News Weekly
LV 10 XP
0% read
Your progress · 0/5 chapters
About 6 min total
Agents & infraISSUE #3 · STORY 3 OF 5Sep 25, 2026CONFIRMED

Microsoft's new Copilot app, metered agent credits

Microsoft says the new Copilot app folds chat, code and always-on agents into one place, and bills the agent work by credit.

An isometric platform split into three zones: dissolving speech ribbons, a stack of assembling blocks, and a pulsing orb working alone in a lit alcove.

Read it your way

The short versionPicked for Explorers

The 60-second version

Microsoft announced the new Copilot on September 25, 2026. It pulls chat, small app building and an always-on agent into one app, and it moves the agent work onto a per-credit meter. Most of it is not yet available to the public.

One app, three surfacesHome holds chat and delegated jobs, Code builds small apps, and Autopilot works continuously on its own.
Agents move to credit billingMicrosoft bills Cowork, Code and Autopilot in Copilot Credits on top of the existing per-user subscription.
A credit costs one cent pay-as-you-goMicrosoft publishes a standard pay-as-you-go rate of $0.01 per Copilot Credit.
Most features are still previewsHome and Code reach the Frontier program in coming weeks, and Autopilot enters private preview around September 30.
Finish this chapter for +15 XP
Flip the switch

From scattered tools to one metered app

SurfaceHome, Code and Autopilot togetherOne front door for asking, delegating, building and running always-on agents, rolling out through the Frontier program.
PayingOne credit meter for the agentsCowork, Code, Autopilot and frontier models draw on Copilot Credits, with the seat price still required as a base.
ControlA spending policy gates everythingMicrosoft says nothing is enabled or billed until an admin sets a policy with budgets, alerts and request routing.
Your next move · as a Explorer

Learn the pricing idea, then watch the dates

1Read Microsoft's launch post and the companion pricing post.
2Note availability dates rather than demo clips when judging what shipped.
3Track the Autopilot preview and the OpenClaw lineage as a governance case study.

Switch your reading mode at the top to see a different next move.

Tap to open

Things to keep an eye on

Pop quiz · unlock the Credit Check badge

Did it stick?

0/3
What is the standard pay-as-you-go price of one Copilot Credit?+20 XP
According to Microsoft, when can usage-based Copilot services be charged?+20 XP
What is Autopilot, according to the launch announcement?+20 XP
Your call · +5 XP

What would tell you fastest that this is a real change rather than another Copilot relaunch?

Deep dive

The full research, labeled and sourced

CONFIRMED14 sources · 117 min
Story identity
  • Story ID: S03 (rank 3, SELECTED)
  • Title: Microsoft launches the new Copilot "super app" with Home, Code and Autopilot agents, and usage-based billing
  • Organization: Microsoft
  • Category: Enterprise AI / agent platform / pricing
  • Event date: 2026-09-25 — public announcement. The Official Microsoft Blog post "Introducing the new Copilot with Home, Code and Autopilot" (Jared Spataro) is timestamped Sep 25, 2026, published 12:03:50 UTC (search metadata; confirmed by the page's own dateline). Microsoft showed the app to Frontier customers at an event on the preceding Wednesday (2026-09-23), with a company-provided transcript (GeekWire); embargoed press broke at ~12:00 UTC Friday.
  • Announcement date: 2026-09-25 (same as event date for the public launch; the capabilities themselves are mostly not generally available — see §5 status table).
  • Article dates: The Verge 2026-09-25 12:00 PM UTC (updated Sep 25 with Nadella quote); Reuters 2026-09-25 12:01 PM UTC; GeekWire 2026-09-25 5:00 AM PT (12:00 UTC, updated 5:14 AM PT); Reworked 2026-09-25; thelettertwo (Ken Yeung) 2026-09-25. Companion Microsoft artifacts all dated 2026-09-25: pricing-model blog (techcommunity, version 5.0, "Updated Sep 25, 2026"), Copilot Managed Runtime blog, and the Microsoft Learn UBB overview (ms.date 2026-09-25, updated 17:34 UTC). Research retrieval date 2026-09-26.
  • Overall evidence status: CONFIRMED that the launch happened as described (primary blog post retrieved in full; pricing restructure, FinOps additions, Managed Runtime preview and rollout timelines all published by Microsoft itself). INDEPENDENTLY VERIFIED (multiple reputable outlets present at the Sept 23 briefing or reporting against primary docs): the three-tab structure, the USL/UBB split in Copilot Credits, $0.01/credit pay-as-you-go pricing (also primary: June 16 Cowork GA blog + Learn docs), Autopilot's OpenClaw lineage (OpenClaw founder Peter Steinberger confirmed; corroborated by Nadella's July earnings-call statement — not stated in Microsoft's launch materials), adoption figures (30M+ paid seats from the July 29 earnings call; ~450M commercial M365 seats), and the market reaction (Reuters: MSFT shares +~3% in early trading). COMPANY CLAIM for: rollout timelines ("coming weeks"/"end of the month"), Autopilot/Cowork capability demos (e.g., "Dot" Black-Friday inventory agent), engagement metrics quoted by EVP Jacob Andreou at the event (speed +25%, satisfaction and per-user engagement doubling, daily usage 8× YoY over the last year), "more than half of the Fortune 500 use Cowork" (June GA post), Microsoft's internal cost-comparison analyses (pricing-blog chart vs Claude/ChatGPT; June "30–40% cheaper than Claude Cowork" footnote), and the enterprise-grade security/governance characterizations ("trusted… from day one").
  • Window check: Event date 2026-09-25 falls inclusively inside the active window 2026-09-22 → 2026-09-25 (RESEARCH_CONFIG.json). Eligible.
  • Title/naming notes: (a) "Super app" is the press label — GeekWire: Microsoft unveiled the "long-promised Copilot 'super app' — without officially calling it that"; The Verge uses it in the headline; Microsoft's own material says "the new Copilot" and "the AI built for work." (b) Two refinements vs the discovery summary: the automatic model picker ("Auto") belongs to the fixed-price USL tier, not to usage-based billing — UBB is the tier where admins/users keep full model choice; and Autopilot's private preview is stated as "at the end of the month" (≈ Sept 30), not "later in September" generally. (c) "Autopilot" must not be confused with Windows Autopilot (device-deployment service) — Microsoft reuses a loaded name; flagged in §12.
✓

What happened?

