The Copilot Credit Trap- Why Your AI Economy is Already Broken
For decades, enterprise software followed a predictable financial model. Organizations purchased licenses, assigned them to users, and budgeted annual IT spending with confidence. AI changes that completely. Modern AI platforms are no longer sold purely as software—they're becoming consumption-based services where autonomous agents perform work on your behalf. Every action, every reasoning cycle, every orchestration task, and every AI workflow consumes credits instead of simply using a fixed license. This episode explains why Copilot Credits fundamentally change enterprise budgeting, why governance becomes more important than licensing, and how organizations must rethink identity, permissions, auditing, FinOps, and AI compliance before autonomous agents become part of everyday business operations.
FROM SOFTWARE LICENSES TO AI ECONOMICS
Traditional enterprise software was easy to budget. Organizations counted employees, purchased licenses, and forecasted annual costs with relatively little uncertainty. AI introduces a completely different financial model. Instead of paying only for access, organizations increasingly pay for work performed. Every autonomous action performed by an AI agent consumes credits based on:
- Reasoning complexity
- Runtime
- Context size
- Tool usage
- Model selection
THE COPILOT CREDIT TRAP
The biggest misconception surrounding Copilot Credits is that they simply represent another licensing model. They don't. Credits become the currency of AI work. A lightweight task may consume relatively few credits. Complex reasoning tasks involving multiple enterprise systems, long context windows, and autonomous orchestration consume dramatically more. Costs now scale according to:
- Agent behavior
- Task complexity
- Organizational adoption
- Workflow automation
WHY FINANCE CAN NO LONGER PREDICT COSTS
Finance departments have traditionally planned annual software budgets using fixed subscription pricing. Consumption-based AI disrupts that model. Instead of budgeting for employees, organizations must now forecast:
- Daily agent activity
- Departmental usage
- Business workflows
- Credit consumption
- Seasonal demand
- Automation growth
VISIBILITY IS THE FIRST GOVERNANCE PROBLEM
Many organizations cannot accurately answer basic questions such as:
- Which AI agents currently exist?
- Which departments deployed them?
- Which systems can they access?
- Which business processes do they automate?
- How much do they cost?
- Copilot Studio
- Power Automate
- Departmental automation
- Third-party AI integrations
- Custom workflows
PERMISSIONS BECOME MULTIPLIED
One of the most significant risks discussed throughout the session is permission amplification. AI agents inherit the permissions of the identities under which they operate. If a user can access HR records, the agent can also access them. If a user can modify SharePoint documents, schedule meetings, or send emails, so can the agent. Unlike humans, however, agents perform these actions at machine speed and enterprise scale. This dramatically amplifies existing governance weaknesses, especially in environments suffering from years of permission creep and excessive data sharing. The presentation argues that AI doesn't create governance problems—it magnifies the ones organizations already have.
AUTONOMY REQUIRES NEW GOVERNANCE
Traditional software waits for users. Autonomous agents do not. Modern AI systems:
- Send emails
- Update records
- Schedule meetings
- Trigger workflows
- Coordinate with other agents
- Human approval gates
- Escalation rules
- Spending thresholds
- Risk classifications
- Continuous monitoring
THE EU AI ACT CHANGES EVERYTHING
One of the central themes of the presentation is the approaching regulatory landscape. Organizations deploying AI into HR, finance, customer services, or other sensitive business functions face increasing governance obligations under the EU AI Act. High-risk AI systems require:
- Risk management
- Technical documentation
- Human oversight
- Audit trails
- Incident reporting
- Continuous monitoring
IDENTITY IS THE FOUNDATION
The presentation argues that autonomous agents require independent identities rather than sharing user accounts. Each agent should receive:
- Dedicated identity
- Scoped permissions
- Least-privilege access
- Independent audit trail
- Lifecycle management
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.
🚀 Want to be part of m365.fm?
Then stop just listening… and start showing up.
👉 Connect with me on LinkedIn and let’s make something happen:
- 🎙️ Be a podcast guest and share your story
- 🎧 Host your own episode (yes, seriously)
- 💡 Pitch topics the community actually wants to hear
- 🌍 Build your personal brand in the Microsoft 365 space
This isn’t just a podcast — it’s a platform for people who take action.
🔥 Most people wait. The best ones don’t.
👉 Connect with me on LinkedIn and send me a message:
"I want in"
Let’s build something awesome 👊
00:00:00,000 --> 00:00:02,640
The assumption was simple, AI is a tool you buy,
2
00:00:02,640 --> 00:00:04,960
like software, like seats, you license it,
3
00:00:04,960 --> 00:00:06,960
you control it, and you budget for it.
4
00:00:06,960 --> 00:00:08,200
That assumption is dead.
5
00:00:08,200 --> 00:00:11,920
In reality, AI is a resource you consume,
6
00:00:11,920 --> 00:00:13,280
and that changes everything.
7
00:00:13,280 --> 00:00:14,960
The shift from seats to credits
8
00:00:14,960 --> 00:00:16,920
isn't just a new way to price software.
9
00:00:16,920 --> 00:00:19,880
It's a structural overhaul of how your organization operates.
10
00:00:19,880 --> 00:00:21,200
It's an inversion of control.
11
00:00:21,200 --> 00:00:23,080
Instead of buying access to a service,
12
00:00:23,080 --> 00:00:24,960
you're now paying for work performed
13
00:00:24,960 --> 00:00:26,400
by something you didn't hire.
14
00:00:26,400 --> 00:00:28,000
Under conditions you didn't negotiate,
15
00:00:28,000 --> 00:00:30,240
operating across every system it can reach.
16
00:00:30,240 --> 00:00:33,440
By August of 2026, if you haven't built a governance layer,
17
00:00:33,440 --> 00:00:34,800
you're not just overspending.
18
00:00:34,800 --> 00:00:38,120
You're exposed to regulatory fines, to audit failures,
19
00:00:38,120 --> 00:00:40,520
to incidents you won't see coming because in reality,
20
00:00:40,520 --> 00:00:42,920
you don't even know what agents are running inside your tenant.
21
00:00:42,920 --> 00:00:45,920
This is what actually happens when you deploy autonomous agents
22
00:00:45,920 --> 00:00:49,240
into an unprepared M365 environment.
23
00:00:49,240 --> 00:00:50,200
And here's the trap.
24
00:00:50,200 --> 00:00:53,040
Most organizations will discover this too late.
25
00:00:53,040 --> 00:00:54,880
The death of predictable aid budgeting,
26
00:00:54,880 --> 00:00:57,120
the old model was simple, you bought seats,
27
00:00:57,120 --> 00:00:59,320
you knew the cost, you knew who could use it.
28
00:00:59,320 --> 00:01:02,840
Microsoft CEO Satyan Adela made the strategy explicit
29
00:01:02,840 --> 00:01:04,680
when he said that any per user business of theirs
30
00:01:04,680 --> 00:01:06,440
will become a per user and usage business.
31
00:01:06,440 --> 00:01:08,440
That wasn't speculation, that was a declaration.
32
00:01:08,440 --> 00:01:11,360
The seat model is being systematically dismantled.
33
00:01:11,360 --> 00:01:14,440
For 20 years, IT budgeting followed a predictable path.
34
00:01:14,440 --> 00:01:17,720
You calculated your head count, multiplied it by a monthly rate
35
00:01:17,720 --> 00:01:19,280
and added 10% for growth.
36
00:01:19,280 --> 00:01:21,160
The budget was locked and the costs were predictable
37
00:01:21,160 --> 00:01:22,960
by October for the following year.
38
00:01:22,960 --> 00:01:24,240
Seeds gave you that.
39
00:01:24,240 --> 00:01:26,440
They gave you something precious in corporate finance,
40
00:01:26,440 --> 00:01:29,240
predictability, credits, destroy it.
41
00:01:29,240 --> 00:01:32,960
In the old model, 500 users at $30 per month for co-pilot
42
00:01:32,960 --> 00:01:35,440
equals $180,000 per year.
43
00:01:35,440 --> 00:01:38,640
It was calculable, it was for costable, it was safe.
44
00:01:38,640 --> 00:01:39,960
But the new model is different.
45
00:01:39,960 --> 00:01:42,240
500 users can now trigger consumption
46
00:01:42,240 --> 00:01:44,800
that scales with behavior, not head count.
47
00:01:44,800 --> 00:01:47,640
One agent can consume 1500 credits per task,
48
00:01:47,640 --> 00:01:49,640
which comes out to $15 per task.
49
00:01:49,640 --> 00:01:53,000
If 100 of those users run five agents a day,
50
00:01:53,000 --> 00:01:56,760
you're looking at 500 tasks, that's $7,500 in one day.
51
00:01:56,760 --> 00:01:59,600
When you multiply that by 250 working days,
52
00:01:59,600 --> 00:02:03,080
you're looking at $1.875 million in a single year.
53
00:02:03,080 --> 00:02:06,520
Unforcasted, un-budgeted, unconstrained.
54
00:02:06,520 --> 00:02:08,280
This is exactly what happened to GitHub.
55
00:02:08,280 --> 00:02:10,640
When GitHub co-pilot moved to full usage-based billing
56
00:02:10,640 --> 00:02:13,280
in June of 2026, it served as the template
57
00:02:13,280 --> 00:02:14,480
for the entire company.
58
00:02:14,480 --> 00:02:16,120
That's the direction Microsoft is moving
59
00:02:16,120 --> 00:02:17,400
with co-pilot credits.
60
00:02:17,400 --> 00:02:19,160
Per token pricing at one cent per credit
61
00:02:19,160 --> 00:02:21,320
means cost scales with behavior,
62
00:02:21,320 --> 00:02:23,000
not with how many people you license,
63
00:02:23,000 --> 00:02:25,640
with what those people and their agents actually do.
64
00:02:25,640 --> 00:02:27,600
Organizations budgeted for 500 seats
65
00:02:27,600 --> 00:02:29,400
at $30 per user per month.
66
00:02:29,400 --> 00:02:33,400
Now, they're discovering agents consuming 10,000 credits per task.
67
00:02:33,400 --> 00:02:35,280
They're discovering that the budget they thought
68
00:02:35,280 --> 00:02:36,960
was locked is actually variable.
69
00:02:36,960 --> 00:02:39,400
And the variable isn't on a monthly or quarterly cycle.
70
00:02:39,400 --> 00:02:41,280
It's daily, it's real time.
71
00:02:41,280 --> 00:02:44,040
The financial model breaks because you no longer paying for access,
72
00:02:44,040 --> 00:02:45,600
you're paying for work performed.
73
00:02:45,600 --> 00:02:47,320
And work performed is autonomous now.
74
00:02:47,320 --> 00:02:48,560
It's happening at machine speed.
75
00:02:48,560 --> 00:02:50,280
It's happening in volumes you didn't predict.
76
00:02:50,280 --> 00:02:51,880
It's happening without human oversight
77
00:02:51,880 --> 00:02:53,320
for each unit of consumption.
78
00:02:53,320 --> 00:02:54,760
This creates a structural problem.
79
00:02:54,760 --> 00:02:56,200
Finance expects predictability,
80
00:02:56,200 --> 00:02:57,800
but I just delivering volatility.
81
00:02:57,800 --> 00:02:59,560
The board expects a fixed line item,
82
00:02:59,560 --> 00:03:02,600
but CFOs are getting variable costs tied to agent autonomy.
83
00:03:02,600 --> 00:03:04,760
That's a mismatch that cascades through budgeting,
84
00:03:04,760 --> 00:03:06,400
forecasting and capital planning.
85
00:03:06,400 --> 00:03:07,880
But here's where it gets structural.
86
00:03:07,880 --> 00:03:09,080
The problem isn't the pricing.
87
00:03:09,080 --> 00:03:10,680
The problem is what you're actually paying for.
88
00:03:10,680 --> 00:03:12,920
You're not buying access to a tool anymore.
89
00:03:12,920 --> 00:03:15,160
You're buying agency, you're paying Microsoft
90
00:03:15,160 --> 00:03:17,560
to let something autonomous operate inside your tenant,
91
00:03:17,560 --> 00:03:19,200
something that can make decisions.
92
00:03:19,200 --> 00:03:20,440
Something that can take actions,
93
00:03:20,440 --> 00:03:23,040
something that can consume resources on your behalf.
94
00:03:23,040 --> 00:03:25,520
And you're being charged per unit of that autonomy.
95
00:03:25,520 --> 00:03:27,200
That's a completely different financial model.
96
00:03:27,200 --> 00:03:29,680
And it requires a completely different governance model.
97
00:03:29,680 --> 00:03:31,200
Because if you're paying for autonomous work,
98
00:03:31,200 --> 00:03:33,120
you need to know what work is happening,
99
00:03:33,120 --> 00:03:35,680
who authorized it, what data is it touching?
100
00:03:35,680 --> 00:03:38,520
Most organizations don't have answers to those questions yet.
101
00:03:38,520 --> 00:03:41,040
And they're about to get very expensive bills.
102
00:03:41,040 --> 00:03:43,160
What you're actually buying and what you're not.
103
00:03:43,160 --> 00:03:44,880
So what are co-pilot credits exactly?
104
00:03:44,880 --> 00:03:46,240
They aren't just tokens.
105
00:03:46,240 --> 00:03:48,360
They aren't just a way to measure usage.
106
00:03:48,360 --> 00:03:50,520
They are a currency for autonomous agency.
107
00:03:50,520 --> 00:03:52,160
When you spend a credit, you aren't paying
108
00:03:52,160 --> 00:03:54,000
for a model call in the way you think.
109
00:03:54,000 --> 00:03:55,840
You're paying for an agent to make a decision
110
00:03:55,840 --> 00:03:57,760
to take an action and to orchestrate work
111
00:03:57,760 --> 00:04:00,880
across your systems without waiting for a human to click next.
112
00:04:00,880 --> 00:04:03,040
You're paying for the doing, not the thinking.
113
00:04:03,040 --> 00:04:05,040
That's the distinction most organizations miss.
114
00:04:05,040 --> 00:04:07,800
A single co-work task consumes credits in tears
115
00:04:07,800 --> 00:04:09,400
based on what it has to do.
116
00:04:09,400 --> 00:04:11,840
Light work, like a quick summary or a status update,
117
00:04:11,840 --> 00:04:13,440
pulled from your calendar and emails
118
00:04:13,440 --> 00:04:15,280
runs 70 to 200 credits.
119
00:04:15,280 --> 00:04:17,160
Medium complexity work that requires
120
00:04:17,160 --> 00:04:19,280
stitching together data from multiple sources
121
00:04:19,280 --> 00:04:23,360
and formatting it into a structured output costs 400 to 600 credits.
122
00:04:23,360 --> 00:04:26,000
Heavy reasoning work where the agent has to analyze trends,
123
00:04:26,000 --> 00:04:28,640
spot patterns, and generate a leadership ready-breathing
124
00:04:28,640 --> 00:04:30,920
costs 1,500 credits or more.
125
00:04:30,920 --> 00:04:35,440
That is $15 per task for one agent on one problem running once.
126
00:04:35,440 --> 00:04:37,600
But here's the trap that catches every organization.
127
00:04:37,600 --> 00:04:41,120
The M365 co-pilot license costs $30 per user per month.
128
00:04:41,120 --> 00:04:43,520
That's the advertised price and the line item in your budget.
129
00:04:43,520 --> 00:04:46,320
But that license doesn't include any co-work credits.
130
00:04:46,320 --> 00:04:48,160
It's not a bundle, it's not all inclusive.
131
00:04:48,160 --> 00:04:50,600
You're licensing the capability to deploy agents,
132
00:04:50,600 --> 00:04:53,640
but you aren't licensing the agents themselves or the work they do.
133
00:04:53,640 --> 00:04:54,720
Those are separate.
134
00:04:54,720 --> 00:04:57,680
It's like licensing word but not paying for the paper you print on.
135
00:04:57,680 --> 00:04:59,440
Credits cover four cost buckets.
136
00:04:59,440 --> 00:05:00,640
First, the model.
137
00:05:00,640 --> 00:05:02,680
The agent picks the right LLM for the task,
138
00:05:02,680 --> 00:05:05,360
whether that's Claude, GPT-4 or a smaller model,
139
00:05:05,360 --> 00:05:07,200
and you pay the difference in cost.
140
00:05:07,200 --> 00:05:09,160
Second, runtime.
141
00:05:09,160 --> 00:05:10,960
Longer reasoning chains cost more
142
00:05:10,960 --> 00:05:14,360
because the agent needs more time to think through a complex decision.
143
00:05:14,360 --> 00:05:15,920
Third, context.
144
00:05:15,920 --> 00:05:17,840
A small context window costs less.
