Copilot Training NZ, home

11 min read. Updated 6 October 2026

Copilot vs ChatGPT vs Claude for New Zealand businesses

The useful comparison is not which chatbot writes the smoothest paragraph. It is which product can see your files, what the vendor does with a prompt, and which New Zealand rules still sit with your business.

Illustration generated with AI.

Start with the work, not the logo

Most New Zealand firms already have people trying a generative tool on a phone or a home account. That experiment is not the same decision as buying a work product for the whole team. MBIE's strategy for artificial intelligence treats New Zealand as a country of adopters: the gain is in applying tools to local work, not in building a foundation model1. The same strategy reports a 2024 Datacom survey in which 67 percent of larger New Zealand businesses used some form of AI, up from 48 percent in 2023, while an NZIER and Spark survey the same year found that 68 percent of small and medium businesses had no plan to evaluate or invest1.

A head office in Auckland, Wellington or Christchurch may already pay for a work account, while a smaller firm is still deciding. Stats NZ paused the Business Operations Survey for 2024 and 20252. With MBIE, it is running a 2026 Survey of Business Operations that adds questions on the use and impact of artificial intelligence2. Until that release, treat a commercial survey as a signal, not as a national rate.

Copilot, ChatGPT and Claude can all draft, summarise and answer questions. They do not start from the same place. Microsoft 365 Copilot, which Microsoft's current documentation also calls Microsoft Copilot, is built to work inside the Microsoft 365 tenant you already run. ChatGPT and Claude are separate products. A fair trial asks each one to do a job you already do, on data you are allowed to use, and then checks the contract before anyone pastes a client file.

Where each product sits in the working day

Microsoft describes Copilot as a service inside the Microsoft 365 boundary. A prompt in an app such as Word or PowerPoint can be grounded with material from Microsoft Graph: email, chats and documents that the signed-in person is allowed to open3. The same page is clear that sitting inside the tenant does not give Copilot a view of every file in the organisation. Access follows that person's existing permissions. That is the feature accounting, legal, council and operations teams usually want, and it is also the reason a messy SharePoint library becomes a problem.

ChatGPT, from OpenAI, is a workspace you sign in to. On the business products OpenAI names, including ChatGPT Enterprise, ChatGPT Business and ChatGPT Edu, the organisation's inputs and outputs are not used to train models unless someone opts in4. The product can hold projects and admin controls. It does not, by itself, open the mailbox and the SharePoint library the way Copilot does. If a firm wants ChatGPT to read a live client folder, that is a separate connection, with its own permission design.

Claude, from Anthropic, is the same kind of choice: a chat product with commercial plans, not an add-in that inherits a Microsoft 365 identity. Anthropic says that, by default, inputs and outputs from commercial products such as Claude for Work and the Anthropic API are not used to train its models5. Consumer plans are a different article on the same site. A staff member using a personal Claude account is not covered by the commercial sentence. Write that distinction into the staff rule before you compare answer quality.

  • Choose Copilot when the source material already lives in Outlook, Teams, Word, Excel, PowerPoint, SharePoint or OneDrive, and you want answers limited to what that person can open3.
  • Choose a ChatGPT or Claude work plan when the task is drafting, analysis or research in a separate workspace, and you will decide file by file what is uploaded4,5.
  • Do not treat a personal login as a cheap version of the work plan. The training commitment you are relying on may not apply to it4,5.

What the vendors say about training and retention

Microsoft's enterprise data protection page says prompts, responses, and data reached through Microsoft Graph are not used to train foundation models. Prompts and responses are covered by the Microsoft Products and Services Data Protection Addendum and the Product Terms, with Microsoft acting as a processor. The page also says the commitments match those used for Exchange email and SharePoint files, including encryption and tenant isolation6. Microsoft notes that the product name has moved from Microsoft 365 Copilot to Microsoft Copilot, and that security, compliance and privacy commitments are unchanged.

