OpenAI as Copilot Subprocessor
This might seem a little confusing, since we know Copilot has been using the OpenAI models since the beginning, but it has always been a version of the model that lives in Azure.
This meant Microsoft could abide by its enterprise data protection agreements, but it also meant a delay in new OpenAI features for users.
This plugs that gap, but comes with an important caveat:
The following exclusions apply:
-
OpenAI operated models available through Microsoft aren’t FedRAMP High authorized. If your organization requires FedRAMP High prior to use, consult with your authorization official to determine whether use of OpenAI operated models is permitted within your environment.
-
A Payment Card Industry (PCI) Data Security Standard (DSS) Attestation of Compliance (AOC) isn’t available for OpenAI operated models.
-
A Health Information Trust Alliance (HITRUST) Common Security Framework (CSF) Certification Letter isn’t available for OpenAI operated models.
-
A System and Organization Controls (SOC) 1 Type 2 report isn’t available for OpenAI operated models.
That seems significant. As someone who works in the legal industry, this is concerning. Some of our clients will not look kindly on us using any third-party tool that can’t provide SOC reports, and I know anyone working with the federal government is looking at that first bullet point about FedRAMP and wondering if they should make sure this isn’t enabled in their environment.
Are these exceptions giving you pause? Also, can anyone tell me if ChatGPT users are also subject to the same exceptions, or is this unique to the partnership with Microsoft? I’m going to try to dig into that, but I’m not very familiar with ChatGPT’s security posture as someone who doesn’t have an account with them. I feel like if the ChatGPT service didn’t have those items, I would have heard about it, though.
Let me know what you think.

Reposts