145
00:05:17,840 --> 00:05:20,240
But pulling in months of email and full calendar history
146
00:05:20,240 --> 00:05:21,800
costs significantly more.
147
00:05:21,800 --> 00:05:23,120
Fourth, tools.
148
00:05:23,120 --> 00:05:25,520
Every tool the agent can access has a cost.
149
00:05:25,520 --> 00:05:27,880
And every time it sends an email or modifies a record,
150
00:05:27,880 --> 00:05:29,160
it adds to that total.
151
00:05:29,160 --> 00:05:30,560
This is the fundamental difference
152
00:05:30,560 --> 00:05:32,800
that executives and architects need to understand.
153
00:05:32,800 --> 00:05:34,720
You aren't buying a service you control anymore.
154
00:05:34,720 --> 00:05:36,360
This is a service that controls itself.
155
00:05:36,360 --> 00:05:38,480
With traditional software, you buy a license
156
00:05:38,480 --> 00:05:39,680
and you own the configuration.
157
00:05:39,680 --> 00:05:42,000
You decide who can use it, you control when it runs,
158
00:05:42,000 --> 00:05:44,480
and the software is your asset bound by your terms.
159
00:05:44,480 --> 00:05:46,680
With co-pilot credits and co-work agents,
160
00:05:46,680 --> 00:05:48,200
the relationship inverts.
161
00:05:48,200 --> 00:05:49,880
Microsoft owns the system.
162
00:05:49,880 --> 00:05:51,560
The agent decides when to run.
163
00:05:51,560 --> 00:05:53,360
The agent decides what it needs to access.
164
00:05:53,360 --> 00:05:55,600
You're the tenant hosting the autonomous actor.
165
00:05:55,600 --> 00:05:57,160
You pay per unit of its autonomy
166
00:05:57,160 --> 00:05:58,520
because you're purchasing the freedom
167
00:05:58,520 --> 00:06:00,760
for something else to make decisions on your behalf.
168
00:06:00,760 --> 00:06:03,440
It happens inside your systems and uses your data
169
00:06:03,440 --> 00:06:06,440
without your explicit approval for each action.
170
00:06:06,440 --> 00:06:08,400
That's a different risk profile entirely.
171
00:06:08,400 --> 00:06:11,280
It changes everything about how you think about cost governance
172
00:06:11,280 --> 00:06:12,400
and access control.
173
00:06:12,400 --> 00:06:14,040
You aren't just paying for consumption.
174
00:06:14,040 --> 00:06:15,960
You're paying for unsupervised work
175
00:06:15,960 --> 00:06:18,400
and that requires a completely different governance layer
176
00:06:18,400 --> 00:06:20,240
than most organizations have built,
177
00:06:20,240 --> 00:06:23,200
which means the first governance problem isn't cost.
178
00:06:23,200 --> 00:06:24,280
It's visibility.
179
00:06:24,280 --> 00:06:25,520
The visibility crisis.
180
00:06:25,520 --> 00:06:26,760
Here's what you don't know.
181
00:06:26,760 --> 00:06:30,400
82% of enterprises have AI workflows running in production
182
00:06:30,400 --> 00:06:33,120
that their security teams are completely unaware of.
183
00:06:33,120 --> 00:06:34,240
They aren't tracking them.
184
00:06:34,240 --> 00:06:36,720
They aren't including them in any approval process.
185
00:06:36,720 --> 00:06:38,080
They are simply unknown.
186
00:06:38,080 --> 00:06:39,080
This isn't speculation.
187
00:06:39,080 --> 00:06:43,720
This is the baseline of enterprise AI deployment in 2026.
188
00:06:43,720 --> 00:06:45,960
The majority of organizations have autonomous systems
189
00:06:45,960 --> 00:06:47,640
operating inside their infrastructure
190
00:06:47,640 --> 00:06:50,680
that nobody in IT security has cataloged or even seen.
191
00:06:50,680 --> 00:06:52,200
Start with what you actually have.
192
00:06:52,200 --> 00:06:55,000
Somewhere inside your M365 tenant, shadow agents are running.
193
00:06:55,000 --> 00:06:57,640
You have power automate flows with co-pilot connectors
194
00:06:57,640 --> 00:06:59,840
and co-pilot studio agents built by departments
195
00:06:59,840 --> 00:07:01,680
without central IT involvement.
196
00:07:01,680 --> 00:07:03,520
There are custom integrations that somebody
197
00:07:03,520 --> 00:07:05,360
built six months ago and never documented
198
00:07:05,360 --> 00:07:07,720
plus third party tools that somehow got integrated
199
00:07:07,720 --> 00:07:09,440
into teams or SharePoint.
200
00:07:09,440 --> 00:07:12,480
Most organizations have zero inventory of which agents exist.
201
00:07:12,480 --> 00:07:14,760
They have zero understanding of what data they can access
202
00:07:14,760 --> 00:07:16,600
and zero tracking of what they cost.
203
00:07:16,600 --> 00:07:18,680
They deployed co-pilot, enabled co-work,
204
00:07:18,680 --> 00:07:21,720
and then lost visibility into what happened next.
205
00:07:21,720 --> 00:07:23,320
This creates a structural problem
206
00:07:23,320 --> 00:07:25,400
that governance can't solve retroactively
207
00:07:25,400 --> 00:07:27,640
because here's the design flow nobody acknowledges.
208
00:07:27,640 --> 00:07:30,520
Co-pilot co-work doesn't operate under a separate identity.
209
00:07:30,520 --> 00:07:32,040
It doesn't run under a service account
210
00:07:32,040 --> 00:07:33,560
and it doesn't ask for special permission.
211
00:07:33,560 --> 00:07:35,520
It operates within the user's identity
212
00:07:35,520 --> 00:07:36,960
and the user's permissions.
213
00:07:36,960 --> 00:07:37,720
Full stop.
214
00:07:37,720 --> 00:07:41,240
If you have access to HR data, the agent has access to HR data.
215
00:07:41,240 --> 00:07:43,960
If you can read personnel files and salary information,
216
00:07:43,960 --> 00:07:45,720
so can the agent running on your behalf.
217
00:07:45,720 --> 00:07:47,680
If you can delete files from SharePoint
218
00:07:47,680 --> 00:07:49,560
or modify records in your CRM,
219
00:07:49,560 --> 00:07:51,320
the agent can do all of that too.
220
00:07:51,320 --> 00:07:52,920
It doesn't need separate authorization
221
00:07:52,920 --> 00:07:55,560
because it simply inherits everything you can do
222
00:07:55,560 --> 00:07:57,680
and operates at a scale you never could manually.
223
00:07:57,680 --> 00:07:58,520
This is by design.
224
00:07:58,520 --> 00:08:01,640
The integration is seamless, which is exactly why it's dangerous.
225
00:08:01,640 --> 00:08:03,360
Now layer that over what we already know
226
00:08:03,360 --> 00:08:06,560
about M365 governance, 16% of business critical data
227
00:08:06,560 --> 00:08:08,440
is overshared across typical enterprises
228
00:08:08,440 --> 00:08:12,080
and the average organization has about 802,000 files at risk
229
00:08:12,080 --> 00:08:13,960
because permissions are misconfigured.
230
00:08:13,960 --> 00:08:17,120
Marketing has access to finance data
231
00:08:17,120 --> 00:08:19,080
and sales teams can read HR documents
232
00:08:19,080 --> 00:08:21,480
because permissions accumulate and people move teams
233
00:08:21,480 --> 00:08:23,720
without their old access being revoked.
234
00:08:23,720 --> 00:08:25,000
In a world of manual work,
235
00:08:25,000 --> 00:08:27,280
this oversharing is dangerous but limited.
236
00:08:27,280 --> 00:08:28,640
Humans search for what they need.
237
00:08:28,640 --> 00:08:30,360
Humans respect informal boundaries.
238
00:08:30,360 --> 00:08:31,640
Humans have cognitive limits.
239
00:08:31,640 --> 00:08:33,120
Agents don't have those limits.
240
00:08:33,120 --> 00:08:35,240
A co-work agent that you ask to summarize a project
241
00:08:35,240 --> 00:08:36,840
doesn't just read the obvious files.
242
00:08:36,840 --> 00:08:40,040
It aggregates data and crosses silos to surface connections
243
00:08:40,040 --> 00:08:42,200
that a human operator would never manually discover.
244
00:08:42,200 --> 00:08:43,840
It isn't necessarily smarter,
245
00:08:43,840 --> 00:08:46,040
but it can read 10,000 files in seconds
246
00:08:46,040 --> 00:08:48,120
and surface what's relevant without getting tired
247
00:08:48,120 --> 00:08:50,440
or respecting the boundaries that humans maintain.
248
00:08:50,440 --> 00:08:51,720
You aren't just deploying a tool
249
00:08:51,720 --> 00:08:53,640
into an over-permissioned environment.
250
00:08:53,640 --> 00:08:55,200
You're deploying an aggregator.
251
00:08:55,200 --> 00:08:57,480
You're deploying a system that connects information faster
252
00:08:57,480 --> 00:08:59,120
than your governance can prevent it.
253
00:08:59,120 --> 00:09:01,920
Agents amplify the risk that already exists.
254
00:09:01,920 --> 00:09:04,600
They make invisible problems visible to themselves
255
00:09:04,600 --> 00:09:06,440
and then they act on what they find.
256
00:09:06,440 --> 00:09:09,720
That's where the architecture starts to show its fault lines.
257
00:09:09,720 --> 00:09:11,480
The permission amplification problem,
258
00:09:11,480 --> 00:09:14,320
co-work doesn't just work, it exposes.
259
00:09:14,320 --> 00:09:15,800
When an agent inherits your permissions,
260
00:09:15,800 --> 00:09:17,520
it isn't thinking about boundaries.
261
00:09:17,520 --> 00:09:19,800
It doesn't care about the unwritten rules of your role
262
00:09:19,800 --> 00:09:21,600
or who you're actually supposed to be talking to.
263
00:09:21,600 --> 00:09:22,960
It takes your technical permissions,
264
00:09:22,960 --> 00:09:24,960
the simple yes or no inactive directory
265
00:09:24,960 --> 00:09:27,120
and it applies them at a scale you can't match.
266
00:09:27,120 --> 00:09:28,760
Take an agent summarizing your emails.
267
00:09:28,760 --> 00:09:30,360
It doesn't just look at today's messages
268
00:09:30,360 --> 00:09:31,840
or the ones you mark is important.
269
00:09:31,840 --> 00:09:33,000
It reads everything.
270
00:09:33,000 --> 00:09:34,760
Because technically, you have the right to read
271
00:09:34,760 --> 00:09:35,760
your own mailbox.
272
00:09:35,760 --> 00:09:37,760
The agent uses your identity
273
00:09:37,760 --> 00:09:39,840
to dig through five years of history.
274
00:09:39,840 --> 00:09:41,200
It finds patterns you missed
275
00:09:41,200 --> 00:09:44,000
and spots contradictions between what people said years ago
276
00:09:44,000 --> 00:09:45,240
versus what they're saying now.
277
00:09:45,240 --> 00:09:46,280
It pulls out information.
278
00:09:46,280 --> 00:09:47,960
You didn't even realize you could access.
279
00:09:47,960 --> 00:09:49,480
The same thing happens with your calendar.
280
00:09:49,480 --> 00:09:51,400
If you have permission to book conference rooms,
281
00:09:51,400 --> 00:09:52,640
the agent books them.
282
00:09:52,640 --> 00:09:54,480
If your role allows you to schedule meetings
283
00:09:54,480 --> 00:09:56,640
for your team, the agent schedules them.
284
00:09:56,640 --> 00:09:59,280
If you have delegation access for an executive's calendar,
285
00:09:59,280 --> 00:10:00,800
the agent manages that too.
286
00:10:00,800 --> 00:10:03,680
It isn't trying to be careful or second guessing its actions.
287
00:10:03,680 --> 00:10:05,560
It just sees a permission and uses it.
288
00:10:05,560 --> 00:10:06,600
But here's the problem.
289
00:10:06,600 --> 00:10:08,440
There is a massive gap between intent
290
00:10:08,440 --> 00:10:09,840
and technical existence.
291
00:10:09,840 --> 00:10:11,360
As a human, you understand new ones.
292
00:10:11,360 --> 00:10:12,680
You know that having access to a file
293
00:10:12,680 --> 00:10:15,200
doesn't always mean you should change it without asking first.
294
00:10:15,200 --> 00:10:16,880
You might technically be able to send an email
295
00:10:16,880 --> 00:10:19,240
from the CFO's account if the delegation is there,
296
00:10:19,240 --> 00:10:21,000
but you know better than to actually do it.
297
00:10:21,000 --> 00:10:22,320
Agents don't have that restraint.
298
00:10:22,320 --> 00:10:24,200
They don't understand what you intended.
299
00:10:24,200 --> 00:10:26,120
They only understand the technical boundary.
300
00:10:26,120 --> 00:10:27,840
If a permission is there, the agent views it
301
00:10:27,840 --> 00:10:29,320
as a tool that should be used.
302
00:10:29,320 --> 00:10:30,680
There is no internal voice saying
303
00:10:30,680 --> 00:10:32,120
this might be crossing a line.
304
00:10:32,120 --> 00:10:35,160
There is only the permission, the tool, and the task.
305
00:10:35,160 --> 00:10:36,680
The moment agents start running,
306
00:10:36,680 --> 00:10:38,920
every probably shouldn't, but technically could,
307
00:10:38,920 --> 00:10:40,520
scenario becomes a live risk.
308
00:10:40,520 --> 00:10:41,840
But there's a second layer to this.
309
00:10:41,840 --> 00:10:43,440
Agents can be redirected.
310
00:10:43,440 --> 00:10:45,800
In May of 2026, a vulnerability showed
311
00:10:45,800 --> 00:10:47,600
how file-based prompt injection works
312
00:10:47,600 --> 00:10:49,280
in Frontier Enrolled Tenants.
313
00:10:49,280 --> 00:10:52,040
The attack is simple, an attacker hides malicious instructions
314
00:10:52,040 --> 00:10:54,720
inside a document and leaves it in one drive or sharepoint
315
00:10:54,720 --> 00:10:56,200
where the agent can find it.
316
00:10:56,200 --> 00:10:58,840
When the agent reads that file to complete a task,
317
00:10:58,840 --> 00:11:01,920
it sees hidden text telling it to send all matching files
318
00:11:01,920 --> 00:11:03,480
to an external email address.
319
00:11:03,480 --> 00:11:06,080
The agent treats that instruction as a legitimate command
320
00:11:06,080 --> 00:11:08,000
and executes it immediately.
321
00:11:08,000 --> 00:11:10,760
By the end of May 2026, this was still unpatched.
322
00:11:10,760 --> 00:11:12,640
Microsoft knew about it, but fixing it
323
00:11:12,640 --> 00:11:14,520
requires a total architectural change.
324
00:11:14,520 --> 00:11:16,800
You have to teach an agent to tell the difference
325
00:11:16,800 --> 00:11:20,160
between a user's intent and instructions buried in data.
326
00:11:20,160 --> 00:11:22,520
That is a much harder problem than people realize.
327
00:11:22,520 --> 00:11:24,120
This leads to the third permission problem,
328
00:11:24,120 --> 00:11:26,840
even if your permissions were perfect, which they aren't.
329
00:11:26,840 --> 00:11:29,800
The agent can be compromised by the very data it reads.
330
00:11:29,800 --> 00:11:31,840
Prompt injection turns your tools against you.
331
00:11:31,840 --> 00:11:34,720
It takes your permissions and uses them to execute someone else's
332
00:11:34,720 --> 00:11:37,560
intent, so you have three problems stacked on top of each other.
333
00:11:37,560 --> 00:11:39,360
First, the agent inherits your permissions
334
00:11:39,360 --> 00:11:41,040
without any human nuance.
335
00:11:41,040 --> 00:11:42,920
Second, those permissions are usually a mess
336
00:11:42,920 --> 00:11:46,320
because of years of permission creep in Microsoft 365.
337
00:11:46,320 --> 00:11:49,280
Third, the agent can be hijacked through malicious data
338
00:11:49,280 --> 00:11:52,200
to use those permissions in ways you never authorized.
339
00:11:52,200 --> 00:11:52,880
It compounds.
340
00:11:52,880 --> 00:11:54,840
One compromised agent doesn't just touch one file.
341
00:11:54,840 --> 00:11:57,000
It accesses everything you can access.
342
00:11:57,000 --> 00:11:59,400
And in most companies, what you can access is way more
343
00:11:59,400 --> 00:12:00,360
than what you actually need.
344
00:12:00,360 --> 00:12:01,560
You have visibility problems.
