Microsoft's July 29 fiscal fourth-quarter report is the clearest recent statement of how the company is financing and pricing AI, and one number outside it now reframes the rest. It reported $90.0 billion in quarterly revenue, up 18%, Azure and other cloud-services growth of 43%, full-year Azure revenue past $100 billion, and more than 30 million paid Microsoft 365 Copilot seats, against $41 billion of capital expenditures in the quarter, roughly two-thirds of it on short-lived assets such as CPUs and GPUs. Microsoft also lowered expected reported calendar-2026 capex to about $175 billion from the roughly $190 billion it gave in April, attributing the change to a shift of future datacenter leases from finance leases to operating leases rather than to a smaller buildout, and said September-quarter capex should exceed $50 billion. Bloomberg then reported that Microsoft recorded $24.1 billion in sales from OpenAI during the year ended in June, accounting for most of its AI revenue under new disclosures, a figure the July 29 earnings release does not state; Nadella's previously cited $37 billion annualized AI run rate covers a different period, so the two should not be compared directly. Concentration of that kind gives the cost story a sharper edge, and cost pressure is already visible in model selection: Microsoft said on July 23 that Bing Image Creator runs end to end on MAI-Image-2.5 and that PowerPoint image-to-image features use up to 84% less GPU capacity than GPT-Image-2, and said on July 27 that an MDASH configuration pairing its new MAI-Cyber-1-Flash model with GPT-5.4 scored 95.95% on CyberGym at nearly 50% lower cost than its previous best setup. For anyone building or buying on these surfaces, the practical reading is that the model behind a familiar Copilot feature is now a routed, cost-driven choice, and Microsoft's own July 6 test of 150 Copilot Chat agent runs, where Claude Sonnet 5 cost $2.01 per code-upgrade run against $0.55 for Sonnet 4.6, shows that a cheaper rate card does not guarantee a cheaper run.
The governance layer is arriving on a slower clock than the distribution layer. Security researcher Håkon Måløy disclosed on July 28 that hidden instructions in a Word document could alter Copilot-assisted output and copy themselves into the generated file, and said the broader class remained reproducible after 144 days of coordination and two mitigation attempts; Microsoft told The Register it had addressed the reported findings and continues to strengthen layered safeguards. Manifold Security's July 21 disclosure showed hidden HTML comments in Azure DevOps pull-request descriptions reaching AI agents through Microsoft's official MCP server, and a July 27 check found the public repository's pull-request path still returning the description without the spotlighting wrapper. Barracuda published a controlled proof of concept on August 4 in which an attacker who already controlled an employee mailbox used Microsoft Copilot to find targets, imitate trusted colleagues and escalate to a CEO account, redirecting a simulated $247,500 wire transfer; that was a laboratory scenario, not a disclosed customer breach, and the assistant accelerated use of access the compromised account already had. Microsoft's counterweights are real but partial: a Purview Data Loss Prevention rule that excludes externally received email from Copilot grounding, summarization and citation is only in preview with general availability listed for January 2027, and it evaluates sender-domain metadata rather than message bodies; an update to Restricted Content Discovery reported on August 5 stops recently accessed files from RCD-protected SharePoint sites from resurfacing through Microsoft Search and Copilot discovery, with existing configurations applying without administrator action. Microsoft is also buying outside scrutiny, awarding more than $20 million to 562 researchers from 64 countries in the year ended June 30 and funding 18 university labs through the EXTRA red-team alliance. Teams standardizing on Copilot and agent surfaces should still treat repository text, partner documents and inbound email as untrusted input today, and evaluate controls at the feature level rather than assuming a tenant-wide switch exists.