Every week, a client asks us some version of the same question. Here's how we actually answer it, and it's got almost nothing to do with which one writes the best email.
Before any of the above, it's worth being clear on what you're actually trying to do, because "AI" covers two very different things.
1. User AI, the subscription. Drafting emails, research, help with a spreadsheet. This is what we'd call user AI, and it helps individual people become more productive. It doesn't make the business an "AI business", it just makes your team faster at the tasks they already do.
2. Business AI, where AI is integrated into business systems and processes to produce better outcomes without human interaction. This is a different project entirely, with different tooling, different governance, and a different conversation to have with us. Everything in this article is about the first kind. If you're asking about the second, that's a separate conversation, and we'd rather have it properly than squeeze it into a comparison table.
Claude, our first choice on raw capability. Best reasoning, best for genuinely complex work like analysis, drafting and coding, and strong enterprise-grade controls once you're on the right plan.
Microsoft Copilot, our recommendation for data-sensitive businesses. If you're already running Microsoft 365 and handle sensitive client or personal data, Copilot keeps everything inside a compliance boundary you've already invested in and your team already understands.
ChatGPT, not something we currently include in our standard recommendations. It's a legitimate, widely-used enterprise product with its own admin controls and no-training guarantees on paid tiers, we simply don't lead with it, mainly because it sits outside the Microsoft ecosystem most of our SME clients are already governed by. If you're specifically evaluating it, we're happy to talk it through.
The free or personal version of any of these tools is not the same product as the business version, and for compliance purposes, the two are worlds apart.
Personal ChatGPT accounts, free Claude accounts and consumer Copilot aren't covered by a Data Processing Agreement. No admin console, no enforced SSO, no audit trail, and in some cases your inputs can be used to improve the underlying model. None of this belongs anywhere near client data, HR files, or anything commercially sensitive.
The business tiers, Claude Team/Enterprise, Microsoft 365 Copilot licensed against Business/Enterprise M365 plans, and ChatGPT Team/Enterprise, all come with a Data Processing Agreement, a default of your data not being used to train the model, and centralised admin control.
If someone on your team is quietly using a personal AI account for work "because it's useful", that's the single biggest AI-related compliance risk we see in SME environments, regardless of which product it is.
| ChatGPT | Copilot | Claude | |
|---|---|---|---|
| Sits inside your existing Microsoft 365 boundary | No, separate platform, separate admin console | Yes, runs inside your M365 tenant, inherits Purview/DLP, permissions and sensitivity labels | Partial, connects to M365 via connectors, but data flows to a separate vendor |
| Requires a paid business tier before you should touch client data | Yes, Team/Enterprise, not the personal app | Yes, needs Business Standard/Premium or E3/E5 plus the Copilot add-on licence | Yes, Team or Enterprise, not the free/Pro consumer plan |
| No training on your data by default (paid tier) | Yes | Yes | Yes |
| SSO available | Yes, on Team/Enterprise | Yes, inherited automatically from Entra ID | Yes, Team plan includes SSO with domain capture; Enterprise adds SCIM |
| MFA | Enforced via your identity provider once SSO is configured | Enforced via your identity provider once SSO is configured | Enforced via your identity provider once SSO is configured |
| EU/UK data residency options | Available on Enterprise tier | EU Data Boundary applies for EU/UK tenants under standard config | Available on Enterprise tier |
| Best fit if… | Widest range of third-party integrations | You're already in M365 and want the lowest-risk option for sensitive data | Strongest reasoning for complex work, run through SSO properly |
A note on that MFA row: enabling MFA inside the app itself is a valid baseline, it's better than nothing. But where SSO is available, route sign-in through your organisation's identity provider (Microsoft Entra ID, Google Workspace, Okta) instead, so MFA, conditional access and device compliance policies are inherited automatically from your existing tenant baseline rather than managed separately in each app.
Choose Microsoft Copilot if:
You already run Microsoft 365 Business Premium or E3/E5. You handle client personal data, financial records, health data, or anything with a regulatory dimension. You want a Data Protection Impact Assessment and your existing Purview/DLP/access control setup to simply extend to AI, rather than standing up a second governance framework from scratch.
Choose Claude if:
Quality of output on genuinely difficult work, analysis, strategy, technical writing, coding, is the priority. You're prepared to buy Team or Enterprise (never the free or Pro personal plan) and enforce SSO from day one. You don't need your AI tool to sit natively inside the Microsoft 365 permissions model.
We don't currently put ChatGPT in front of clients as our recommendation, not because it lacks enterprise features, but because it's the one option of the three that doesn't extend an ecosystem most of our SME clients are already standardised on and governed by. If you're set on evaluating it anyway, talk to us first, we can tell you what to lock down before anyone touches client data with it.