345
00:12:01,560 --> 00:12:02,880
You have permission problems.
346
00:12:02,880 --> 00:12:04,120
Now, add autonomy.
347
00:12:04,120 --> 00:12:05,280
The autonomy problem.
348
00:12:05,280 --> 00:12:06,240
Agents execute.
349
00:12:06,240 --> 00:12:07,960
They don't ask for permission first.
350
00:12:07,960 --> 00:12:09,600
This is the shift that most organizations
351
00:12:09,600 --> 00:12:11,320
haven't wrapped their heads around yet.
352
00:12:11,320 --> 00:12:12,880
You're used to tools that wait for you.
353
00:12:12,880 --> 00:12:15,520
You open word, you click print, and you confirm the settings.
354
00:12:15,520 --> 00:12:18,040
Every action is a separate step that stops and waits
355
00:12:18,040 --> 00:12:20,040
for a human to say, go.
356
00:12:20,040 --> 00:12:22,720
Co-pilot co-work uses a completely different model.
357
00:12:22,720 --> 00:12:25,080
It sends emails, books, meetings, and modifies files
358
00:12:25,080 --> 00:12:27,200
without asking you about every single move.
359
00:12:27,200 --> 00:12:29,120
The architecture isn't built to wait for you.
360
00:12:29,120 --> 00:12:30,800
Instead, it uses a checkpoint model.
361
00:12:30,800 --> 00:12:33,280
The agent builds a plan and shows you what it wants to do.
362
00:12:33,280 --> 00:12:35,480
It might say it's going to email three people,
363
00:12:35,480 --> 00:12:38,760
summarize a document, and book a meeting for next Tuesday.
364
00:12:38,760 --> 00:12:40,680
You look at the plan and you hit approve.
365
00:12:40,680 --> 00:12:42,680
From that moment on, the system assumes
366
00:12:42,680 --> 00:12:44,960
it has the green light for everything that follows.
367
00:12:44,960 --> 00:12:46,520
But here's the structural flaw.
368
00:12:46,520 --> 00:12:48,720
You're approving a plan, not the actual actions,
369
00:12:48,720 --> 00:12:49,880
and plans change.
370
00:12:49,880 --> 00:12:52,160
Once the agent starts, it sends that first email.
371
00:12:52,160 --> 00:12:53,440
The person on the other end replies,
372
00:12:53,440 --> 00:12:55,320
the agent reads that reply and realizes
373
00:12:55,320 --> 00:12:56,680
the situation has shifted.
374
00:12:56,680 --> 00:12:58,400
Now, the summary needs to be different.
375
00:12:58,400 --> 00:12:59,800
The meeting needs different people.
376
00:12:59,800 --> 00:13:00,840
The agent adapts.
377
00:13:00,840 --> 00:13:03,000
It changes what it's doing in the middle of the job,
378
00:13:03,000 --> 00:13:06,000
based on information that didn't exist when you hit approve.
379
00:13:06,000 --> 00:13:07,320
This happens all the time.
380
00:13:07,320 --> 00:13:10,120
Data drifts in the model starts doing things you didn't predict.
381
00:13:10,120 --> 00:13:12,440
It finds new context or hits a system that reacts
382
00:13:12,440 --> 00:13:13,480
in an unexpected way.
383
00:13:13,480 --> 00:13:15,200
The agent just improvises and keeps going
384
00:13:15,200 --> 00:13:16,960
without ever coming back to check with you.
385
00:13:16,960 --> 00:13:18,520
By the time you see what happened,
386
00:13:18,520 --> 00:13:20,000
the emails are already sent.
387
00:13:20,000 --> 00:13:21,400
The records are already updated.
388
00:13:21,400 --> 00:13:23,760
The downstream workflows are already triggered.
389
00:13:23,760 --> 00:13:25,080
None of those specific versions
390
00:13:25,080 --> 00:13:26,440
were in the plan you signed off on.
391
00:13:26,440 --> 00:13:27,320
This isn't a bug.
392
00:13:27,320 --> 00:13:28,360
It's the whole point.
393
00:13:28,360 --> 00:13:30,560
If the agent had to ask you for permission every time
394
00:13:30,560 --> 00:13:33,360
it sent a message, it wouldn't be an autonomous agent.
395
00:13:33,360 --> 00:13:36,720
You'd be back to clicking next 1,000 times a day.
396
00:13:36,720 --> 00:13:39,920
The value comes from the agent making decisions without you.
397
00:13:39,920 --> 00:13:41,640
But for a company without governance,
398
00:13:41,640 --> 00:13:43,560
that creates a massive liability.
399
00:13:43,560 --> 00:13:46,560
Now, imagine this across multi-step workflows
400
00:13:46,560 --> 00:13:48,400
where agents talk to other agents.
401
00:13:48,400 --> 00:13:50,920
Agent A writes a proposal and hands it to Agent B.
402
00:13:50,920 --> 00:13:54,320
Agent B finds some issues and tells agency to pull more data.
403
00:13:54,320 --> 00:13:57,840
Agency runs the numbers and sends a report back to Agent A,
404
00:13:57,840 --> 00:13:59,520
who then changes the original proposal.
405
00:13:59,520 --> 00:14:01,840
Not a single human was involved in those handoffs.
406
00:14:01,840 --> 00:14:04,560
They are all chained together, making unsupervised decisions.
407
00:14:04,560 --> 00:14:06,840
Each agent is operating on the authority you gave it
408
00:14:06,840 --> 00:14:07,920
at the very beginning.
409
00:14:07,920 --> 00:14:10,160
Each one is adjusting its behavior based on things
410
00:14:10,160 --> 00:14:11,720
it wasn't designed to handle.
411
00:14:11,720 --> 00:14:13,520
You can't even interrupt the chain without killing
412
00:14:13,520 --> 00:14:14,440
the whole sequence.
413
00:14:14,440 --> 00:14:16,440
This is why governance models build for old tools
414
00:14:16,440 --> 00:14:17,760
just don't work here.
415
00:14:17,760 --> 00:14:20,120
Your current process assumes a human will check the work
416
00:14:20,120 --> 00:14:21,040
before it goes out.
417
00:14:21,040 --> 00:14:22,840
It assumes tasks happen in a vacuum.
418
00:14:22,840 --> 00:14:25,360
It assumes you can course correct it every step.
419
00:14:25,360 --> 00:14:27,760
Autonomous agents break all three of those assumptions.
420
00:14:27,760 --> 00:14:29,520
The result is that you only see what happened
421
00:14:29,520 --> 00:14:31,000
after the damage is done.
422
00:14:31,000 --> 00:14:33,520
By the time you realize an email went to the wrong person
423
00:14:33,520 --> 00:14:36,080
or a record was messed up, the action is over.
424
00:14:36,080 --> 00:14:37,880
You aren't preventing problems anymore.
425
00:14:37,880 --> 00:14:39,520
You're just investigating the aftermath.
426
00:14:39,520 --> 00:14:41,920
If you're dealing with HR, finance, or customer data,
427
00:14:41,920 --> 00:14:43,360
this is a huge deal.
428
00:14:43,360 --> 00:14:45,200
And that leads us to the governance deadline
429
00:14:45,200 --> 00:14:47,120
that almost everyone is missing.
430
00:14:47,120 --> 00:14:49,320
The August 2026 regulatory cliff.
431
00:14:49,320 --> 00:14:51,080
The EU AI Act isn't coming.
432
00:14:51,080 --> 00:14:52,120
It's already here.
433
00:14:52,120 --> 00:14:54,360
And August 2nd, 2026 is when it bites.
434
00:14:54,360 --> 00:14:57,440
Most organizations talk about the Act as though it's a future threat.
435
00:14:57,440 --> 00:14:59,600
A deadline to prepare for a compliance project
436
00:14:59,600 --> 00:15:00,680
you'll start next year.
437
00:15:00,680 --> 00:15:02,000
That assumption is broken.
438
00:15:02,000 --> 00:15:04,800
The Act entered into force on August 1st, 2024.
439
00:15:04,800 --> 00:15:05,920
That's already happened.
440
00:15:05,920 --> 00:15:08,240
Prehibited practices are already enforceable.
441
00:15:08,240 --> 00:15:11,640
Specific uses of AI, social scoring, manipulative apps,
442
00:15:11,640 --> 00:15:14,760
or biometric profiling are already illegal in the EU.
443
00:15:14,760 --> 00:15:16,280
It doesn't matter if you knew it or not.
444
00:15:16,280 --> 00:15:19,480
What's happening now is a staggered rollout of obligations.
445
00:15:19,480 --> 00:15:23,280
August 2nd, 2025 brought GPI obligations into force.
446
00:15:23,280 --> 00:15:25,560
General purpose AI providers, that's Microsoft,
447
00:15:25,560 --> 00:15:28,560
now have to disclose training data and publish model cards.
448
00:15:28,560 --> 00:15:30,080
That deadline has already passed.
449
00:15:30,080 --> 00:15:33,040
Your vendor now has obligations they didn't have before.
450
00:15:33,040 --> 00:15:35,040
But the deadline that matters for your organization
451
00:15:35,040 --> 00:15:37,000
is August 2nd, 2026.
452
00:15:37,000 --> 00:15:39,960
That's the one that creates immediate enforceable liability.
453
00:15:39,960 --> 00:15:41,080
It's not theoretical.
454
00:15:41,080 --> 00:15:43,080
It's five months away as of this recording.
455
00:15:43,080 --> 00:15:45,880
That's when high-risk AI system obligations apply to employers.
456
00:15:45,880 --> 00:15:47,080
That's your organization.
457
00:15:47,080 --> 00:15:48,040
Not Microsoft.
458
00:15:48,040 --> 00:15:51,240
You high-risk under the Act includes any AI system
459
00:15:51,240 --> 00:15:53,080
that affects employment decisions
460
00:15:53,080 --> 00:15:54,840
or influences credit access.
461
00:15:54,840 --> 00:15:57,960
It covers systems determining access to essential services
462
00:15:57,960 --> 00:16:00,400
or impacting a person's fundamental rights.
463
00:16:00,400 --> 00:16:02,080
The list is long, but the pattern is clear.
464
00:16:02,080 --> 00:16:05,480
If an AI system makes a decision that affects someone's life opportunities,
465
00:16:05,480 --> 00:16:06,600
it's high risk.
466
00:16:06,600 --> 00:16:10,120
Now ask yourself, do you have COVID agents drafting performance reviews?
467
00:16:10,120 --> 00:16:11,960
Do you have agents screening job candidates
468
00:16:11,960 --> 00:16:13,440
or recommending who to interview?
469
00:16:13,440 --> 00:16:16,960
Are you using agents to allocate work based on predicted productivity?
470
00:16:16,960 --> 00:16:20,600
If the answer to any of these is yes, you have high-risk AI systems.
471
00:16:20,600 --> 00:16:22,360
And as of August 2nd, 2026,
472
00:16:22,360 --> 00:16:26,200
those systems trigger a specific legally mandated governance framework.
473
00:16:26,200 --> 00:16:27,480
High-risk doesn't mean banned.
474
00:16:27,480 --> 00:16:29,360
It means the cost of operation goes up.
475
00:16:29,360 --> 00:16:31,200
You need a formal risk management system.
476
00:16:31,200 --> 00:16:35,040
You need technical documentation that proves the system works and doesn't discriminate.
477
00:16:35,040 --> 00:16:37,000
You need to maintain audit trails
478
00:16:37,000 --> 00:16:39,000
that log every decision the system makes
479
00:16:39,000 --> 00:16:40,800
and every piece of data it touched.
480
00:16:40,800 --> 00:16:43,360
You need human oversight, not a checkbox,
481
00:16:43,360 --> 00:16:46,240
but actual humans reviewing outputs before they affect people.
482
00:16:46,240 --> 00:16:47,680
The penalties are material.
483
00:16:47,680 --> 00:16:49,880
You're looking at up to 15 million euros
484
00:16:49,880 --> 00:16:53,080
or 3% of global turnover for high-risk violations.
485
00:16:53,080 --> 00:16:57,160
For prohibited practices, that jumps to 35 million euros or 7%.
486
00:16:57,160 --> 00:16:59,520
For most enterprises, this is board-level exposure.
487
00:16:59,520 --> 00:17:01,080
This isn't an IT budget issue.
488
00:17:01,080 --> 00:17:02,160
It's a shareholder issue.
489
00:17:02,160 --> 00:17:03,400
An insurance issue.
490
00:17:03,400 --> 00:17:05,320
A liability question for executives.
491
00:17:05,320 --> 00:17:07,960
But here's what catches most organizations off guard.
492
00:17:07,960 --> 00:17:10,120
The deadline isn't when compliance becomes optional.
493
00:17:10,120 --> 00:17:13,600
The deadline is when regulators can legally enforce violations.
494
00:17:13,600 --> 00:17:15,160
If you deploy a high-risk system
495
00:17:15,160 --> 00:17:16,760
and haven't built the governance layer,
496
00:17:16,760 --> 00:17:19,840
you're non-compliant starting August 2nd, 2026.
497
00:17:19,840 --> 00:17:21,640
Regulators don't need to warn you first.
498
00:17:21,640 --> 00:17:23,280
They don't need to wait for a complaint.
499
00:17:23,280 --> 00:17:25,240
They can investigate, audit, and find.
500
00:17:25,240 --> 00:17:27,040
Your customers won't tell you they have a problem.
501
00:17:27,040 --> 00:17:28,000
Regulators will.
502
00:17:28,000 --> 00:17:30,960
And by then, the cost of fixing it exceeds the cost of building it
503
00:17:30,960 --> 00:17:31,960
right from the beginning.
504
00:17:31,960 --> 00:17:34,040
Most organizations are still in discovery mode.
505
00:17:34,040 --> 00:17:35,360
They don't know which agents they have.
506
00:17:35,360 --> 00:17:37,360
They haven't classified them against the act.
507
00:17:37,360 --> 00:17:38,560
They haven't built governance.
508
00:17:38,560 --> 00:17:41,120
And they're five months away from a deadline with teeth.
509
00:17:41,120 --> 00:17:43,040
But the deadline is only the enforcement date.
510
00:17:43,040 --> 00:17:44,800
The real problem is what comes before it.
511
00:17:44,800 --> 00:17:47,440
What high-risk actually means for your agents?
512
00:17:47,440 --> 00:17:48,760
Here's the critical distinction.
513
00:17:48,760 --> 00:17:50,680
Almost every organization misses.
514
00:17:50,680 --> 00:17:52,800
The EUAI Act doesn't regulate co-pilot.
515
00:17:52,800 --> 00:17:55,400
It regulates how you use co-pilot, the same tool.
516
00:17:55,400 --> 00:17:57,840
Different use case, completely different obligation tier.
517
00:17:57,840 --> 00:18:00,280
Take a co-work agent that drafts your meeting notes.
518
00:18:00,280 --> 00:18:03,200
You ask it to listen to recordings, extract action items,
519
00:18:03,200 --> 00:18:04,720
and write them into a summary.
520
00:18:04,720 --> 00:18:06,720
That's low risk you have transparency.
521
00:18:06,720 --> 00:18:10,200
Duties, you need to disclose that the content is AI generated.
522
00:18:10,200 --> 00:18:12,360
But the Act doesn't require extensive governance.
523
00:18:12,360 --> 00:18:15,080
The agent isn't making consequential decisions about anyone.
524
00:18:15,080 --> 00:18:16,880
It's producing a draft for human review.
525
00:18:16,880 --> 00:18:19,200
Now take a co-work agent that scores job candidates.
526
00:18:19,200 --> 00:18:22,040
You feed it resumes, it rates them on predicted fit,
527
00:18:22,040 --> 00:18:23,480
and recommends who to interview.
528
00:18:23,480 --> 00:18:24,600
That's high risk.
529
00:18:24,600 --> 00:18:27,560
The Act treats this as operating in the employment domain.
530
00:18:27,560 --> 00:18:30,160
The agent is materially influencing hiring decisions.
531
00:18:30,160 --> 00:18:31,440
That triggers full obligations.
532
00:18:31,440 --> 00:18:33,640
You need a formal risk management system.
533
00:18:33,640 --> 00:18:35,840
You need technical documentation proving the system
534
00:18:35,840 --> 00:18:36,960
doesn't discriminate.
535
00:18:36,960 --> 00:18:38,960
You need to demonstrate you tested for buyers.
536
00:18:38,960 --> 00:18:40,520
You need continuous human oversight.
537
00:18:40,520 --> 00:18:42,360
Actual humans reviewing the agent scores
538
00:18:42,360 --> 00:18:43,520
before decisions are made.