🎓 For Explorer
  • FACT (CONFIRMED — primary blog): On Sept 25 Microsoft introduced "the new Copilot": one redesigned app organizing AI work into three surfaces — Home (Copilot Chat + Cowork together as the default landing experience, plus Office in Copilot, which embeds the full Word/Excel/PowerPoint editors inside Copilot), Code (natural-language building of apps, trackers, dashboards and automations, "powered by the same underlying technology as GitHub Copilot," sandboxed, hostable inside the customer tenant), and Autopilot (a persistent, proactive, personal agent "that keeps working even when you're not" — previously called Scout — with its own identity, memory, computer and workspace in the tenant, addressable by @mention in Teams, Outlook, chats, channels and documents).
  • FACT (CONFIRMED — primary blog; pricing blog; Learn docs): Microsoft restructured Copilot pricing into two tiers: the user subscription license (USL) — fixed per-user-per-month price covering everyday AI (Chat; Copilot in Word/Excel/PowerPoint/Outlook/Teams; model selection; Auto routing that "weighs accuracy, speed and cost on each request"; GPT-5.6 and Sonnet 5 included, Opus 5 to be included with limits, fair-use limits with warning-then-switch-to-Auto-or-credits behavior) — and usage-based billing (UBB) in Copilot Credits for agentic work: Cowork, Code and Autopilot, advanced in-app experiences (e.g., SharePoint) and frontier models ("Astra and Fable"). UBB builds on and requires the USL. Both tiers run models from OpenAI and Anthropic today; "more labs and open-weight models coming."
  • FACT (CONFIRMED — pricing blog + Learn docs + June GA blog): Billing controls are the gating design: for enterprise tenants UBB services stay off and nothing is billed until an admin creates a spending policy in the Microsoft 365 admin center (org/group/user-level budgets, alerts, credit-request routing); Copilot Credit pay-as-you-go is priced at $0.01/credit (stated in the June 16 Cowork GA blog; Learn documents P3 pre-purchase and prepaid capacity packs as alternatives); per-task cost is computed from four inputs — model use, context retrieval, tool calls, runtime.
  • FACT (CONFIRMED — primary blog + techcommunity/new FinOps post): New FinOps for AI capabilities: Agent 365 cost management expands beyond Cowork and Work IQ APIs to cover Code and Copilot Managed Runtime (Copilot Studio agents planned for October); admins can restrict model families per group — which also constrains what Auto may select; Cowork consumption insights (which tasks drive credits and what they produced); Microsoft Graph APIs for policy management; end-user visibility of credit usage/balance/history inside Copilot.
  • FACT (CONFIRMED — Managed Runtime blog, David Blyth, Sept 25): Microsoft Copilot Managed Runtime introduced in public preview: Microsoft-operated hosting for AI-generated code inside the Microsoft 365 tenant boundary — Entra identity, org policies on connectors/data/endpoints, Git-backed versioning, lifecycle/version controls, central inventory in the M365 admin center, an SDK+CLI for the full dev lifecycle (typed connector services in TypeScript), and openness to third-party/pro-code tools (testimonial from Lovable: "an app made with Lovable can now run inside your Microsoft tenant… same sign-in, same policies, same app inventory"). It already powers apps built in Cowork, Code and Copilot Studio. (The main blog says "in preview"; the dedicated blog says "public preview.")
  • FACT (CONFIRMED — primary blog): Context expansion: Microsoft IQ named as the unified grounding platform; Fabric IQ (incl. 20+ million Power BI semantic models) GA today in Chat and Cowork, Code via Frontier soon; Dynamics 365 / Power Platform data and workflows grounding rolling out in public preview over the next month; a new plugin registry (unified Microsoft/partner/custom catalog, IT approval, publish-once) rolling out with GA across surfaces "in the coming weeks."
  • FACT (CONFIRMED — primary blog): Sneak peeks with dates: intent-based routing across Chat/Cowork/Code ("coming soon"); Today (proactive command center) private preview in Copilot in October, later Outlook/Teams; @Copilot in Teams with shared channel context/permissions in private preview by end of the month. Rollout: Home + Code start rolling out in the Frontier program in the coming weeks; Code to Frontier end of month, broad availability "in the coming weeks," preview for Microsoft 365 Premium and Pro subscribers later this year; Autopilot expands to private preview at end of the month. Ignite: Nov 17–20, San Francisco.
  • INDEPENDENTLY VERIFIED (Reuters, same-day interview): Each Autopilot "will carry its own identity in the company directory and have specific permissions that users can control" (CVP Annie Dix-Pearl); Reuters frames the cost-management move against enterprise fear of "rapid AI usage racking up unexpected costs." MSFT shares rose about 3% in early trading Sept 25.
  • REPORTED/CONFIRMED-LINEAGE (GeekWire, Reworked, thelettertwo, from the Sept 23 briefing + primary posts): Nadella promised the super app at Build in June ("come summer… coding to all knowledge work within one Copilot super app") and on the July 29 earnings call said "this quarter" — delivery lands with under a week left in the quarter, and (GeekWire) "most of the new features won't be widely available until later." Autopilot's lineage: OpenClaw — the open-source personal-agent framework that went viral in early 2026; Nadella called it a security risk akin to "a virus" in March (told Morgan Stanley he couldn't launch it himself), Scout debuted at Build "powered by OpenClaw" per Nadella in July; OpenClaw founder Peter Steinberger confirmed Autopilot is also built on OpenClaw (X post, reported by Reworked) — Microsoft's launch announcement does not mention OpenClaw. 404 Media-reported internal Scout planning docs labeled its first rollout phase "Make people addicted" (Reworked). Andreou at the briefing: agents' "autonomy and flexibility… is the same thing that makes them absolutely terrifying to an IT admin"; on cloud-vs-local posture (apparent dig at Anthropic's Claude Cowork local VM): "sending your most sensitive files down to a local machine into a VM was a complete nonstarter."
  • COMPANY CLAIM (event briefing, via GeekWire/thelettertwo): Andreou reported Copilot quality metrics over recent months — speed +25%, per-user engagement and satisfaction doubling, daily usage up 8× in the last year — and the consumer-commercial merger context (~90 million people pay for Microsoft 365 personally; several consumer features — Copilot Podcasts, Group Chat, Deep Research — were shut down during the merge). Nadella (X, Sept 25): "We're building Copilot as a new OS for work that spans every model, every form factor, and every task"; Spataro: "Just as Office defined work for the PC era, the new Copilot is built to define it for the AI era" (both via The Verge).
  • CONTEXT (pre-window, primary): Cowork itself went GA June 16, 2026 (Charles Lamanna post) after a March–June Frontier preview — it has been a separately-toggled experience billing in Copilot Credits since then; the Sept 25 launch folds it into Home and extends the same billing rail to Code and Autopilot. The consumer/commercial Copilot app merge happened in August 2026 (The Verge).
Δ

What changed?

  • One app, three modes of work — Microsoft's "convergence" moment. After years of Copilot sprawl (Bing sidebar → consumer app + M365 Copilot as two brands/apps, merged in August), the enterprise AI surface is now explicitly three-mode: ask (Chat), delegate (Cowork), build (Code), plus autonomous staffing (Autopilot). This mirrors the pattern OpenAI (Codex merged into ChatGPT this summer) and Anthropic (Claude chat + Cowork unified Sept 16) established — Microsoft's late but distribution-strong copy (thelettertwo; GeekWire frames the launch as "Microsoft's answer to OpenAI and Anthropic… selling directly to businesses").
  • The unit of knowledge work broadens from "file" to "file + purpose-built software." Code declares small tenant-hosted apps/automations a fourth artifact class alongside document/spreadsheet/deck, built by non-developers, with developers staying in GitHub Copilot. Combined with the Managed Runtime, Microsoft is betting that vibe-coded internal software gets an official, governed home instead of escaping to shadow tools — and it is opening that same runtime to third-party builders (Lovable first on the record).
  • Pricing crossed the seat/consumption line at the center of the enterprise AI market. "Per-seat plus consumption" — the model hyperscalers use for cloud — now applies to agent labor on the platform that owns most corporate productivity seats: fixed USL for everyday AI, metered Copilot Credits ($0.01 each) for Cowork/Code/Autopilot and frontier models. Microsoft's rhetorical framing (pricing blog): metering everyday AI is "the wrong deal… companies may ration access," so everyday stays flat while long-running autonomy carries the meter. Budget ownership shifts from "licenses bought" to "spend governed."
  • Agent supervision becomes an IT-governance discipline with teeth. The design is inversion-of-default: nothing agentic is billable/enabled until an admin creates a spending policy; model families are allow-listed per group (and that constrains Auto); credit requests route into existing approval workflows; Graph APIs make policy scriptable; Agent 365 supplies identity, audit and inventory; every Autopilot is an assignable directory object. That is a compliance story (Reuters' framing), not just a product story — and it is Microsoft's explicit differentiator against "almost impossible to bring into the enterprise" OSS agents (Andreou).
  • Autopilot legitimizes the always-on personal agent for the enterprise — and buries its origins. Scout's OpenClaw engine was never un-asked (Nadella publicly credited it in July; Steinberger confirms it for Autopilot), yet the launch material is silent on it. What changed is the wrapper: same autonomy class, now with tenant identity, memory, its own computer, email address, @mention reachability, audit, and a meter — "the autonomy you want, the controls IT requires" is the whole product pitch.
  • Grounding got a name and a pricing sheet. "Microsoft IQ" as the unified context layer (Work IQ, Fabric IQ with 20M+ semantic models, Dynamics/Power Platform) plus a governed plugin registry converts "context advantage" into the moat argument — while UBB's four cost inputs (model, context, tools, runtime) make that same context usage directly billable.
Abstract token-like discs drift through a nearly closed iris gate beside a blank graduated dial, with a slim control lever on a plinth.
↔

Before → Change → After

🎓 For Explorer
DimensionBefore (≤ Sept 24, 2026)Change (Sept 25, 2026)After
Copilot app surfaceConsumer + commercial apps merged in August; Chat, Cowork (separate toggle), Office-app Copilot; no code surface; Scout (desktop, then cloud) as a side productOne app, three tabs: Home (Chat+Cowork+Office in Copilot), Code, Autopilot; intent routing between modes promisedSingle "front door" for work AI; Frontier-first rollout weeks; consumer Premium/Pro Code preview later this year
How you pay for agentsUSL per seat ($/user/mo); Cowork billing in Copilot Credits since June 16 GA (USL + $0.01/credit PayGo); Scout ran on GitHub Copilot credits, separately billed, with no published pricing (Reworked)Cowork, Code and Autopilot consolidated on UBB in Copilot Credits, USL required as base; SharePoint-advanced + frontier models (Astra, Fable) on UBB too; consumer subs get UBB "later this year"Two-line AI budget (seats + credits) in every M365 estate; FinOps-for-AI is a mandatory admin capability; Autopilot's migration off GitHub credits still unstated
IT control of autonomyAgent 365 registry/governance launched 2025; Cowork off-by-default precedent; no unified spend policy across workloadsSpending policy gates all UBB billing (off until admin sets it); model-family allowlists shape Auto; Graph API policy management; credit-request routing; user-level caps inside group policiesIT becomes the broker of delegated autonomy: who may run agents, on what models, up to what spend, with what audit
Long-running agentsOpenClaw & variants (viral, feared by IT); Claude Cowork in local VM; Muse for consumers; Scout as niche previewAutopilot: first-party, tenant-resident, own identity/memory/computer/email, @mention like a colleague, permissions+audit, metered"Digital teammate" is a procurement object; identity lifecycle (joiner/mover/leaver for agents) becomes a real admin workflow question
Non-developer software buildingPower Apps (pro-ish), Copilot Studio (makers), vibe-coding tools outside the tenant (Lovable etc.), shadow codeCode: natural-language → sandboxed, tenant-hosted apps; Managed Runtime (preview) as shared governed host, SDK/CLI, Git-backed, opened to third-party/pro-codeFormal "fourth document type"; platform convergence play — external builder apps target the Microsoft tenant runtime
Grounding/contextWork IQ in M365; Fabric/Power BI separate; ad-hoc connectorsFabric IQ GA in Chat + Cowork (20M+ semantic models); D365/Power Platform preview next month; unified plugin registry (IT-approved, publish-once)Context breadth = product claim and metered input; registry positions Microsoft as gatekeeper of agent extensions
Competitive frameOpenAI/Anthropic consumer-first, encroaching on enterprise seatsExplicit super-app parity + enterprise-control pitch; Nadella: hedge labs, "private eval… substitute a model"; cloud-not-local VM dig at Claude CoworkFight moves to IT-approved platform of record; Google/Meta/Salesforce agents remain outside the seat base
⚙

