Microsoft wins on ecosystem integration and it wins decisively. Copilot Studio is a native surface inside Teams, SharePoint, Outlook, Excel, OneDrive, and the entire Power Platform. The agent can read a SharePoint document with the same authentication the user already has, post a result to a Teams channel, attach a sensitivity label that propagates automatically into the next document the agent touches, and surface its audit trail inside the same eDiscovery view the legal department already uses for email. For a buyer whose document gravity is fully inside Microsoft 365, and for most large European enterprises that is the truthful description of where their data lives, that integration depth is real, it is hard to replicate from outside, and it is the right reason to choose Copilot Studio for workloads where Cloud Act exposure and policy-layer governance are acceptable.
Microsoft also wins on enterprise procurement friction. Copilot Studio is part of the existing Microsoft Enterprise Agreement that the buyer's procurement team has already negotiated, the existing MSA covers the contractual posture, and the existing CISO sign-off on Microsoft 365 extends naturally to a new agent surface inside the same tenant. Adding a new vendor, even one with stronger hardware controls, means a fresh vendor risk assessment, a fresh DPA, a fresh penetration-test review, and a fresh procurement cycle. For a fast-moving internal automation program with limited compliance ambition, the friction cost of "yet another vendor" is non-trivial and Copilot Studio wins the moment the buyer decides the workload does not need hardware enforcement.
Microsoft does not win on hardware seal. Copilot Studio agents run on standard Azure tenant compute, the underlying host is administered by Microsoft, and there is no attestation surface that lets the buyer verify cryptographically that the operator cannot read the agent context. Azure has confidential VM SKUs with Intel TDX and AMD SEV-SNP, but Copilot Studio agents do not run inside those SKUs as of May 2026 and Microsoft has not published a roadmap commitment to put them inside that boundary. For workloads where the threat model assumes the cloud operator is part of the attack surface, which is the standard threat model for client files under professional secrecy, for patient records under HDS, and for any data subject to a foreign sovereign's discovery powers, Copilot Studio cannot satisfy that threat model and VoltageGPU's Intel TDX deployment under a French controller can.
Microsoft does not win on EU sovereignty without caveats. The Data Privacy Framework is a legal posture, not a hardware posture. It reduces the documentary friction of GDPR Chapter V transfers but it does not change the fact that the ultimate processor is US-incorporated and subject to US extraterritorial law. For buyers whose compliance team has flagged the CLOUD Act as a residual risk that needs a technical mitigation rather than a contractual one, the answer is a non-US operator running on hardware where the operator cannot technically read the data. VoltageGPU's combination, French SIREN, GDPR Article 28 DPA under French law, Intel TDX silicon enforcement, Intel DCAP attestation per session, is the architecture that produces that mitigation. The honest summary: if your data is already in Microsoft 365 and Cloud Act exposure is acceptable, Copilot Studio is the path of least resistance and the right answer; if your data is governed by GDPR Article 28 with strict technical-measures requirements, HDS, French bar secrecy, or EU AI Act high-risk classification, VoltageGPU is the only architecture that mathematically proves Microsoft and us cannot read it.