On 24 September, the Microsoft 365 account on X, followed by over 61,000 people, quietly changed its bio to point followers towards @MSFTCopilot instead. The account it redirected them to, the dedicated Copilot profile, has since been locked, its posts wiped. It is the latest entry in a naming history that has run the old Office app through four names in four years: Office, Microsoft 365 (November 2022), Microsoft 365 Copilot (January 2025), and now Microsoft Copilot (August 2026), with the web presence consolidating onto a single address, copilot.cloud.microsoft.
The reaction on X was, by most accounts, an unflattering mix of confusion and mockery. One popular reply accused Microsoft of trying to force an inferior AI tool onto customers who had already soured on the earlier integration attempt. Someone else suggested the company just call the whole thing “Clippy” and be done with it. It is tempting, and largely fair, to read this as a branding failure: four names, two merged social accounts, a company that cannot settle internally on what to call its own flagship AI product from one year to the next.
But the branding chaos is the least interesting part of this story.
The app consolidated. The backend did not.
For its first two years, Copilot was, functionally, a rebadged OpenAI product wearing Microsoft's colours. That stopped being true some time ago. Microsoft first opened the door to a second model family in September 2025, adding Anthropic's Claude alongside OpenAI's models inside the Researcher agent and Copilot Studio, initially gated behind the Frontier programme for enterprise customers willing to opt in. That toggle has since become a genuine router: organisations can now choose per-agent between OpenAI and Anthropic models from a dropdown in Copilot Studio, and Microsoft 365 Copilot itself will automatically select whichever model suits a given task, Claude for visual and presentation work, GPT for research with citations, without the user choosing anything at all.
Layered on top of that is a third contender Microsoft built itself. Since March 2024, Mustafa Suleyman's Microsoft AI division has been shipping its own MAI family: a general foundation model, MAI-1-preview, a dedicated reasoning model, MAI-Thinking-1, and a coding model, MAI-Code-1-Flash, each reaching public preview through 2025 and 2026. Suleyman told VentureBeat at Microsoft Build 2026 that a contractual renegotiation with OpenAI roughly six months earlier had “set free” his division to pursue independent frontier models. The direction since has been unambiguous: MAI models are no longer a hedge sitting quietly in reserve. Bloomberg reported that, from July 2026, Microsoft began shifting routine, high-volume prompts in Excel, Outlook, Bing, and PowerPoint away from OpenAI and Anthropic to in-house MAI models specifically to curb third-party API licensing costs. The reported direction of travel is to make the cheaper in-house models the default across Copilot products, with OpenAI and Anthropic held back as a tier customers pay extra to reach.
None of this is visible from inside the product. The user sees “Copilot”. They do not see which of at least three separate model providers, running under three separate commercial and data-processing arrangements, just answered their prompt.
It helps to be precise about what “Copilot” actually refers to, because it spans three distinct things Microsoft has folded into a single brand.
The foundation model layer is the actual reasoning engine behind an answer: currently a live-routed mix of OpenAI's GPT family, Anthropic's Claude, and Microsoft's own MAI models, selected dynamically per task or per cost target. The harness and orchestration layer is where agents actually run: Copilot Studio for building them, Agent 365 as the governance and audit wrapper Microsoft sells alongside it, and Copilot Cowork, which is not something Microsoft engineered from scratch. Microsoft's own 9 March 2026 blog post is explicit on the point: “Working closely with Anthropic, we have integrated the technology behind Claude Cowork into Microsoft 365 Copilot.” Claude is the reasoning engine underneath Copilot Cowork; what Microsoft built is the hosting environment around it, a sandboxed Microsoft 365 tenant with Work IQ context and Microsoft's own governance and identity controls, in place of Claude Cowork's local, on-device execution. Finally, the application layer is the part users actually see: Word, Excel, Outlook, Teams, and the chat interface itself, now unified under one icon after four renames.
Microsoft owns the third layer outright. It is increasingly competing to own the first. The second is a mix of built and licensed, depending on which feature you happen to be using.
The move towards MAI as the default is not being framed internally as a quality story. It is a cost story. Every Anthropic or OpenAI call Microsoft routes through Copilot is a call Microsoft pays a third party for; every MAI call is one it does not. That is a rational move for Microsoft's margins. It is a considerably less comfortable one for anyone trying to document what actually processes their organisation's data, because it means the model behind a given answer is liable to change not because the task changed, but because Microsoft's internal routing economics shifted that quarter.
Microsoft has also described MAI's training data as clean and commercially licensed, safe for business use by design. Its own MAI-Thinking-1 technical paper, published June 2026, tells a slightly different story: alongside a proprietary 1.2 trillion page web crawl, the training pipeline ingested 24.2 billion pages directly from Common Crawl, a broad scrape of the open web whose legal status for AI training purposes remains genuinely unsettled. That is the same underlying dataset every other frontier lab draws on to some degree, dressed here in language that implies a cleaner provenance than the paper itself supports.
When Copilot routes a request to Claude, that request does not stay inside Microsoft's own infrastructure. It goes to Anthropic's, governed by Anthropic's own terms of service rather than Microsoft's: a separate contract, a separate data processing relationship, a separate retention clock. Anthropic's standard terms specify a default 30-day retention period for conversation logs on backend systems, extending to as long as two years for inputs and outputs flagged by trust and safety systems, with the classification scores themselves held for up to seven years. Zero data retention, the option many enterprise buyers assume comes as standard once they are paying enterprise prices, is not available through the consumer or enterprise pass-through routes Microsoft uses to embed these agentic features, in sharp contrast to the data boundary agreements Microsoft's own native Azure OpenAI integration offers. That is a materially different retention posture from a request Microsoft keeps inside its own OpenAI arrangement, which is different again from a request an in-house MAI model answers entirely on Microsoft's own infrastructure.
Three model providers. Three retention regimes. Three sets of contractual terms governing what happens to the data in a single prompt. The product surfaces none of it. A user typing into Word has no indication which of the three just read what they typed.
Article 35 of the GDPR asks an organisation processing personal data at scale to document, among other things, the nature and scope of that processing and the recipients the data will be disclosed to. That documentation assumes a data flow that is at least knowable, even if it changes over time through a formal change control process.
Dynamic model routing breaks that assumption at the root. If a payroll query typed into Copilot this morning went to Anthropic under Anthropic's retention terms, and the identical query typed tomorrow goes to an in-house MAI model trained partly on unresolved Common Crawl provenance, under Microsoft's own terms, with no user action and no visible change on screen, then the “recipients” a DPIA is meant to name are not a fixed list. They are whatever Microsoft's cost-optimisation router decided that week. No data protection officer can complete Article 35 documentation against a target that moves without notice and without a UI element that says which target it moved to.
This is not a hypothetical gap. It is the operational consequence of a real, already-shipping architecture, arrived at for entirely rational commercial reasons, that happens to be incompatible with the accountability obligations sitting directly on top of it.
The rename saga makes a tidy news story because it is visible: a locked X account, a changed bio, a reply thread full of people asking why Microsoft built two Copilot apps in the first place. The real story sits underneath that, and it is the opposite of visible. Four years of renaming just collapsed the entire product line into a single name, Microsoft Copilot, at precisely the moment the thing behind that name became a live-routed mix of three separate vendors, three separate data processing regimes, and one internally undisclosed cost function deciding which one answers on any given day.
One brand. At least three procurement relationships. No way, from inside the product, for a user, a DPO, or an auditor to know which door they just walked through.
The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy, with particular focus on Isle of Man jurisdiction and Crown Dependency issues.
Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.