How it works

What is actually available on the event date (announced vs live) — critical for grading claims:

CapabilityStatus on 2026-09-25Source
New Copilot app (Home/Code/Autopilot tabs)Rolling out via Frontier "in the coming weeks"; not GAprimary blog (COMPANY CLAIM)
Home (Chat + Cowork unified)Frontier rollout starts weeks outprimary blog
Office in Copilot (full W/E/P editors)Coming weeks, Frontier + consumersprimary blog; GeekWire
CodeA few Frontier customers already (GeekWire); Frontier end of month; broad availability "coming weeks"; consumer Premium/Pro preview later this yearprimary blog; GeekWire (COMPANY CLAIM)
Autopilot (cloud agent)Private preview at end of month (was Scout preview)primary blog; Reuters
Copilot Managed RuntimePublic preview (host + SDK); powers Cowork/Code/Studio appsdedicated blog (COMPANY CLAIM)
Pricing: USL unchanged for everyday AI; UBB for Cowork/Code/Autopilot in Copilot CreditsPricing structure live/announced today; Cowork billing already live since June 16pricing blog (COMPANY CLAIM; Cowork GA = primary June post)
Admin spending-policy gate ("off until policy")Stated as existing/rollingpricing blog (COMPANY CLAIM)
FinOps additions (Code + Managed Runtime in cost mgmt; model-family control; Graph APIs)"Rolling out today"; Copilot Studio agents Octoberpricing blog (COMPANY CLAIM)
Fabric IQ in Chat + CoworkGA today per Microsoftprimary blog (COMPANY CLAIM)
D365/Power Platform groundingPublic preview over next monthprimary blog
Plugin registry"Rolling out now," GA across surfaces in coming weeks (Andreou briefing: "launch by end of September")primary blog; thelettertwo (minor timing tension — §13)
Today (proactive dashboard)Private preview Octoberprimary blog
@Copilot in Teams (shared context)Private preview by end of monthprimary blog
Learn-doc noteAs of its Sept 25 17:34 UTC update, the UBB service inventory still lists only Cowork, Cowork apps, Work IQ API — Code/Autopilot/Managed Runtime "will be added over time"; auto-apply of policies to future services is on by defaultLearn docs (FACT)
  • The three surfaces (FACT as described; capabilities COMPANY CLAIM until shipped): Home = activity recap + suggestions + Chat (instant Q&A/drafting) + Cowork (delegate an end-to-end job: RFP response, launch kit, briefing, financial close package) + Office in Copilot (real, editable, live-synced docs; @mention teammates; "not just some simplified viewer" — Andreou). Code = NL spec → Copilot picks an approach → builds widget/dashboard/cloud-hosted internal app in a sandbox, hosted in-tenant, grounded by Microsoft IQ, plugins auto-sync, sharing "as simple as saving and sharing a Word document." Autopilot = named agent with role+goal; watches channels, follows up on threads, runs recurring work, resumes projects days later, unattended in a cloud computer inside the tenant; @mention in Teams/Outlook/docs; identity in the company directory with user-controlled permissions (Reuters); Microsoft demo: "Dot," a regional manager's agent that tracked Black Friday inventory across Teams channels, email threads and inventory data, sent daily summaries and flagged a shipment problem affecting 18 stores.
  • Model/routing layer (FACT — pricing blog; primary): USL includes manual model choice (GPT-5.6, Sonnet 5 in; Opus 5 arriving with limits) and Auto, which scores each request on accuracy/speed/cost and routes to a model and reasoning-effort level; fair-use caps with warn→(Auto free | credits) behavior. UBB exposes the frontier end (Astra, Fable) with full model choice. Admins' model-family allowlists propagate into Auto's candidate set — so routing policy is a governance object, not just a product setting.
  • Metering mechanics (FACT — primary docs): UBB is denominated in Copilot Credits = common currency across eligible services ($0.01/credit standard PayGo; P3 pre-purchase with discount; Azure-subscription linkage for billing; consumption reporting by policy/user/group/agent/service/funding source; read-only finance roles). Per-task credit cost = f(model use, context retrieval, tool calls, runtime) — the runtime term is what makes unattended agents financially different: spend accrues while you sleep.
  • Microsoft IQ / grounding (FACT as stated): unified intelligence layer across Work IQ (emails/docs/meetings), Fabric IQ (semantic models), Dynamics/Power Platform data and workflows; plugins = skills + connectors, governed via a single registry with central IT approval.
  • Managed Runtime (FACT as stated — its blog): the tenant-boundary execution plane for generated code: Entra identity, policy-governed connectors/endpoints/auditing, Git-based version/source control with preview/current versioning, TypeScript SDK typed connector services, CLI full-lifecycle, M365 admin-center app inventory (access/usage/health/policy). "Open build, managed run" — third-party tools (SDK-compatible, e.g., Lovable) can deploy into the same governed host.
  • Under the hood (REPORTED, Microsoft-silent at launch): Autopilot is built on OpenClaw (founder confirmation via X, reported by Reworked; Nadella's July "powered by OpenClaw" for Scout; Verge's Build-season Scout/OpenClaw piece). The open question Microsoft didn't resolve at launch is what wrapper-vs-engine governance boundaries look like when the engine is an OSS framework IT departments may themselves block.
!

Why it matters

🎓 For Explorer
  • The pricing model for agentic work just got standardized for the biggest installed base in enterprise software (FACT + INTERPRETATION). USL-for-everyday + Credits-for-autonomy is now the default mental model for roughly 450M commercial seats' worth of organizations, and Microsoft explicitly invites the industry to treat agent spend as FinOps. Finance teams get a new line item class ("where are we spending, are we on track?" is verbatim admin-docs language); rivals (Google, Salesforce, OpenAI, Anthropic) will be priced against this rail.
  • Long-running agents got a first-class identity + governance template (INDEPENDENTLY VERIFIED direction of travel; FACT as to Microsoft's design claims). Own directory identity, scoped permissions, audit, email address, @mention reach, spend caps, model allowlists — the package converts "scary autonomy" (Andreou's own framing) into something procurement can actually sign, and sets the checklist security vendors (cf. Okta's Oktane "Blueprint Alliance" for agent security, Sept 22) and regulators will reference.
  • The autonomy/cost coupling is the honest economics story (FACT mechanics; INTERPRETATION on impact). Frontier agent work is unbounded in runtime; per-task pricing on model+context+tools+runtime with a $0.01 credit is Microsoft saying agent work is a consumption service, not a seat. Combined with off-by-default gating, it is the first big attempt to industrialize agent budgeting before the bill-shock wave — but Reworked's point stands: an Autopilot that keeps operating after you log off "opens a business up to unexpected bills down the line," and cap-setting becomes a new admin art form.
  • Convergence of chat/coding/agents is now contested ground everywhere (INDEPENDENTLY VERIFIED pattern). OpenAI folded Codex into ChatGPT; Anthropic unified Claude chat + Cowork on Sept 16; Microsoft's answer adds the one thing labs lack: the tenant, the identity fabric, the Office files, and 30M+ paying seats to attach agents to. The "AI built for work" positioning (and Verge's skepticism: consumer Copilot "has failed… compared to Claude or ChatGPT") makes this a distribution-and-trust play rather than a raw-capability play.
  • The OpenClaw arc is a live case study in how enterprise AI absorbs open-source (INDEPENDENTLY VERIFIED lineage; INTERPRETATION). From "a virus" (March) to product engine (June, credited in July) to unmentioned launch substrate (Sept): autonomy innovation came from OSS; Microsoft's contribution is wrapper — identity, tenancy, meter, audit. Expect that wrapper-value argument to echo through every agent-platform discussion, and expect Steinberger/OpenClaw licensing terms to matter.
  • Context is becoming the moat with a price tag (FACT + INTERPRETATION). 20M+ semantic models, Work IQ, Dynamics data: grounding breadth is the stated differentiator (Andreou's "hallucination" reassurance framing) — and the same retrieval volume is a billing input. Vendors selling enterprise context (Glean et al., per thelettertwo) just got told the platform owner competes with them at zero migration friction.
✦

What became possible?

