Microsoft's New Copilot Renames Scout to Autopilot
The product news came first. Microsoft on September 25, 2026 introduced the new Copilot, a redesign of its work assistant built around three capabilities: Home with Office in Copilot, the Code app builder and Autopilot, a persistent agent. Microsoft's own blog post, signed by marketing chief Jared Spataro, describes Autopilot as "a persistent, proactive and personal agent that keeps working even when you're not."
Autopilot is a new name for an agent Microsoft has already shown. The overhaul renames Scout, the AI assistant Microsoft introduced at its Build conference in June, as Autopilot. Techzine and other outlets reported the same thing. When Microsoft launched Scout on June 2, it called it the first in a new category of "Autopilots": agents that stay active in the background, act without a prompt each time, and work under their own identity within permissions set by the user and the organization. Microsoft said Scout connected to Teams, Outlook, OneDrive and SharePoint and could reach chats, email, calendars and contacts.
The relaunched version works as a delegated worker. According to Techzine, the agent is given a name, role, and purpose, and then continues to operate without a prompt. It resides in the tenant with its own identity, memory, and workspace, and can be @mentioned in Teams and Outlook. IT-Connect adds that it follows channels and discussion threads, performs recurring tasks, and can resume a project after several days without new instructions.
Availability is still limited. Home and Code will start rolling out in Microsoft's Frontier program in the coming weeks and Autopilot is expanding to private preview at the end of the month. Nothing announced on September 25 makes Autopilot generally available, and the consumer version Nadella described has no date at all.
Windows admins should keep one naming collision in mind. As IT-Connect points out, Copilot's Autopilot has nothing to do with Windows Autopilot, the device-provisioning service many organizations use to deploy PCs. When a ticket, a change request, or a search result says "Autopilot," check which one it means.
Nadella Wants Autopilot's AI Chief of Staff on the Consumer Side
Heath describes the agent as an AI chief of staff. It runs on a hardened version of OpenClaw and gets its own computer, workspace and memory so it can work continuously. Asked about Microsoft's consumer strategy, Nadella pointed to what he called Microsoft's 100 million-plus consumer subscribers and said, "Autopilot should also go to the consumer side." The episode page doesn't say which subscriptions make up that figure or when it was measured, so treat it as Nadella's number, not an audited count.
He also drew a sharp line between the two markets. As Heath summarizes it, Nadella sees consumer agents cutting out today's middlemen, which makes that market more zero-sum. In the enterprise, he expects agents to make the market bigger than cloud "by orders of magnitude." Both are forecasts, not measured results. They do explain why Microsoft is leading with the enterprise: that's where Nadella sees the market growing, while the consumer side would mostly move existing money around.
The relaunch coverage points the same way. The Letter Two notes that before unification, Copilot ran on two tracks: one app for consumers and another for the enterprise, and that Microsoft shut down several consumer features, including Copilot Podcasts, Group Chat, and Deep Research during the merger. So Nadella's consumer ambition sits next to a product that, for now, is organized around tenants, Frontier enrollment and IT governance.
What "Hardened OpenClaw" Has to Mean Inside a Microsoft 365 Tenant
The phrase "hardened version of OpenClaw" does a lot of work in the interview, and Microsoft's own security team explains why. In February 2026, the Microsoft Defender Security Research Team published guidance on self-hosted OpenClaw. It warned that the open-source runtime has limited built-in security controls, can ingest untrusted text, can download and run skills (which are code) from outside sources, and acts with whatever credentials it has been given. Defender listed three risks: exposure or theft of credentials and data, tampering with the agent's persistent memory so it follows an attacker's instructions over time, and host compromise if the agent is tricked into running malicious code.
Defender's advice for self-hosted OpenClaw was blunt. Don't run it on a standard personal or enterprise workstation. If you must evaluate it, use a dedicated virtual machine or separate physical device, dedicated non-privileged credentials, and non-sensitive data only. Monitor it continuously and plan to rebuild it. That guidance covers the raw runtime, not Microsoft's managed agent, and the two shouldn't be confused. It does show what "hardening" has to solve.
