The conversation about which AI engine to use is being held in every IT leadership team, and the pattern is broadly the same. The development lead wants ChatGPT. The platform people prefer Claude. The Google loyalist prefers Gemini, already sitting in their inbox. Most end users default to Copilot because it is already there. The engine is the part everyone argues about, and it is the part that matters least.
The Landscape, Engine by Engine
The market the organisation actually has to navigate breaks down roughly as follows:
- Claude (Anthropic): strong on long-context analysis and prose that needs little editing; a US provider with the attendant jurisdictional exposure.
- ChatGPT (OpenAI): broad ecosystem, fast, strong on multimodal and agentic workflows.
- Gemini (Google): already embedded in Workspace and the inbox for organisations on Google.
- Microsoft 365 Copilot: the default for most staff because the data already lives in M365, now routing some requests to Claude via the Anthropic subprocessor toggle.
- DeepSeek: capable and cheap, but carries a material security and jurisdiction risk that rules it out for most regulated work.
- Mistral: the European option, reserved for workloads where sovereignty is a hard constraint.
Beyond the big six, xAI Grok, Perplexity, Cohere, IBM Watsonx and Granite, and Amazon Nova are each worth knowing about for specific use cases.
The Anthropic Subprocessor Question
Copilot Chat, Researcher, and Excel route some requests to Claude models, with the Anthropic subprocessor toggle enabled by default for most commercial tenants. EU, EFTA, and UK tenants have it disabled by default. Administrators need to make a deliberate decision about this rather than discover it after the fact. The Anthropic-routed requests run on Anthropic-managed infrastructure and are not currently covered by Microsoft's standard data residency commitments.
The single biggest practical risk on a Copilot rollout is not the model, the residency, or the Anthropic sub-processor question. It is oversharing.
Oversharing Is the Real Risk
Copilot will surface documents, mailbox content, and Teams messages that users have access to but never realised they had. A SharePoint estate that has accumulated permissions over fifteen years without a coherent labelling and access-control review will produce some uncomfortable conversations. Microsoft Purview information protection labels, Restricted SharePoint Search, and a real access-control review are the work that has to happen before broad deployment, not alongside it.
Building Your Own
For organisations that want more control, the options run from cloud-hosted managed services, through self-hosted open-weight models, to multi-model gateways that let you route workloads between engines. Each trades convenience against control and sovereignty. Self-hosting an open-weight model keeps data in-house but moves the operational burden onto you; a managed service is easier but reintroduces the jurisdiction question. There is no single right answer, only the right answer for a given workload and data classification.
The Cost Reality
Subscription pricing is the visible cost and the smaller one. Training, governance, the SharePoint clean-up, and the long tail of shadow IT typically add 30-50% on top. Different user tiers justify very different spend: a productivity user on Copilot and a power user on a premium Claude seat are not remotely the same line item, and the premium seats only earn their keep through measurable output quality.
What Actually Decides the Outcome
The engine choice is a small part of the picture. The components that must withstand regulatory or contractual scrutiny are the architecture, the deployment patterns, the data classification scheme staff can actually apply, and the governance that signs off use cases by data tier. Get those right and almost any of the major engines will serve. Get them wrong and the best model in the market will still leak your data, oversurface your documents, and leave you explaining yourself to a regulator. Design around capabilities and risk classes rather than product names, because this month's favourite is next month's has-been.