539
00:18:43,520 --> 00:18:45,520
You need audit trails capturing every resume
540
00:18:45,520 --> 00:18:48,040
to the agent evaluated and what criteria it used.
541
00:18:48,040 --> 00:18:49,960
You need evidence that a human could override
542
00:18:49,960 --> 00:18:52,640
the recommendation, same tool, different outcome,
543
00:18:52,640 --> 00:18:54,160
different governance costs.
544
00:18:54,160 --> 00:18:57,040
This matters because organizations typically deploy agents
545
00:18:57,040 --> 00:18:59,800
without mapping use cases to the Act's risk framework.
546
00:18:59,800 --> 00:19:00,720
They turn on co-work.
547
00:19:00,720 --> 00:19:01,840
They let teams use it.
548
00:19:01,840 --> 00:19:04,480
Then they discover too late that a department is using an agent
549
00:19:04,480 --> 00:19:06,720
for something that qualifies as high risk.
550
00:19:06,720 --> 00:19:08,000
What defines high risk?
551
00:19:08,000 --> 00:19:10,160
The Act lists specific categories.
552
00:19:10,160 --> 00:19:11,760
Anything affecting employment decisions,
553
00:19:11,760 --> 00:19:14,360
anything influencing credit or financial access,
554
00:19:14,360 --> 00:19:17,440
anything determining eligibility for benefits or public services,
555
00:19:17,440 --> 00:19:19,760
anything making safety critical decisions.
556
00:19:19,760 --> 00:19:22,000
Within those categories, high risk triggers
557
00:19:22,000 --> 00:19:24,280
five non-negotiable obligations.
558
00:19:24,280 --> 00:19:27,400
First, a risk management system, not a document on a shelf.
559
00:19:27,400 --> 00:19:29,760
An active continuous process that identifies risks
560
00:19:29,760 --> 00:19:31,160
and implements mitigations.
561
00:19:31,160 --> 00:19:34,160
You're continuously asking, what could this agent get wrong?
562
00:19:34,160 --> 00:19:36,000
What data could corrupt its decision?
563
00:19:36,000 --> 00:19:37,600
How would we detect problems?
564
00:19:37,600 --> 00:19:39,640
Second, technical documentation.
565
00:19:39,640 --> 00:19:42,080
Article 12 requires you to document the system's design,
566
00:19:42,080 --> 00:19:43,560
training data and testing procedures.
567
00:19:43,560 --> 00:19:45,720
You can't just say you deployed Claude and it works.
568
00:19:45,720 --> 00:19:48,040
You need documented evidence that you tested the model
569
00:19:48,040 --> 00:19:50,520
for accuracy, fairness and security.
570
00:19:50,520 --> 00:19:53,200
Third, logging and auditability.
571
00:19:53,200 --> 00:19:54,960
Article 12 requires you to maintain
572
00:19:54,960 --> 00:19:58,120
tamper evident logs of every decision the system makes.
573
00:19:58,120 --> 00:19:58,880
Not summaries.
574
00:19:58,880 --> 00:20:01,040
Detailed transaction logs capturing the input,
575
00:20:01,040 --> 00:20:03,560
the agent received and the reasoning chain it followed.
576
00:20:03,560 --> 00:20:05,320
You need a minimum six month retention
577
00:20:05,320 --> 00:20:07,000
because regulators will ask for evidence
578
00:20:07,000 --> 00:20:08,360
and you need to show it.
579
00:20:08,360 --> 00:20:09,800
Fourth, human oversight.
580
00:20:09,800 --> 00:20:12,720
Article 14 requires meaningful human intervention.
581
00:20:12,720 --> 00:20:15,200
Not a checkbox where someone clicks approve.
582
00:20:15,200 --> 00:20:17,960
Real human review where someone understands the system
583
00:20:17,960 --> 00:20:19,480
and monitors its outputs.
584
00:20:19,480 --> 00:20:21,280
The oversight has to be effective.
585
00:20:21,280 --> 00:20:24,080
That means the human has the time, information and authority
586
00:20:24,080 --> 00:20:26,520
to actually override the agent's decision.
587
00:20:26,520 --> 00:20:28,200
Fifth, incident reporting.
588
00:20:28,200 --> 00:20:31,400
When something goes wrong, the agent makes a discriminatory decision
589
00:20:31,400 --> 00:20:33,880
or gets compromised by a prompt injection attack.
590
00:20:33,880 --> 00:20:36,400
You need procedures to escalate to regulators.
591
00:20:36,400 --> 00:20:37,360
This is mandatory.
592
00:20:37,360 --> 00:20:38,960
For serious incidents, the act requires
593
00:20:38,960 --> 00:20:41,000
notification to supervisory authorities.
594
00:20:41,000 --> 00:20:42,880
This is what high risk actually means.
595
00:20:42,880 --> 00:20:43,880
It's not a label.
596
00:20:43,880 --> 00:20:45,320
It's an operating burden.
597
00:20:45,320 --> 00:20:48,760
It means infrastructure requirements, staffing implications,
598
00:20:48,760 --> 00:20:51,480
audit expenses, continuous monitoring overhead,
599
00:20:51,480 --> 00:20:53,200
which means governance isn't optional.
600
00:20:53,200 --> 00:20:55,120
It's a design constraint.
601
00:20:55,120 --> 00:20:56,400
The identity problem.
602
00:20:56,400 --> 00:20:58,720
Agent 365 and the control plane.
603
00:20:58,720 --> 00:21:00,680
Most organizations are still treating agents
604
00:21:00,680 --> 00:21:02,640
the way they treated bots five years ago.
605
00:21:02,640 --> 00:21:04,680
You deploy them under a shared service account.
606
00:21:04,680 --> 00:21:06,400
You let them borrow a user's credentials.
607
00:21:06,400 --> 00:21:09,440
They run as background processes that nobody explicitly owns.
608
00:21:09,440 --> 00:21:10,360
But here's the problem.
609
00:21:10,360 --> 00:21:12,240
That approach is a structural mistake.
610
00:21:12,240 --> 00:21:13,880
It makes governance impossible.
611
00:21:13,880 --> 00:21:16,200
Because when an agent runs under a user's identity,
612
00:21:16,200 --> 00:21:18,600
everything it does gets attributed to that human.
613
00:21:18,600 --> 00:21:21,240
Every email it sends shows up in your send folder.
614
00:21:21,240 --> 00:21:23,560
Every file it creates appears under your name.
615
00:21:23,560 --> 00:21:27,120
Every action it takes registers as though you perform it yourself.
616
00:21:27,120 --> 00:21:28,560
This creates an attribution nightmare.
617
00:21:28,560 --> 00:21:30,480
You can't tell where the user's work ends
618
00:21:30,480 --> 00:21:32,120
and the agent's work begins.
619
00:21:32,120 --> 00:21:34,760
You can't prove a human made a specific decision
620
00:21:34,760 --> 00:21:36,560
if an agent made it on their behalf.
621
00:21:36,560 --> 00:21:39,360
And you definitely can't demonstrate who authorized what.
622
00:21:39,360 --> 00:21:40,720
Because from the systems perspective,
623
00:21:40,720 --> 00:21:42,320
the user authorized everything.
624
00:21:42,320 --> 00:21:44,720
Now layer that over the regulatory requirement.
625
00:21:44,720 --> 00:21:47,120
The EU AI Act demands human oversight.
626
00:21:47,120 --> 00:21:48,560
It demands audit trails.
627
00:21:48,560 --> 00:21:51,240
It requires you to show which agent made which decision
628
00:21:51,240 --> 00:21:53,040
and prove that a human could have stopped it.
629
00:21:53,040 --> 00:21:54,600
If the agent's actions are indistinguishable
630
00:21:54,600 --> 00:21:57,360
from the user's actions, you can't meet that obligation.
631
00:21:57,360 --> 00:21:58,520
You can't show oversight.
632
00:21:58,520 --> 00:21:59,600
You can't show governance.
633
00:21:59,600 --> 00:22:01,120
Or you can show as user activity
634
00:22:01,120 --> 00:22:02,640
that doesn't satisfy Article 14.
635
00:22:02,640 --> 00:22:04,400
This is why Agent 365 exists.
636
00:22:04,400 --> 00:22:07,600
Microsoft made Agent 365 generally available on May 1,
637
00:22:07,600 --> 00:22:10,520
which in 2020-26 it's priced at $15 per user per month,
638
00:22:10,520 --> 00:22:13,720
which puts it in the Microsoft 365 e7 bundle.
639
00:22:13,720 --> 00:22:15,400
It's the answer to the identity problem.
640
00:22:15,400 --> 00:22:17,280
Instead of Agent's borrowing identities,
641
00:22:17,280 --> 00:22:20,360
Agent 365 gives each agent a first-class identity
642
00:22:20,360 --> 00:22:21,400
in Entra ID.
643
00:22:21,400 --> 00:22:23,800
Not a shared service account, not a borrowed credential.
644
00:22:23,800 --> 00:22:26,200
It's a distinct principle with its own life cycle,
645
00:22:26,200 --> 00:22:28,440
its own permissions and its own audit trail.
646
00:22:28,440 --> 00:22:30,480
Under the old model, you deploy an agent
647
00:22:30,480 --> 00:22:31,640
and granted broad permissions
648
00:22:31,640 --> 00:22:34,160
because managing scoped access was too complex.
649
00:22:34,160 --> 00:22:36,040
The agent needed to read files, send emails,
650
00:22:36,040 --> 00:22:37,120
and modify records.
651
00:22:37,120 --> 00:22:38,320
So you'd give it a service account
652
00:22:38,320 --> 00:22:40,520
with blanket access to do all of those things.
653
00:22:40,520 --> 00:22:41,880
That service account would be shared
654
00:22:41,880 --> 00:22:43,880
across multiple agents and workflows.
655
00:22:43,880 --> 00:22:46,120
When something went wrong, you couldn't pinpoint
656
00:22:46,120 --> 00:22:47,480
which agent caused it.
657
00:22:47,480 --> 00:22:49,680
The account touched everything, so everything was suspect.
658
00:22:49,680 --> 00:22:52,240
Agent 365 inverts that.
659
00:22:52,240 --> 00:22:55,080
Each agent gets its own identity with scoped permissions.
660
00:22:55,080 --> 00:22:58,320
One agent can send emails, but not read financial data.
661
00:22:58,320 --> 00:23:01,560
Another can schedule meetings, but can't access HR records.
662
00:23:01,560 --> 00:23:04,720
A third can modify documents in one specific sharepoint site
663
00:23:04,720 --> 00:23:06,440
but is blocked from everything else.
664
00:23:06,440 --> 00:23:07,840
The permissions are bound to the agent,
665
00:23:07,840 --> 00:23:09,040
not to a shared account.
666
00:23:09,040 --> 00:23:11,120
When the agent acts, the audit log shows exactly
667
00:23:11,120 --> 00:23:12,280
which agent acted.
668
00:23:12,280 --> 00:23:13,720
When you need to revoke access,
669
00:23:13,720 --> 00:23:15,800
you revoke it for that specific agent,
670
00:23:15,800 --> 00:23:18,200
not for everyone running under the same service account.
671
00:23:18,200 --> 00:23:20,080
This is non-negotiable for compliance.
672
00:23:20,080 --> 00:23:21,320
You can't demonstrate governance
673
00:23:21,320 --> 00:23:22,920
if you can't identify the actor.
674
00:23:22,920 --> 00:23:25,480
Regulators will ask which agent made this decision?
675
00:23:25,480 --> 00:23:27,680
When, using what data did a human review it?
676
00:23:27,680 --> 00:23:30,240
If the agent's identity is blurred into a user's identity,
677
00:23:30,240 --> 00:23:31,600
you have no answer.
678
00:23:31,600 --> 00:23:33,720
If the agent has a distinct identity and enter ID,
679
00:23:33,720 --> 00:23:34,880
the answer is clear.
680
00:23:34,880 --> 00:23:37,440
But there's a secondary benefit that organizations often
681
00:23:37,440 --> 00:23:38,280
missed.
682
00:23:38,280 --> 00:23:40,920
With agent 365, you can enforce policy at the identity level.
683
00:23:40,920 --> 00:23:43,000
You can use inter-conditional access to control
684
00:23:43,000 --> 00:23:44,600
when agents operate.
685
00:23:44,600 --> 00:23:46,480
You can restrict them from accessing data
686
00:23:46,480 --> 00:23:49,520
outside their assigned scope or create information barriers
687
00:23:49,520 --> 00:23:50,640
between departments.
688
00:23:50,640 --> 00:23:53,400
You can even enforce MFA for sensitive operations.
689
00:23:53,400 --> 00:23:55,720
You can audit every single action the agent takes
690
00:23:55,720 --> 00:23:57,760
because it's operating under its own identity, not
691
00:23:57,760 --> 00:23:59,160
masquerading as a user.
692
00:23:59,160 --> 00:24:02,280
The first layer of governance isn't just knowing what agents exist.
693
00:24:02,280 --> 00:24:04,560
It's ensuring they operate as distinct identities
694
00:24:04,560 --> 00:24:06,600
with auditable, scoped permissions.
695
00:24:06,600 --> 00:24:09,560
Agent 365 is the infrastructure that makes that possible.
696
00:24:09,560 --> 00:24:11,160
But identity alone isn't enough.
697
00:24:11,160 --> 00:24:14,080
You also need to know what the agent can actually do.
698
00:24:14,080 --> 00:24:16,560
The tool access problem, scope and escalation.
699
00:24:16,560 --> 00:24:18,200
Agents don't just think they act.
700
00:24:18,200 --> 00:24:19,400
An acting requires access.
701
00:24:19,400 --> 00:24:21,080
Copilot co-work can invoke tools.
702
00:24:21,080 --> 00:24:23,720
It can send emails to anyone in your organization,
703
00:24:23,720 --> 00:24:27,080
create files and SharePoint, call APIs, or trigger
704
00:24:27,080 --> 00:24:28,280
power automate flows.
705
00:24:28,280 --> 00:24:30,240
Every one of those capabilities is a tool.
706
00:24:30,240 --> 00:24:32,040
And the agent can use any tool that's technically
707
00:24:32,040 --> 00:24:33,200
allowed to access.
708
00:24:33,200 --> 00:24:34,200
But here's the problem.
709
00:24:34,200 --> 00:24:36,360
Most organizations have no tool inventory.
710
00:24:36,360 --> 00:24:38,880
They have no framework for what agents are allowed to do.
711
00:24:38,880 --> 00:24:40,880
There is no distinction between tools that
712
00:24:40,880 --> 00:24:43,520
are safe for autonomous execution and tools that
713
00:24:43,520 --> 00:24:44,640
require human approval.
714
00:24:44,640 --> 00:24:46,360
They deployed co-work and granted access
715
00:24:46,360 --> 00:24:49,000
to standard connectors like email, calendar, and teams.
716
00:24:49,000 --> 00:24:50,480
Then they handed the keys to the agents
717
00:24:50,480 --> 00:24:52,960
and assumed governance would happen organically.
718
00:24:52,960 --> 00:24:53,480
It doesn't.
719
00:24:53,480 --> 00:24:56,080
If an agent can access a connector, it will use it.
720
00:24:56,080 --> 00:24:59,000
Not because it's malicious, but because the logic of the system
721
00:24:59,000 --> 00:25:01,640
is that available tools solve problems.
722
00:25:01,640 --> 00:25:04,040
The user asks the agent to prepare a summary and send it
723
00:25:04,040 --> 00:25:05,200
to stakeholders.
724
00:25:05,200 --> 00:25:06,800
The agent can send emails, so it sends.
725
00:25:06,800 --> 00:25:08,760
It doesn't check if external email is forbidden.
726
00:25:08,760 --> 00:25:10,800
It doesn't ask if these particular stakeholders
727
00:25:10,800 --> 00:25:11,960
should receive this data.
728
00:25:11,960 --> 00:25:14,040
It just executes because the tool is available
729
00:25:14,040 --> 00:25:15,920
and the prompt implies it should use it.
730
00:25:15,920 --> 00:25:19,280
Escalation rules are nearly entirely absent in most systems.
731
00:25:19,280 --> 00:25:21,280
Which actions require human approval?
732
00:25:21,280 --> 00:25:23,200
Most organizations can't answer that.
733
00:25:23,200 --> 00:25:24,320
Which actions are forbidden?
734
00:25:24,320 --> 00:25:24,920
Unknown.
735
00:25:24,920 --> 00:25:26,520
Which actions have spending caps?
736
00:25:26,520 --> 00:25:27,720
Nobody has configured that.
737
00:25:27,720 --> 00:25:30,120
A co-work task that consumes 1,500 credits
738
00:25:30,120 --> 00:25:32,400
runs to completion because there's no cost threshold
739
00:25:32,400 --> 00:25:33,200
to stop it.
