CG TECH

Insights

Grok Joins Microsoft Copilot: Is Your Data Ready?

Two colleagues reviewing an AI interface on a laptop in a modern Australian office, illustrating secure AI adoption and workplace collaboration.

Microsoft Copilot is becoming less about one AI model and more about choosing the right model for the work in front of you.

That’s an exciting step for businesses. More choice can mean better outcomes, more useful AI experiences and less reliance on any single provider.

But when a new model enters the Microsoft 365 environment, there’s another question that deserves just as much attention:

Do you know where your data goes, who processes it and what controls still apply once it gets there?

On 12 September, Microsoft announced that Grok models from SpaceXAI are being added to Copilot in Word, Excel and PowerPoint.

The rollout is happening through Microsoft Frontier, which gives eligible customers access to selected preview features.

At first glance, it looks like another AI model joining the growing list of options inside Microsoft Copilot.

I think it’s more than that.

It’s a timely reminder that AI choice, data governance and data sovereignty now need to be discussed together.


What Microsoft Has Announced

Grok isn’t being switched on for every Microsoft 365 customer.

Microsoft says Grok models are being released through the Microsoft Frontier Program, starting with a focused preview for eligible customers. The first supported Microsoft 365 applications are:

  • Microsoft Word
  • Microsoft Excel
  • Microsoft PowerPoint

Microsoft refers to Grok as a model family from SpaceXAI. It hasn’t named a specific Grok version in the announcement, so businesses should avoid making assumptions about model capabilities or future availability.

The preview is also not available to Frontier customers in the European Union, the European Free Trade Association or the United Kingdom.

For Australian businesses, the key point is that this is an opt-in decision.

Access is controlled by a dedicated Microsoft 365 administrator setting, and it is disabled by default.

A Global Administrator can enable SpaceXAI in the Microsoft 365 admin centre, review the relevant terms and decide whether access applies to all users, selected groups or no users at all.

That gives IT and business leaders a useful pause before the technology reaches everyday work.


The Part Leaders Should Notice

Microsoft has added SpaceXAI to its Online Services Subprocessor List.

That may sound like a technical detail, but it’s one of the most important parts of the announcement.

A subprocessor is a third party that may process customer or personal data while helping deliver a cloud service.

Microsoft publishes this list so customers can understand which providers may handle data in connection with Microsoft Online Services.

In this case, Microsoft says administrators retain transparency and control over data processed by SpaceXAI models in supported Copilot experiences.

That means the question is not simply, “Do we want to give our people another AI option?”

The better question is:

“Are we comfortable with the data, provider, contractual and governance position that comes with this option?”

For some businesses, the answer may be yes, particularly for low-risk tasks using approved content. For others, especially those with strict contractual requirements, sensitive client information or sector-specific obligations, the right first step may be a more detailed review.

Neither response is wrong. The important thing is that it’s a deliberate decision.

Data Governance Comes Before Model Choice

Data governance is the everyday discipline of knowing what data you have, who can use it, how it can be used and who is accountable for it.

It’s not just a policy sitting in a folder somewhere. It shows up in practical decisions, including:

  • Which files can be used with AI tools
  • Who has access to SharePoint, Teams and OneDrive content
  • Whether sensitive documents have clear labels
  • Which AI providers have been approved
  • Who can enable a new AI service
  • When human review is needed before content is used or shared

This is especially relevant in Microsoft 365 because Copilot works with the information users already have permission to access.

If permissions are overly broad, a new AI model won’t fix that problem. It may make the consequences of that problem easier to see.

That’s why Copilot readiness should cover more than licences and user training. It should include a realistic review of the information, permissions and controls that sit behind the AI experience.

The same rule applies whether a business is using one model or many.

Data Residency and Data Sovereignty Aren’t the Same

These two terms are often used as though they mean the same thing. They don’t.

Data residency is about location. It asks where data is stored and processed.

Data sovereignty is broader. It asks which laws, legal powers, operational arrangements and personnel controls apply to that data.

A business can know the physical location of its data and still need to consider who operates the service, what contractual terms govern processing and whether the provider arrangement meets customer or regulatory expectations.

For Australian business leaders, that distinction matters.

Microsoft’s current guidance says Microsoft 365 Copilot maintains Microsoft’s existing privacy, security, compliance and data-residency commitments.

It also says that customers outside the European Union may have Copilot queries processed in the United States, the European Union or other regions.

When a business considers an AI provider that sits outside Microsoft-managed infrastructure, it should avoid assuming that the provider’s data arrangements are identical to Microsoft’s standard Copilot service.

That doesn’t automatically make the option unsuitable.

It simply means the assessment needs to be based on the specific service, feature, data type and terms in play.

This is why data sovereignty should be part of the conversation before a preview is enabled, not something handled after people start using it.


Four Questions to Ask Before Enabling Grok

A practical review doesn’t need to slow everything down. It can begin with four straightforward questions.

1. What information will people use?

Start with the data, not the model.

Will people use public information, approved internal documents, customer material, financial information, HR records or commercially sensitive plans?

For an early test, it makes sense to use low-risk content that has been specifically approved for the pilot. That lets people test the quality of the model without introducing unnecessary data concerns.

2. Where is the data processed?

Review Microsoft’s current documentation, the Online Services Subprocessor List and the applicable terms for the feature before enabling access.

