Microsoft turns on usage-based billing by default for Copilot Business, and ends its promotions first
Sep 16, 2026
Three dated items sit on one Microsoft partner page and run in sequence. September 30: "Microsoft 365 E5, Microsoft 365 E7, and Copilot promotions end with the transition to growth margins." October 1: CSP license-based growth margins become generally available. November 2: pay-as-you-go becomes "the default billing configuration to help customers access eligible usage-based experiences, including Copilot Cowork, Work IQ APIs, and GitHub Copilot Harness, with less billing setup," applying to "New purchases of Microsoft 365 Copilot Business (standalone and bundles) through CSP" (Microsoft Partner Center).
"With less billing setup" is the sales framing of a change in who absorbs surprise. Today a Copilot seat is a fixed number you can budget; from November 2 a new seat bought through a partner arrives with Azure billing pre-wired and a meter behind it. Microsoft tells partners to "Familiarize your teams with the upcoming change and the preset monthly limit," which confirms both that a limit exists and that it needs explaining. Three moves follow. Adding seats before November 2 keeps the current billing shape; switch the usage-based features on deliberately rather than inheriting them; and get the preset monthly limit from your reseller in dollars before the first invoice teaches you. Reseller blogs put Copilot Business at $21 per user per month list with an $18 promotional rate through September 30, but those figures appear on no Microsoft page, so treat the dates as solid and the prices as something to get in writing.
Back to topOpenAI retires four legacy models on Monday, and the video API went dark today
Date not stated
OpenAI's deprecations page lists a run of shutdowns, and the near ones bite (OpenAI deprecations):
The September 28 group is this week's job. Those completions-era models are what old integration code calls: a classifier someone wired up in 2023, an autocomplete inside an internal tool, a script that has run quietly ever since. They are exactly the integrations with no owner and no monitoring, and they stop working on Monday. If you ever paid a contractor to add AI to something and then forgot about it, that is the code to go find. The Videos API retirement is harder, because no replacement is listed at all: a workflow built on Sora has nowhere to migrate inside OpenAI, which is a reminder that a vendor retiring a capability is not the same as a vendor upgrading it.
Back to topConnecticut's AI employment law takes effect October 1, and the vendor-blame defence goes with it
Date not stated
Senate Bill 5, the Connecticut Artificial Intelligence Responsibility and Transparency Act, was signed on May 29, 2026 (Holland & Knight). What starts next Thursday is narrower than most summaries suggest and also sharper: "the anti-discrimination amendments, the developer-deployer framework, and a new WARN Act disclosure requirement" (Fisher Phillips).
The anti-discrimination provision is the one with teeth: "the use of an automated employment-related decision technology is not a defense to a complaint alleging a discriminatory employment practice." You cannot point at the vendor's algorithm. The WARN piece requires an employer filing a layoff notice to tell the state labor department whether the layoffs relate to its use of AI, and Connecticut WARN reaches employers with 100 or more employees, so it misses the smallest firms. The interactive disclosure and pre-decision notice obligations, the paperwork most people picture, are the October 2027 tranche. Enforcement runs through the attorney general only, with a 60-day cure period and no private right of action (Ogletree).
What makes this reach ordinary businesses is the breadth of the definition, written widely enough to capture resume screening, assessment tools, scheduling algorithms and performance analytics, which is ordinary HR software rather than anything an owner would call AI, with no minimum-employee threshold on the framework generally. A Connecticut firm with a dozen staff picks up no new filing duty next week, but from October 1 the liability for what its hiring software does sits with the firm rather than the software.
Back to topAmazon opens seller accounts to an outside AI agent, and publishes the permission model in source
Sep 23, 2026
Seller Assistant now "carries persistent memory of each seller's pricing patterns, inventory cycles, and growth goals," alongside "Seller Assistant workflows: custom automations that run continuously" that execute restocking and pricing tasks "with full audit trails and seller-defined guardrails." A Selling Partner plugin launches "first with Amazon Quick and in beta with Anthropic's Claude," built on Amazon Bedrock, for US sellers (About Amazon, GeekWire).
The guardrails are unusually checkable, because the toolkit is published under Apache 2.0. Its README states that "Write actions are always human-in-the-loop (drafted for your approval)," and the strongest control appears in no coverage: "Access is granted through the Seller Central OAuth consent flow and is limited to the tools your Seller Central roles allow" (toolkit). The agent inherits the authorising person's permissions and cannot exceed them, and the registry entry confirms markdown only, no hooks or scripts, so no arbitrary code runs on your machine (registry PR).