740
00:25:33,200 --> 00:25:35,120
There is no budget gate that says this task
741
00:25:35,120 --> 00:25:38,040
exceeded the limit, escalate to a human before continuing.
742
00:25:38,040 --> 00:25:41,520
The task runs, the credits get consumed, the agent finishes.
743
00:25:41,520 --> 00:25:43,080
You see the bill later, but by then,
744
00:25:43,080 --> 00:25:45,560
the decision is made and the cost is locked in.
745
00:25:45,560 --> 00:25:47,760
This creates a structural vulnerability
746
00:25:47,760 --> 00:25:49,920
that governance frameworks can't touch.
747
00:25:49,920 --> 00:25:52,560
You can write policies and document what agents should do,
748
00:25:52,560 --> 00:25:54,840
but if the technical layer doesn't enforce those rules,
749
00:25:54,840 --> 00:25:56,360
the policies are just theater.
750
00:25:56,360 --> 00:25:58,520
What you actually need are hard constraints.
751
00:25:58,520 --> 00:26:00,200
Agents shouldn't be able to make purchases
752
00:26:00,200 --> 00:26:03,200
over a specific dollar amount without explicit human approval
753
00:26:03,200 --> 00:26:04,720
before the purchase executes.
754
00:26:04,720 --> 00:26:07,880
Not after, not with a reversal process before.
755
00:26:07,880 --> 00:26:10,320
The tool must prevent the agent from completing the action
756
00:26:10,320 --> 00:26:12,400
until a human reviews and authorizes it.
757
00:26:12,400 --> 00:26:14,200
The same applies to communication.
758
00:26:14,200 --> 00:26:16,360
Agents shouldn't send emails to external domains
759
00:26:16,360 --> 00:26:17,840
without going through an approval gate.
760
00:26:17,840 --> 00:26:20,680
Internal collaboration is fine, but external messages
761
00:26:20,680 --> 00:26:23,080
should be escalated to a human who reviews the content
762
00:26:23,080 --> 00:26:25,960
and the recipient list before the agent hits send.
763
00:26:25,960 --> 00:26:29,320
And agents should never be allowed to delete data, period.
764
00:26:29,320 --> 00:26:31,120
Deletion requires human authorization
765
00:26:31,120 --> 00:26:32,520
for every single instance.
766
00:26:32,520 --> 00:26:35,040
The agent wants to delete a file, a human approves it,
767
00:26:35,040 --> 00:26:37,080
and only then does the deletion happen and get logged.
768
00:26:37,080 --> 00:26:38,440
These aren't nice to have additions.
769
00:26:38,440 --> 00:26:40,800
These are foundational control requirements.
770
00:26:40,800 --> 00:26:42,840
They require integration between the agents,
771
00:26:42,840 --> 00:26:45,200
the tools they invoke, and approval systems
772
00:26:45,200 --> 00:26:48,000
that can actually stop agent execution mid workflow
773
00:26:48,000 --> 00:26:49,840
until a human validates the action.
774
00:26:49,840 --> 00:26:51,440
Most organizations haven't built this.
775
00:26:51,440 --> 00:26:53,520
They've deployed the agents, granted broad access
776
00:26:53,520 --> 00:26:54,840
and hoped for the best.
777
00:26:54,840 --> 00:26:57,360
You need identity and permissions scope to the agent.
778
00:26:57,360 --> 00:26:59,080
You need tools classified by risk.
779
00:26:59,080 --> 00:27:01,520
You need escalation rules that root high-risk actions
780
00:27:01,520 --> 00:27:02,960
to humans before execution.
781
00:27:02,960 --> 00:27:04,880
You need spending limits that prevent agents
782
00:27:04,880 --> 00:27:07,520
from burning unlimited credits on a single task.
783
00:27:07,520 --> 00:27:10,600
And you need audit trails that show which agent invoked
784
00:27:10,600 --> 00:27:13,240
which tool with what parameters and what the outcome was.
785
00:27:13,240 --> 00:27:15,800
Without this layer, agents operate without constraints.
786
00:27:15,800 --> 00:27:18,240
They inherit your permissions, they access every tool
787
00:27:18,240 --> 00:27:21,640
you've granted them, and they spend whatever the task costs.
788
00:27:21,640 --> 00:27:24,240
And you only find out what happened after it's already done.
789
00:27:24,240 --> 00:27:26,680
So you need identity, scoped tools, and escalation.
790
00:27:26,680 --> 00:27:28,320
You also need to see what happened.
791
00:27:28,320 --> 00:27:31,400
The audit trail problem, logging and reconstruction.
792
00:27:31,400 --> 00:27:33,360
You can't govern what you can't see
793
00:27:33,360 --> 00:27:35,400
and you definitely can't defend what you can't explain.
794
00:27:35,400 --> 00:27:37,480
This is the hard limit that separates governance
795
00:27:37,480 --> 00:27:39,080
theater from actual control.
796
00:27:39,080 --> 00:27:42,440
And it's exactly where most M365 environments hit a wall.
797
00:27:42,440 --> 00:27:45,000
By default, copilot-co-work doesn't log prompts or reasoning.
798
00:27:45,000 --> 00:27:46,360
It only logs actions.
799
00:27:46,360 --> 00:27:48,520
You'll see email sent in your audit log.
800
00:27:48,520 --> 00:27:51,720
You'll see document created or calendar modified.
801
00:27:51,720 --> 00:27:53,160
But you won't see what the agent was thinking
802
00:27:53,160 --> 00:27:54,200
when it made that decision.
803
00:27:54,200 --> 00:27:56,800
And you won't see the data it read to arrive at its conclusion.
804
00:27:56,800 --> 00:27:58,120
The chain of reasoning is missing.
805
00:27:58,120 --> 00:28:00,200
You don't know why it sent that specific email
806
00:28:00,200 --> 00:28:03,000
to those specific people using that exact phrasing.
807
00:28:03,000 --> 00:28:05,440
From a regulatory standpoint, this is a disaster.
808
00:28:05,440 --> 00:28:08,480
For high-risk workflows in HR, finance, or compliance,
809
00:28:08,480 --> 00:28:11,240
you need the full chain from input to reasoning to action.
810
00:28:11,240 --> 00:28:13,400
You have to be able to reconstruct what the agent observed
811
00:28:13,400 --> 00:28:14,960
and what problem it thought it was solving.
812
00:28:14,960 --> 00:28:16,560
You need to know which rules it followed
813
00:28:16,560 --> 00:28:19,240
to conclude that a specific action was the right one.
814
00:28:19,240 --> 00:28:21,800
The EU AI Act calls this explainability.
815
00:28:21,800 --> 00:28:23,360
Regulators call it accountability.
816
00:28:23,360 --> 00:28:25,560
What it really means is that if something goes wrong,
817
00:28:25,560 --> 00:28:27,760
you have to explain how the agent got there
818
00:28:27,760 --> 00:28:30,440
and where a human could have stepped in to stop it.
819
00:28:30,440 --> 00:28:32,880
Microsoft purview audit logs capture the outcome,
820
00:28:32,880 --> 00:28:34,280
but they missed the why.
821
00:28:34,280 --> 00:28:35,560
They record that an action happened
822
00:28:35,560 --> 00:28:37,240
and who it appeared to come from along
823
00:28:37,240 --> 00:28:38,960
with timestamps and success rates.
824
00:28:38,960 --> 00:28:41,480
But they don't capture AI-specific metadata.
825
00:28:41,480 --> 00:28:43,440
Like the model version or the temperature settings,
826
00:28:43,440 --> 00:28:45,960
they don't record which data sources the agent queried
827
00:28:45,960 --> 00:28:48,120
or the full prompt that triggered the task.
828
00:28:48,120 --> 00:28:50,880
For compliance, showing the result without the reasoning
829
00:28:50,880 --> 00:28:52,160
is simply not enough.
830
00:28:52,160 --> 00:28:54,040
You actually need a separate logging infrastructure
831
00:28:54,040 --> 00:28:55,920
built just for agent activities.
832
00:28:55,920 --> 00:28:58,280
This shouldn't be a feature added to your existing log.
833
00:28:58,280 --> 00:29:01,160
It needs to be a dedicated layer that captures the agent ID,
834
00:29:01,160 --> 00:29:03,200
the user ID, the active model version,
835
00:29:03,200 --> 00:29:04,920
and every tool the agent called.
836
00:29:04,920 --> 00:29:07,440
It needs to show the parameters used, the data accessed,
837
00:29:07,440 --> 00:29:09,760
and whether a human reviewed or overrode the output.
838
00:29:09,760 --> 00:29:12,480
Your retention requirement is at least six months.
839
00:29:12,480 --> 00:29:14,680
The data must be non-deleteable and tamper evident,
840
00:29:14,680 --> 00:29:16,640
meaning you build storage that makes it mathematically
841
00:29:16,640 --> 00:29:19,320
impossible to change a log entry after it's created.
842
00:29:19,320 --> 00:29:22,040
By hashing each entry, any tampering becomes immediately
843
00:29:22,040 --> 00:29:24,360
detectable because it invalidates the hash.
844
00:29:24,360 --> 00:29:27,320
You should also store copies in different geographic locations,
845
00:29:27,320 --> 00:29:29,440
so no single failure can wipe your records.
846
00:29:29,440 --> 00:29:31,640
These logs have to be searchable immediately.
847
00:29:31,640 --> 00:29:34,440
You can't wait for a background job to index them tomorrow.
848
00:29:34,440 --> 00:29:37,040
When a regulator asks to see every hiring decision
849
00:29:37,040 --> 00:29:39,600
affecting a specific demographic over the last six months,
850
00:29:39,600 --> 00:29:41,440
you need to pull that data in minutes.
851
00:29:41,440 --> 00:29:43,200
This requires real infrastructure investment
852
00:29:43,200 --> 00:29:45,520
in database design and integration between co-work,
853
00:29:45,520 --> 00:29:47,520
power, automate, and your identity system.
854
00:29:47,520 --> 00:29:49,120
Most organizations haven't built this yet.
855
00:29:49,120 --> 00:29:50,680
They're relying on purview, but purview
856
00:29:50,680 --> 00:29:52,280
was built for compliance professionals
857
00:29:52,280 --> 00:29:54,960
to search the past, not for real-time agent auditing.
858
00:29:54,960 --> 00:29:56,400
The reason this matters is simple.
859
00:29:56,400 --> 00:29:58,680
When an agent makes a discriminatory hiring decision
860
00:29:58,680 --> 00:30:01,040
or accesses data it shouldn't have, regulators
861
00:30:01,040 --> 00:30:02,760
will demand the decision chain.
862
00:30:02,760 --> 00:30:04,520
If your infrastructure doesn't capture that chain,
863
00:30:04,520 --> 00:30:05,800
you can't defend yourself.
864
00:30:05,800 --> 00:30:07,800
You can't show that you had oversight or prove
865
00:30:07,800 --> 00:30:09,440
that a human could have intervened.
866
00:30:09,440 --> 00:30:11,360
Without this layer, you're running blind.
867
00:30:11,360 --> 00:30:13,920
You're putting autonomous systems into regulated spaces
868
00:30:13,920 --> 00:30:16,120
without the tools to prove you're in control.
869
00:30:16,120 --> 00:30:19,080
By August, 2026, that won't just be a technical gap.
870
00:30:19,080 --> 00:30:20,840
It will be a massive liability.
871
00:30:20,840 --> 00:30:24,120
The data governance prerequisite, classification and boundaries.
872
00:30:24,120 --> 00:30:27,160
Here's what breaks most co-work deployments before they even start.
873
00:30:27,160 --> 00:30:30,400
You can't deploy agents safely into a poorly governed environment.
874
00:30:30,400 --> 00:30:34,560
And the reality is that 80% of M365 tenants aren't copilot-ready.
875
00:30:34,560 --> 00:30:35,720
This isn't about licenses.
876
00:30:35,720 --> 00:30:37,200
It's about the foundational governance
877
00:30:37,200 --> 00:30:39,800
that most companies skipped during their cloud migration.
878
00:30:39,800 --> 00:30:41,800
We're talking about over-permission sites,
879
00:30:41,800 --> 00:30:44,400
missing sensitivity labels, and DLP policies
880
00:30:44,400 --> 00:30:46,600
that never planned for AI-generated content.
881
00:30:46,600 --> 00:30:49,040
You might have information barriers in a policy document
882
00:30:49,040 --> 00:30:51,480
that they aren't enforced at the technical layer.
883
00:30:51,480 --> 00:30:53,080
When you drop co-work into that mess,
884
00:30:53,080 --> 00:30:54,400
the agent doesn't learn new rules.
885
00:30:54,400 --> 00:30:57,320
It inherits the oversharing and the missing controls.
886
00:30:57,320 --> 00:30:59,040
It operates under the assumption
887
00:30:59,040 --> 00:31:01,200
that the infrastructure boundaries are correct.
888
00:31:01,200 --> 00:31:04,960
But if those boundaries are broken, the agent will cross them.
889
00:31:04,960 --> 00:31:06,320
This creates a compounding problem
890
00:31:06,320 --> 00:31:08,280
because agents don't just access data.
891
00:31:08,280 --> 00:31:09,720
They aggregate it.
892
00:31:09,720 --> 00:31:11,880
Data classification has to be a technical boundary,
893
00:31:11,880 --> 00:31:13,520
not just a tagging exercise.
894
00:31:13,520 --> 00:31:15,640
Sensitivity labels are the signals that control
895
00:31:15,640 --> 00:31:17,560
what agents can do with information.
896
00:31:17,560 --> 00:31:19,160
These labels need to be applied consistently
897
00:31:19,160 --> 00:31:20,520
across the entire organization,
898
00:31:20,520 --> 00:31:22,480
meaning every internal doc, customer record,
899
00:31:22,480 --> 00:31:24,560
and strategic plan must be classified.
900
00:31:24,560 --> 00:31:27,720
The agent relies on these labels to understand what it's touching.
901
00:31:27,720 --> 00:31:29,080
If your labeling is spotty,
902
00:31:29,080 --> 00:31:31,040
the agent operates in the gaps and treats
903
00:31:31,040 --> 00:31:33,520
unclassified sensitive files as fair game.
904
00:31:33,520 --> 00:31:37,400
The enforcement tool here is data loss prevention or DLP.
905
00:31:37,400 --> 00:31:40,440
Most DLP frameworks were designed to stop human mistakes,
906
00:31:40,440 --> 00:31:43,080
like blocking a user from emailing a confidential file
907
00:31:43,080 --> 00:31:44,320
to a personal account.
908
00:31:44,320 --> 00:31:46,040
Agents make different mistakes.
909
00:31:46,040 --> 00:31:48,200
An agent won't try to mail a spreadsheet to Gmail.
910
00:31:48,200 --> 00:31:50,320
Instead, it will read a confidential file,
911
00:31:50,320 --> 00:31:51,880
summarize the sensitive parts,
912
00:31:51,880 --> 00:31:53,600
and include that summary in a new report
913
00:31:53,600 --> 00:31:54,920
for a much larger audience.
914
00:31:54,920 --> 00:31:57,040
Since the agent generated the new report,
915
00:31:57,040 --> 00:31:58,680
it isn't marked as confidential,
916
00:31:58,680 --> 00:32:00,400
so the DLP doesn't stop it.
917
00:32:00,400 --> 00:32:02,160
The sensitive data leaked through aggregation
918
00:32:02,160 --> 00:32:03,600
instead of a direct transfer.
919
00:32:03,600 --> 00:32:06,320
Your DLP policies have to evolve to handle this.
920
00:32:06,320 --> 00:32:07,960
When an agent creates a document,
921
00:32:07,960 --> 00:32:11,160
that file should inherit the highest sensitivity level
922
00:32:11,160 --> 00:32:12,760
of any data used to build it.
923
00:32:12,760 --> 00:32:14,760
If the agent reads confidential customer info
924
00:32:14,760 --> 00:32:15,840
to write a summary,
925
00:32:15,840 --> 00:32:17,440
that summary is now confidential.
926
00:32:17,440 --> 00:32:20,080
This rule must be explicit and enforced automatically.
927
00:32:20,080 --> 00:32:21,680
Then there are information barriers.
928
00:32:21,680 --> 00:32:23,520
Marketing shouldn't see product roadmaps
929
00:32:23,520 --> 00:32:25,720
and sales shouldn't see internal pricing.
930
00:32:25,720 --> 00:32:27,680
With human users, these silos usually hold
931
00:32:27,680 --> 00:32:29,120
because of social norms and the fact
932
00:32:29,120 --> 00:32:30,840
that nobody wants to be caught snooping.