🎓 For Explorer
  • Budgeted autonomy: organizations can now formally delegate open-ended, multi-day, unattended work to an employee-like agent (name, role, goal, directory identity) with pre-set financial and model guardrails — instead of shadow-deploying OpenClaw builds on laptops.
  • A governed home for citizen-dev software: purpose-built trackers/dashboards/apps from natural language, tenant-hosted, IT-inventoried, Git-versioned — and now a published path for third-party builders (Lovable pattern) to land in the same runtime.
  • FinOps for AI as a concrete practice: spend policies per group/user, model-family allowlists, credit-request approval flows, Graph API automation of policy, outcome-vs-consumption insights for Cowork — the vocabulary and tooling for agent budgets exists in-product, not just in whitepapers.
  • Model-portability politics at enterprise scale: Nadella's "private eval… substitute a model" hedge, multi-lab USL+UBB, promised open-weight support — buyers get a credible switching story inside one bill; labs get metered distribution; MAI models stay demo-menu-absent for now (GeekWire observation).
  • @mention-to-agent workflows: humans and agents share the same collaboration surface (Teams/Outlook/docs), enabling "delegate in channel, review in channel" patterns — with @Copilot in Teams giving whole channels shared-context AI.
  • A testable template for agent governance (identity + permissions + audit + meter + kill switch via policy) that other platforms, standards efforts (Okta's alliance; S10's rumored lab standards body), and regulators will measure against.
◎

Implications

Technical

  • Runtime becomes a billing dimension and a risk surface: UBB's model+context+tools+runtime formula means agent architectures with unbounded loops have unbounded invoices; expect demand for per-task credit ceilings, step budgets, and "cost-of-completion" telemetry. The Learn "auto-apply new services (default ON)" design means governance policy must be written against future agent services, not today's list — unusual and consequential.
  • Agent identity goes first-class: directory object with own identity/permissions/email + @mention addressability implies joiner-mover-leaver semantics, credential lifecycle, mailbox presence (phishing surface), and audit trails for autonomous actions — Entra/Agent 365 plumbing becomes load-bearing for every long-running agent in the org.
  • Tenant-hosted autonomy vs local-VM autonomy is now an explicit architectural fork: Microsoft bets the enterprise posture (files never leave tenant; Andreou's "local machine into a VM… nonstarter" line vs Claude Cowork's local VM) — pushing sandboxed cloud computers per agent as the compliance-preferred pattern.
  • The "managed run" plane consolidates generated code: Git-backed versioning, typed SDK connector services, policy-enforced endpoints, centralized inventory — a shared runtime for Cowork/Code/Studio apps reduces one-off platform work per app (Blyth: "enterprise readiness becomes the default path") and quietly standardizes how vibe-coded apps touch enterprise data (prompt-injection and data-exfiltration surfaces now pass through one governed choke point — a control and a concentration risk).
  • Grounding-as-a-service: Fabric IQ GA at the semantic-model layer + Work IQ process data (D365 tickets, deal history) means retrieval breadth is now the differentiation vector for agent quality — and grounding volume is metered. Model-family allowlists reshaping Auto's routing is a nice example of governance directly editing inference-path behavior.
  • Multi-model plumbing normalizes frontier churn: Astra/Fable/Opus-5-with-limits/GPT-5.6 + promised open weights — Copilot is explicitly a model channel, with USL absorbing commodity models and UBB exposing premium ones; the pricing split encodes a capability tiering Microsoft expects labs to keep feeding.

Developer

  • Two developer personas now share one tenant: pro developers stay on GitHub Copilot "with more connectivity into the Copilot platform"; citizen developers build via Code. Managed Runtime SDK/CLI (TypeScript, typed connector services, full lifecycle, Git-backed) is the bridge — the interesting new job is making vibe-built artifacts production-tractable inside IT policy. Expect a skills niche: "Copilot Managed Runtime app ops."
  • Build once, distribute into Copilot surfaces: the plugin registry lets ISVs/partners publish skills+connectors once and appear across supported experiences, with IT approval as the gate — a new enterprise distribution channel (and a new app-store-compliance argument to watch).
  • Third-party builders target the Microsoft runtime: Lovable's endorsement previews the pattern — external app builders can deliver into tenant-managed hosting instead of DIY infra. If SDK adoption spreads, "where the app runs" decouples from "where the app was made."
  • Cost-aware engineering enters the stack: with credits tied to model/context/tools/runtime, developers own spend characteristics; the Copilot Credit Estimator (Learn) and Graph policy APIs make cost a first-class configurable — scriptable budgeting is now part of the dev/DevOps surface.
  • Autopilot-as-platform primitive: giving agents a name/role/goal, an identity and an @mention handle invites agent-ops tooling (monitoring dashboards, approval bots, review workflows) and — per this week's S02 disclosures — is exactly the class of autonomous, connected, long-running workload that misalignment and injection research warns about. Agent regression testing and containment hygiene become developer duties, not lab luxuries.

Enterprise

  • Procurement math changes now, rollout later: every M365 Copilot tenant must plan a second budget line (credits) and a policy owner before Cowork/Code/Autopilot are useful; "UBB off until admin creates a spending policy" means an unprepared IT org simply gets no agent value — adoption will track FinOps maturity, not feature availability.
  • The bill-shock question (FACT mechanics; INTERPRETATION risk): runtime-billed unattended agents + default auto-apply of policies to new services = the classic cloud-cost surprise vector; the mitigations are real (caps, alerts, model allowlists, approval routing) but configuring them well is judgment work (what's a per-Autopilot monthly cap? what happens when 50 groups each spin up "Dots"?). Reworked's expert reaction — "how is its identity scoped, audited, and revoked if the user's role changes mid-task?" — is the governance checklist the org must answer before the private preview lands.
  • Finance/security/compliance converge on Agent 365: read-only finance roles, consumption by funding source, Azure subscription/resource-group cost mapping (pricing blog) put AI spend inside existing chargeback machinery — CFO-visible agent economics arrive with the tooling.
  • Seat economics under scrutiny: with USL unchanged and UBB additive, the launch pressures the historical complaint that Copilot adoption was slow — 30M+ paid seats vs 450M commercial seats (~7%, July earnings, reported by GeekWire/Reworked; M365 cloud revenue $100.3B FY26, Copilot share undisclosed). The consumption layer is the answer to "we bought Copilot, it didn't transform us": value re-enters the funnel via usage rather than re-licensing.
  • Shadow-agent consolidation: the practical alternative for most orgs — unsanctioned OpenClaw-family installs on laptops — now has a sanctioned, governed equivalent inside the trust boundary (Andreou: these agents are "almost impossible to bring into the enterprise"). Expect security teams to trade in shadow agents for metered, identifiable ones — and to demand the revocation/mid-task-role-change guarantees Reworked flagged.
  • Consumer/prosumer spillover: M365 Premium/Pro get Code preview and consumer subs get UBB "later this year" — small businesses and prosumers will face credit-budgeting without dedicated FinOps staff; Microsoft's Auto-by-default and warning-then-choose UX are the mitigation to evaluate for your own policies.

Strategic

  • Microsoft converts its distribution/trust advantage into the agent-platform standard (INTERPRETATION): while labs race on raw capability, Microsoft's triple — identity fabric (Entra), context fabric (IQ), and metered billing (credits) — is what CIOs buy. The three-week-old financial-reporting reorg into an "Agents and Infra" segment (SEC 8-K exhibit; Nadella: "connecting the entire trajectory of a 'job to be done'") shows the internal P&L already reorganized around this thesis.
  • "New OS for work" is a land-grab frame with a hedge argument attached (FACT-as-quotes; INTERPRETATION): Nadella's OS claim + his "true independence = private eval you can hill climb on and substitute a model" test recode the anti-lock-in debate: platform-neutral inside a proprietary platform. That is the same posture Microsoft sells Azure on — multi-model as a retention feature. The labs' counter-risk: being metered channels erodes their direct enterprise relationships, hence their own super-app/unification moves (Codex-in-ChatGPT; Claude+Cowork on Sept 16).
  • The OpenClaw arc ends with the platform eating the movement (INDEPENDENTLY VERIFIED lineage; INTERPRETATION): the viral OSS agent ecosystem (OpenClaw, Claw variants — also the ancestor lineage The Verge traced in Meta's Muse) delivered autonomy; Microsoft delivered compliance; Scout→Autopilot is the enclosure moment. Strategic questions left open: what happens to the OSS community's leverage (licensing, attribution — Steinberger is at least publicly credited by his own confirmation), and whether enterprises treat "powered by OpenClaw" as a selling point or a liability (cf. Nadella's own March "virus" line, which Reworked's 404-Media detail keeps alive).
  • Credibility debt is the real currency at stake (INDEPENDENT EVIDENCE): Copilot's brand history is repeated redesigns and missed promises (Verge: "redesigned Copilot plenty of times"; consumer failure vs ChatGPT/Claude; features killed in the merge). The Verge's skeptical frame — Microsoft "has certainly fallen behind the likes of Google, OpenAI, Anthropic, and now Meta" — means the market will grade this launch by shipped availability and bill predictability, not keynotes; the preview-heavy rollout schedule makes Ignite (Nov 17–20) and the Frontier timeline the real proof points.
  • Competitive map for agents, restated: Microsoft's differentiation is explicitly not the frontier agent itself (it buys the engine) but the tenant-resident, governed, metered wrapper — against Google's Gemini Enterprise surface, Salesforce/Slack's "agentic OS" (thelettertwo comparison), and the labs' direct-to-enterprise apps. If consumption attach works, the Copilot bill becomes the platform's gravity well.
⚠

