All insights

Industry Copilot · 5 min read

Auto, GPT or Claude for legal document review? A law firm's guide to the Copilot picker

By James Wilkinson 7 June 2026 Updated 3 October 2026

Which Copilot model for matter prep and contract review, plus the governance points UK law firms should settle before switching Claude on inside Copilot.

TL;DR
  • Copilot Chat lets you choose the model behind each request. For routine legal tasks Auto, the default, is fine. For close contract review or matter analysis, choose Claude Opus or one of the newer GPT models on purpose.
  • Settle the governance before the model. Claude models in Copilot are processed by Anthropic as a Microsoft subprocessor, outside the EU Data Boundary, and are off by default in UK tenants, so approve them deliberately.
  • Doing the work inside Copilot keeps client matters in your governed tenant rather than a public tool, but no model output reaches a client, court or the other side without a qualified human checking it.

Law firms use Copilot for the work around the work as much as the law itself. Prepping a matter, reading into a contract, finding the right precedent in the firm’s own files, drafting a first version of a letter that a fee earner will then take apart. Some of that is routine. Some of it is careful reading, where a wrong inference is a real problem.

Copilot Chat lets you choose which model handles each request. It starts on Auto, which picks a model for you, and most people never open the picker. For legal work that choice deserves more thought than it usually gets, and so does the governance sitting underneath it.

Why model choice matters for careful reading

For routine tasks Auto is fine. A quick summary, a tidy-up of a file note, a first cut of a standard email. The picker earns its keep when the reading has to be careful.

Close contract review, spotting the clause that does not match the rest, reading a long document for what it does not say as much as what it does: these reward a model built for sustained reasoning. As the fuller guide to the Copilot model picker sets out, the newer GPT models are built for multi-step analytical work, and Claude Opus tends to flag where it is uncertain rather than present a confident guess. The current models in each part of Copilot are on our living list. For legal reading, a model that says this clause is ambiguous, check it, is worth more than one that glosses over it. A smooth, wrong answer is the dangerous kind.

This is not about trusting the model more. It is about trusting it appropriately. A model that surfaces its own doubt gives the reviewing lawyer somewhere to look first, which is the opposite of a tool that buries a bad inference in confident prose. On a long document under time pressure, that signal is worth real money.

Governance comes first

For a law firm the model question cannot be separated from the governance question. Settle this before anyone starts switching models on live matters. This is the part to get right.

Client confidentiality and the tenant. The reason to do this work inside Copilot rather than a public tool is that the matter stays under your firm’s Microsoft agreement and controls. Pasting a client document into a personal ChatGPT or Claude.ai account is the risk to design out. Copilot keeps the work governed by your tenant settings, whichever model answers. Our practical guide to using Copilot with client data goes through this properly.

The distinction is simple to state and easy to forget under deadline. Inside Copilot the matter stays in an environment your firm governs and can audit. In a personal account it does not, and you have lost the ability to say where it went. For a firm that owes a duty of confidence, that difference is the whole point.

The Anthropic approval and hosting nuance. Using Claude inside Copilot is not automatic. Your firm has to approve Anthropic models first. Anthropic works as a Microsoft subprocessor, so Microsoft’s Product Terms and Data Protection Addendum apply, but the models are operated by Anthropic, outside the EU Data Boundary and outside in-country processing commitments. In the UK the models are off by default in the admin centre for that reason. Some of Anthropic’s newest models are offered with data retention under Anthropic’s own terms, behind a separate setting, and those deserve a harder look still. This does not make Claude unusable for legal work. It makes it a decision the firm should take deliberately, with the people who own risk in the room, rather than a switch a fee earner flips mid-matter. It is still far safer than the public-tool habit it replaces, because the work stays inside Copilot.

The OpenAI setting that is already on. Since July 2026 some GPT models in Copilot have been run by OpenAI as a Microsoft subprocessor, and that setting has been on by default for eligible commercial customers. Microsoft’s Product Terms and Data Protection Addendum apply, but those models are currently outside in-country processing commitments. If the firm has told clients where their data is processed, someone should look at this setting as deliberately as the Anthropic one.

Where human review is non-negotiable. No model output goes to a client, a court or the other side without a qualified human checking it. That holds whichever model produced it. A more capable model gives you a better draft. It does not carry professional responsibility, and it cannot.

Set that expectation early, before anyone gets comfortable. The better the drafts get, the stronger the pull to wave them through, and that is exactly when a missed error does the most damage. The model speeds up the first draft. The final review, the part that protects the client and the firm, stays human.

An SRA-aware mindset. The questions a regulator would ask are the questions to ask yourself. Do you know where the data went. Can you supervise the work. Is there a named human accountable for the output. If you can answer those for every model in the picker, you are on solid ground. If you cannot, the answer is to settle the governance, not to avoid the tool.

None of this is unique to AI. It is the same supervision and confidentiality discipline the firm already applies to a junior’s work or an outsourced task. The model is new. The duties are not, and the firms that frame it that way tend to adopt faster, because the questions already have owners.

