M365AILasith IyanAI Consultant to the Estate
Weekly  ·  Published Thursdays  ·  No Email Required

What Changed in AI —
And What It Means
for Your Tenant

Most AI newsletters report the announcement. This one reports the consequence: the administrative surface a release just added to your estate, the control that became available, and the thing that now needs a decision before your renewal. Anthropic, OpenAI, Microsoft Copilot, Google, and regulation, cited back to primary sources.

Issue 01  ·  10 September 2026

The Week the Frontier Labs Both Shipped

Anthropic and OpenAI each released a flagship model inside seven days, Microsoft moved a set of Copilot governance controls to general availability, and the EU AI Act's transparency obligations became enforceable. For anyone running a tenant, the Microsoft items matter most — several of them change what an administrator can see and control.

The short version. Two new frontier models are now reachable from inside your Azure tenant. Copilot gained a credit-consumption dashboard, a content-ranking lever for SharePoint, and a private Viva Engage grounding source. The legacy Copilot Chat API endpoints are being replaced. And if you operate a customer-facing agent in the EU, disclosure is no longer advisory.

Microsoft 365 Copilot

Nine Changes, and Three That Need an Administrator

The richest week of the five for tenant operators. All of the following reached general availability unless noted.

ChangeWhat it doesWhat it means for your tenant
Consumption Dashboard for Copilot credits
Viva Insights · GA
Tracks credit consumption for Cowork and Work IQ API services. Scoped to managers with five or more reports, Insights analysts, and Global Administrators. Requires usage-based billing configured in Cost Management. Consumption is now measurable, so capture a baseline before agent usage scales. Note that tenant-wide leader access is not in this release — the reporting line you may have assumed exists does not yet.
SharePoint Authoritative Sites
SharePoint admin centre · GA
Administrators designate specific sites as authoritative, so company news, policy, and canonical reference rank ahead of other content in Copilot Search. A ranking lever, not a permissions fix. It improves which correct answer surfaces first; it does nothing about content a user should never have been able to retrieve. Oversharing remediation still has to happen on its own track.
Viva Engage private content as a grounding source
Copilot · GA
Private Engage community and event content now grounds Copilot responses, restricted to content the user is already permitted to access. Your oversharing position now extends to Engage communities. Permission trimming is honoured, but "honoured" means it reproduces whatever your community membership actually is — which in most tenants nobody has audited.
Work IQ APIs — unified REST endpoint
Copilot extensibility · GA
A single REST endpoint for invoking agents and workflows, replacing the legacy Copilot Chat endpoints. This is a deprecation in disguise. Inventory anything calling the legacy endpoints — custom agents, integrations, scripts — before the replacement window closes.
Admin reporting: row-level exports
Copilot & Agent 365 dashboards · rolling out
Custom reports built from de-identified, row-level metrics and attributes exported from the Copilot and Agent 365 dashboards. The first genuinely analysable export of Copilot usage. If you have been unable to evidence value to a funding stakeholder, this is the data that lets you.
Parallel content and identity crawl
Copilot extensibility · GA
Content and identity crawls now run concurrently rather than sequentially, cutting the lag before new content is reachable, with permission accuracy preserved. Shortens the window in which a newly created document is indexed but its permissions are not yet fully reflected.
ServiceNow connectors: role-based permissions
Copilot extensibility · GA
Knowledge and Catalog connectors now evaluate admin, knowledge manager, and knowledge admin roles rather than user criteria alone. If you federated ServiceNow into Copilot early, re-check what the connector exposes — the evaluation model has changed underneath it.
Copilot and Planner
rolling out
Copilot can create Planner tasks and query task information. A small adoption win worth putting in front of project managers, who are usually the cohort with the weakest measured Copilot usage.
Organizational Messages on hybrid-joined devices
Microsoft 365 admin centre · GA
Organizational Messages now reach hybrid Entra-joined devices, not only cloud or on-premises joined ones. Removes the gap that made in-product change communication unusable for mixed fleets — relevant if your adoption plan depends on it.

Source: Microsoft 365 Copilot release notes, Microsoft Learn.