Risks & limitations

Risks
  • Bill-shock / cap-miscalibration: runtime-metered autonomy plus auto-applying policies to future services; one mis-set group policy and an overnight agent fleet burns budget (Reworked's core warning; Microsoft's mitigations are admin-config, i.e., human-dependent).
  • Agent identity lifecycle gaps (unresolved as of launch): mid-task permission changes, agent offboarding, delegated-authority creep, and @mention-ability as a social-engineering surface (an employee can now DM a tenant-resident computer with org data access). Microsoft's launch materials assert "permissions, audit and governance" without publishing revocation semantics — exactly the question practitioners asked.
  • Prompt-injection scaling (INTERPRETATION, anchored by this week's independent evidence): a persistent agent that watches channels/email and executes in-tenant is a high-value target for injected instructions; S02's disclosure week showed frontier agents misbehaving in exactly these connected environments. Governance wrappers don't fix model-level vulnerabilities; watch how Copilot's content-provenance/instruction-hierarchy claims hold up.
  • Preview-washing and credibility burn: nearly everything is "coming weeks"/"end of month"/"later this year"/private preview; the Learn UBB inventory hadn't yet listed Code/Autopilot at launch day 17:34 UTC; plugin-registry timing differs slightly between the blog and the briefing. If GA slips (Copilot has form), the FinOps story gets discounted too.
  • Naming/collision confusion: "Autopilot" collides with Windows Autopilot and Tesla's brand memory; "Code" vs GitHub Copilot; "Home/Today" vs Windows/Outlook constructs — adoption materials will face disambiguation friction (minor, real).
  • Dependence asymmetry: Microsoft meters and markets OpenAI/Anthropic frontier capacity while its own MAI models were absent from the demo menu (GeekWire) — the multi-model hedge is currently thin on Microsoft-side premium capability; UBB margins and lab relationships can both squeeze it.
  • Citizen-dev sprawl: Managed Runtime governance is policy-based, but the quality/maintenance of thousands of vibe-built internal apps remains someone's problem; "the fourth document type" invites an internal-software debt class IT isn't staffed for.
  • Regulatory/standards exposure: FTC chair's same-day statement (reported by Reuters in the Sept 25 news cycle) that AI developers should be liable for agent conduct lands squarely on metered-tenant-agents; agent audit standards are being written by others (Okta alliance) — Microsoft's stack must keep answering external criteria, not just its own.
Limitations
  • No hands-on access: the app, Code, Autopilot and Managed Runtime are preview/Frontier-gated; every capability behavior here rests on Microsoft's posts/briefing transcript + journalist briefing reports. Nothing in this file has been operationally verified by us; all such claims are labeled COMPANY CLAIM.
  • Techcommunity fetch gating: the pricing blog and FinOps blog are 403 to this environment's fetchers; the pricing blog was read in full via the dated Wayback snapshot 2026-09-25 14:09:58 UTC (content complete, version 5.0). The dedicated FinOps-for-AI post (aka.ms/finopsforai/optimization → techcommunity) has no retrievable snapshot; its content is represented in the pricing blog's own FinOps section, so no claim rests on the un-fetched page.
  • Primary-doc lag found: the Microsoft Learn UBB overview (updated Sept 25 17:34 UTC) lists only Cowork/Cowork-apps/Work IQ API as UBB-managed services — Code/Autopilot/Managed Runtime are not yet enumerated there, consistent with Reworked's "moving target" and unresolved Autopilot-credit-migration question. Don't over-read "announced" as "documented/administered."
  • Media-event quotes are second-hand: Andreou/Nadella/Spataro briefing quotes come via GeekWire/thelettertwo (from a Microsoft-provided transcript) and The Verge/Reworked; Nadella's X post and Steinberger's X post were not directly retrievable here and are cited through those carriers.
  • Internal analyses are Microsoft's: the USL-vs-competitors cost chart (pricing blog), the "30–40% cheaper than Claude Cowork" claim (June blog, 125 internal test runs), "most of the Fortune 500" Cowork usage, engagement metrics (+25% speed, 8× daily usage) and the "over 30 million seats" figure are unaudited company numbers.
  • Model-name ambiguity: Astra/Fable/GPT-5.6 Sol/Opus 5/Sonnet 5 naming follows Microsoft's and GeekWire's usage (GeekWire glosses "OpenAI's Astra and Anthropic's Claude Fable"); the launch blog does not attribute Astra/Fable to specific labs — treat lab attribution as reported-by-GeekWire.
  • Scout blog not directly fetched (June 2 post; identified via launch links and The Verge/Reuters' "unveiled in June"); its Build-era OpenClaw framing is carried by The Verge/GeekWire/Reworked/thelettertwo.
  • Discovery-summary corrections applied (see §1: Auto belongs to USL; "end of month" not "later in September"); no material discovery claim failed verification. The rejected-candidate note that tied "ChatGPT Voice agentic mobile rollout" to S03 was not confirmed by any retrieved S03 artifact and is not carried here.
?

Open questions

  • Autopilot's actual billing rail and rate card: does it move fully onto Copilot Credits from GitHub Copilot credits (Reworked: unstated), and what does an always-on Autopilot-hour cost in credits at GA? Microsoft has published no per-task credit prices for Code or Autopilot yet.
  • Revocation semantics: when a human's role changes mid-task, what happens to their Autopilot's delegated access (Reworked's practitioner question)? Does Agent 365 publish agent-identity lifecycle docs before Ignite?
  • Consumer UBB design: what do "later this year" usage-based billing consumer M365 Premium/Pro users actually see — caps, warnings, or hard stops — and will consumer agent bills become a support/social-media story?
  • GA timeline discipline: do Home/Code land "within weeks" and Autopilot private preview by Sept 30 as stated? Does the plugin registry ship end-of-September (briefing) or "coming weeks" (blog)?
  • Model economics: will anything move back from UBB into USL (pricing blog promises some will as "economics allow")? When do open-weight models join, and does MAI ever reach the demo menu? How tight does Auto actually route once Opus 5-with-limits lands?
  • Third-party runtime adoption: beyond Lovable, do Cursor-class/agent builders deploy Managed Runtime SDK targets, and does GitHub Copilot feed the same host (blog says Code reuses its technology)?
  • Liability stance: with metered, supervised agents, how does Microsoft answer "developer liable for agent conduct" (FTC chair) — does audit/evidence packaging for Autopilot actions become part of the compliance offer?
  • Does "powered by OpenClaw" survive contact with enterprise security review — do any Autopilot private-preview participants get the "same autonomy, plus a meter" pitch tested against OSS supply-chain concerns Nadella himself raised in March?
↗

What happens next?

🎓 For Explorer

Days–weeks: Autopilot private preview opens (≈ Sept 30); Code reaches Frontier end of month; Home/Office-in-Copilot to Frontier "coming weeks"; D365/Power Platform grounding enters public preview through October; plugin registry GA. Expect preview-billing anecdotes and first real-world credit-cost reports (and first cap-misconfiguration horror stories) within weeks of Autopilot preview landing. October: Copilot Studio agents join Agent 365 cost management; Today private preview. Nov 17–20: Ignite — the credibility checkpoint where preview→GA conversion, per-service credit rate cards, and Autopilot's GitHub-credits-vs-Credits billing question should be answered; Q1 FY27 earnings (late Oct) will be the first to report under the "Agents and Infra" segment and the first to carry any consumption revenue narrative. PREDICTION: (a) Google's Gemini Enterprise will extend seat-plus-consumption pricing within ~two quarters because Microsoft just gave CIOs a comparison rail; (b) at least one bill-shock incident (unattended-agent overrun) will surface publicly before GA, and Microsoft will respond with per-agent hard caps/step budgets rather than policy docs; (c) the Managed Runtime will add a marketplace-like discovery surface by mid-2027, pulling Copilot Studio and third-party builders into one inventory; (d) expect a rename/consolidation of "Autopilot" naming collisions (Windows Autopilot) to be clarified at Ignite; (e) Auto-router telemetry published later will show the allowlist-constrained picker materially shaping lab mix — an early read on whether "multi-model hedge" changes OpenAI/Anthropic enterprise revenue share.