Per-job guidance

With the governance settled, the per-task picture is straightforward.

  • Routine drafting, summaries and internal notes: Auto is fine.
  • Close contract review, matter analysis, reading where nuance matters: choose a heavier model, such as Claude Opus or one of the newer GPT models, with Claude Opus the natural choice where you want flagged uncertainty.
  • Anything client-facing, anything filed, anything advised on: switch if it helps, then review it in full. Never rely on any model unchecked.

Choosing a heavier model in Chat or Word does not add to the bill today. The everyday models are part of the Copilot licence, and Microsoft says heavier ones such as Opus will come with usage limits. Work handed to Cowork, or to the frontier models, is paid in Copilot Credits.

The shift towards software that acts on its own, not just answers, is already visible in what autonomous agents mean for professional services. The firms that handle the model picker thoughtfully now are the ones that will handle that next step well.

Where to start

Choosing a model is the small decision. Building the judgement and the governance around it is the work. For the split between what an agent can take on in a small firm and what stays with the fee earner, written after the SRA’s August 2026 warning notice, see where an agent fits in a 20-person law firm.

We design and build Copilot Studio agents for law firms, inside your own Microsoft 365 tenant, with the governance settled before anything goes live. If you want to settle the governance before you settle the model, book a free 30-minute call and we will start with where your controls stand today.

Sources checked

Last checked: 3 October 2026.

Related reading

More on Industry Copilot

Industry Copilot Which Copilot model should your finance team actually use? Auto for a quick email, but not for a forecast. When finance teams should choose Claude Opus or a heavier GPT model in Copilot, and keep the P&L under their own Microsoft controls. Industry Copilot Where an agent fits in a 20-person law firm, and what stays with the fee earner After the SRA's August 2026 warning notice: intake, correspondence and chronologies for an agent, advice and judgement for the solicitor and what it costs. Copilot Updates Claude Opus 4.8 in Microsoft 365 Copilot: why a model that admits uncertainty matters Claude Opus 4.8 is in Copilot Cowork and rolling out across Microsoft 365 Copilot. The upgrade that matters is honesty about uncertainty, plus a UK admin point to check. Copilot Explainers What AI models does Microsoft Copilot use? The current list, by surface Which models power Microsoft Copilot (formerly Microsoft 365 Copilot) right now in Chat, Word, Excel, PowerPoint, Cowork and Copilot Studio, how each is billed and the admin and UK data points. Kept up to date. Copilot Explainers The Copilot model picker nobody switches: when to leave it on Auto and when to choose GPT or Claude Microsoft Copilot has a model picker most teams never touch. When to leave it on Auto, when to choose a GPT or Claude model, what it costs and why the work stays under your Microsoft agreement. Copilot Updates Claude Opus 5 in Microsoft 365 Copilot: should UK businesses switch it on? Claude Opus 5 is live in the Microsoft 365 Copilot model selector. When it beats GPT-5.6, why UK tenants have it switched off and what enabling it involves. Copilot Governance Can you use Microsoft Copilot with client data? A practical governance guide Can you use Microsoft Copilot with client data? Yes, but only inside clear governance, approved tools and a review process built around risk levels. Copilot Agents Microsoft Scout and Autopilots: what autonomous agents mean for professional services Microsoft Scout is its first autonomous assistant and the start of a new category called Autopilots. A practical, sceptical guide for UK professional services. Industry AI agent development for law firms Agents that start on their own when a new matter opens, a meeting ends or post arrives, do the checking, drafting and filing, then stop for the fee earner to approve. Built in your own Microsoft 365. Next step Book a free 30-minute call A free 30-minute call about the work an agent could take off your team, and whether Discover is the right next step.

Common questions

Questions about Copilot model for legal document review

Which Copilot model is best for contract review?
For close contract review, choose a heavier model rather than leaving it to Auto. Claude Opus suits careful reading because it tends to flag uncertainty rather than present a confident guess. Always have a qualified human review the output.
Can UK law firms use Claude inside Copilot?
Yes, but not by default. An administrator has to enable Anthropic models first, and they are off by default in UK tenants. Anthropic works as a Microsoft subprocessor, so Microsoft's Product Terms and Data Protection Addendum apply, but the processing sits outside the EU Data Boundary and in-country processing commitments. Take the decision deliberately, with risk owners involved. It remains far safer than pasting client documents into a public tool.
Does using Copilot for legal work keep client data confidential?
Doing the work inside Microsoft Copilot keeps it under your firm's Microsoft agreement and tenant controls rather than in a public ChatGPT or Claude.ai account. Confidentiality still depends on your firm's controls, which model providers you approve and human review of any output.
Can Copilot replace a lawyer's review of a document?
No. A more capable model produces a better draft, but it does not carry professional responsibility. Client-facing or filed work must always be reviewed by a qualified human.