Skip to content
MicrosoftCopilotAgentsVendor RiskPricingSmall Business

Microsoft's new Copilot gives Autopilot its own identity and its own computer. Write its job description before Frontier access lands.

On Friday, September 25, 2026, Microsoft unveiled a unified Copilot app with three tabs: Home (Chat plus Cowork), Code (natural-language apps and dashboards on the same technology as GitHub Copilot), and Autopilot, a revamp of the Scout agent Microsoft introduced in June. Autopilot is a cloud-hosted digital teammate with its own identity, controllable permissions, and its own computer. Home and Code reach Frontier-program organizations in the coming weeks; Autopilot enters private preview at the end of the month. Cowork, Code, and Autopilot move to usage-based billing. For a small team, that means an employee-shaped agent and a variable bill, both of which need written limits.

Steve Defendre
September 25, 2026
8 min read
Microsoft's new Copilot gives Autopilot its own identity and its own computer. Write its job description before Frontier access lands.

On Friday, September 25, 2026, Microsoft unveiled a redesigned Copilot app that folds chat, coding, and an always-on agent into one window. Reuters framed it as Microsoft trying to turn its assistant into a one-stop shop for office workers. Thurrott and The Verge carried the product detail and the Jared Spataro quotes. Today is the announcement. It is not a general availability date for any of the three pieces, and I want to keep that line clean before anyone plans a rollout around a headline.

It also sits on its own page. Thursday's post covered the Australian disclosure of an OpenAI agent in a Medicare statistics portal. Wednesday covered the Opus 5.5 and GPT-6 Sol/Luna price drops. Tuesday was Plugin4Shell and SHA pinning. The September 20 post covered the AI Force announcement. This one is only about Microsoft's Copilot redesign and what it asks of a small team's admin and vendor files.

What Microsoft announced on Friday

The new app has three tabs.

Home holds Chat and Cowork. Cowork is the agentic mode Microsoft had already introduced in the Microsoft 365 Copilot app: it completes multi-step tasks on its own. Office documents created from Home sync with Word, Excel, and PowerPoint, so a Copilot draft is a real file your coworkers can open. Spataro says a future version will route a request to Chat, Cowork, or Code without the user picking a mode.

Code lets people build apps, dashboards, trackers, and automations from natural-language prompts. Microsoft says it runs on the same underlying technology as GitHub Copilot, that work started in Code syncs with GitHub Copilot, and that the generated software runs in a sandboxed environment that can be hosted within your tenant. Microsoft is pitching it at non-developers first.

Autopilot is the one to read twice. It is a revamp of Scout, the personal agent Microsoft introduced in June 2026. Spataro calls it a "digital teammate" with access to its own computer. It is cloud-hosted, so it keeps working while you sleep. His example is a supplier review: build the schedule, handle prep and meetings, and follow up with stakeholders on its own. Microsoft's June Scout announcement already said each of these agents operates under its own governed directory identity rather than a shared service account. Friday's reporting adds explicit permissions, audit logs, and human-set autonomy levels. Annie Pearl, the Copilot corporate vice president, told Reuters the company focused on security, compliance, and governance so enterprises can actually deploy it.

The timing is staged. Home and Code start rolling out to organizations in Microsoft's Frontier early-access program in the coming weeks. Code reaches Microsoft 365 Premium and Pro subscribers as a preview later this year. Autopilot enters private preview at the end of September. None of that is general availability.

The billing changes too. Cowork, Code, and Autopilot move to usage-based billing. Chat stays on per-user subscription licenses. Microsoft also described cost-management views so organizations can see their AI spend. I am not going to guess at per-unit rates that Microsoft has not published.

A glass workstation cube on a dark plain, surrounded by a thin glowing blue perimeter line with a small amber key resting at its edge

Autopilot is an employee-shaped agent

Most small teams still think of AI as a feature inside a tool someone is using. Autopilot is shaped differently. It has a name you assign, a role, a goal, a directory identity, its own computer, and a schedule that does not end when you close your laptop. It messages people. It follows up. That is closer to a new hire than to a sidebar.

So write the paperwork you would write for a new hire, and write it before Frontier or preview access reaches your tenant, not after the first surprising email goes out under its name.

  1. Give it its own account and a short list of rights. One agent, one identity, and no borrowed credentials. List which mailboxes, Teams channels, SharePoint sites, and external contacts it can read, and separately which it can write to or message. Read-wide, write-narrow is a good default.

  2. Draw the outbound line. Messaging a coworker and messaging a supplier are different risk classes. Anything that leaves your organization (email to a vendor, a calendar invite to a customer, a file shared outside the tenant) should need human approval until you have weeks of logs showing it behaves.

  3. Put a human gate on overnight work. "Keeps working while you sleep" is the selling point and also the risk. Decide which tasks may run unattended, and which must pause and wait for a person in the morning. Recurring summaries are fine. New commitments on your behalf are not.

  4. Read the audit log weekly. Microsoft says the logs exist. Someone on your team should actually open them, on a calendar reminder, for the first month.

  5. Keep Code output inside the sandbox until reviewed. A dashboard someone built on Tuesday with a prompt is now an internal app. Decide who can share it, what data it can touch, and who owns it when the person who prompted it leaves.

A river of blue and cyan light particles flowing between a lower floor plane and an upper ceiling plane, both edged in amber light

Usage billing needs a floor and a ceiling, not a seat count

Seat licensing made the vendor file easy: count people, multiply, done. Friday's billing change breaks that for the parts of Copilot that do the most work. Chat stays per seat. Cowork, Code, and Autopilot bill on usage, and an always-on agent is exactly the kind of workload whose usage you cannot eyeball.

Three changes to the vendor file:

  • Set a monthly floor and ceiling. The floor is what you expect from normal use. The ceiling is the number at which someone gets paged and agents pause. Write both down before the first invoice.

  • Budget per agent, not only per person. One Autopilot running a recurring process can outspend a dozen chat users. Give each agent its own budget line, the same way you would give a contractor a not-to-exceed amount.

  • Use the cost views from day one. Microsoft says it is shipping cost-management surfaces. Turn them on during the preview, when volumes are small and mistakes are cheap, so you learn your real unit costs before broad rollout.

None of this is a reason to skip the preview. A governed identity, explicit permissions, and audit logs are better starting points than many agent products offer. The work is on your side: decide what the teammate is allowed to do and how much it is allowed to spend, then let it run inside those lines.

If you want a calm second set of eyes on agent permissions, spend limits, and the vendor file for a small team, DefendResolutions is built for that kind of operator work.

Was this article helpful?

Share this post

Copy the link or send it across your usual channels.

Newsletter

Get the weekly field notes

One concise email each week with the latest insights on defense tech, AI, and software engineering.

Get the latest field notes once a week.

Discussion

Comments

Leave a comment

Loading comments…