933
00:32:30,840 --> 00:32:32,720
Agents don't have those social restraints.
934
00:32:32,720 --> 00:32:34,440
If an agent has the technical permission
935
00:32:34,440 --> 00:32:36,280
to cross a boundary, it will do it
936
00:32:36,280 --> 00:32:39,120
because the prompt told it to find relevant information.
937
00:32:39,120 --> 00:32:41,560
It doesn't care which side of the fence that info is on.
938
00:32:41,560 --> 00:32:43,080
You have to enforce these barriers
939
00:32:43,080 --> 00:32:45,240
at the tool level as technical constraints.
940
00:32:45,240 --> 00:32:47,480
The agent should be allowed to access department A
941
00:32:47,480 --> 00:32:50,000
or department B, but never both at once.
942
00:32:50,000 --> 00:32:52,160
It needs to be restricted to specific databases
943
00:32:52,160 --> 00:32:53,600
and file paths by design.
944
00:32:53,600 --> 00:32:54,960
This is the prerequisite layer.
945
00:32:54,960 --> 00:32:56,840
You can't build a governance model for agents
946
00:32:56,840 --> 00:32:58,280
if your foundation is shifting.
947
00:32:58,280 --> 00:33:02,280
You need consistent labels, DLP that understands AI behavior,
948
00:33:02,280 --> 00:33:04,680
and technical barriers that actually stop access.
949
00:33:04,680 --> 00:33:06,480
Most organizations are deploying co-work
950
00:33:06,480 --> 00:33:08,800
into environments where governance is just a suggestion.
951
00:33:08,800 --> 00:33:11,560
When you do that, the agent doesn't fix your problems.
952
00:33:11,560 --> 00:33:14,400
It immediately amplifies every weakness you already had.
953
00:33:15,280 --> 00:33:16,600
The cost attribution problem,
954
00:33:16,600 --> 00:33:18,280
fin ops and unit economics.
955
00:33:18,280 --> 00:33:19,720
Now we get to the economic discipline
956
00:33:19,720 --> 00:33:21,080
that almost nobody has built
957
00:33:21,080 --> 00:33:23,400
because you can't optimize what you can't measure
958
00:33:23,400 --> 00:33:25,400
and you can't measure what you can't attribute.
959
00:33:25,400 --> 00:33:26,760
The shift from seats to credits
960
00:33:26,760 --> 00:33:28,080
creates a measurement problem
961
00:33:28,080 --> 00:33:30,280
that traditional cloud accounting never solved.
962
00:33:30,280 --> 00:33:32,400
When you bought software licenses in the past,
963
00:33:32,400 --> 00:33:33,520
the math was simple.
964
00:33:33,520 --> 00:33:36,800
You took 500 users, multiplied them by $30 a month,
965
00:33:36,800 --> 00:33:40,360
and you had a predictable $15,000 line item in your budget.
966
00:33:40,360 --> 00:33:41,240
It was done.
967
00:33:41,240 --> 00:33:42,640
You could forecast five years out
968
00:33:42,640 --> 00:33:43,800
with reasonable accuracy
969
00:33:43,800 --> 00:33:45,680
because the relationship between your head count
970
00:33:45,680 --> 00:33:47,280
and your cost was linear.
971
00:33:47,280 --> 00:33:49,320
Credits break that relationship entirely.
972
00:33:49,320 --> 00:33:51,400
Imagine two teams with the exact same head count,
973
00:33:51,400 --> 00:33:53,880
the same number of users, and the same licenses.
974
00:33:53,880 --> 00:33:56,760
One team uses co-work agents for 30% of their daily work
975
00:33:56,760 --> 00:33:58,280
and sees significant time savings.
976
00:33:58,280 --> 00:33:59,280
They are optimizing.
977
00:33:59,280 --> 00:34:01,040
They use the tool for high-value tasks
978
00:34:01,040 --> 00:34:03,720
where agents excel and their credit consumption
979
00:34:03,720 --> 00:34:05,920
reflects that targeted approach.
980
00:34:05,920 --> 00:34:08,720
The other team uses agents for 60% of their work,
981
00:34:08,720 --> 00:34:10,920
but sees no productivity improvement at all.
982
00:34:10,920 --> 00:34:12,440
They are using the tool indiscriminately.
983
00:34:12,440 --> 00:34:14,000
They are applying agents to tasks
984
00:34:14,000 --> 00:34:16,080
that are actually faster to do manually,
985
00:34:16,080 --> 00:34:18,440
burning through credits on low-value automation
986
00:34:18,440 --> 00:34:19,920
just because it is available.
987
00:34:19,920 --> 00:34:21,840
Both teams have the same licensing cost
988
00:34:21,840 --> 00:34:24,560
but their credit consumption is wildly different.
989
00:34:24,560 --> 00:34:26,680
One is spending $2,000 a month on co-work
990
00:34:26,680 --> 00:34:29,280
while the other is spending $8,000, same head count,
991
00:34:29,280 --> 00:34:30,360
different economics,
992
00:34:30,360 --> 00:34:32,800
and nobody at the organizational level understands why
993
00:34:32,800 --> 00:34:34,160
because nobody is tracking it.
994
00:34:34,160 --> 00:34:35,520
This is where AI Finops comes in.
995
00:34:35,520 --> 00:34:36,960
It is the discipline of measuring
996
00:34:36,960 --> 00:34:38,920
and attributing AI consumption,
997
00:34:38,920 --> 00:34:41,240
the way you would measure any other operational resource.
998
00:34:41,240 --> 00:34:43,440
But it requires a completely different approach
999
00:34:43,440 --> 00:34:45,480
than traditional cloud cost management.
1000
00:34:45,480 --> 00:34:47,880
AI Finops moves away from total cloud spend
1001
00:34:47,880 --> 00:34:51,160
and toward cost per inference or cost per agent task.
1002
00:34:51,160 --> 00:34:54,040
It means you are not asking how much you spend on AI this month
1003
00:34:54,040 --> 00:34:56,560
but rather how much you spend per resolved ticket,
1004
00:34:56,560 --> 00:34:59,040
per document drafted, or per candidate screened.
1005
00:34:59,040 --> 00:35:01,360
You are measuring cost against outcome,
1006
00:35:01,360 --> 00:35:02,840
not just against usage,
1007
00:35:02,840 --> 00:35:04,920
but attribution is where it gets complicated.
1008
00:35:04,920 --> 00:35:07,520
Most organizations today track credits at the tenant level.
1009
00:35:07,520 --> 00:35:09,880
You turn on billing, Microsoft sends you a bill,
1010
00:35:09,880 --> 00:35:10,640
and you pay it.
1011
00:35:10,640 --> 00:35:12,240
That is the extent of your visibility.
1012
00:35:12,240 --> 00:35:14,840
You have zero idea which team generated which costs.
1013
00:35:14,840 --> 00:35:17,240
You can't tell if the finance department's agent deployments
1014
00:35:17,240 --> 00:35:19,160
cost more or less than the marketing departments
1015
00:35:19,160 --> 00:35:21,440
and you can't see whether one specific agent
1016
00:35:21,440 --> 00:35:25,000
is consuming a disproportionate share of your budget.
1017
00:35:25,000 --> 00:35:27,440
Real attribution requires tagging at the request level.
1018
00:35:27,440 --> 00:35:29,600
Every time an agent executes a task,
1019
00:35:29,600 --> 00:35:32,200
that task needs to be tagged with which agent ran it,
1020
00:35:32,200 --> 00:35:33,520
which user triggered it,
1021
00:35:33,520 --> 00:35:35,120
and which department owns it.
1022
00:35:35,120 --> 00:35:37,000
You need to know which business process
1023
00:35:37,000 --> 00:35:39,320
it was serving and which outcome it was targeting.
1024
00:35:39,320 --> 00:35:41,320
That metadata flows through the system,
1025
00:35:41,320 --> 00:35:43,160
the cloud billing system captures it,
1026
00:35:43,160 --> 00:35:44,640
and at the end of the month,
1027
00:35:44,640 --> 00:35:46,240
you don't just have a credit total,
1028
00:35:46,240 --> 00:35:49,120
you have a cost breakdown by agent, by team,
1029
00:35:49,120 --> 00:35:51,560
by department, and by business process.
1030
00:35:51,560 --> 00:35:53,040
Then showback comes first.
1031
00:35:53,040 --> 00:35:54,520
Showback is just reporting.
1032
00:35:54,520 --> 00:35:57,240
You pull the data and show each team what they consumed.
1033
00:35:57,240 --> 00:36:00,520
You tell them marketing spent $12,000 on co-work this month,
1034
00:36:00,520 --> 00:36:03,640
finance spent $8,000, and operation spent $3,000.
1035
00:36:03,640 --> 00:36:06,440
There is no billing and no direct charge to their budget.
1036
00:36:06,440 --> 00:36:08,280
It is just visibility.
1037
00:36:08,280 --> 00:36:11,040
You are training the organization to see what is happening.
1038
00:36:11,040 --> 00:36:12,680
After two or three months of showback,
1039
00:36:12,680 --> 00:36:15,440
once the data is clean and teams understand the patterns,
1040
00:36:15,440 --> 00:36:16,320
you move to chargeback.
1041
00:36:16,320 --> 00:36:19,240
Now the costs flow back to the teams that incurred them.
1042
00:36:19,240 --> 00:36:21,720
Their budgets are charged and they see the direct financial
1043
00:36:21,720 --> 00:36:23,480
consequence of their agent usage.
1044
00:36:23,480 --> 00:36:25,040
Suddenly they care about optimizing.
1045
00:36:25,040 --> 00:36:27,200
They stop using agents for low-value tasks
1046
00:36:27,200 --> 00:36:29,600
because those tasks are now visibly expensive.
1047
00:36:29,600 --> 00:36:32,440
Without chargeback, teams have no incentive to optimize.
1048
00:36:32,440 --> 00:36:34,400
Agents keep running, credits keep burning,
1049
00:36:34,400 --> 00:36:35,800
someone else pays the bill.
1050
00:36:35,800 --> 00:36:37,280
The incentive structure is broken.
1051
00:36:37,280 --> 00:36:39,520
You also need to build a cost model that makes sense.
1052
00:36:39,520 --> 00:36:41,920
Not just cost per credit but cost per outcome.
1053
00:36:41,920 --> 00:36:44,720
A light task might cost 70 to 200 credits,
1054
00:36:44,720 --> 00:36:46,760
which is about $1 to $2.
1055
00:36:46,760 --> 00:36:50,960
A medium task costs $400 to $600 credits or about $4 to $6.
1056
00:36:50,960 --> 00:36:54,280
A heavy reasoning task costs 1,500 credits or more,
1057
00:36:54,280 --> 00:36:57,480
which means you are paying $15 or more for a single execution.
1058
00:36:57,480 --> 00:36:59,640
Then you map those costs to business value.
1059
00:36:59,640 --> 00:37:01,840
If a task takes one hour to do manually,
1060
00:37:01,840 --> 00:37:04,680
and an agent does it in two minutes at a cost of $5,
1061
00:37:04,680 --> 00:37:06,960
that is $5 for one hour of labor savings.
1062
00:37:06,960 --> 00:37:09,520
Whether that is a good trade depends on your labor costs.
1063
00:37:09,520 --> 00:37:11,760
If the hour is being billed to a customer
1064
00:37:11,760 --> 00:37:13,720
who pays $200 for that hour,
1065
00:37:13,720 --> 00:37:17,360
then you are saving $195 in labor cost.
1066
00:37:17,360 --> 00:37:20,800
If the task is internal work and the labor cost is $40 per hour,
1067
00:37:20,800 --> 00:37:23,720
the math is still good because you are saving $35,
1068
00:37:23,720 --> 00:37:25,600
but you only see this value if you have built
1069
00:37:25,600 --> 00:37:27,480
the measurement infrastructure to track it.
1070
00:37:27,480 --> 00:37:30,680
Credits need to be tied to outcomes, not just consumed, understood.
1071
00:37:30,680 --> 00:37:33,240
The ROI problem, value versus cost.
1072
00:37:33,240 --> 00:37:36,400
Credits are consumption, but consumption isn't automatically value.
1073
00:37:36,400 --> 00:37:38,040
And here is where the economic model starts
1074
00:37:38,040 --> 00:37:40,400
to reveal its broken incentive structure.
1075
00:37:40,400 --> 00:37:43,440
87% of enterprises report no measurable ROI
1076
00:37:43,440 --> 00:37:44,840
from co-pilot deployments.
1077
00:37:44,840 --> 00:37:48,160
This isn't because the tool is bad or because agents don't work.
1078
00:37:48,160 --> 00:37:49,840
It is because they deployed without building
1079
00:37:49,840 --> 00:37:51,320
the measurement framework first.
1080
00:37:51,320 --> 00:37:53,640
They turned on the feature, let teams use it and paid the bill,
1081
00:37:53,640 --> 00:37:56,040
but then they couldn't tell if anything actually improved.
1082
00:37:56,040 --> 00:37:59,200
The difference between seat-based ROI and credit-based ROI
1083
00:37:59,200 --> 00:38:00,240
is instructive.
1084
00:38:00,240 --> 00:38:02,360
Seat-based is simple arithmetic.
1085
00:38:02,360 --> 00:38:04,760
You buy 500 seats at $30 a month,
1086
00:38:04,760 --> 00:38:07,200
which is $15,000 in known cost.
1087
00:38:07,200 --> 00:38:09,320
Then you measure whether this unlocked productivity.
1088
00:38:09,320 --> 00:38:13,360
If each user saves two hours per week at a $75 hourly labor cost,
1089
00:38:13,360 --> 00:38:16,000
that is $150 in value per user.
1090
00:38:16,000 --> 00:38:20,080
Multiplying that by 500 users gives you $75,000 in monthly value
1091
00:38:20,080 --> 00:38:21,640
against $15,000 in cost.
1092
00:38:21,640 --> 00:38:23,640
The ROI works.
1093
00:38:23,640 --> 00:38:25,920
Credit-based ROI is harder because the relationship
1094
00:38:25,920 --> 00:38:27,680
between cost and outcome is buried.
1095
00:38:27,680 --> 00:38:29,920
You deploy an agent and it performs tasks.
1096
00:38:29,920 --> 00:38:33,120
Each task costs variable credits, maybe 100 or maybe 2000,
1097
00:38:33,120 --> 00:38:34,480
depending on complexity.
1098
00:38:34,480 --> 00:38:35,960
The credits add up into a bill,
1099
00:38:35,960 --> 00:38:38,160
but what did those credits actually accomplish?
1100
00:38:38,160 --> 00:38:40,760
That is the question most organizations can't answer,
1101
00:38:40,760 --> 00:38:42,440
because here is what happens in practice.
1102
00:38:42,440 --> 00:38:45,480
Most organizations don't track value per completion.
1103
00:38:45,480 --> 00:38:47,200
They don't know the cost per resolved ticket
1104
00:38:47,200 --> 00:38:48,480
when an agent handles it,
1105
00:38:48,480 --> 00:38:50,320
and they don't measure cost per document
1106
00:38:50,320 --> 00:38:52,640
drafted or cost per analysis performed.
1107
00:38:52,640 --> 00:38:54,360
They just watch the credit meter spin.
1108
00:38:54,360 --> 00:38:57,800
A team uses co-work agents extensively and the credit bill goes up,
1109
00:38:57,800 --> 00:39:00,120
but nobody knows if they got proportional value.
1110
00:39:00,120 --> 00:39:02,200
GitHub Copilot provides the baseline data.
1111
00:39:02,200 --> 00:39:05,760
Users who actually get value from Copilot spend an average of about
1112
00:39:05,760 --> 00:39:07,360
two hours per week using it.
1113
00:39:07,360 --> 00:39:09,600
Below that threshold, the seat isn't paying for itself
1114
00:39:09,600 --> 00:39:12,280
because the user isn't getting enough value to offset the cost.
1115
00:39:12,280 --> 00:39:14,160
That is the minimum engagement level.
1116
00:39:14,160 --> 00:39:15,880
Below it, you are throwing away the license.
1117
00:39:15,880 --> 00:39:17,960
Co-work is too new to have similar baselines,
1118
00:39:17,960 --> 00:39:20,120
but early data shows extreme variance.
1119
00:39:20,120 --> 00:39:23,240
Some teams report 50% time savings on their daily work
1120
00:39:23,240 --> 00:39:26,240
because they use agents for exactly the tasks where agents excel.
1121
00:39:26,240 --> 00:39:29,160
They focus on routine, data heavy, multi-step work,
1122
00:39:29,160 --> 00:39:30,680
that humans find tedious.