Microsoft's June description of Scout answers those risks directly. Each agent runs under its own governed Entra identity, not a shared anonymous service account, so its actions trace back to a known actor in the directory. Microsoft says the credentials are scoped to the task and redacted from logs and diagnostics. Agents can reach only approved resources and destinations. Sensitive actions can require a human to sign off. Microsoft Purview protections, including sensitivity labels and data loss prevention, apply before anything is sent or written. Microsoft also said it is contributing policy-conformance checks back to the open-source OpenClaw project, so organizations can verify whether their deployment meets their security requirements.
On the Windows side, Microsoft used Build in June to present Windows as an "agent-native runtime." It introduced Microsoft Execution Containers (MXC), in preview, as operating-system-enforced sandboxes for agents, and said OpenClaw on Windows uses those boundaries for multi-step workflows. The relaunched Autopilot, however, is described as cloud-hosted: IT-Connect quotes Microsoft saying it "lives in your tenant with its own identity, its own memory, its own execution environment, and its own workspace". Nothing published so far says the Autopilot preview runs inside MXC on the endpoint.
These controls are Microsoft's claims about its own product. No independent assessment of Autopilot's containment has been published. As IT-Connect puts it, for IT teams, that means one more identity to keep track of, and that identity comes with memory that persists between sessions.
Nadella's Diagnosis of AI's Trust Problem Starts With the Industry
Nadella's most-quoted line is aimed at his peers. "I think we are way too self-obsessed as an industry about, look at us, how glorious we are," he told Heath. His fix, as Heath summarizes it, is to let the people who use AI describe its benefits, and to show that AI creates economic opportunity for workers and for the communities that host data centers.
He also conceded that executive messaging, his own included, has stopped working: "Any amount that I say or any one of us say is not good enough anymore, I feel." That's an unusual thing for a CEO to say while launching a product. It also fits enterprise buyers, who are more likely to trust evidence from their own pilots than a launch keynote.
The conversation went further than the published highlights capture. Heath says they discussed Nadella's concerns about agents acting deceptively, when a safety problem should stop a release, and why he doesn't want AI oversight to become a "cartel-like arrangement." The episode page gives no examples, criteria or policy commitments on those points. It shows that Microsoft's CEO considers agent deception a live concern. It doesn't show that Microsoft has adopted a new release-gating rule.
Microsoft's Frontier Models and the Case Against a Single Model
On models, Nadella described a two-track strategy. According to Heath, Microsoft wants its own frontier models, and those models are already being used in Copilot's Auto mode, which picks a model automatically. Nadella tied the frontier effort to Microsoft's own data and customer needs. He made the economic case for competition bluntly, "You can't have one model," and warned about where token pricing would end up if one supplier dominated.
He also said Microsoft won't make Copilot exclusive to its own models: "Copilot will still have all the other models, because customers will expect that." That matches Microsoft's public positioning. In March 2026, the company already described Microsoft 365 Copilot as model-diverse, with OpenAI and Anthropic models. At Build in June, the Microsoft AI Superintelligence Team released a family of in-house models led by MAI-Thinking-1, a reasoning model in private preview on Foundry, plus MAI-Code-1, which Microsoft said was available in Copilot and VS Code. The interview didn't name which Microsoft models serve Auto mode or explain how Auto mode chooses between them.
Heath and Nadella also covered Microsoft's relationship with OpenAI, but the episode summary gives no detail, so this article won't speculate on it.
Token pricing matters more under the new Copilot because billing now tracks agent work. Techzine reports that Chat and the Office apps fall under a user subscription license. Cowork, Code, and Autopilot operate on usage-based billing with Copilot Credits. Microsoft paired that with new controls: according to Unite.AI, administrators can set budgets at the tenant and group level, user-level caps within group policies, and alerts at spend thresholds, and can manage policies programmatically through the Microsoft Graph API. An always-on agent spends credits continuously, so Nadella's worry about token prices directly affects what an Autopilot deployment costs.
