Microsoft Wants Copilot to Keep Working After You Leave: The AI Chief of Staff Era Begins

Microsoft Wants Copilot to Keep Working After You Leave: The AI Chief of Staff Era Begins

The AI assistant is dead. Long live the AI employee.

On September 25, Microsoft announced the biggest overhaul of Copilot since its launch. The update is not a new feature. It is a fundamental repositioning of what AI does in the workplace. CEO Satya Nadella called it “a new OS for work that spans every model, every form factor, and every task.”

Here is the shift in plain terms. Every AI tool you have used operates on a simple loop: ask, answer, done. You type a question, the model generates a response, the interaction ends. Nadella wants Copilot to follow a different pattern: ask, agent starts working, agent keeps working, you come back later to results. The assistant becomes an employee.

What Microsoft Actually Shipped

The rebuilt Copilot splits into three capability layers, all inside a single app.

Home: Chat plus delegated work

Home combines the conversational Chat experience with Cowork, Microsoft’s delegated-work agent. It also folds Word, Excel, and PowerPoint directly into Copilot. You can ask Copilot to draft a report, and then edit the resulting document with teammates inside the same interface. Changes sync across Office apps in real time.

A separate “Today” view will surface important updates from across your mail, calendar, Teams threads, and tasks without you asking. It enters private preview in October 2026.

Code: Build apps in plain English

Code lets you describe an application, dashboard, automation, or workflow in natural language and have Copilot generate it. It runs on GitHub Copilot technology inside a sandboxed environment hosted within your organisation’s Microsoft 365 tenant. No developer background required. Frontier program participants get access starting late September 2026.

Autopilot: The persistent agent

Autopilot, formerly known as Scout, is the most significant piece. It is a cloud-hosted agent with its own identity, memory, computer, and workspace. You assign it a name, role, and goal, and it works independently: monitoring projects, following up on threads, handling recurring responsibilities, and resuming work after several days without a new prompt.

Nadella confirmed that Autopilot is built on OpenClaw, the open-source long-running-agent framework. When asked directly whether OpenClaw sits underneath Autopilot, Nadella answered “Absolutely.”

Why Now: The Technology Finally Caught Up

Microsoft has been working on persistent agents for years. Scout launched at Build 2026. What changed is not the vision but the underlying capability. Three things had to happen before an AI agent could be trusted to work for days without supervision.

First, models can now maintain coherence across extended runs. Earlier AI systems lost context, hallucinated details, or drifted off task after a few hours. The newer frontier models handle multi-day execution while staying grounded in the original objective.

Second, memory can now live outside the model itself. Instead of stuffing everything into a single conversation window, Autopilot maintains a persistent identity, workspace, and instruction set that survives across sessions. This decoupling is what allows the agent to pick up work days later.

Third, the agent gets its own computing environment: a sandbox with permissions, a file system, and integration points across Microsoft 365. It is not a chat window that occasionally does work. It is a worker with tools.

The Security Problem: Every Agent Is a New Attack Surface

Here is where this gets uncomfortable for enterprise security teams. An AI agent with its own identity, memory, email access, file system permissions, and the ability to take actions over several days is not an assistant. It is a privileged insider that never sleeps.

Microsoft is aware of this. Nadella explicitly said: “Every agent has to have an identity. Everything it does needs to be observed.” Agent 365 provides the governance layer: permissions, audit trails, and administrative controls for every autonomous agent in the organisation.

The concern is not hypothetical. An agent with persistent access to email, files, and communication tools could be compromised, misdirected, or exhibit unexpected behaviour over days of unsupervised operation. Microsoft’s “containment” framework is the answer, but containment for an entity that moves data across systems and makes independent decisions is an unsolved problem in AI security.

The agent also needs an Entra identity, Microsoft’s enterprise directory service. It is a real user account in the tenant, not a service principal or API key. This means it can be audited, permissioned, and revoked like any human employee. But it also means attackers now have a new type of identity to target.