Two products here have two control models, and that is the decision. The plugin approves each write. The workflows run continuously, and sellers "choose whether it just surfaces recommendations or takes actions on their behalf," which is pre-authorised action without per-instance review; the audit trail then records what already happened rather than gating it, and an audit trail nobody reads is not a control. The writes touch price, listing content, inventory reorder and inbound shipments, the levers that move cash and are slow to unwind, so run it recommend-only first.
Two things to hold. Amazon says it "keeps seller data within Amazon's infrastructure and never shares it outside of Amazon," while the README is more precise, following the Amazon Privacy Notice "for server-side processing and your AI assistant's terms for client-side processing." And the free offer is being misread: the December 31, 2026 date on the free 12-month Quick Plus subscription governs when you can "sign up," not when the free period ends, and Amazon says nothing about price afterwards.
Back to topXiaomi ships a top-ranked open-weights model at a tenth of frontier price, and one repeated benchmark line is backwards
Sep 22, 2026
MiMo-V2.6-Pro is MIT licensed, 1.02 trillion total parameters with 42 billion activated, and a context window of exactly 1,048,576 tokens (model card). Xiaomi also released the technical report, more than 7,000 reinforcement-learning task environments and an end-to-end RL framework, which is a real open release rather than weights over the wall; pre-training data is not released (VentureBeat).
Pricing, from the marketplace API rather than a press release, is $0.435 per million input tokens and $0.87 output for Pro, and $0.14 / $0.28 for Flash, with no context-length price tier and cache reads at $0.0036 per million, roughly one one-hundred-and-twenty-first of the uncached input rate (OpenRouter). That cache figure is the commercially interesting number and almost every write-up dropped it. Independently measured, the model scores 46 and ranks first of 113 on an index whose publisher states "All evaluations are conducted independently by Artificial Analysis," against 58, 56 or 54 for Claude Opus 5.5 (Artificial Analysis): best open-weights model available, roughly twelve points behind the frontier.
The claim that MiMo beats Claude Opus 5 on Terminal Bench, 89.9 to 89.1, does not survive Xiaomi's own model card, which publishes both benchmark versions one row apart. On Terminal Bench 4.0, the current version, it is MiMo 34.9 against Opus 5 49.0. The 89.9 is version 2.1, superseded, and its maintainers state the new version is "not directly comparable with Terminal-Bench 2.x" (Terminal Bench). The winning row on the old version got printed and the losing row on the current one got dropped. The "$3.5 million training cost" is likewise Xiaomi's disclosed reinforcement-learning post-training spend, which excludes pre-training a 1.02-trillion-parameter model (Xiaomi).
For a small business the read is not "switch." Open weights removes the legal barrier to self-hosting and leaves the physical one intact: a terabyte of weights needs roughly thirteen to sixteen 80GB accelerators, and the only self-hostable artifact is a much weaker 9B distillation. The price is what is real, and it licenses a design choice: at these rates, re-sending a fixed corpus such as a price list, SOPs or contract templates on every call becomes sensible in a way it is not at frontier rates. Price the work rather than the token, and keep a provider-agnostic layer, because an owner whose automation is written against one vendor's SDK cannot collect a price decline when it arrives.
Back to topA phishing service that reached 12,000 inboxes did not bypass MFA, and that changes the defence
Sep 22, 2026
Microsoft disrupted EvilTokens, a subscription phishing service with an AI chatbot inside it, reporting "more than 12,000 compromised email inboxes across over 10,000 organizations worldwide," access sold for "a $1,500 initiation fee and a recurring $500 subscription," and the seizure of 50 websites. Two men aged 32 and 38 were arrested on September 11, 2026 (Microsoft).
The mechanism is the story. Microsoft describes a kit that "helped criminals gain access to email accounts by tricking victims into entering an authentication code on Microsoft's legitimate sign-in page," and independent reporting is blunter: it "abuses the device-code authentication flow to obtain authentication tokens despite MFA protections, allowing attackers to compromise accounts without needing credential theft" (BleepingComputer). The victim completes multi-factor authentication successfully, on the real Microsoft page, and the attacker takes the resulting token.
So "we have MFA turned on" is not a defence here, because MFA is the thing the victim performs. What works are tenant settings: disable device-code authentication where it is not required, and move to FIDO2 keys or passkeys. Microsoft adds a control worth repeating to anyone who handles money, which is to verify requests to change payment information or redirect funds through a trusted second channel. The AI component is why: with a model reading a compromised mailbox, assume criminals understand its contents in minutes rather than days.
Two calibrations. This was a disruption, not a takedown, and the threat remains active. And an independent recapture count found "more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries," smaller than Microsoft's count and derived differently.
Back to top