A team collaborates with a central AI assistant linked to digital dashboards, cloud services, and security tools.
Who owns the customer, and the data, once an AI agent sits in the middle? That was the question Madrona's IA40 Summit kept circling without answering. Executives from Microsoft, Amazon, Anthropic and Stripe agreed on plenty about where AI is heading. The unresolved part was who keeps the customer relationship, and the data that comes from it. If you run Microsoft 365, Copilot or any SaaS stack, this is a licensing, security and architecture issue, not just a venture-capital talking point.

The summit ran in Seattle, and Madrona's agenda lists September 29 – 30, 2026 at the Four Seasons. The main program ran on September 30. Everything below is a speaker's claim or forecast as reported by GeekWire, not independently measured fact. Where other sources add context, I say so.

The Microsoft angle: the agent is your customer​

Charles Lamanna oversees Copilot, Agents and Platform at Microsoft. In the opening keynote he said, "If my agent interacts with your app exclusively, the agent's your customer, not the end user." He added that agents are very harsh customers.

His reasoning is simple. Agents will pick whatever service is cheapest, fastest and most reliable, and will move people to another one quickly. Apps behind agents therefore struggle to keep pricing power or loyalty.

Lamanna sorts software into two groups:

  • Thick apps are where people spend most of their workweek. His examples were CAD programs, contact-center software, and Excel for a full-time financial modeler.
  • Thin apps are the ones people drop into and leave. He said that covers the vast majority of business software, and that these apps will run "headless" with AI assistants doing the work through the back end.

Microsoft's own products aren't exempt. Word, Excel and PowerPoint won't go away, Lamanna said, but most people will use them inside Copilot, which can now run Office without switching apps.

There's a tension here worth stating plainly. Copilot needs other vendors' software to cooperate behind it. GeekWire noted that Lamanna has said Copilot uses connectors to pull data from services such as Salesforce and ServiceNow. Microsoft is both the agent that squeezes other vendors and a vendor that could be squeezed by someone else's agent.

Agents versus apps: the "thin app" argument​

Jean-Denis Greze, CEO of Town, went further. He said AI has been able to operate a browser or computer almost as well as a person since about July, at a reasonable cost. In his view, an assistant can then work through an app's interface without the vendor providing an API. His summary was that "the less the app matters as a unit of software."

For IT admins, UI-driving agents raise questions that API-based integrations were built to answer:

  • Which identity is the agent using, and what can it reach?
  • Is its activity logged in a way your security team can audit?
  • Does the vendor's license permit automated access to the interface?

These are my questions, not ones the summit panels resolved. They matter most where a vendor never agreed to the agent's access.

Commerce shows the conflict early​

Stripe's Maia Josebachvili said agent-driven commerce on Stripe was roughly flat for eight or nine months, then rose sharply in the past six weeks. Merchants earn money from checkout add-ons and advertising, she said, and an agent doing the buying removes those chances. She said that arrangement won't hold over the long term. Stripe's data wasn't published, so treat this as her characterization.

The live example is Amazon and Meta. GeekWire reported that days after blocking Meta's Muse agent, Amazon opened its seller tools to Anthropic's Claude. Amazon's position appears to be that agents are welcome on its terms. For enterprise software, expect a similar split between agents vendors permit and agents they block.

Who owns the agent's work record?​

Moderator Raphaëlle d'Ornano put a pointed question to Anthropic CTO Rahul Patil. She asked who owns the record of an AI agent's work, including its mistakes and corrections, and whether it belongs to the customer. She said she has never gotten a clear answer.

Patil didn't answer directly. He said each company supplying agent software will work to improve its agents and will use all the data available to it. He also said it's good for the ecosystem if agents improve. That isn't a statement of Anthropic's contract terms or of the law. If you're buying agent platforms, ask for the data-use and retention terms in writing rather than relying on conference remarks.

AWS offered one concrete piece of context on the data side. Swami Sivasubramanian said getting agents the right company data is one of the least appreciated parts of making them work. AWS's own announcement describes AWS Context as a service that maps relationships across existing data into a knowledge graph, with agentic search for agents to reach governed data and business rules at runtime. The AWS post also says each call is designed to inherit the calling user's IAM and Lake Formation permissions. The post labels the service "Coming soon", so it wasn't generally available when announced.

The human bottleneck and the deployment gap​

Several speakers said the limit is organizational, not technical.