There is a split inside Copilot that many pilots miss. If web search is on, Copilot can send a short query to Bing. Microsoft says user and tenant identifiers are removed, the query is not used to train foundation models, and it is not covered by the Data Protection Addendum. Bing is handled under the Microsoft Services Agreement and the Microsoft Privacy Statement, with Microsoft as an independent controller7. A privacy officer who has approved Copilot for client files has not, by that approval, approved every web query.

OpenAI's business-data page lists the products whose data it does not train on by default, and it says qualifying organisations can set retention, including a zero-retention option on the API4. Anthropic's commercial article is narrower than a blanket promise. Feedback sent with the thumbs-up or thumbs-down control can be stored, de-linked from user and customer identifiers, and used to train models. Anthropic says that stored feedback can be kept for up to 5 years. An owner of a Team or Enterprise plan can turn off that feedback control5. Read the exception before you tell staff that nothing they type is kept.

Location, permissions and the overseas-disclosure test

The Privacy Act 2020 applies to New Zealand agencies, including private-sector businesses, when they handle personal information8. Information privacy principle 12 limits disclosure of personal information to a foreign person or entity8. One of the permitted grounds is a reasonable belief that the recipient must protect the information with safeguards comparable, overall, to the Act, for example under an agreement between the two parties8. Sending a client spreadsheet to a chatbot can be that kind of disclosure. The contract and the data-location settings are how you form the belief. They are not a slogan on a pricing page.

Microsoft lists New Zealand as a Local Region Geography and lists an Auckland data centre. The standard Product Terms commitment for storing Copilot and Copilot Chat customer data at rest applies to a named list of countries and regions. New Zealand is not on that list. The Advanced Data Residency add-on is the commitment that covers Local Region Geographies, including New Zealand, for a defined set of services that includes Microsoft Copilot and Copilot Chat9. An admin can see current and committed locations on the Data Location Card in the Microsoft 365 admin centre. Check the card for your tenant. Do not assume every New Zealand signup is stored in Auckland.

OpenAI offers data residency for eligible Enterprise, Edu, healthcare and API customers in a list that includes Australia, and does not include New Zealand4. Australia may be acceptable to a privacy officer. It is still outside New Zealand, so information privacy principle 12 still has to be worked through and recorded8. Anthropic's commercial training article does not, on the page opened for this guide, set out a New Zealand data-centre commitment5. Ask for the processing locations in the agreement the business will actually sign.

Microsoft's enterprise data protection page adds one further caution. It says Anthropic models used with Copilot are currently excluded from the EU Data Boundary and, where those commitments apply, from in-country processing commitments6. If a Copilot feature in your tenant calls a model from another provider, do not assume the location promise you read for Microsoft's own model covers that call. Ask which model the feature uses, and read the page Microsoft links from that note.

What New Zealand authorities expect, whichever tool you pick

The Office of the Privacy Commissioner expects an agency that is considering a generative tool to get senior approval, test whether the tool is necessary and proportionate, complete a privacy impact assessment, tell people when the use affects them, engage with Māori about impacts on communities and on information that is a taonga, set procedures for accuracy and for access and correction, keep a human review before action, and keep personal or confidential information out of a tool unless it is confirmed that the provider does not retain or disclose it10. The Commissioner does not approve or rank vendors. The obligation stays with the agency10.

The Government Chief Digital Officer, in the Department of Internal Affairs, publishes responsible AI guidance for the public service. It is not a statute for a private company. Its privacy chapter says the Privacy Act 2020 applies to generative AI, and that government information put into a public generative system must already be public, or be acceptable to make public11. MBIE's responsible AI guidance is the voluntary companion for firms. It says to appoint a privacy officer where personal information is handled, to classify data, and to assess the use against the information privacy principles12.

The National Cyber Security Centre, with CERT NZ and partner agencies, tells organisations that use a third-party AI system to find out whether their inputs will retrain the model, to consider a private version where one exists, and to check that the service can meet data-residency obligations13. Staff need a plain rule for what may be typed or uploaded. Multi-factor authentication should protect the account. None of that advice picks a winner between Copilot, ChatGPT and Claude. It asks you to know which account is in use.