★

Editorial takeaway

🎓 For Explorer

The app redesign is the headline; the meter is the story. Microsoft quietly did what nobody else had: made long-running autonomy a billable, budgeted, IT-gated utility for the platform that owns the world's office seats — everyday AI stays a flat subscription ("metering everyday AI is the wrong deal"), while agents that work while you sleep run on runtime-metered credits with names, identities, email addresses and — crucially — spending policies that are off by default. It's also the most candid launch in Copilot's history about where the good ideas came from: the autonomy engine is OpenClaw, the thing Nadella called a virus in March, now tenant-wrapped and un-mentioned in the blog post. So give the demo its due — @mention your agent like a colleague, it flags a shipment problem across 18 stores — but hold the keynote confidence against the calendar: Home, Code and Autopilot are previews and "coming weeks," the Learn admin inventory didn't even list the new services on launch evening, and Copilot's brand promise has been redesigned into the ground before. Judge Microsoft on two dates, not one: Sept 30 (does Autopilot preview actually open) and Ignite in November (does anyone's bill survive it). If both hold, seat-plus-consumption becomes the enterprise AI standard and agent governance becomes this decade's cloud cost management. If they slip, this joins the long list of Copilot relaunches — with a meter nobody's paid yet.

⌘

Lab: NO-LAB

Step 1 — VERIFY: launch-day "announced vs administered" audit (executed 2026-09-26)

Check which of the three UBB surfaces (Cowork, Code, Autopilot) are actually wired into the billing machinery on the event date, using only primary docs:

  1. Pricing blog (Sept 25): announces all three under UBB + Copilot Credits, with the "off until a spending policy exists" gate. ✅ as claimed.
  2. Learn UBB overview (ms.date 2026-09-25, updated 17:34 UTC same day): the enumerated "services managed by usage-based billing" list contains only Cowork, Cowork-built apps and Work IQ API — Code and Autopilot are not yet listed; "Microsoft will add more agents and services over time," and spending policies auto-apply to future services by default. Executed: curl + fetch of https://learn.microsoft.com/en-us/microsoft-365/copilot/usage-based-billing-overview-copilot-credits confirms this inventory on retrieval 2026-09-26.
  3. Plugin registry timing: launch blog says GA across surfaces "in the coming weeks"; Andreou at the briefing said "launch by the end of September" (thelettertwo). Minor discrepancy; unresolved.
  4. Credit constant: $0.01/credit PayGo stated independently in two primary docs (June 16 GA blog; Learn) and carried by Reworked — cross-checked. ✅ consistent.

Pass criteria: every research/S03.md §5 status-table row is traceable to a fetched primary doc, and the gap between "announced pricing" and "documented admin inventory" is recorded. Result: PASS — gap found and flagged (research/S03.md §5, §13): treat "UBB now covers Code/Autopilot" as COMPANY CLAIM (announced) while the admin-documented inventory lags, and note that auto-apply default-ON means your future services inherit policies silently.

Step 2 — SIMULATE: 1,000-seat org monthly agent bill (the bill-shock model)

Constants from Microsoft (FACT-as-published): 1 Copilot Credit = $0.01 (PayGo); task cost = f(model, context, tools, runtime); model at all is a per-group choice variable. Everything else below is ASSUMPTION (illustrative; no Microsoft rate card exists for Code/Autopilot yet — that is itself finding #1).

Model: monthly cost = seats·S + Σ(users × task-mix × per-task credits) + agents × R × hours·mo × $0.01, with S = negotiated seat price (example: $30/mo — substitute yours).

Toy 1,000-seat org (all ASSUMPTIONS, clearly flagged):

InputIllustrative valueSource/status
USL seats1,000 × $30 = $30,000/moS assumed; USL unchanged per pricing blog
Cowork task creditslight 10 / medium 50 / heavy 200 credits (= $0.10 / $0.50 / $2.00 per task)ASSUMPTION — Microsoft's per-task figures live in infographics/estimator; replace with your Frontier logs
Cowork usage40% of users: 20 light + 4 medium + 1 heavy monthlyASSUMPTION
→ Cowork subtotal400 users × (20·10 + 4·50 + 1·200) = 400 × 600 = 240,000 credits = $2,400/mocomputed
Autopilot fleet50 agents, 24×7×365 ≈ 730 h/moscenario
Autopilot burn rate Rscenario sweep: 2 / 20 / 100 / 411 credits per hourASSUMPTION (runtime term unknown)

Sensitivity result (the headline arithmetic): one always-on Autopilot costs 730·R·$0.01 = $7.30 × R per month.

  • R = 2 (idle watcher): $14.60/mo — cheap as a seat.
  • R = 20 (active): $146/mo ≈ 5 seats each → 50 agents ≈ $7,300/mo.
  • R = 100 (heavy tool-use loop): $730/mo each → 50 agents ≈ $36,500/mo > the entire $30,000 seat bill.
  • Break-even: one agent matches one $30 seat at R ≈ 4.1 credits/hour.

Deliverable: this table in a spreadsheet with your S, your task mix, and three R scenarios; plus the policy answer each scenario forces: which group caps, model-family allowlists (they shrink R by routing to cheaper models — pricing blog), and stop-conditions does each fleet get before preview access is enabled? Also compute the auto-apply exposure: services added later (Copilot Studio agents, October) inherit your policy defaults silently.

Step 3 — VERIFY (design): agent-identity governance checklist vs Microsoft's own answers

Take the practitioner questions raised on-record (Reworked reactions + Reuters interview) and turn each into a tenant-readiness test you can run on paper before Autopilot private preview lands: (1) identity in directory → does your IAM process handle agent joiner-mover-leaver, and who owns an agent when its human leaves? (2) mid-task role change → what is your expected revocation semantics, and does Microsoft document them yet? (check https://learn.microsoft.com/en-us/microsoft-365/copilot/ monthly + Agent 365 docs; record gap). (3) @mention reach in Teams/Outlook → add "agent-addressable assets" to your phishing/injection model (connect to S02 evidence: connected agents + injected instructions is this week's demonstrated failure class). (4) audit → confirm which Autopilot actions emit to your audit log/SISA and export path. Deliverable: one-page readiness memo with owner assigned per control, citing the specific Microsoft doc or "not documented — ask vendor" per row.

Step 4 — TEST (deferred; requires Frontier/preview access): first-contact protocol for Autopilot + Managed Runtime

When your tenant gets preview access: (a) create one Autopilot with a trivial 2-week goal; log every day its realized credit burn, what the runtime term actually bills for (idle vs active hours split), and whether alerts/caps fire at your threshold — this replaces Step 2's ASSUMPTION R with a measured R; (b) deploy one Managed Runtime sample app via SDK/CLI from a normal dev machine — verify Git-backed versioning, typed connector services, Entra sign-in inheritance, and admin-center inventory appearance latency; (c) try the sanctioned failure: ask Code to build a tracker that reads a data source your policy disallows — verify the policy gate bites before code runs, not after. Record screenshots; publish as a measured-vs-claimed comparison. Guardrail: stay inside your own tenant; no probing third-party data; disable the agent and set a per-user credit cap as step (a)(0).

Safety & scope guardrails (binding)

  • Steps 1–3 read public documents and compute arithmetic; Step 4 is design-only until preview access exists.
  • All non-Microsoft numbers in Step 2 are ASSUMPTIONS by construction and must be labeled as such in any reuse; never present the simulated bill as Microsoft pricing.
  • In Step 4, the policy-gate test (c) uses your own tenant data only.

Deliverable

One page: (1) the VERIFY audit finding (announced-UBB vs documented-UBB inventory gap + auto-apply exposure + registry-timing discrepancy); (2) the parameterized spend model with the break-even insight (R ≈ 4.1 credits/hour turns one always-on agent into one seat of cost; at R=100, a 50-agent fleet outbills 1,000 seats); (3) the identity-governance readiness memo mapped to Microsoft's published control surface. Feeds the FinOps-advisory and agent-governance consulting lines (research/S03.md §18) and the Circle-2/3 actions (§16–17) — with your measured numbers replacing our assumptions the moment preview access lands.

Duration: ~2–3 hours; steps 1 and 2 are done/cheap; step 3 is a facilitated checklist; step 4 costs nothing until GA-adjacent access.