  • Patil said Anthropic writes about 200 times as much code as it did 18 months ago. Some customers have doubled or tripled output, but almost none have seen gains like Anthropic's.
  • Goldman Sachs' Archana Vemulapalli said the bottleneck is human, because roles and processes were built before AI.
  • Sivasubramanian said Amazon teams built impressive agents in two or three weeks. Almost all of them still had to work out security, identity and monitoring before rollout.
  • McKinsey's Lari Hämäläinen said about 40% of companies say AI has raised profits, but only 6% call the increase substantial. No survey method was given at the event.

A working demo says nothing about whether permissions, oversight and monitoring are ready for production. That is the admin's job, and it's where most of the delay seems to sit.

Single provider or many?​

The panel split on model lock-in.

PositionSpeakerArgument
Don't over-invest in switchingRahul Patil, AnthropicLarge companies build for what all models share, miss work only they can do, and miss gains from newer models
Own your AICarlos Guestrin, NoeriIntelligence shouldn't be controlled by one or two model owners
Control worryEno Reyes, FactoryMany businesses see no path that avoids ceding control to one lab
ChoiceThomas Dohmke, EntireDevelopers always want choice

Patil is an interested party, since Anthropic sells the models. Guestrin runs a company selling the alternative. Neither view is neutral, and the right answer likely depends on your workload and your tolerance for dependency.

Amazon's own position shows the hedge. Dan Grossman noted that Amazon launched a managed-agents product with OpenAI that week. AWS's announcement confirms that Amazon Bedrock Managed Agents, powered by OpenAI, entered preview on September 29, 2026, in US East (N. Virginia), US West (Oregon) and US East (Ohio). AWS says each agent operates with its own IAM role, supports human approval before consequential actions, and records supported API activity with CloudTrail. There is no additional charge during preview beyond underlying resources, and pricing may change at general availability. Those are useful governance features, though whether any of this resolves the ownership question is a separate matter.

Trust and control​

Zico Kolter said control of AI systems has to keep pace with capability, which might mean developing them more slowly than is possible. Sivasubramanian said executives worry whether agents will always follow company rules. His suggestion was to pair models with separate systems that check their work against those rules. That's a conference recommendation, not proof that it eliminates the risk.

The money​

Madrona's figures, as reported:

  • The IA40 companies have raised $410 billion in total, with OpenAI, Anthropic and Databricks accounting for 92%. GeekWire's earlier coverage confirms the same figures and notes the list covers 45 private companies because of ties.
  • Anthropic raised $143 billion of its $161 billion total in the 12 months ending Aug. 15, including debt.
  • Reuters reported Anthropic filed confidentially for an IPO and seeks a roughly $2 trillion valuation. Bloomberg reported a possible listing as early as mid-November. I haven't verified either report, so treat them as attributed and unconfirmed.
  • PitchBook figures presented by Madrona project capital spending by Amazon, Alphabet, Microsoft, Meta and Apple to rise 74% this year to about $742 billion.
  • Lamanna said Microsoft's heaviest AI-using developers are each on track to spend over $1 million a year on AI usage, even with the internal discount. This is his statement and Microsoft hasn't published the underlying data.

Madrona's closing slide said AI returns are still early for most users but look inevitable based on early adopters.

What this means for Windows and Microsoft 365 admins​

  1. Inventory agent access. Know which agents and assistants touch your business apps, and whether through APIs, connectors or the UI.
  2. Treat agent identity as a first-class concern. Security, identity and monitoring were the stated blockers inside Amazon. The same list applies in a Microsoft shop.
  3. Get data terms in writing. The ownership of agent logs, corrections and interaction data was unanswered on stage.
  4. Plan for pricing pressure and vendor changes. If Lamanna is right, thin-app vendors will face price competition, and may restrict agent access in response.
  5. Be skeptical of ROI claims. The 40% and 6% figures show how far adoption has run ahead of measurable gains.

The summit's conclusion was an honest one: the technology is moving faster than the answers about control and data. The vendors building the agents are also the ones best placed to answer, and so far they haven't.

 

References

  1. The biggest unresolved question in AI right now, and more takeaways from Madrona's IA40 Summit - GeekWire GeekWire 2026-10-02T19:17:29+00:00
  2. 'Agents are very harsh customers': Microsoft exec warns many apps will lose pricing leverage – GeekWire geekwire.com
  3. IA40 Summit 2026 — Intelligent Applications 40 ia40.com