This is particularly important for businesses with contractual commitments around data location, client confidentiality, cross-border processing or approved suppliers.

Your legal, privacy, security and procurement teams may not need to approve every prompt. They should, however, be part of the decision when a new provider may process business information.

3. Who can use the model?

Microsoft’s administrator controls allow businesses to provide SpaceXAI access to selected users or groups.

That makes a small pilot possible. There’s no need to make the model available across the whole business on day one.

Choose people who have a clear use case, understand the rules and can provide useful feedback. A small group from marketing, sales operations or a project office may be suitable, depending on the data they work with.

Avoid starting with content that includes sensitive employee records, customer information or commercially sensitive work unless the governance review supports it.

4. What happens if the pilot needs to stop?

Every pilot should have a simple off switch.

Microsoft’s settings allow administrators to remove access by choosing “No users” for SpaceXAI models. Microsoft says it may take several hours for the service to be fully disabled for users after this change.

That should be part of the pilot plan from the start. If the business finds that the model doesn’t suit the task, data handling isn’t acceptable or results aren’t good enough, access can be removed while the team reviews what it learned.


Your Knowledge Layer Still Matters Most

It’s easy to become focused on which model is newest, fastest or getting the most attention online.

But the information behind the model usually matters more.

Your knowledge layer is the collection of documents, data, policies, records and permissions that support work across the business. It’s where people look for answers today, and it’s what AI tools draw from when they help draft, summarise and analyse content.

A strong knowledge layer gives every approved AI model a better chance of producing useful results.

Before enabling another provider, I’d check:

  • Are important documents current and owned by the right people?
  • Are SharePoint, Teams and OneDrive permissions accurate?
  • Is sensitive content clearly labelled?
  • Have old sharing links and broad access groups been reviewed?
  • Can teams identify the approved source of truth for key business information?
  • Do users know what they can and can’t include in an AI prompt?

If the answer to several of these questions is no, that’s not a reason to avoid AI. It’s a reason to prepare properly before expanding access.

A Simple Governance Plan for a Grok Pilot

A good pilot doesn’t need a large program behind it. It does need a few clear decisions.

Define one business task

Choose a repeatable task where a better first draft, summary or presentation would save time.

For example, a team could use approved, non-sensitive project material to create a first draft of a status update in Word or turn a set of agreed points into a PowerPoint presentation.

The task should be clear enough that people can judge whether the model has helped.

Choose the right test group

Use Microsoft’s group-based controls to limit access to a small set of users.

The group should understand that this is a preview, know what data they can use and agree to give feedback on the results.

Set data boundaries

Write down what information can be used in the pilot and what stays out of scope.

Keep the guidance simple. People should be able to understand it before they start using the model.

For example:

  • Use approved internal content prepared for the test
  • Don’t use client-confidential, financial, HR or personal information unless specifically approved
  • Don’t use AI-generated content as a final answer without review
  • Don’t send external communication without the usual business approval

Measure the outcome

Track the time saved, quality of the first draft, number of corrections and user confidence.

The point isn’t to prove that one model wins every time. It’s to learn whether the model is useful for a defined job and whether the data settings remain acceptable.

Review before expanding

Bring together the business owner, IT lead, data owner and pilot users. Review the results, issues and feedback before deciding whether to expand, change or stop the pilot.

That process turns a new AI feature into a controlled business decision.

Model Choice Is Becoming a Leadership Issue

Microsoft’s move to add Grok to Copilot signals that model choice is moving closer to everyday business work.

People won’t need to leave Word, Excel or PowerPoint to access different AI capabilities. That may make AI more useful, but it also means leaders need clear answers to questions that were once left to technical teams.

Which providers are approved?

Which tasks are appropriate?

What data can be used?

What stays under human review?

Who can decide when a new model enters the business?

The good news is that businesses don’t need to answer every future question today. They just need a sensible way to assess the next one.

Choice Is Good When Control Stays With You

I see Microsoft’s decision to offer Grok models in Copilot as a positive development.

Businesses should have more than one path when they’re deciding how to use AI. They should be able to test different models, compare results and find the right fit for the work they need done.

At the same time, choice works best when the business stays in control.

That means knowing where data goes, setting clear boundaries, keeping permissions in order and testing new features with a purpose.

The right model can change over time. Good data governance and a clear view of data sovereignty will remain important regardless of which model is selected next.

If you’re considering Microsoft Copilot, reviewing AI data governance or planning a model-choice pilot, CG TECH can help you assess your Microsoft 365 environment, prepare your data and permissions, and create practical rules that give your people room to use AI with confidence.

Recommended SEO alt text:

**Microsoft Copilot data readiness banner showing secure AI governance, data controls and business information on a laptop.**

About the Author

Carlos Garcia is the Founder and Managing Director of CG TECH, where he leads enterprise digital transformation projects across Australia.

With deep experience in business process automation, Microsoft 365, and AI-powered workplace solutions, Carlos has helped businesses in government, healthcare, and enterprise sectors streamline workflows and improve efficiency.

He holds Microsoft certifications in Power Platform and Azure and regularly shares practical guidance on Copilot readiness, data strategy, and AI adoption.

Connect with Carlos Garcia, Founder and Managing Director of CG TECH, on LinkedIn.

Sources

More insights

Want help applying any of this?

Talk to the CG TECH team about what it means for your business.

Contact us
Scroll to Top