The Short Answer
Microsoft's rebuilt Copilot runs its persistent Autopilot agent under a governed identity and bills it through usage-based billing rather than the per-seat licence, with Agent 365 supplying the governance on a separate per-user licence. On ibl.ai you own all the code and the data, so the equivalent identity, permission and audit layer is source you run in your own perimeter, model-agnostic across any LLM, with no per-seat entry ticket in front of it.
On 25 September 2026 Microsoft showed Copilot reorganized around three surfaces — Home, Code and Autopilot — with Autopilot as an agent that keeps working inside Microsoft 365 when nobody is prompting it.
Two things in the announcement deserve credit before anything else: the governance model is substantive, and the billing shape for agent work is consumption, not seats. This page then asks the question those two advances leave open, which is who owns the control plane.
What did Microsoft actually announce for Copilot on 25 September 2026?
A rebuilt product, not a new model, announced on the Microsoft blog. Copilot now presents as Home, Code and Autopilot, where Code hosts AI-generated applications and Autopilot runs continuously against an objective and role the user assigns.
Microsoft describes Autopilot as having "its own identity, memory, computer and workspace" inside the organization's tenant, rather than sharing a service account with every other automation.
One detail the coverage almost universally drops: Microsoft's own post states that Autopilot was previously called Scout.
The agent and its identity are not new as of September — they were introduced earlier in 2026, and September is when they were folded into the rebuilt Copilot.
The surrounding governance is documented separately, in Agent 365 rather than in the launch post. Agent 365 supplies a centralized agent registry, lifecycle management and access control through the Microsoft 365 admin center, Microsoft Entra and Microsoft Purview.
Its documentation states that together those capabilities "ensure agents only access authorized resources, prevent data leakage, and defend against evolving threats" — with Purview providing information protection and DLP, and Defender adding threat detection.
What does it mean for an AI agent to have its own identity?
It means the agent is a directory object, and that changes what you can do about it. Instead of an API key shared across automations, the agent resolves to a known actor that Entra can apply risk-based access control to.
Three capabilities follow, and they are why this matters more than a feature release. An agent with a directory identity can be scoped to specific resources rather than inheriting a service account's accumulated permissions.
It can be audited, because the trail names an entity rather than a credential. And it can be revoked in one place, the way a departing employee's access is revoked.
This is the concession CISOs have been asking for. The hard part of bringing agents into an enterprise was never capability — an autonomous process holding a shared credential is invisible to every control the organization already runs.
Is Autopilot available to deploy today?
Not generally. Microsoft describes Autopilot as expanding to private preview at the end of the month, so it is a direction to plan architecture against rather than something to put in this quarter's compliance narrative.
Agent 365 is the opposite case and the distinction is worth keeping straight: it has been generally available since 1 May 2026, licensed per user, and its documentation notes it works best with Microsoft E5 as a prerequisite.
We drew the same preview-versus-shipping line on NVIDIA's agent safety launch, where the strongest control is described by NVIDIA as a reference system design rather than a product: Agent Containment Moved Into Silicon. What You Still Own.
Who controls an Autopilot agent's permissions — the user or the administrator?
The administrator. A user assigns the agent an objective and a role, but the registry, the access control and the data-protection policy are administered centrally through Agent 365, Entra and Purview.
The difference is not pedantic. "User-controlled permissions" implies whoever launched the agent decides what it may reach; what Microsoft built is the opposite, and better — the agent's reach is bounded by policy the organization sets.
It does mean the control plane is Microsoft's. Your administrators configure it; Microsoft defines what is configurable, ships changes to it, and holds the implementation.
How is agent work actually billed?
By consumption, which is the right answer and worth saying plainly. Microsoft's announcement states that "Cowork, Code, and Autopilot, new long-running agentic capabilities, and frontier models like Astra and Fable all run on UBB" — usage-based billing.
The per-seat user subscription licence covers something narrower: Copilot in chat and across Word, Excel, PowerPoint, Outlook and Teams, plus model selection.
Microsoft 365 Copilot lists at $30 per user per month on an annual plan, and it is an add-on requiring a qualifying Microsoft 365 licence underneath.
So the shape is not "per seat" and it is not "usage-based". It is three meters stacked:
| Meter | What it buys | Scales with |
|---|---|---|
| Per-seat entry ticket $30/user/month, annual, add-on |
Copilot in chat and the Office apps; model selection | Headcount |
| Usage-based billing | Autopilot, Code and the long-running agentic capabilities | Work actually done |
| Agent 365 separate per-user licence, GA 1 May 2026 |
The registry, access control and governance plane | Headcount |
| ibl.ai | Flat licence, source code included — identity, permissions, audit and sandbox in the stack you own | Tokens actually consumed, or the GPU you own |
The consumption meter is the part that gets agents right, and Microsoft deserves credit for it — a persistent agent's cost is a function of how much work it does, and a pure seat licence cannot see that.
What the stack still requires is a per-seat entry ticket in front of the consumption, twice: once for Copilot and again for the governance layer. Headcount still gates access to a capability whose cost has nothing to do with headcount.
What can a tenant-governed agent identity not give you?
Three things, and each is a question to ask before standardizing on it.
It cannot follow you out. The identity, its permissions model and its audit records are artifacts of Microsoft's governance plane, and portability is bounded by whatever export the platform offers.
It cannot run where the platform does not. An agent identity administered in a Microsoft 365 tenant is not available in a disconnected network or an environment with no outbound connectivity.
It cannot be inspected. You can configure the policy; you cannot read the enforcement. For an agency that must attest to how a control works rather than that it is enabled, that gap is the audit finding.
Note what is not on that list. Agent 365 is explicitly built to register and govern third-party agents, not only Microsoft's own, so "it only works with Microsoft models" is not a fair criticism and we are not making it.
On ibl.ai you own all the code and the data — agent identity, scoped permissions, audit logging and the runtime sandbox ship as source you deploy in your own perimeter, model-agnostic across any LLM, with no per-seat pricing. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
Where agent identity fits alongside provisioning, evaluation and simulation is the subject of Forward-Deployed Engineering: The Four-Layer Agent Stack.
And the experiment a governed-but-rented stack makes hard is the one Nubank ran — screening open-weight configurations across 16,000+ simulated conversations and switching to the winner: Nubank Screened 16,000 Simulated Chats Before Going Live.
Want governed agent identity on a stack you own?
We deploy agent identity, permissions and audit as source code you keep, in your cloud, on-premise, GovCloud, or fully air-gapped. Book a 30-minute demo or talk to the ibl.ai team — ibl.ai is family-owned and operated from New York, NY.