and then does the work in your systems."
Ainora is a multi-channel AI teammate built EU-native by design. The structural differences from Copilot are three: a phone and voice channel, which Copilot does not have at all; multilingual coverage including small EU languages that platforms built for the largest markets do not reach; and a deployment measured in days rather than in the quarters a tenant-wide permissions review takes. Uptime is 99.9%.
Where we are behind, we will say so on the same page. Microsoft holds SOC 2, ISO 27001 and ISO 42001. Ainora holds none of those, and no certification of any kind. If a certificate is a hard procurement gate for you, that is a real reason to choose Microsoft, and we would rather you learned it here than three weeks into an evaluation.
Ainora pricing is individual. You can hear the product running in production before you talk to anyone: +1 (218) 636-0234 (English) and +370 5 200 2620 (Lithuanian).
2. Gemini for Google Workspace
The direct structural equivalent on the other stack. Google stopped selling it as an add-on and bundled it into the paid Workspace tiers on 15 January 2025, so it arrives with the seat rather than beside it. It is the only vendor in the nine we checked with a documented processing-region control, and that control is gated to Enterprise Plus. Right answer if your organisation is on Workspace rather than Microsoft 365.
3. Glean
The specialist for search across many non-Microsoft SaaS tools, with permission-aware retrieval across a large connector library. Two caveats worth pricing in: it has published no price since January 2023, and its own documentation frames the guarantee the same way Microsoft does, as what you could already access rather than what you were meant to see.
4. Notion AI
Cheaper and lighter, and the most candid vendor in the field on the residency question. EU data residency is Enterprise-only and sales-gated, and Notion states in its own help page that processing outside the data region can include "Customer Data processed by Notion subprocessors, including LLM providers". Business lists at EUR 19.50 per member per month on the EU-served pricing page, fetched 2026-09-06.
5. Slack AI
If the knowledge that matters lives in conversations rather than documents. Slack retired the separate AI add-on on 17 August 2025 and folded the features into the paid plans. Slack holds ISO 42001 with downloadable certificates. Its data-residency documentation lists the categories it covers, and AI is not among them.
6. Atlassian Rovo
The right shape if your operating system is Jira and Confluence. Bundled from 9 April 2025 and metered in credits with overage enabled by default. Its own documentation states that Rovo indexes the entire workspace of a connected third-party app and lets you narrow it with a blocklist afterwards, which is the inverse of least privilege and worth understanding before connecting a large Drive or SharePoint.
Frequently Asked Questions
Microsoft 365 Copilot is Microsoft’s AI assistant embedded in Word, Excel, PowerPoint, Outlook and Teams, grounded in the tenant’s own content through Microsoft Graph. It is sold as an add-on: Microsoft states that "A separate license for a qualifying Microsoft 365 plan is required." A smaller SKU, Microsoft 365 Copilot Business, reached general availability on 2 December 2025.Source: Microsoft, fetched 2026-09-06
Microsoft publishes USD 30.00 per user per month paid yearly, or USD 31.50 paid monthly on an annual commitment, for the enterprise SKU. The EU-served page shows EUR 26.00 per user per month paid yearly, VAT excluded. Microsoft 365 Copilot Business lists at USD 21.00 per user per month paid yearly. All figures read from Microsoft’s own pricing pages on 2026-09-06. A qualifying Microsoft 365 licence is required on top.Source: Microsoft, fetched 2026-09-06
Not by default any more. Microsoft’s own EU Data Boundary exception register states that Copilot prompts, responses and grounding data may be processed outside the EU Data Boundary for AI inferencing, including in the United States, Canada and Australia. Microsoft calls the mechanism flex routing and documents that it "is on by default for eligible tenants that were created after March 25, 2026". EU and EFTA administrators can disable it in the Microsoft 365 admin center at any time, after which "LLM inferencing will occur inside the EU Data Boundary, even during periods of peak demand". Two further carve-outs exist: Anthropic models inside Microsoft offerings are excluded from the EU Data Boundary, although Microsoft also states that EU Data Boundary and UK customers have those models disabled by default; and customers who purchased Multi-Geo Capabilities "are not in scope for the EU Data Boundary" at all.Source: Microsoft Learn, fetched 2026-09-06
Microsoft publishes no default retention period for Copilot interaction data. We searched the Copilot privacy document and the Purview retention, governance and audit pages on 2026-09-06 for "default", "by default", "indefinite", "indefinitely", "forever", "without a retention policy", "not configured" and "retention". The only "forever" match describes an administrator-chosen option. Retention therefore exists once an administrator configures a Purview policy, and not before. The widely repeated claim that Copilot data is retained indefinitely by default is not supported by any Microsoft page we could find, and we do not publish it. Control is shared: administrators set Purview policy, and users can delete their own Copilot activity history from the My Account portal.Source: Microsoft Learn, fetched 2026-09-06
No. Microsoft states that "Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs, including those used by Microsoft Copilot." Optional customer feedback may be used to improve the product, and Microsoft states it is not used to train the foundation models either. No opt-out is required because the default is already off.Source: Microsoft Learn, fetched 2026-09-06
Microsoft documents this failure mode against its own product. In the Restricted SharePoint Search documentation it walks through a marketing specialist who can reach a budgeting site because "Most people don’t know about this site, so the site owner hasn’t set up proper permissions", and then notes that when he asks Copilot for budgeting information, Copilot gets information from that site. Microsoft has shipped two successive controls for this and calls both temporary. Restricted SharePoint Search caps at 100 sites, "isn’t a security boundary", and stops accepting new enablement from 31 July 2026. Its replacement, Restricted Content Discovery, requires SharePoint Advanced Management on top of a Copilot licence, and Microsoft warns that "Excessive use can reduce the amount of content available to organization-wide search and Microsoft Copilot experiences".Source: Microsoft Learn, fetched 2026-09-06
Yes, one disclosed and patched by Microsoft itself. Microsoft assigned itself a CVSS 9.3 information-disclosure CVE against Microsoft 365 Copilot in June 2025, CVE-2025-32711, for an AI command-injection flaw requiring no user interaction, and states it was fully mitigated and not exploited. Microsoft’s advisory records "Publicly Disclosed:No" and "Exploited:No", and says "There is no action for users of this service to take. The purpose of this CVE is to provide further transparency." This is a disclosed and patched vulnerability class, not a confirmed real-world breach.Source: NVD, fetched 2026-09-06
It depends on the gap you are filling. Copilot is strong inside the Microsoft estate and weak on two axes European mid-market teams care about: it has no phone channel, and its EU inferencing is a setting rather than a guarantee. Ainora is EU-native by design, multilingual including small EU languages, adds a phone and voice channel that Copilot does not have, and ships in days rather than quarters, with 99.9% uptime. Ainora pricing is individual. For knowledge search across many non-Microsoft SaaS tools, Glean is the specialist, although it has published no price since January 2023.
Founder & CEO, AInora
Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.
View all articles