  • Write one rule for work accounts and a stricter rule for personal accounts.
  • Name a privacy officer and a senior manager who can stop a rollout.
  • Record, for each tool, whether prompts are used for training, how long they are kept, and where they are stored4,5,6.
  • Turn web search off for teams that handle client or employee information, unless the privacy impact assessment covers it7.

A way to choose without a bake-off theatre

Pick three tasks the team already does every week. A useful set is a long email thread that needs a reply, a meeting that needs actions, and a spreadsheet that needs a checked summary. Run the tasks in Copilot only if the source files are already in Microsoft 365 and the person doing the test is allowed to open them3. Run the same tasks in ChatGPT or Claude only with files you have copied in on purpose, and only on a work plan whose training terms you have read4,5.

Score the trial on four points, not on style. Did the person finish faster? Did a second person find an error a client would have seen? Did the tool stay inside the files it was allowed to use? Could the privacy officer say where the prompt went? A fluent wrong answer is a fail. The Privacy Commissioner warns that generative tools produce confident errors, and says not to rely on output without a check10. A firm can keep Copilot for tenant files and a separate work plan for drafting, if the staff rule says which window is for which job.

Before you train the team

Training on the wrong account teaches the wrong habit. If the pilot group will use Copilot inside Outlook, Teams, Word and Excel, they need the licence that includes those apps, and they need a tenant whose sharing has been looked at. If the pilot is ChatGPT or Claude, use the business plan, not a personal subscription paid on a card. MBIE's business guidance treats a usage policy as the way to say which system is approved, and it warns that personal, confidential or proprietary information can be retained or surfaced by an AI system that was allowed to learn from it12.

The National Cyber Security Centre also notes that generative tools help attackers write more convincing phishing14. A comparison that only measures speed will miss that. Add a short exercise on a fake invoice, then teach people to read the answer against the source file.

When the choice is made, write it down beside the privacy statement. Say which product is approved, which plan, whether web search is allowed, who may upload personal information, and who checks the output. Revisit the note when a plan name or a retention setting changes.

Questions

Is Copilot just ChatGPT inside Microsoft 365?

No. Copilot can use email, chats and files the signed-in person already has access to. ChatGPT is a separate product. Some Copilot features call other providers' models, and those calls do not all carry the same processing commitments.

Can a small firm use the free or personal versions?

A personal account is a poor place for client or staff information. The training limits published for ChatGPT business plans and for Claude commercial plans are stated for those plans, not for every consumer login. If the work is sensitive, use a work plan whose terms you have read, or keep the sensitive material out.

Does New Zealand law tell us which product to buy?

No. The Privacy Act 2020 sets duties for any tool that collects, uses or discloses personal information8. MBIE's business guidance is voluntary12. Public-service generative AI guidance binds agencies in that guidance's scope, and it is a useful benchmark for everyone else11.

We already have Microsoft 365. Should we still look at ChatGPT or Claude?

Yes, for jobs that should not search the whole mailbox. A separate workspace can be the safer place for a one-off draft, provided the plan is a work plan and staff do not paste client records into it out of habit. Copilot remains the better fit when the answer has to come from files the person already works in.

Who should make the decision?

A senior manager, with the privacy officer and whoever administers Microsoft 365 or the other account. The Privacy Commissioner expects senior approval and a privacy impact assessment before a generative tool is adopted10. IT can run the trial. It should not be the only signature.

Train your team

  1. ScopeHeadcount, sites, Microsoft 365 plan and licences, and the teams you want to start with.
  2. PlanWe propose a course, a pilot group and a format, and agree the files and meetings to use.
  3. TrainOn-site or over Teams, in Outlook, Word, Excel and Teams, with your own work.
  • In person
  • Remote
  • Half-day workshop
  • Full-day workshop
  • Team rollout

Independent training by TheColab. Not affiliated with Microsoft.

Enquire

Tell us about your team. We reply by email with a suggested course and format.

We use these details only to reply to you, and store them securely with TheColab. Privacy

Sources