≡

Research sources

Primary Sources (9)
Primary
TechCrunch — "Anthropic merges Claude chat and Cowork into one interface" (cited by thelettertwo for the convergence pattern) URL: https://techcrunch.com/2026-09-16/anthropic-merges-claude-chat-and-cowork-in-one-interface/ Type: Reputable technology news (pre-window context) Date: 2026-09-16 Used for: competitive-convergence claim in §3/§11 (OpenAI/Anthropic super-app moves); not fetched — carried via thelettertwo's citation. Evidence role: secondary note.
URL unavailable
Primary
Microsoft SEC 8-K/press exhibit — financial reporting segment change (Agents and Infra) URL: https://www.sec.gov/Archives/edgar/data/789019/000119312526380280/d291965dex991.htm Type: Regulatory filing (company publication) Date: early September 2026 (three weeks before launch, per GeekWire) Used for: re-segmentation context cited in §4/§11 — carried via GeekWire's report; filing itself not independently parsed this session. Evidence role: identified primary; via GeekWire.
URL unavailable
Primary
Satya Nadella X post and Peter Steinberger X post URLs: https://x.com/satyanadella/status/2103455884366188544 ; https://x.com/steipete/status/2103491173927272531 Type: Directly-involved individuals' public posts Date: 2026-09-25 (per The Verge "this morning" and Reworked reporting) Used for: Nadella's "new OS for work" quote (carried by The Verge) and Steinberger's OpenClaw-confirmation for Autopilot (carried by Reworked). X posts not directly retrievable in this environment; quotes used via the named reputable carriers. Evidence role: independent individuals' statements via carriers.
URL unavailable
Primary
Microsoft Scout introduction blog — "Introducing Microsoft Scout, your always-on personal agent" URL: https://www.microsoft.com/en-us/copilot/blog/2026-06-02/introducing-microsoft-scout-your-always-on-personal-agent/ Type: Official announcement (pre-window; Scout's Build debut) Date: 2026-06-02 (per linked URL; not fetched this session) Used for: Scout launch-date context, corroborated by Reuters ("unveiled in June"), The Verge ("at Build earlier this year"), GeekWire and thelettertwo. Listed for provenance; no claim rests solely on it. Evidence role: identified primary; not retrieved.
URL unavailable
Primary
Microsoft Copilot Blog (AI at Work) — "Copilot Cowork is now generally available" (Charles Lamanna, EVP Copilot, Agents, and Platform) URL: https://www.microsoft.com/en-us/copilot/blog/2026-06-16/copilot-cowork-is-now-generally-available/ Type: Official product announcement (pre-window context; linked from the Sept 25 launch blog) Date: 2026-06-16 Used for: The "Before" baseline — Cowork GA after 3-month Frontier preview (Mar 30–Jun 16); "more than half of the Fortune 500" (COMPANY CLAIM); usage-based billing in Copilot Credits with USL required; **PayGo priced at $0.01 per Copilot Credit**; per-task price computed from four inputs (model use, context retrieval, tool calls, runtime); light/medium/heavy task pattern framework + four user personas + downloadable cost estimator (https://aka.ms/CustomerCoworkEstimator — xlsx, not fetched); models at GA (Anthropic Opus 4.8, Sonnet 4.6; GPT 5.5 in Frontier; "Cowork 1" own model promised); cost-management controls at GA (off by default, tenant/group/user limits, alerts, credit requests, per-task user-level pricing display); grace-period billing history; the "30–40% cheaper than Claude Cowork" internal-analysis footnote (125 test runs; COMPANY CLAIM); cloud hosting (files not local; tasks keep running when laptop off). Evidence role: Primary; independently corroborates the credit-pricing constant used across reporting and in our lab simulation.
URL unavailable
Primary
Microsoft Copilot Studio Blog — "Build where you want, run with confidence: Now Microsoft hosts and manages the code created by Copilot" (David Blyth, VP & GM, Managed Apps and Agents) URL: https://www.microsoft.com/en-us/copilot/blog/copilot-studio/build-where-you-want-run-with-confidence-now-microsoft-hosts-and-manages-the-code-created-by-copilot/ Type: Official product announcement (companion post, linked from launch blog via https://aka.ms/CopilotManagedRuntime-Blog) Date: September 25 (2026), 5-min read Used for: Copilot Managed Runtime **public preview** detail — enterprise-grade platform running AI-generated code within the Microsoft 365 tenant boundary; already powers apps built in Copilot Cowork, Copilot Code and Copilot Studio; opening to third-party tools and professional developers (SDK-compatible); Entra identity, org policies for connectors/data/endpoints/auditing, Git-backed automatic version/source control, Work IQ + connector integration; host capabilities list (Microsoft-hosted runtime, deployment/versioning/lifecycle controls, central inventory/monitoring in M365 admin center); SDK/CLI full lifecycle (scaffold, typed TypeScript connector services, run/preview, deploy/version); "open build and managed run" separation thesis; Lovable testimonial (Lan Roche, Head of Global Partnerships): apps made with Lovable run inside the tenant "same sign-in, same policies, same app inventory." Evidence role: Primary; the architecture behind the Code/runtime claims.
URL unavailable
Primary
Microsoft Learn — "Usage-Based Billing and Cost Management for Copilot Credits" URL: https://learn.microsoft.com/en-us/microsoft-365/copilot/usage-based-billing-overview-copilot-credits Type: Official product documentation (admin-facing) Date: ms.date 2026-09-25; page updated_at 2026-09-25T17:34 UTC (retrieved 2026-09-26) Used for: Credits as "common currency" across eligible services; billing methods (fixed licensing, Copilot Credit Pre-purchase Plan P3, pay-as-you-go, prepaid capacity packs); M365 admin-center Cost management dashboard capabilities (spending policies, access control, org/user limits, alerts, credit-request routing, consumption by policy/user/group/agent/service/funding source, read-only finance roles); **the launch-day service inventory under UBB still lists only Cowork, Cowork-built apps and Work IQ API** (Code/Autopilot/Managed Runtime "added over time"); the "Auto-apply new services" default-ON policy behavior; Azure subscription linkage; Copilot Credit Estimator link; Cowork toggle enabling app-building by default; Apps inventory in admin center. Evidence role: Primary; independent-of-marketing confirmation of the billing machinery, and the source of the launch-day "announced vs documented" gap noted in research/S03.md §5 and §13.
URL unavailable
Primary
Microsoft Tech Community (Microsoft Copilot Blog) — "Evolution of the Copilot pricing model" (Nicole Herskowitz, corporate VP AI at Work) Canonical URL: https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/evolution-of-the-copilot-pricing-model/4559416 Retrieved via: https://web.archive.org/web/20260925140958/https://techcommunity.microsoft.com/blog/microsoft-copilot-blog/evolution-of-the-copilot-pricing-model/4559416 (Wayback snapshot of 2026-09-25 14:09:58 UTC; page "Updated Sep 25, 2026, Version 5.0") Type: Official pricing/licensing explainer (companion post linked from the launch blog via https://aka.ms/Sept25/EvolvingModel) Date: 2026-09-25 Used for: USL = everyday AI at fixed per-user-per-month price ("no changes to the value you already have"; anti-metered-everyday positioning: "when every task has a meter, companies may ration access"); "saturation" concept; Auto routing to model *and reasoning effort*; GPT-5.6 and Sonnet 5 included, Opus 5 "with limits"; fair-use limits (warn → Auto free or credits); Advanced AI = Cowork, Code, Autopilot, SharePoint advanced experiences, frontier models Fable and Astra, all on usage-based billing in **Copilot Credits**, UBB requires USL ("plug-in hybrid" analogy); multi-lab (OpenAI + Anthropic today, more labs and open-weight coming); the enterprise gating design — "UBB services stay off until an admin creates a spending policy… nothing is billed before that"; budgets at tenant/group/user levels, alerts, configurable limit behavior; Azure subscription/resource-group spend mapping; reporting by user/group/workload/policy/payment method; new FinOps capabilities (Code + Managed Runtime coverage, Copilot Studio October; model-family access per group starting Cowork; Cowork consumption insights; Microsoft Graph API policy management; end-user spend visibility); the "some capabilities will move from UBB into the USL as economics allow" commitment; internal cost-comparison chart (Microsoft internal analysis, Sept 2026, 40 prompts × 10, Copilot vs Claude vs ChatGPT for everyday/advanced profiles). Evidence role: Primary; the authoritative statement of the pricing change (the story's critical claim). Direct fetch returned 403; Wayback used (content complete).
URL unavailable
Primary
Official Microsoft Blog — "Introducing the new Copilot with Home, Code and Autopilot" (Jared Spataro, Chief Marketing Officer, AI at Work) URL: https://blogs.microsoft.com/blog/2026-09-25/introducing-the-new-copilot-with-home-code-and-autopilot/ Type: Official company announcement (launch blog; primary source of record) Date: 2026-09-25 (published 12:03:50 UTC per search metadata) Used for: The entire launch frame — three surfaces (Home = Chat + Cowork + Office in Copilot; Code powered by GitHub Copilot technology, sandboxed/tenant-hosted; Autopilot formerly Scout — persistent proactive personal agent with own identity, memory, computer and workspace in tenant, @mention in Teams/Outlook/channels/documents); rollout timelines (Home + Code via Frontier "coming weeks," Code Frontier end of month + broad availability in weeks + M365 Premium/Pro preview later this year; Autopilot private preview end of month); Microsoft IQ grounding layer; Fabric IQ GA in Chat and Cowork with 20M+ Power BI semantic models; Dynamics 365/Power Platform grounding public preview next month; plugin registry (unified catalog, IT approval, GA across surfaces in coming weeks); pricing frame (USL with Auto routing weighing accuracy/speed/cost; UBB for Cowork, Code, Autopilot and frontier models Astra and Fable); FinOps for AI intro (Agent 365 cost management expanding to Code + Managed Runtime, Copilot Studio October; model-family allowlists shaping Auto; credit-request routing; Graph APIs; user credit visibility); Today (private preview October) and @Copilot in Teams (private preview end of month); Frontier program; Ignite Nov 17–20; link to Cowork GA June 16 post. Evidence role: Primary; anchors the event date and every feature/rollout claim (COMPANY CLAIM on capabilities/timing, CONFIRMED on the announcement's content).
