Resource

Anthropic Claude Data Residency in Australia

A compliance briefing on where your data actually goes when you use Claude across Microsoft 365 Copilot, Copilot Studio, Claude for Work, and Azure AI Foundry.

Anthropic’s Claude models are now embedded across multiple Microsoft products - from M365 Copilot and Copilot Studio through to Azure AI Foundry - plus Anthropic’s own Claude for Work (Teams and Enterprise) plans. For Australian organisations, this raises an immediate question: where does my data actually go?

We assessed all four deployment paths against Australian data residency, privacy and regulatory requirements. The findings are significant for any organisation handling sensitive data, operating under APRA regulation, or working with government or health information.

The short version: All four paths process data primarily in United States infrastructure. None offers an Australian-region inference guarantee as of May 2026. For unregulated commercial workloads, all four are workable with appropriate disclosure. For APRA-regulated, IRAP-required or health (PHI) workloads, none is clean today.

Full Briefing Paper (PDF)
Anthropic Claude Data Residency & Compliance - 11 pages, updated May 2026
Download

The four deployment paths

Australian organisations considering Claude have four distinct consumption models, each with its own data flow, contractual structure and compliance profile:

1. Microsoft 365 Copilot

Claude now powers several M365 Copilot experiences including Copilot in Word, Excel and PowerPoint, the Researcher agent, Agent Mode in Excel, and Copilot Cowork. When Anthropic models are invoked, data processing occurs outside Microsoft’s in-country commitments for Australia. Microsoft made in-country Copilot processing available for Australia in late 2025, but Anthropic models are explicitly excluded from those guarantees.

There are two independent admin toggles controlling Anthropic use - a global subprocessor toggle and a separate per-app toggle for Word, Excel and PowerPoint. The global toggle has been ON by default for Australian commercial tenants since 7 January 2026. Most organisations will not know it is on.

2. Copilot Studio and Power Platform

When a Copilot Studio agent invokes Claude, the request does not run entirely within Microsoft’s infrastructure. Anthropic models are excluded from the EU Data Boundary and in-country processing commitments. Microsoft does not publicly confirm whether the integration calls Anthropic’s direct API, AWS Bedrock or a Microsoft-hosted instance - a critical ambiguity for regulated clients.

3. Claude for Work (Teams and Enterprise)

Anthropic’s commercial Claude.ai SKUs are sold directly by Anthropic. Traffic may route via servers in the US, Europe, Asia and Australia, but data is stored in the US by default. There is no published Australian data residency option. Commercial products do not use customer conversations for model training by default, and the Enterprise plan offers custom data retention controls and SSO/SCIM provisioning.

4. Azure AI Foundry

This is perhaps the most surprising finding. Although you call an Azure endpoint, Anthropic’s own documentation confirms that “Claude models run on Anthropic’s infrastructure.” Microsoft authenticates and meters the call, but the actual inference happens outside the Azure trust boundary. Australia East is not listed as a supported region for Anthropic models.

The common thread: US processing

Across all four paths, inference occurs on Anthropic infrastructure in the United States. Microsoft onboarded Anthropic as a subprocessor in January 2026, but Anthropic models are explicitly excluded from Microsoft’s EU Data Boundary and in-country processing commitments. This exclusion extends to Australia.

For Copilot Studio and M365 Copilot, Anthropic retains inputs and outputs for up to 30 days for abuse detection, with retention extending up to 2 years if content is flagged for a policy violation. Zero Data Retention (ZDR) is not available for any Microsoft consumption path.

Australian regulatory implications

Privacy Act 1988

All four paths involve cross-border transfer to US infrastructure, which must be disclosed under Australian Privacy Principle 8. This is workable with appropriate privacy notices and contractual safeguards (Microsoft DPA or Anthropic DPA), but it must be disclosed - not assumed.

APRA CPS 230 (banking and insurance)

Regulated entities must manage risks from material service providers and their fourth parties. Using Anthropic via any of the four paths for material business operations requires a formal board-approved fourth-party risk assessment. Given the Anthropic toggle is on by default, APRA-regulated entities may already be exposed without knowing it.

IRAP (government - PROTECTED data)

The Anthropic layer has no published IRAP assessment across any of the four paths. Government agencies handling PROTECTED data should not use Anthropic via any path and should default to Azure OpenAI in Australia East.

Health (PHI)

Anthropic’s HIPAA BAA does not flow through to M365 Copilot, Copilot Studio or Azure AI Foundry. Only Anthropic’s direct API with a signed BAA gives a defensible posture, and even then, Australian health information should be treated as overseas disclosure with strict controls.

Key risks at a glance

Risk Severity Mitigation
Data leaves Australia (all four paths) High Disclose in privacy notice; APP 8 contractual safeguards; consider Azure OpenAI in AU East
No published AU inference region for Anthropic High Wait for AU support, or fall back to Azure OpenAI / native Foundry models
Anthropic enabled by default in M365 Copilot (AU) High Audit both global and per-app toggles immediately; scope to Entra security groups
APRA CPS 230 fourth-party risk High Formal board-approved assessment of Anthropic and AWS/Azure as material service providers
IRAP not assessed for Anthropic layer High Do not use Anthropic for PROTECTED data; use Azure OpenAI in AU East
Anthropic training use under Copilot Studio not explicit Medium Get written confirmation from Microsoft
Copilot Cowork identity governance Medium Map audit trail implications; Cowork uses user identity, not a dedicated AI agent identity
ZDR not available for any Microsoft path Medium Use Anthropic direct API + ZDR for the most sensitive workloads

Which path should you choose?

Unregulated commercial workload where AU residency is preferred but not mandatory - any of the four paths works. Choose by developer or user experience: M365 Copilot for Frontier features in Office, Copilot Studio for low-code agents, Foundry for code-first developers, Claude for Work for chat-style knowledge work. Just remember the Anthropic toggle is on by default - raise this proactively.

AU residency is a hard contractual rule - none of the four is suitable today. Recommend Azure OpenAI in Australia East, with a roadmap watch on Anthropic AU regions.

APRA-regulated entity - any path is conditional on a CPS 230 fourth-party risk assessment with board sign-off. Lead with Azure OpenAI in AU East if residency is the gating concern. Check the Anthropic toggle immediately.

Australian Government (PROTECTED data) - do not use any of the four Anthropic paths. Use Azure OpenAI in AU East.

Health PHI - only Anthropic’s direct API with a signed BAA gives a defensible posture.

Need help navigating this? We help organisations assess AI data residency risk and implement the right controls for their regulatory profile. Get in touch to talk through your situation.

Download the full briefing paper
Includes the complete comparative matrix, all 11 questions to put to Microsoft and Anthropic, and full citations.
Download

Based on the FutureAbility briefing paper Anthropic Claude on Microsoft and Anthropic Platforms - Data Residency and Compliance Briefing for Australian Client Engagements, updated 11 May 2026. Sources include Microsoft Learn documentation, Anthropic Trust Center, and the Privacy Act 1988 (Cth).

Not sure where your AI data is going?

We help Australian organisations navigate data residency, compliance and AI governance - so you can adopt AI with confidence.