Artificial intelligence tools that answer questions or generate text on request have become standard in many offices. The newer category of AI software is built around a different premise: It takes multiple steps, interacts with outside programs, and carries out tasks from start to finish without requiring a new instruction at every stage.
That shift gives the technology more practical utility. It also creates a problem that simpler AI tools do not face.
When a system operates with meaningful autonomy across several steps, the consequences of an error or an unauthorized action may be several layers in before anyone catches them. That is a different kind of exposure than a chatbot that delivers a wrong answer to a direct question.
Microsoft CEO Satya Nadella said trust has become the central challenge as AI moves from answering prompts to carrying out work more independently.
His comments came as Microsoft launched a redesigned Copilot platform on Sept. 25, consolidating its AI offerings into a unified product combining chat, coding, and agentic capabilities, as GeekWire reported.
What the Microsoft CEO said about AI trust
“Trust is going to be the biggest issue for us,” Nadella said in an interview with Yahoo Finance. He said the question he keeps returning to is whether users would be willing to hand AI their login credentials and allow it to act on their behalf without close oversight at each step.
“Can I really trust [AI] with all of my credentials when it does autonomous activity?” Nadella asked. He explained that concern grows when AI operates inside a business, where the systems it can reach and the actions it can take carry far more weight than they would for an individual user working on a personal task.
More Microsoft:
- Morgan Stanley resets Microsoft stock forecast ahead of earnings
- Bank of America doubles down on Microsoft stock ahead of earnings
- Citi revamps Microsoft stock price target for the rest of 2026
The underlying dynamic is a change in how AI relates to the person using it. An AI assistant waits for a request. An AI agent receives a goal, then works through a sequence of steps to reach it, pulling in data, interacting with software and making intermediate decisions along the way.
The end result may be exactly what the user wanted, or it may reflect a misunderstanding several steps back that nobody caught while it was forming.
What the redesigned Copilot includes
The updated platform is organized into three sections.
- A Home section handles conversational tasks.
- A Code section lets non-technical users build apps and dashboards using AI-powered development tools.
- Autopilot is where persistent AI agents operate: Users create an agent by naming it, assigning it a role, and giving it goals, then deploy it for tasks such as project tracking, deadline management, or sending reminders to colleagues.
Each agent runs continuously in the cloud within a company’s Microsoft 365 environment and carries its own identity, memory, and email address. Users can tag an agent directly in Teams or Outlook to pull it into a workflow.
Microsoft 365 Copilot reached 30 million paid seats in July 2026, with net additions doubling quarter-over-quarter, as Fortune reported.
The September launch came as rivals were moving on similar ground. OpenAI introduced its own unified AI application in July, and Meta has been developing an agent platform of its own.
Microsoft’s response was to consolidate what had been a fragmented set of Copilot products into one interface.
The platform routes each request automatically to what it determines is the best available model, choosing between AI systems from OpenAI and Anthropic. Users can also select a model manually, and the company said it plans to add more providers over time.
Nadella said companies should be able to run their own performance evaluations and switch between vendors, treating model selection as a decision they control rather than one built into the platform.
Stephen Brashear / Getty Images
How Microsoft is pricing Copilot
Microsoft is moving toward what it calls a per-seat-plus-consumption billing structure. A standard monthly subscription covers everyday AI work, including conversational tasks and standard Copilot features. Token limits under that plan are ones the company said most users are unlikely to reach.
Customers with heavier workloads can switch to usage-based billing, which covers additional capabilities and the longer, more demanding agentic tasks that draw more from the system.
Administrators can set spending limits to keep those costs within defined budgets. Nadella said the combination is designed to offer broad access while keeping the cost of advanced AI work tied to the value each customer draws from the platform.
He also said usage-based pricing will grow in importance as AI companies pull back from the subsidized rates they used to drive early adoption.
Running AI infrastructure is expensive, and that cost climbs when tasks require multiple model calls or sustained processing time. A flat subscription spreads those costs across a user base. Usage-based billing recovers them from the customers generating them.
The business case that still needs to be made
The version of AI Microsoft is building toward requires businesses to hand it access to systems and information they have historically kept tightly controlled.
Internal data, employee credentials, communication tools, and operational software are all areas where agentic AI could deliver real value. They are also areas where a misrouted action or unexpected behavior is difficult to contain once it has happened.
Microsoft has put governance measures in place to address those concerns. The platform requires explicit permissions before an agent can access a new system, maintains audit logs of agent activity, and runs agents inside isolated execution environments.
Those controls were developed in part in response to recent AI security incidents, Fortune reported, a concern that grows more serious when agents operate inside business networks with access to real data and real systems.
Whether those measures hold up will depend on how Autopilot agents perform across a wide range of business environments.
An agent that monitors and flags is useful. An agent that sends communications, modifies records, or takes actions on behalf of employees is held to a higher standard. Microsoft can show that Copilot works as described.
Businesses deploying it across real operations, with real employee credentials and real internal systems, will reach their own conclusions.
Related: Microsoft killing an Office app you’ve used for decades