URL unavailable
Independent Sources (5)
Independent
The AI Economy at thelettertwo.com — "Microsoft's Rebuilt Copilot Is a Bet on How Companies Will Work Next" (Ken Yeung) URL: https://thelettertwo.com/2026-09-25/microsoft-copilot-rebuilt-home-code-autopilot/ Type: Independent technology/business analysis newsletter-blog (former VentureBeat writer) Date: 2026-09-25 (16-min read) Used for: Sept 23 Frontier customer event detail (Nadella 1981 Excel anecdote; "architects of that new frontier of work"); consumer/commercial merger history and June Build "chat, Cowork, and code all in Copilot" phrasing; the OpenAI-Codex-merge and Anthropic-Claude+Cowork-merge (Sept 16) convergence pattern; Andreou consumerization quotes and ~90M self-paying M365 users; Andreou quality metrics (speed +25%, engagement/satisfaction doubling, daily usage 8× — COMPANY CLAIMs via briefing); consumer features killed in the merge (Copilot Podcasts, Group Chat, Deep Research); Andreou's three-barriers rationale for Code (CLI intimidation, local setup, hosting/sharing) and "as simple as saving and sharing a Word document"; sandbox-by-default development; competitor list for long-running agents (OpenClaw + Claw variants, Hermes Agent, Gemini Spark, Instinct, Meta's Muse) and "almost impossible to bring into the enterprise"; Slack/Slackbot agentic-OS comparison and Microsoft's files/distribution/identity differentiators; Cowork first introduced in March with Anthropic help (VentureBeat link); Spataro USL/UBB explainer quotes incl. consumer UBB later this year; Agent 365 governance framing; "Autopilot is equipped with enterprise-grade security and control… trusted… from day one" (COMPANY CLAIM); Microsoft IQ emphasis as context-moat trend (Glean/Salesforce/Google); Fabric IQ GA-today; Work IQ D365/Power Platform preview; **plugin registry "launch by end of September"** (minor timing tension vs blog's "coming weeks" — flagged); Today and @Copilot in Teams detail incl. Slackbot parallel; Scout June 2 blog link https://www.microsoft.com/en-us/copilot/blog/2026-06-02/introducing-microsoft-scout-your-always-on-personal-agent/ (identified, not fetched). Evidence role: Independent; briefing-level color, convergence framing and the registry-timing discrepancy used in §5/§13.
URL unavailable
Independent
Reworked (Simpler Media) — "Microsoft Rebuilds Copilot as an 'OS for Work'" / "Microsoft Overhauls Copilot and Splits Copilot Pricing Between Seats and Credits" (Siobhan Fagan, editor-in-chief) URL: https://www.reworked.co/digital-workplace/microsoft-rebuilds-copilot-as-an-os-for-work/ Type: Reputable enterprise digital-workplace trade press (independent analysis + practitioner reactions) Date: 2026-09-25 Used for: Nadella "biggest Copilot update to date" + LinkedIn post; preview-status inventory (Home weeks / Code end of month / Autopilot private preview end of month); pricing breakdown incl. **Copilot Credit costs a penny under standard pay-as-you-go pricing** (citing https://learn.microsoft.com/en-us/microsoft-365/copilot/usage-based-billing-overview-copilot-credits), task credits = model/data-read/tools/runtime, and the **bill-shock analysis** ("Given Autopilot's ability to continue operating after the user logs off, this opens a business up to unexpected bills down the line"); the Autopilot billing-migration gap (July licensing: Scout on GitHub Copilot credits, no published pricing — Orchestry CEO Michael Pisarek; "hasn't said whether it moves fully onto Copilot Credits"); **OpenClaw founder Peter Steinberger confirmed Autopilot is built on OpenClaw** (https://x.com/steipete/status/2103491173927272531) and Scout's June OpenClaw build (own prior coverage https://www.reworked.co/digital-workplace/microsoft-scout-is-built-on-openclaw/), Nadella's Morgan Stanley "launching a virus" anecdote, 404 Media's "Make people addicted" internal-docs detail; practitioner reactions (training/certification demand quote; "value… got stuck wherever we asked the tool to act on its own and nobody had pinned down what 'done' meant"; identity-scope/audit/revoke-mid-task security question); adoption history (January 15M-seats disclosure as first slow-adoption sign; July >30M; 450M base). Evidence role: Independent; pricing analysis, lineage confirmation and the governance-question set that shapes §12–§17.
URL unavailable
Independent
GeekWire — "Microsoft unveils all-in-one Copilot app, taking on Anthropic and OpenAI in new push to boost adoption" (Todd Bishop) URL: https://www.geekwire.com/2026/microsoft-unveils-all-in-one-copilot-app-taking-on-anthropic-and-openai-in-new-push-to-boost-adoption/ Type: Reputable regional technology news (Microsoft beat) Date: 2026-09-25, 5:00 AM PT (12:00 UTC), updated 5:14 AM PT Used for: Wednesday briefing + Microsoft-provided transcript; promises timeline (Build June "come summer"; July 29 earnings "this quarter" ending Sept 30; "meets that deadline with less than a week to spare, and most of the new features won't be widely available until later"); "without officially calling it that" for super app; OpenAI/Anthropic direct-to-enterprise competitive frame; Andreou's local-VM "complete nonstarter" line (apparent Claude Cowork contrast); Nadella's "private eval… hill climb… substitute a model" independence test and knowledge-transfer warning; demo model menu (GPT/Opus/Auto; MAI + xAI on slides but not menu); Office-in-Copilot demo detail and "not just some simplified viewer"; Spataro "two kinds of AI at work… two very different ways of paying"; consumer M365 subs adding UBB later this year; Nadella July "per-seat-plus-consumption"; Agent 365 limits control; the OpenClaw→Scout→Autopilot arc (March "virus" remark; June Scout "first of its Autopilots"; July "powered by OpenClaw"; Scout name dropped; users create/name their own Autopilots); Andreou autonomy/IT-terrifying quote; Autopilot own identity/memory/**email address**; the "Dot" Black-Friday inventory demo (18-store shipment flag); adoption math (>30M paid seats July, up from 20M April; ~7% of 450M+ commercial seats; M365 cloud revenue $100.3B FY26 +19%; Copilot not disclosed); the financial-reporting reorg three weeks prior (Agents and Infra segment; GitHub cloud revenue into M365; SEC exhibit https://www.sec.gov/Archives/edgar/data/789019/000119312526380280/d291965dex991.htm and Nadella "job to be done" quote); Ignite Nov 17–20. Evidence role: Independent; the deepest corroborating record of briefing statements, timelines and business context.
URL unavailable
Independent
Reuters — "Microsoft revamps Copilot with code generation, agentic AI tools" (Deborah Mary Sophia; editing Leroy Leo) URL: https://www.reuters.com/technology/microsoft-revamps-copilot-with-code-generation-agentic-ai-tools-2026-09-25/ Type: Reputable wire service (independent news + same-day executive interview) Date: 2026-09-25, 12:01 PM UTC Used for: Independent confirmation of the launch shape (one-stop shop; Office embedded; Code end-of-month early access, Premium/Pro preview later this year; Autopilot = "revamp of the Scout AI agent it unveiled in June," private preview end of month); Autopilot "will carry its own identity in the company directory and have specific permissions that users can control" (Annie Dix-Pearl, corporate VP of Copilot Product, interview); the security/compliance/governance difficulty quote ("very hard for many organizations to bring agents into the enterprise"); cost-management framing against enterprise fear of "rapid AI usage racking up unexpected costs"; market reaction: **shares rose about 3% in early trading**. Evidence role: Independent; wire-grade verification + the identity-in-directory detail and market reaction.
URL unavailable
Independent
The Verge — "Microsoft thinks its new Copilot 'super app' will be as influential as Office" (Tom Warren) URL: https://www.theverge.com/news/1000532/microsoft-copilot-super-app-chat-coding-autopilot Type: Reputable technology news Date: 2026-09-25, 12:00 PM UTC (updated Sept 25 with Nadella's comments) Used for: "Super app" framing (headline use; "after teasing… last month" with link to https://www.theverge.com/tech/972927/microsoft-copilot-super-app-confirmed); Scout originally unveiled at Build earlier in the year (link https://www.theverge.com/news/939713/microsoft-scout-assistant-openclaw), initially a desktop app, Autopilot the cloud equivalent; three-tab design building on the consumer/commercial app merge (https://www.theverge.com/tech/979466/microsoft-copilot-365-app-unified-experience) and leadership changes / first single Copilot boss (https://www.theverge.com/news/895963/microsoft-copilot-leadership-changes-consumer-commercial); Nadella X quote "new OS for work that spans every model, every form factor, and every task" (https://x.com/satyanadella/status/2103455884366188544) and Spataro's Office-era comparison quote; skeptical frame (Copilot failed in consumer vs Claude/ChatGPT; "not really designed to compete with things like Muse"; Microsoft "fallen behind… Google, OpenAI, Anthropic, and now Meta"); pricing/rollout confirmation (UBB for Cowork/Code/Autopilot and Astra/Fable; USL for Chat+Office apps; auto model picker; FinOps needed to keep agentic usage in check; Home/Code Frontier "coming weeks"; Autopilot private preview later this month; Code preview for M365 Premium/Pro later this year). Evidence role: Independent; launch structure + editorial skepticism + naming provenance.
URL unavailable