Microsoft announced on February 19 that U.S.-based makers in early access environments could use Grok 4.1 Fast after an administrator opted in. The Copilot Blog described a fast-reasoning text model for large context windows, deep tool use, and complex workflows. But Microsoft Learn’s current model-availability record, updated after the announcement, lists only the non-reasoning variant, restricted to U.S. early access environments, with no public availability entry for other regions.
That change in framing matters more than the provider logo in the model picker. Copilot Studio administrators evaluating Grok should treat it as a narrowly controlled test of an externally hosted model—not as a drop-in replacement for the generally available Microsoft-hosted models already available to their makers.
Microsoft’s current warning goes beyond ordinary preview language
The February launch post said Grok 4.1 Fast was in preview, off by default, and subject to explicit administrator opt-in. Microsoft’s current Learn documentation goes further. It identifies the offering as an experimental, non-reasoning model and says Microsoft’s safety and responsible AI evaluations found it less aligned than other models evaluated.
Microsoft says the results mean a higher risk of potentially harmful outputs and lower scores on its safety and jailbreak benchmarks. The documentation also warns that Grok 4.1 Fast may produce explicit content with greater propensity than other models, and that there may be harm categories its content-safety systems do not cover.
This is the substantive disclosure missing from the short launch item. “Preview” can mean an unfinished feature, limited capacity, or an incomplete regional rollout. Here, Microsoft has documented a specific safety and alignment concern alongside the usual experimental-model warning about variable quality, latency, availability, and potential timeouts.
The current record does not explain when or why Microsoft changed the public designation from the February post’s “preview” wording to Experimental, nor does it say whether the assessment arose from new testing, a revised disclosure policy, or both. The difference is real in the published documentation: Microsoft’s February blog advertised a fast-reasoning model, while the active product table exposes Non-reasoning as a General-category model and cautions customers against production deployment.
xAI’s own November 2025 announcement helps explain the naming distinction. It released two API variants: a reasoning version intended for maximum intelligence and a non-reasoning version intended for fast responses. xAI promotes the family for a two-million-token context window and tool-calling workloads. Copilot Studio, however, is not presenting both variants to makers in the current availability list. Teams should therefore test the model they can actually select in Copilot Studio rather than extrapolating from xAI’s broader API claims or benchmarks.
The external-hosting boundary changes the governance decision
The sharper operational issue is data handling. Microsoft’s February announcement said customer data would not be retained or used to train xAI models. That statement is important, but it is not the same as saying the workload remains within Microsoft’s enterprise service boundary.
Microsoft’s current documentation states that data sent to the provider is processed outside Microsoft-managed environments and outside Microsoft audit controls. It says Microsoft customer agreements, Product Terms, and the Microsoft Data Processing Addendum do not apply to this use. Microsoft’s data-residency commitments, audit and compliance requirements, service-level agreements, and Customer Copyright Commitment are also excluded.
Instead, Microsoft says the organization’s use is governed by xAI’s Enterprise Terms of Service and Data Processing Addendum. The current Microsoft 365 documentation calls the provider “SpaceXAI,” while pointing customers to xAI’s enterprise legal terms. The naming is secondary to the contractual point: enabling the model creates a direct, separately governed provider relationship rather than placing xAI in the same role Microsoft documents for an integrated Microsoft subprocessor.
For compliance teams, “not used for training” should therefore be read as one privacy control among several—not as a blanket equivalence to Microsoft-hosted Copilot Studio models. An organization that requires Microsoft contractual coverage, Microsoft auditability, a defined data-residency commitment, or Microsoft’s copyright commitment should not assume those protections carry over simply because the agent is built and managed in Copilot Studio.
Microsoft’s own external-model documentation draws the dividing line plainly. Anthropic models are described separately as operating with Microsoft oversight when used as a Microsoft subprocessor, subject to stated exceptions. xAI models are categorized as externally hosted and subject to xAI’s terms and data handling. The result is a policy decision, not merely a maker-level model preference.
Admin approval has multiple gates, not one toggle
The February launch language correctly said administrators must opt in, but the implementation requires more than a single consent screen. Microsoft’s current guidance says a Global Administrator first enables the provider in the Microsoft 365 admin center, reviews and accepts the legal terms, and chooses which users or Microsoft Entra ID security groups may access the models.
Those assignments apply at the provider level across Microsoft Copilot and Copilot Studio experiences. A narrow pilot group is therefore possible, and it is the sensible starting point. Granting access broadly would make the provider eligible across those connected experiences for the users selected, rather than containing the decision solely to one experimental Copilot Studio agent.
Copilot Studio then has its own layer of controls in the Power Platform admin center. Administrators must allow external models at the environment or environment-group level. Because Grok 4.1 Fast is experimental, the environment also needs experimental and preview models enabled. Microsoft’s model documentation adds that experimental-model processing may occur outside an organization’s geographical boundary, and that tenant administrators manage the setting that permits data movement across regions.
This is a useful protection against accidental adoption, but it also means troubleshooting requires checking controls in both the Microsoft 365 and Power Platform administrative surfaces. A maker who cannot see Grok in the model picker may lack provider entitlement, be working in an environment where external models are blocked, be ineligible because the environment is not an early access U.S. environment, or be blocked by the experimental-model configuration.
The sequence for a controlled evaluation should be straightforward:
- Restrict provider access to a small Entra ID security group rather than enabling it for all users.
- Limit the Power Platform configuration to a dedicated development or test environment with no sensitive production knowledge sources.
- Review xAI’s enterprise terms and data-processing addendum as the governing documents for prompts, responses, and connected workflow data.
- Test prompt-injection resistance, content filtering, grounding behavior, latency, and tool-use failure modes with the organization’s own agent instructions and data classifications.
- Document a fallback model before allowing makers to publish anything that depends on Grok.
Removal can change an agent’s behavior
Microsoft’s external-model documentation contains another detail administrators should plan for: external-model access is reversible, but removal does not necessarily preserve the agent’s existing behavior.
If an administrator withdraws access to an external provider after makers have selected that model, Copilot Studio changes affected agents to another suitable internal model. If no suitable internal model exists, the agent errors and the maker must explicitly select an internal replacement.
That behavior avoids leaving an agent silently connected to a provider the tenant no longer permits. It can also create a difficult support problem if an agent’s prompts, grounding instructions, topic routing, or tool orchestration were tuned around the behavior of the external model. A fallback may keep the agent online, but it does not guarantee equivalent answers, action selection, or refusal behavior.
This makes model choice part of change management. Production agents should record their selected model, fallback behavior, test baseline, and data-classification approval in the same way an IT team would record a connector or identity-provider dependency. The relevant question is not whether Grok can generate a compelling demonstration; it is whether a particular agent remains safe, supportable, and contractually acceptable when its model is external, experimental, or later disabled.
Microsoft has supplied the mechanism for controlled experimentation, and xAI’s model may be worth evaluating for text-heavy, large-context workflows in isolated environments. But the current documentation supplies the more important conclusion: Grok 4.1 Fast in Copilot Studio is available for U.S. early-access testing, not production deployment, and its use moves customer data and contractual responsibility beyond Microsoft’s managed environment.