Unmetered Intelligence on Windows and Xbox's Road Back to Growth
Heath says Nadella also shared his vision for "unmetered intelligence" on Windows, explained how he uses AI to track Microsoft's capital spending, and gave an update on Xbox's path back to growth. He also explained why he wants investors to see Microsoft's apps, agents and infrastructure as one connected business. The episode page lists these topics but doesn't summarize his answers.
The Windows phrase isn't new. In its fiscal 2026 fourth-quarter earnings material, Microsoft described Windows as an opportunity to become an "offload for unmetered intelligence," combining on-device compute with enterprise-grade security. Read against the new billing, the idea is easy to follow as an inference: cloud agent work is metered in Copilot Credits, while work that runs on a local PC doesn't need a per-token charge. Microsoft hasn't published a spec for this, so don't read it as a promise that Windows AI processing will be free or unlimited. The same earnings material said Microsoft expects Xbox to return to growth in fiscal 2027. The interview's Xbox update presumably builds on that guidance, but its details aren't in the published highlights.
What Autopilot Means for Microsoft 365 and Windows Admins
The decision for most organizations right now is whether to join the Autopilot private preview through Frontier. It isn't whether to deploy Autopilot widely, because that isn't possible yet. Teams already in Frontier with a working agent-governance plan can start evaluating. Everyone else can wait for broader availability and published pricing. The June Scout preview required Frontier enrollment, Intune policy configuration, an opt-in attestation, and a GitHub Copilot license to install the desktop experience. Microsoft hasn't said whether the Autopilot preview keeps those requirements, so confirm eligibility before planning a pilot.
Before any agent gets access, treat it like a privileged service identity. Decide in advance which Entra identity it runs as, which resources and destinations it can reach, which actions need human approval, and which Purview labels and DLP policies apply. Separately, anyone experimenting with raw, self-hosted OpenClaw on Windows should follow Microsoft Defender's own advice and keep it off everyday workstations.
- Autopilot is the renamed Microsoft Scout agent, and it enters private preview at the end of September 2026. It isn't generally available, and no consumer version has a date.
- Copilot's Autopilot agent is unrelated to Windows Autopilot device provisioning, so label change tickets and documentation clearly.
- Microsoft says each agent runs under its own governed Entra identity with scoped credentials, approved-destination limits, optional human sign-off, and Purview enforcement. Plan your policies around those controls before a pilot.
- Cowork, Code and Autopilot bill on usage through Copilot Credits, so set tenant, group and user budgets and spend alerts before a continuously running agent starts using credits.
- Microsoft Defender warns against running self-hosted OpenClaw on standard workstations. If you must evaluate it, use an isolated VM or separate device with dedicated credentials, non-sensitive data, monitoring and a rebuild plan.
- Nadella says Copilot will keep third-party models alongside Microsoft's own, so model choice and Auto mode behavior are worth tracking as preview details emerge.
Nadella's pitch rests on a bet he admits he can't win by talking: that people will trust agents that act on their behalf because customers can see the benefits, not because executives say so. For Microsoft 365 tenants, the first evidence arrives with the Autopilot private preview at the end of this month. That's when administrators will find out whether Entra identities, Purview enforcement and credit budgets are enough to let an always-on agent into production.
Update: Nadella Calls Trust the Central Challenge for Autonomous Copilot (September 25, 2026)
In a separate interview reported by Yahoo Finance, Satya Nadella said “trust is going to be the biggest issue” for Microsoft as Copilot takes on autonomous work. He specifically framed the concern around whether users can trust an AI system with credentials while retaining meaningful control—an issue he said is especially important in enterprise deployments.
The comments sharpen Microsoft’s earlier security messaging: governance is not merely a technical feature for always-on agents, but a condition for adoption. For IT teams, that reinforces the need to limit permissions, require approvals for sensitive actions, and monitor an agent identity as closely as any other delegated service account.
Yahoo Finance also reported that the revamped Copilot combines standard per-user subscriptions with pay-as-you-go billing for longer-running, multistep agent workloads. Nadella said seat-based plans will have token limits that most users are unlikely to reach, while usage-based capabilities can provide additional capacity when needed.