1123
00:39:30,680 --> 00:39:33,480
Those teams are winning, their cost per outcome is favorable,
1124
00:39:33,480 --> 00:39:35,000
and they are optimizing.
1125
00:39:35,000 --> 00:39:36,960
Other teams see zero productivity improvement.
1126
00:39:36,960 --> 00:39:39,560
They are using agents just because the feature is available.
1127
00:39:39,560 --> 00:39:43,000
They apply agents to tasks that are actually faster done manually,
1128
00:39:43,000 --> 00:39:44,880
burning credits on low-value automation
1129
00:39:44,880 --> 00:39:46,680
just because someone gave them access.
1130
00:39:46,680 --> 00:39:48,800
Those teams are losing, they are consuming credits
1131
00:39:48,800 --> 00:39:50,920
without generating corresponding value.
1132
00:39:50,920 --> 00:39:53,680
Now, here is the behavioral trap embedded in the consumption model
1133
00:39:53,680 --> 00:39:54,760
you are paying per action.
1134
00:39:54,760 --> 00:39:57,160
So the economic incentive is to use the agent more,
1135
00:39:57,160 --> 00:39:58,680
not to use it better.
1136
00:39:58,680 --> 00:40:01,680
The logic suggests that the more tasks the agent completes,
1137
00:40:01,680 --> 00:40:04,360
the more value you are extracting from your credit investment,
1138
00:40:04,360 --> 00:40:06,120
except that is backward.
1139
00:40:06,120 --> 00:40:07,800
The value isn't in action volume.
1140
00:40:07,800 --> 00:40:09,760
The value is an outcome efficiency.
1141
00:40:09,760 --> 00:40:12,160
A team that uses agents for 30% of their work,
1142
00:40:12,160 --> 00:40:14,280
but see significant improvement per action
1143
00:40:14,280 --> 00:40:16,760
is getting better ROI than a team using agents
1144
00:40:16,760 --> 00:40:19,760
for 70% of their work with marginal gains.
1145
00:40:19,760 --> 00:40:22,680
But the consumption model doesn't incentivize that distinction.
1146
00:40:22,680 --> 00:40:25,640
It incentivizes volume, use more agents,
1147
00:40:25,640 --> 00:40:28,040
automate more tasks, spend more credits.
1148
00:40:28,040 --> 00:40:30,040
Because the more you use the system,
1149
00:40:30,040 --> 00:40:32,440
the more value you are supposedly extracting,
1150
00:40:32,440 --> 00:40:35,000
measured purely in terms of work automation
1151
00:40:35,000 --> 00:40:36,800
rather than business outcome.
1152
00:40:36,800 --> 00:40:38,640
This creates a perverse dynamic.
1153
00:40:38,640 --> 00:40:40,440
Teams optimize for agent utilization
1154
00:40:40,440 --> 00:40:41,840
instead of for outcome value.
1155
00:40:41,840 --> 00:40:43,720
They look for additional tasks to automate
1156
00:40:43,720 --> 00:40:46,160
rather than better ways to automate existing tasks.
1157
00:40:46,160 --> 00:40:48,320
The agent becomes a tool to consume credits,
1158
00:40:48,320 --> 00:40:50,080
instead of a tool to create value,
1159
00:40:50,080 --> 00:40:52,160
which is precisely why governance and measurement
1160
00:40:52,160 --> 00:40:54,040
have to be designed together from the start.
1161
00:40:54,040 --> 00:40:56,480
You can't separate the cost model from the value model,
1162
00:40:56,480 --> 00:40:59,800
you can't deploy agents and then bolt on ROI tracking later.
1163
00:40:59,800 --> 00:41:01,480
The incentive structure of the system
1164
00:41:01,480 --> 00:41:03,440
needs to point toward value creation,
1165
00:41:03,440 --> 00:41:04,920
not toward consumption volume,
1166
00:41:04,920 --> 00:41:07,560
otherwise you will optimize in the wrong direction.
1167
00:41:07,560 --> 00:41:12,000
The governance operating model rolls and approval gates.
1168
00:41:12,000 --> 00:41:14,000
Governance isn't a compliance checkbox,
1169
00:41:14,000 --> 00:41:15,640
it's an operating model.
1170
00:41:15,640 --> 00:41:17,520
Most organizations are trying to govern agents
1171
00:41:17,520 --> 00:41:20,000
without actually redesigning how decisions get made,
1172
00:41:20,000 --> 00:41:21,200
and that's where the model breaks.
1173
00:41:21,200 --> 00:41:25,240
You need defined roles, not informal, not will figure it out.
1174
00:41:25,240 --> 00:41:28,320
You need explicit roles with clear authority and accountability.
1175
00:41:28,320 --> 00:41:30,040
First, you need an AI owner.
1176
00:41:30,040 --> 00:41:31,480
This is someone from the business side
1177
00:41:31,480 --> 00:41:33,520
who's responsible for whether the agent actually
1178
00:41:33,520 --> 00:41:35,240
solves the problem it's supposed to solve
1179
00:41:35,240 --> 00:41:37,080
and whether the investment is justified.
1180
00:41:37,080 --> 00:41:38,440
Then you need a technical owner.
1181
00:41:38,440 --> 00:41:40,760
They handle the implementation, the configuration,
1182
00:41:40,760 --> 00:41:42,560
and the day-to-day operation.
1183
00:41:42,560 --> 00:41:44,560
Finally, you need a risk and compliance owner.
1184
00:41:44,560 --> 00:41:46,560
Their job is to ensure the system doesn't expose
1185
00:41:46,560 --> 00:41:50,120
the organization to regulatory security or operational risk.
1186
00:41:50,120 --> 00:41:52,480
These aren't just IT roles, they're cross-functional.
1187
00:41:52,480 --> 00:41:55,280
The AI owner might be from the department deploying the agent
1188
00:41:55,280 --> 00:41:56,960
while the technical owner is in IT,
1189
00:41:56,960 --> 00:41:59,360
and the risk owner is shared between compliance, legal,
1190
00:41:59,360 --> 00:42:00,360
and security.
1191
00:42:00,360 --> 00:42:03,720
These roles matter because they create decision accountability.
1192
00:42:03,720 --> 00:42:05,920
When something goes wrong, you know who owns it.
1193
00:42:05,920 --> 00:42:08,760
When a cost question arises, you know who answers it.
1194
00:42:08,760 --> 00:42:10,240
When a risk decision needs to be made,
1195
00:42:10,240 --> 00:42:12,520
you know who has the authority to make it.
1196
00:42:12,520 --> 00:42:14,520
Once the roles are set, you build an approval gate
1197
00:42:14,520 --> 00:42:15,680
for new agents.
1198
00:42:15,680 --> 00:42:17,520
But here's the thing, it's not a single gate.
1199
00:42:17,520 --> 00:42:20,880
It's a structured process that gates complexity proportionally.
1200
00:42:20,880 --> 00:42:22,560
It starts with a use case submission.
1201
00:42:22,560 --> 00:42:25,160
The team proposing the agent documents what problem it solves,
1202
00:42:25,160 --> 00:42:27,040
who it affects, what data it will access,
1203
00:42:27,040 --> 00:42:28,480
and what actions it will take.
1204
00:42:28,480 --> 00:42:30,560
That submission goes to risk classification.
1205
00:42:30,560 --> 00:42:33,240
You have to decide if this is low-risk, medium-risk,
1206
00:42:33,240 --> 00:42:36,360
or high-risk based on the EUAI Act categories
1207
00:42:36,360 --> 00:42:37,680
and your own risk appetite.
1208
00:42:37,680 --> 00:42:39,840
If it's low-risk, like drafting meeting notes
1209
00:42:39,840 --> 00:42:43,560
or summarizing content, it moves fast through the next gate.
1210
00:42:43,560 --> 00:42:46,280
Technical review confirms the configuration is secure,
1211
00:42:46,280 --> 00:42:48,360
and the data access is scoped correctly,
1212
00:42:48,360 --> 00:42:49,680
and then it gets approved.
1213
00:42:49,680 --> 00:42:51,680
High-risk agents need a different gate entirely.
1214
00:42:51,680 --> 00:42:53,760
If the agent is screening job candidates,
1215
00:42:53,760 --> 00:42:56,200
evaluating employees or making credit recommendations,
1216
00:42:56,200 --> 00:42:57,360
it's not moving fast.
1217
00:42:57,360 --> 00:42:59,640
It needs a fundamental rights impact assessment,
1218
00:42:59,640 --> 00:43:02,920
which the EUAI Act calls a FRAIA.
1219
00:43:02,920 --> 00:43:05,200
You have to ask, what's the potential for the system
1220
00:43:05,200 --> 00:43:06,120
to discriminate?
1221
00:43:06,120 --> 00:43:07,680
What's the potential for it to cause harm?
1222
00:43:07,680 --> 00:43:09,520
How will you detect if it's doing either?
1223
00:43:09,520 --> 00:43:11,440
You need human in the loop design documented
1224
00:43:11,440 --> 00:43:12,960
before the agent goes live,
1225
00:43:12,960 --> 00:43:15,560
and you need escalation rules explicitly defined.
1226
00:43:15,560 --> 00:43:17,520
You need evidence that you've tested the system
1227
00:43:17,520 --> 00:43:18,920
for bias and accuracy,
1228
00:43:18,920 --> 00:43:21,280
and you need proof that a human will review outputs
1229
00:43:21,280 --> 00:43:22,920
before they affect decisions.
1230
00:43:22,920 --> 00:43:25,840
Low-risk agents can move faster, but they still need monitoring.
1231
00:43:25,840 --> 00:43:28,320
You're not approving them once and forgetting about them.
1232
00:43:28,320 --> 00:43:30,240
You're approving them for pilot operation
1233
00:43:30,240 --> 00:43:33,400
with the understanding that you'll monitor usage, cost,
1234
00:43:33,400 --> 00:43:36,000
and behavior after 30 days you reassess.
1235
00:43:36,000 --> 00:43:37,120
Is it solving the problem?
1236
00:43:37,120 --> 00:43:38,440
Is it staying within budget?
1237
00:43:38,440 --> 00:43:39,640
Are there incidents?
1238
00:43:39,640 --> 00:43:41,400
If the answer to those questions is yes,
1239
00:43:41,400 --> 00:43:43,160
you can move it to a broader rollout.
1240
00:43:43,160 --> 00:43:45,960
Beyond the approval gate sits the Central AI governance board.
1241
00:43:45,960 --> 00:43:47,480
This isn't just ITO compliance.
1242
00:43:47,480 --> 00:43:48,960
It's a cross-functional committee
1243
00:43:48,960 --> 00:43:51,720
with representation from IT, business, legal,
1244
00:43:51,720 --> 00:43:53,920
security, compliance, HR, and finance.
1245
00:43:53,920 --> 00:43:55,600
This board doesn't approve every agent.
1246
00:43:55,600 --> 00:43:56,960
The approval gates handle that.
1247
00:43:56,960 --> 00:43:58,120
But the board sets policy.
1248
00:43:58,120 --> 00:43:59,400
It defines risk appetite.
1249
00:43:59,400 --> 00:44:00,760
It reviews incidents.
1250
00:44:00,760 --> 00:44:02,800
The operating rhythm matters.
1251
00:44:02,800 --> 00:44:05,920
You need monthly reviews of agent usage, cost, and incidents.
1252
00:44:05,920 --> 00:44:08,480
You pull the data to see which agents are consuming
1253
00:44:08,480 --> 00:44:10,960
the most credits, which teams are using agents most heavily,
1254
00:44:10,960 --> 00:44:13,280
and which agents are generating the most incidents.
1255
00:44:13,280 --> 00:44:16,360
These monthly reviews aren't for punishment, therefore learning.
1256
00:44:16,360 --> 00:44:18,920
You need to know which agents are delivering value
1257
00:44:18,920 --> 00:44:20,440
and which ones are burning credits
1258
00:44:20,440 --> 00:44:22,240
without any equivalent benefit.
1259
00:44:22,240 --> 00:44:25,080
Then you need a quarterly reassessment of risk classification.
1260
00:44:25,080 --> 00:44:27,440
An agent that was low risk six months ago
1261
00:44:27,440 --> 00:44:29,520
might have drifted into medium risk territory
1262
00:44:29,520 --> 00:44:31,720
as teams extended its capabilities.
1263
00:44:31,720 --> 00:44:34,080
And that means you might need to add additional oversight
1264
00:44:34,080 --> 00:44:35,680
or constraints.
1265
00:44:35,680 --> 00:44:37,640
Finally, you need killswitch procedures.
1266
00:44:37,640 --> 00:44:39,800
How do you disable an agent in 60 seconds
1267
00:44:39,800 --> 00:44:41,120
if it's misbehaving?
1268
00:44:41,120 --> 00:44:42,600
Not tomorrow, not after a meeting.
1269
00:44:42,600 --> 00:44:43,840
60 seconds.
1270
00:44:43,840 --> 00:44:44,840
That requires clarity.
1271
00:44:44,840 --> 00:44:47,360
You need to know which person can activate the kill switch
1272
00:44:47,360 --> 00:44:50,400
and whether it requires a single authorization or two sign-offs.
1273
00:44:50,400 --> 00:44:52,240
When an agent is sending unapproved emails
1274
00:44:52,240 --> 00:44:53,880
or accessing restricted data,
1275
00:44:53,880 --> 00:44:56,240
you don't have time to figure out the shutdown process.
1276
00:44:56,240 --> 00:44:57,880
You need to execute it immediately.
1277
00:44:57,880 --> 00:44:59,520
This isn't bureaucracy for its own sake.
1278
00:44:59,520 --> 00:45:03,040
This is the operating structure that separates organizations
1279
00:45:03,040 --> 00:45:05,560
that actually govern their agents from organizations
1280
00:45:05,560 --> 00:45:08,040
that deploy them and hope nothing goes wrong.
1281
00:45:08,040 --> 00:45:11,560
And by August of 2026, hoping nothing goes wrong
1282
00:45:11,560 --> 00:45:14,360
is no longer a viable governance strategy.
1283
00:45:14,360 --> 00:45:18,000
The inventory and discovery problem, cataloging shadow AI.
1284
00:45:18,000 --> 00:45:20,000
You can't govern what you don't know exists.
1285
00:45:20,000 --> 00:45:22,280
This is the gap that kills most governance programs
1286
00:45:22,280 --> 00:45:23,360
before they start.
1287
00:45:23,360 --> 00:45:26,640
Right now, in your organization, agents are running.
1288
00:45:26,640 --> 00:45:28,120
Not all of them are sanctioned.
1289
00:45:28,120 --> 00:45:30,280
Not all of them are visible to IT or compliance.
1290
00:45:30,280 --> 00:45:32,520
Some are built by teams using co-pilot studio,
1291
00:45:32,520 --> 00:45:34,880
some are power automate flows that trigger autonomously
1292
00:45:34,880 --> 00:45:36,800
based on conditions nobody documented,
1293
00:45:36,800 --> 00:45:39,200
some are custom integrations connecting systems
1294
00:45:39,200 --> 00:45:40,840
that weren't supposed to talk to each other.
1295
00:45:40,840 --> 00:45:41,680
They're all operating.
1296
00:45:41,680 --> 00:45:43,000
They're all consuming resources.
1297
00:45:43,000 --> 00:45:44,240
They're all making decisions.
1298
00:45:44,240 --> 00:45:46,200
And your IT team has no idea they exist.
1299
00:45:46,200 --> 00:45:47,440
This is shadow AI.
1300
00:45:47,440 --> 00:45:49,880
And it's the precondition for every governance failure.
1301
00:45:49,880 --> 00:45:51,840
The discovery process is where that changes.
1302
00:45:51,840 --> 00:45:52,440
It's not quick.
1303
00:45:52,440 --> 00:45:53,600
It's not glamorous.
1304
00:45:53,600 --> 00:45:56,240
But it's non-negotiable.
1305
00:45:56,240 --> 00:45:57,600
Start with what you can see.
1306
00:45:57,600 --> 00:45:59,120
Ordered your power automate environment
1307
00:45:59,120 --> 00:46:00,600
and pull a report of every flow that
1308
00:46:00,600 --> 00:46:03,200
has an AI connector or invokes co-pilot.
1309
00:46:03,200 --> 00:46:04,240
Document each one.
1310
00:46:04,240 --> 00:46:06,320
You need the owner, the purpose, the data sources,
1311
00:46:06,320 --> 00:46:07,680
and the tools it invokes.
1312
00:46:07,680 --> 00:46:09,680
Do the same with co-pilot studio agents.
1313
00:46:09,680 --> 00:46:11,440
Any custom agent, anybody has built,
1314
00:46:11,440 --> 00:46:13,120
needs to be documented the same way.