The Frontier Labs

Two Flagship Releases in Seven Days

  • Anthropic
    Claude Fable 5.1 and Mythos 5.1 released
    Fable 5.1 became the generally available flagship on 1 September, carrying a one-million-token context window and up to 128K output tokens, aimed at long-running agents, coding, multi-step research, and document-heavy professional work. For your tenant: a million-token context changes what a document-review or policy-analysis agent can hold in one pass — worth revisiting any use case you shelved for context limits.
  • Anthropic
    Output watermarking arrives across the flagship models
    Text generated by Fable 5.1 and Mythos 5.1 carries Anthropic's text watermark, and supported image and video files carry C2PA Content Credentials. For your tenant: this is provenance infrastructure arriving ahead of the EU transparency rules below, and it is the kind of control an auditor will start asking to see evidenced.
  • Anthropic
    Claudeforce — the Salesforce partnership
    Salesforce and Anthropic announced an expanded partnership, with Salesforce in Claude available to selected pilot customers and an open beta expected during September. For your tenant: if Salesforce is in your estate, this becomes a second AI surface reaching CRM data, governed separately from Copilot. Two AI estates is the pattern to avoid.
  • OpenAI
    GPT-6 Astra announced and rolled out
    Announced in early September and released to ChatGPT, the API, Azure, and Bedrock, positioned for computer use, browsing, software engineering, science, and professional work, with OpenAI reporting near-perfect scores on key reasoning benchmarks. Coverage of the launch also noted rising external scrutiny of safety claims. For your tenant: Azure availability means this is reachable from inside your subscription — confirm which models your Azure OpenAI policy actually permits, because that list is usually older than the catalogue.
  • OpenAI
    DevDay set for 29 September, and a data centre in Ohio
    DevDay 2026 was announced for 29 September in San Francisco. Separately, OpenAI detailed the PORTS-Pike data centre project in Ohio with SB Energy, NVIDIA, and the US Department of Energy — roughly 35,000 construction jobs across a six-year build to 2032, 2,500 long-term roles, and $80 million of initial community investment. For your tenant: nothing immediate, but DevDay is the more likely source of a change that affects you before year end.
  • Google
    Gemini replaces Google Assistant, and 3.8 Flash ships
    Gemini 3.8 Flash was released on 2 September. From 4 September, Google began retiring Google Assistant on Android and Wear OS, with Gemini taking over on phones, tablets, watches, and Android Auto. The September Android Drop added five tools including Guided Vision, which shares a camera feed with Gemini Live to narrate surroundings, designed with the blind and low-vision community. For your tenant: a consumer assistant is being replaced by a capable one on corporate-owned Android devices. If your mobile policy predates this, it is now out of date.
Regulation

The EU AI Act Stopped Being Theoretical

Enforcement began on 2 August 2026, shared between the European Commission's AI Office, the European Data Protection Supervisor, and national competent authorities. The transparency obligations are the ones with immediate operational consequences.

01

Disclosure Is Now Enforceable

Chatbots must identify themselves as automated systems, deepfakes must be labelled, and machine-generated or machine-edited content must carry machine-readable marks. If you run a customer-facing agent in the EU, this is a build item rather than a policy item.

02

The Penalties Have Teeth

Breaching the transparency obligations risks up to €15 million or 3% of worldwide annual turnover, whichever is higher. Prohibited practices reach €35 million or 7%. These are turnover-based, so they scale with the organisation rather than the deployment.

03

The Next Dates Are Already Set

Prohibitions covering non-consensual intimate imagery and child sexual abuse material apply from 2 December 2026. Annex III high-risk rules follow on 2 December 2027, and high-risk systems embedded in regulated products on 2 August 2028.

The governance consequence. An agent inventory — owner, purpose, identity, data reach, review date — has moved from good practice to the artefact you produce when asked. The AI governance overview sets out what that inventory contains and who owns it.

Method

How This Brief Is Assembled

The value of a brief like this is entirely in what it leaves out, so the sourcing rules are worth stating.

  • Primary sources first. Vendor engineering blogs, official release notes, model cards, roadmap entries, and regulatory publications — not aggregator summaries of them.
  • Every item links out. If a claim cannot be traced to a primary source or credible reporting, it does not appear.
  • Rumours are labelled as rumours, or omitted. Most weeks they are omitted.
  • The filter is the estate. Model benchmark results are noted briefly; a change to Copilot's administrative surface is covered in full. The test is whether it changes what a tenant administrator can see, control, or has to decide.
  • No email is required to read it, and there is no list to join.

Sources Monitored

Each issue is compiled from the following, plus credible reporting where a primary source is not yet published.

Microsoft 365 Copilot release notes Microsoft 365 Roadmap Microsoft Community Hub Microsoft Tech Community blogs Anthropic news & model cards OpenAI announcements Google AI & DeepMind blogs EU AI Act & Commission publications NIST AI RMF updates

Views expressed are personal and independent of any employer. Vendor names and trademarks belong to their respective owners.

Archive

Previous Issues

Issues are listed newest first. The brief above is always the current one; earlier issues are summarised here rather than reprinted in full.

  • 10 September 2026

    Issue 01 — The Week the Frontier Labs Both Shipped

    Claude Fable 5.1 · GPT-6 Astra · nine Copilot changes · EU AI Act enforcement

Reading the News Is Not the Same as Being Ready

Four minutes across eight pillars will establish whether any of this week's changes are reachable from where your tenant currently stands.