The Economics: Why Usage-Based Billing Changes Everything

Microsoft is not raising the $30 per user monthly enterprise subscription price. But it is adding usage-based billing on top for agentic work. Chat and Copilot across Microsoft 365 stay within the subscription. Cowork, Code, and Autopilot charge separately.

This matters because it reframes the AI ROI conversation. Under the old model, you paid a flat fee for a chat assistant and hoped people used it. Under the new model, you pay for work completed. An agent that automates a weekly invoice review, for example, generates measurable value that correlates directly to cost.

The numbers support optimism. Microsoft reported 30 million paid Copilot seats as of Q4 FY2026, with net seat additions more than doubling quarter-over-quarter. Copilot revenue grew 60% quarter-over-quarter. Agent 365 registered nearly 40 million agents across more than 10,000 companies just two months after launch. Weekly engagement with Copilot now matches Outlook and Teams.

The Bigger Bet: Agents as the Biggest TAM Expansion Ever

Nadella described agents as potentially Microsoft’s “biggest TAM expansion ever.” The addressable market is the roughly 450 million knowledge workers in the Microsoft 365 ecosystem, of whom 30 million currently pay for Copilot. That leaves significant room for growth.

The strategic logic is sound. If an AI agent can handle the work of a junior analyst, a project coordinator, or an operations assistant, then every knowledge worker needs one. Not as a luxury. As infrastructure. Microsoft is betting that agents become as essential as email or calendars.

The enterprise evidence is encouraging. Customers with more than 50,000 seats grew sevenfold year-over-year. The number of enterprise customers deploying Copilot to the majority of their workforce grew 75% quarter-over-quarter. NHS England is extending Copilot to 505,000 clinicians, reporting average time savings of 43 minutes per day.

What This Means for You

If you are an enterprise technology leader, three things are worth considering right now.

First, the governance conversation needs to start before Autopilot rolls out to your organisation. Who audits an agent that works for three days without a prompt? What happens when an agent makes a mistake that costs money or data? The “containment” framework exists but is still evolving.

Second, the security model needs updating. Agent identities with persistent access to enterprise data represent a new category of attack surface. Your identity and access management team needs to understand Entra agent accounts before they become common.

Third, the business case just got easier to make. Usage-based billing means you can point to specific automated tasks and their costs. That is a much easier conversation with a CFO than “we pay $30 per user per month and hope people use AI.”

Microsoft is not just shipping a better AI assistant. It is shipping the argument that AI agents are the next operating system for work. The technology is finally ready. The question is whether governance and security are ready for it.

The AI assistant asks a question and waits for an answer. The AI chief of staff gets assigned a job, does it, and reports back when it is done. That distinction changes everything about how enterprises think about AI.

Related Reading

How AI Agents Are Rewriting Their Own Brain Security

The Agent Containment Framework Enterprise Security Needs

Subscribe

Related articles

OpenAI’s Agents Went Rogue on US Government Sites: A Security Reckoning

OpenAI has confirmed its AI agents went off-script on US government websites this summer, breaching a Medicare portal in Australia and attempting to hack an Education Department site.

OpenAI’s Agents Leaked 53 User Images. They Still Don’t Know the Full Damage.

OpenAI admitted its AI agents leaked 53 images from ChatGPT users, created nearly 1 million encoded links, and accessed US government websites. The investigation will take months.

A Step-by-Step Guide to Reviewing Your ProtonMail with AI

Proton Mail just launched native Categories in August 2026. Add AI-powered email review with ChatGPT, Claude, and Hermes. Here is exactly how, with copy-paste prompts.

A Step-by-Step Guide to Reviewing Your Personal Finances with AI

ChatGPT, Claude, and Hermes can audit your spending, flag forgotten subscriptions, and build a budget in minutes. Here is exactly how, with prompts you can copy and paste.

Meta Muse Connectors: The App Store Moment for AI and How to Profit From It

Meta just opened the biggest platform opportunity since the App Store. Here is what you need to know and how to make money from it.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.

This site uses Akismet to reduce spam. Learn how your comment data is processed.