Skip to main content

    Executive guide

    Choosing between Microsoft Copilot, ChatGPT, Claude and Gemini

    Start with the assistant your organisation already licenses, and test it on your own tasks before buying another. Microsoft, OpenAI, Anthropic and Google each publish business-tier limits on using your data for training, on different terms, with different data location options. Choose on fit with your systems, controls and tasks.

    Start with what you already pay for

    Ask the owner of your existing platforms to produce the result with tools you already license. These may include Microsoft Copilot (formerly Microsoft 365 Copilot), ChatGPT, Claude or Gemini. If a gap remains, run a short internal test to see the effort involved before you buy another product.

    Test each candidate on your own recurring tasks. Until a tool is approved, use material with no confidential content.

    Compare what each vendor states about training

    Each vendor publishes a statement for its business tiers. The wording differs, and so does what each statement covers. We checked every statement below on the vendor's own page on 6 October 2026.

    ProductWhat the vendor states
    Microsoft CopilotMicrosoft states that 'the prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models'. Its page also states that web search queries are not covered by its Data Protection Addendum.
    ChatGPT Enterprise, Business and EduOpenAI states that by default it does not use data from ChatGPT Enterprise, ChatGPT Business or ChatGPT Edu to train its models.
    Claude EnterpriseAnthropic states: 'Your prompts, data, and results are not used to train our models by default.'
    Gemini in Google WorkspaceGoogle states: 'Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.'

    Microsoft's statement covers Microsoft Copilot used with an organisational account, signed in with Entra ID. Microsoft's consumer Copilot app has a separate privacy FAQ. That FAQ states that it 'does not apply to the use of Microsoft 365 Copilot when signed in with Entra ID'.

    Check where your data can be stored

    Data location options differ by product and by plan. We checked the Microsoft row again on 7 October 2026.

    ProductWhat the vendor states about data locationAustralia
    ChatGPTOpenAI states that eligible customers 'can store sensitive customer content at rest in' a choice of regions. The listed products are ChatGPT Enterprise, ChatGPT Edu, ChatGPT for Healthcare and the API platform. ChatGPT Business is not listed.Listed, for eligible customers
    ClaudeAnthropic lists Australia among the Asia-Pacific regions for regional data residency, in the context of regional endpoints on AWS Bedrock and Google Cloud Vertex. The page does not state it for the Claude Enterprise workplace product.Listed, for regional endpoints
    Gemini in Google WorkspaceGoogle states: 'Customers can control where their data is stored and processed (EU or US).'Not listed on the page checked
    Microsoft CopilotFor Microsoft Copilot, Microsoft's data residency commitment in its Product Terms covers data at rest in Australia. The commitment applies to tenants whose default geography is Australia. Microsoft also states that customers outside the EU 'may have their queries processed in the US, EU, or other regions'. Its update of 3 April 2026 says local processing of Copilot interactions is 'expected to become available in Australia' by the end of 2026.Listed for data at rest; in-country processing expected by the end of 2026

    Retention controls also differ. OpenAI states that qualifying organisations can 'configure how long OpenAI retains business data'. Anthropic states that 'Data retention controls and OTEL monitoring are currently available on Claude Enterprise only.'

    Check the product settings as well as the model

    The same model can behave differently in different products. Each product can set the model version, how much reasoning it applies and what information it can reach. Check those settings in the product you would use.

    Decide with your privacy and security specialists

    A vendor statement describes the vendor's position on the day it was checked. It does not settle how the Privacy Act 1988 or your own contracts apply to your use. Confirm the settings in your own tenancy. Have your privacy and security specialists review the product terms, configuration and data flows before personal or confidential information goes in. Our guide to assessing AI under the Privacy Act sets out the questions.

    Vendor terms change. Check each statement against the vendor's current page before you rely on it.

    Build the capability on the tool you choose

    Once a tool is approved, the Practical AI Workshop builds practice on your own tasks with that tool. Our Build AI capability page sets out the routes for executives and teams. Where the choice of tool is part of a larger investment decision, the AI Roadmap covers it.

    Frequently asked questions

    1. Which AI assistant should our business choose?

      Choose the product that does your own tasks well enough to pass a test. If 2 products pass, compare their training, data location and retention terms.

    2. Do Microsoft Copilot, ChatGPT, Claude and Gemini train on our business data?

      In their business tiers, all 4 vendors state limits on training with your content, and the conditions differ. Google, for example, states that Workspace content is not used for model training outside your domain without permission.

    3. Can AI assistants keep our data in Australia?

      Some can store data at rest in Australia, depending on the product, plan and tenant settings. Microsoft Copilot tenants based in Australia, and eligible ChatGPT Enterprise and Edu customers, can keep data at rest in Australia. Where prompts are processed is a separate question, so ask each vendor about processing as well as storage.

    4. Can staff use free or personal versions of these tools for work?

      Use your organisation's approved business accounts for work. A personal account can carry different training and retention terms from the business tier. The Office of the Australian Information Commissioner recommends that organisations do not enter personal information into publicly available generative AI tools.

    Bring the tools you already license and the tasks you want your people to use them on.