Eyal Marcus / Copilot Flex Routing · Updated: September 2026

Copilot Flex Routing and the EU Data Boundary: What Changed in April 2026 and What to Switch Off

Bottom line: since 17 April 2026, Copilot's Flex Routing can send LLM inference outside the EU Data Boundary when Microsoft's EU processing capacity is under load, unless an admin has switched it off. If your organisation has told anyone that "everything stays in the EU," this is the one setting to check before saying it again.

I test the admin side of Copilot rollouts more often than I would like to admit (most training conversations end up here anyway, in the 15 minutes before or after the actual session). Flex Routing is a small line in Microsoft's documentation that changes a real promise.

What Copilot Flex Routing is

Flex Routing is Microsoft's mechanism for handling demand spikes on Copilot's EU infrastructure. When the usual EU processing capacity is under load, Flex Routing can send the LLM inference call to a data centre outside the EU Data Boundary instead of queuing it. A Copilot response your European staff normally expect to be processed inside the EU may, under load, be processed somewhere else.

"Under load" is doing a lot of work in that sentence. Microsoft does not publish a live figure for how often this triggers (a number I would also like to see), so the honest position is that it can happen, not that it constantly does.

What changed on 17 April 2026

Before 17 April 2026, EU Data Boundary coverage for Copilot read, in practice, closer to a flat guarantee for EU tenants. Since that date, Flex Routing exists as a named, admin-controlled setting layered on top of the Data Boundary, and it is on by default in most tenants.

Two independent write-ups that cover the mechanics in technical detail, changepilot and innfactory, both describe the same change: a real, documented routing behaviour, not a rumour making the rounds in Microsoft 365 admin forums.

Nobody sent out a press release when this landed (Microsoft rarely does for admin-level routing changes), which is exactly why it tends to surface in the middle of a rollout rather than before one. A data protection officer asks a precise question about where processing happens, and the honest answer now has a clause attached to it that did not exist a few months earlier.

Before 17 April 2026

EU tenants generally read Copilot's data handling as staying inside the EU Data Boundary without a named exception to check.

Since 17 April 2026

Flex Routing exists as a separate, admin-visible setting, and the Data Boundary guarantee now has a documented "under load" exception attached to it.

Where inference can go under load

The EU Data Boundary already covers Copilot as an in-scope service for EU customers, following the Preferred Data Location of the user who wrote the prompt in normal operation. I have written that part up in more depth, including exactly where prompts are stored at rest, on the Copilot GDPR and EU Data Boundary page. Flex Routing sits on top of that normal operation as the exception, not a replacement for it. When capacity allows, processing stays where the Data Boundary rules already put it. Under load, it does not.

The admin setting to check

Copilot data residency in Europe does not need a task force or an external audit to verify. It needs 1 specific question, put to whoever holds admin access: is Flex Routing switched on for our tenant right now, and do we know why.

Bottom line: "on" means Copilot can spill outside the EU Data Boundary under load, quietly, unless someone overrides it. "Off" means every request queues instead, even during a spike, no exceptions. Neither answer is wrong. Only one of them should come as a surprise.

01 Find the setting

Flex Routing is controlled from the Microsoft 365 admin center, alongside the other Copilot data controls.

02 Know the trade-off

On favours reliability under load. Off favours a strict EU-only guarantee with occasional queuing. It is an admin and compliance call, not a technical default to leave untouched.

03 Put the answer in the same place as your training plan

Whoever answers "is Copilot GDPR compliant" for your organisation should know the Flex Routing answer too. They are, in practice, the same question asked twice.

Where Anthropic-provided models fit

Anthropic-provided models available inside Copilot are excluded from the EU Data Boundary, regardless of the Flex Routing setting. That exclusion is separate, it was already true before 17 April 2026, and Flex Routing does not change it either way. Admins decide independently whether third-party models power their Copilot experiences at all.

Keep these 2 facts apart when you brief a compliance team (I have watched them get merged into one worry more than once). Flex Routing is about where Microsoft's own models process a request under load. The Anthropic exclusion is about a different provider entirely, and it applies whether Copilot is busy or quiet.

What this means for your rollout and training

None of this should derail a rollout. It should get 1 line on an agenda before the rollout starts: has someone checked the Flex Routing setting, and does the answer match what employees, a works council, or a compliance team have already been told. That question fits naturally into the kind of live online Copilot training for European companies I run, where the admin questions tend to come up in the first 10 minutes anyway.

Training and data residency usually get treated as 2 separate jobs, owned by 2 separate people who rarely sit in the same meeting. In practice they answer to the same audience. The people asking "where does our data go" in a Copilot session are, more often than not, the same people who will ask a works council or a customer the same question a month later. Answering it once, clearly, saves everyone the second version of that conversation.

Bottom line: this is a 5-minute settings check, not a governance programme. Once someone has actually looked, the training conversation can move on to what people do with Copilot, instead of circling back to what nobody checked.

Questions I get about Copilot Flex Routing

What is Copilot Flex Routing?

A Microsoft mechanism that, under load, can send Copilot's LLM inference outside the EU Data Boundary instead of queuing the request, unless an admin has disabled it.

Does Copilot data leave the EU under Flex Routing?

It can, under load, unless Flex Routing has been switched off. In normal operation, Copilot data for EU tenants stays inside the EU Data Boundary.

When did this change take effect?

17 April 2026.

Should we disable Flex Routing?

That is an admin decision that belongs in the same conversation as your training rollout, not a call this page makes for you. Reliability versus a strict EU-only guarantee is the actual trade-off to weigh.

Are Anthropic-provided models in Copilot inside the EU Data Boundary?

No. Anthropic-provided models available in Copilot are excluded from the EU Data Boundary regardless of the Flex Routing setting.

Rolling out Copilot in Europe

Bring this into your training.

Leave your details and I will call you back to talk through your rollout, including questions like this one.

Updated: September 2026 · by Eyal Marcus · AI consultant and trainer, 260 sessions in 112 organisations