1315
00:46:13,120 --> 00:46:15,000
Then expand outward to custom integrations
1316
00:46:15,000 --> 00:46:17,160
and third party AI tools your teams might be using
1317
00:46:17,160 --> 00:46:19,280
like Zapier with AI connectors or custom scripts
1318
00:46:19,280 --> 00:46:20,760
calling OpenAI APIs.
1319
00:46:20,760 --> 00:46:22,600
Anything that's performing autonomous work
1320
00:46:22,600 --> 00:46:23,880
needs to be on the list.
1321
00:46:23,880 --> 00:46:25,680
This discovery phase will be uncomfortable.
1322
00:46:25,680 --> 00:46:28,200
You'll find agents that violate your policies.
1323
00:46:28,200 --> 00:46:30,920
You'll discover workflows that shouldn't be running in production.
1324
00:46:30,920 --> 00:46:33,520
You'll uncover tools that create compliance exposure.
1325
00:46:33,520 --> 00:46:35,200
Your first instinct will be to shut them down.
1326
00:46:35,200 --> 00:46:35,840
Don't.
1327
00:46:35,840 --> 00:46:36,800
Not yet.
1328
00:46:36,800 --> 00:46:38,360
Visibility comes first.
1329
00:46:38,360 --> 00:46:39,760
Understanding comes next.
1330
00:46:39,760 --> 00:46:41,520
Enforcement comes later.
1331
00:46:41,520 --> 00:46:44,520
Once you've cataloged what exists, you classify.
1332
00:46:44,520 --> 00:46:45,960
Each agent gets a risk assessment.
1333
00:46:45,960 --> 00:46:46,840
Is it minimal risk?
1334
00:46:46,840 --> 00:46:47,760
Is it limited risk?
1335
00:46:47,760 --> 00:46:48,480
Is it high risk?
1336
00:46:48,480 --> 00:46:51,080
Or is it prohibited because it violates policy outright?
1337
00:46:51,080 --> 00:46:52,640
Then you map to business outcomes.
1338
00:46:52,640 --> 00:46:54,280
Every agent has a reason for existing.
1339
00:46:54,280 --> 00:46:56,680
It's solving some problem or filling some gap.
1340
00:46:56,680 --> 00:46:58,200
The agent that nobody's heard of,
1341
00:46:58,200 --> 00:47:00,000
the one running in a corner of the marketing department
1342
00:47:00,000 --> 00:47:02,000
is probably solving a real problem for someone.
1343
00:47:02,000 --> 00:47:03,920
Understand what that problem is.
1344
00:47:03,920 --> 00:47:05,880
Understand what value the agent is creating.
1345
00:47:05,880 --> 00:47:07,760
This isn't bureaucratic questioning.
1346
00:47:07,760 --> 00:47:09,320
It's understanding whether the agent deserves
1347
00:47:09,320 --> 00:47:10,360
to keep running.
1348
00:47:10,360 --> 00:47:12,320
Next systematically bring shadow agents
1349
00:47:12,320 --> 00:47:13,480
into the governance process.
1350
00:47:13,480 --> 00:47:15,640
You're not shutting them down because they weren't approved.
1351
00:47:15,640 --> 00:47:17,120
You're saying, we found this.
1352
00:47:17,120 --> 00:47:18,400
We understand what it does.
1353
00:47:18,400 --> 00:47:20,480
It's now part of our managed portfolio.
1354
00:47:20,480 --> 00:47:22,600
This converts shadow AI from a liability
1355
00:47:22,600 --> 00:47:24,040
into a managed asset.
1356
00:47:24,040 --> 00:47:25,960
The final step is operational discipline.
1357
00:47:25,960 --> 00:47:27,920
You can't do this once and forget about it.
1358
00:47:27,920 --> 00:47:29,600
Agents are deployed continuously.
1359
00:47:29,600 --> 00:47:31,320
Teams keep building new workflows.
1360
00:47:31,320 --> 00:47:32,920
New tools get adopted.
1361
00:47:32,920 --> 00:47:35,920
Your inventory goes stale in weeks if you don't maintain it.
1362
00:47:35,920 --> 00:47:38,040
Establish a quarterly review cycle.
1363
00:47:38,040 --> 00:47:40,320
Every three months, you pull the current inventory
1364
00:47:40,320 --> 00:47:41,640
and assess what's new.
1365
00:47:41,640 --> 00:47:43,320
You identify what's been deprecated.
1366
00:47:43,320 --> 00:47:46,560
You reclassify agents if their risk profile has changed.
1367
00:47:46,560 --> 00:47:47,640
You look for drift.
1368
00:47:47,640 --> 00:47:49,240
Agents that are being used for purposes
1369
00:47:49,240 --> 00:47:51,360
beyond their original design.
1370
00:47:51,360 --> 00:47:53,040
The inventory isn't a static document.
1371
00:47:53,040 --> 00:47:55,920
It's a living record of what autonomous systems are
1372
00:47:55,920 --> 00:47:57,600
operating in your organization.
1373
00:47:57,600 --> 00:48:00,880
Once you have visibility, you can start enforcing controls.
1374
00:48:00,880 --> 00:48:03,720
The technical controls layer, enforcement and guardrails.
1375
00:48:03,720 --> 00:48:04,720
Documents are fine.
1376
00:48:04,720 --> 00:48:06,560
Policies are necessary.
1377
00:48:06,560 --> 00:48:08,520
But governance documents don't stop an agent
1378
00:48:08,520 --> 00:48:10,080
from doing something destructive.
1379
00:48:10,080 --> 00:48:12,120
Only technical controls do.
1380
00:48:12,120 --> 00:48:14,200
This is where most governance programs fail.
1381
00:48:14,200 --> 00:48:15,240
They build the framework.
1382
00:48:15,240 --> 00:48:17,880
They define the rules and they publish the policies.
1383
00:48:17,880 --> 00:48:19,880
Then they just rely on people to follow them.
1384
00:48:19,880 --> 00:48:21,600
But agents don't read policies.
1385
00:48:21,600 --> 00:48:23,600
They follow what the infrastructure allows.
1386
00:48:23,600 --> 00:48:25,760
If the infrastructure doesn't enforce the rule,
1387
00:48:25,760 --> 00:48:26,880
the rule doesn't exist.
1388
00:48:26,880 --> 00:48:28,320
Policies code changes that.
1389
00:48:28,320 --> 00:48:29,840
Instead of writing guidelines in English
1390
00:48:29,840 --> 00:48:31,520
and hoping teams interpret them correctly,
1391
00:48:31,520 --> 00:48:34,040
you embed governance into the systems themselves.
1392
00:48:34,040 --> 00:48:35,680
You use antireconditional access policies
1393
00:48:35,680 --> 00:48:37,360
to control when agents operate.
1394
00:48:37,360 --> 00:48:39,720
You set up DLP rules to inspect agent outputs
1395
00:48:39,720 --> 00:48:41,360
before they leave the organization.
1396
00:48:41,360 --> 00:48:43,760
You build information barriers to prevent agents
1397
00:48:43,760 --> 00:48:45,560
from crossing departmental boundaries.
1398
00:48:45,560 --> 00:48:46,560
These aren't suggestions.
1399
00:48:46,560 --> 00:48:48,360
They're enforced at the platform level.
1400
00:48:48,360 --> 00:48:51,480
Agent permissions must follow a least privileged design.
1401
00:48:51,480 --> 00:48:53,920
The agent gets access to exactly the tools and data
1402
00:48:53,920 --> 00:48:55,440
it needs to finish its task.
1403
00:48:55,440 --> 00:48:56,440
And nothing more.
1404
00:48:56,440 --> 00:48:58,560
A scheduling agent doesn't need access to email.
1405
00:48:58,560 --> 00:49:00,200
A document summarization agent doesn't
1406
00:49:00,200 --> 00:49:01,640
need to modify files.
1407
00:49:01,640 --> 00:49:02,960
And a candidate screening agent
1408
00:49:02,960 --> 00:49:04,760
doesn't need calendar permissions.
1409
00:49:04,760 --> 00:49:07,720
Each agent is scoped tightly around its specific purpose.
1410
00:49:07,720 --> 00:49:10,160
You aren't granting broad access and trusting the agent
1411
00:49:10,160 --> 00:49:11,280
to use it wisely.
1412
00:49:11,280 --> 00:49:12,920
You're restricting access by default
1413
00:49:12,920 --> 00:49:14,800
and opening only the specific pathways
1414
00:49:14,800 --> 00:49:16,440
the agent requires to function.
1415
00:49:16,440 --> 00:49:19,320
Spending limits become hard constraints, not budget guidelines.
1416
00:49:19,320 --> 00:49:21,360
Every agent gets a monthly credit allocation.
1417
00:49:21,360 --> 00:49:24,880
If an agent is budgeted for $2,000 a month in co-work consumption,
1418
00:49:24,880 --> 00:49:25,720
that is the ceiling.
1419
00:49:25,720 --> 00:49:26,640
It's not a target.
1420
00:49:26,640 --> 00:49:27,640
It's not a suggestion.
1421
00:49:27,640 --> 00:49:28,520
It's a hard limit.
1422
00:49:28,520 --> 00:49:31,000
The agent can spend 1,500 one month and 500
1423
00:49:31,000 --> 00:49:33,920
the next, but it can never exceed that $2,000 total.
1424
00:49:33,920 --> 00:49:36,240
The billing system enforces this limit automatically
1425
00:49:36,240 --> 00:49:37,800
before the agent can go over.
1426
00:49:37,800 --> 00:49:41,640
You can figure alerts at 50%, 80% and 100% of the budget.
1427
00:49:41,640 --> 00:49:43,160
When spending approaches the limit,
1428
00:49:43,160 --> 00:49:44,480
someone gets notified.
1429
00:49:44,480 --> 00:49:47,440
When the limit is reached, the agent enters a restricted mode
1430
00:49:47,440 --> 00:49:50,000
or stops operating until the next month starts.
1431
00:49:50,000 --> 00:49:52,800
Approval workflows add gates to high-risk actions.
1432
00:49:52,800 --> 00:49:55,160
Certain operations require human authorization
1433
00:49:55,160 --> 00:49:56,880
before the agent can execute them.
1434
00:49:56,880 --> 00:49:58,680
An external email requires approval.
1435
00:49:58,680 --> 00:50:01,400
A file deletion requires approval, a data export,
1436
00:50:01,400 --> 00:50:04,080
or a financial transaction above a certain threshold
1437
00:50:04,080 --> 00:50:05,360
requires approval.
1438
00:50:05,360 --> 00:50:08,240
The agent doesn't just do the action and report the outcome.
1439
00:50:08,240 --> 00:50:10,480
It creates a request, a human reviews it,
1440
00:50:10,480 --> 00:50:12,200
and only after explicit authorization
1441
00:50:12,200 --> 00:50:14,760
does the agent proceed with the entire transaction.
1442
00:50:14,760 --> 00:50:17,720
The request, the review, and the decision
1443
00:50:17,720 --> 00:50:19,160
is logged and auditable.
1444
00:50:19,160 --> 00:50:20,600
Real-time monitoring and dashboards
1445
00:50:20,600 --> 00:50:23,400
give you continuous visibility into what agents are doing.
1446
00:50:23,400 --> 00:50:24,520
This isn't a weekly report.
1447
00:50:24,520 --> 00:50:27,040
These are live dashboards showing credit consumption
1448
00:50:27,040 --> 00:50:29,320
by agent, by team, and by use case.
1449
00:50:29,320 --> 00:50:31,360
You can see which agents are active right now,
1450
00:50:31,360 --> 00:50:33,880
and which ones are consuming the most credits today.
1451
00:50:33,880 --> 00:50:36,080
You can see which ones are operating outside
1452
00:50:36,080 --> 00:50:37,680
their normal behavior patterns.
1453
00:50:37,680 --> 00:50:40,320
These dashboards feed into your operational discipline.
1454
00:50:40,320 --> 00:50:42,040
You aren't waiting for a bill at the end of the month
1455
00:50:42,040 --> 00:50:43,200
to understand what happened.
1456
00:50:43,200 --> 00:50:44,920
You're watching it happen in real time.
1457
00:50:44,920 --> 00:50:47,000
A normally detection is the automated version
1458
00:50:47,000 --> 00:50:48,080
of that monitoring.
1459
00:50:48,080 --> 00:50:49,440
Machine learning models establish
1460
00:50:49,440 --> 00:50:51,520
a baseline of normal agent behavior.
1461
00:50:51,520 --> 00:50:54,280
Usually an agent operates between 8am and 6pm,
1462
00:50:54,280 --> 00:50:56,760
called specific tools in a specific sequence,
1463
00:50:56,760 --> 00:50:59,200
and consumes about 500 credits per day,
1464
00:50:59,200 --> 00:51:01,280
when behavior deviates from that baseline.
1465
00:51:01,280 --> 00:51:03,680
Like an agent operating at midnight or calling tools,
1466
00:51:03,680 --> 00:51:05,080
it has never used before.
1467
00:51:05,080 --> 00:51:07,400
The system detects the anomaly and escalates it.
1468
00:51:07,400 --> 00:51:08,200
This isn't a warning.
1469
00:51:08,200 --> 00:51:10,640
It's an immediate alert requiring investigation.
1470
00:51:10,640 --> 00:51:13,080
Kill switches give you the ability to disable an agent
1471
00:51:13,080 --> 00:51:14,960
or revoke its permissions in seconds.
1472
00:51:14,960 --> 00:51:16,880
This doesn't happen through a request process
1473
00:51:16,880 --> 00:51:18,840
or a change management workflow.
1474
00:51:18,840 --> 00:51:20,720
A single authorized person can flip a switch
1475
00:51:20,720 --> 00:51:22,200
and the agent stops operating.
1476
00:51:22,200 --> 00:51:25,400
Its entry identity is disabled, its permissions are revoked,
1477
00:51:25,400 --> 00:51:27,600
and its access to tools is cut off.
1478
00:51:27,600 --> 00:51:28,960
The agent becomes inert.
1479
00:51:28,960 --> 00:51:31,120
This isn't something you design and hope you never use.
1480
00:51:31,120 --> 00:51:32,520
This is something you test regularly
1481
00:51:32,520 --> 00:51:35,600
so that when an agent behaves unexpectedly or accesses data,
1482
00:51:35,600 --> 00:51:36,440
it shouldn't.
1483
00:51:36,440 --> 00:51:38,600
You can execute it immediately without hesitation.
1484
00:51:38,600 --> 00:51:39,840
These controls shift governance
1485
00:51:39,840 --> 00:51:42,480
from a compliance exercise into an operational reality.
1486
00:51:42,480 --> 00:51:43,720
The rules are enforced.
1487
00:51:43,720 --> 00:51:44,680
The limits are hard.
1488
00:51:44,680 --> 00:51:46,000
The visibility is continuous.
1489
00:51:46,000 --> 00:51:49,320
That's what actually working governance looks like.
1490
00:51:49,320 --> 00:51:52,960
The human oversight problem, article 14 and real oversight.
1491
00:51:52,960 --> 00:51:54,560
The EU AI act requires something
1492
00:51:54,560 --> 00:51:56,280
called meaningful human oversight.
1493
00:51:56,280 --> 00:51:57,880
That phrase is doing a lot of work.
1494
00:51:57,880 --> 00:52:00,360
Most organizations interpreted as a checkbox.
1495
00:52:00,360 --> 00:52:02,640
You document that humans reviewed something
1496
00:52:02,640 --> 00:52:03,480
and then you move on.
1497
00:52:03,480 --> 00:52:05,600
That's not what the regulation actually requires.
1498
00:52:05,600 --> 00:52:07,440
Meaningful oversight isn't a policy.
1499
00:52:07,440 --> 00:52:08,600
It's an operating procedure.
1500
00:52:08,600 --> 00:52:10,680
It means humans actually understand the system.
1501
00:52:10,680 --> 00:52:13,080
They monitor what it's doing in near real time.
1502
00:52:13,080 --> 00:52:15,880
They can intervene and stop it before harm occurs.
1503
00:52:15,880 --> 00:52:18,000
They have the authority and the information
1504
00:52:18,000 --> 00:52:19,560
to override the agent's decision.
1505
00:52:19,560 --> 00:52:20,320
That's the baseline.
1506
00:52:20,320 --> 00:52:23,080
Everything else flows from that at the high risk level.
1507
00:52:23,080 --> 00:52:26,320
Agents that affect employment, credit, or access to services.
1508
00:52:26,320 --> 00:52:28,640
Meaningful oversight means humans' review outputs
1509
00:52:28,640 --> 00:52:29,800
before they go out.
1510
00:52:29,800 --> 00:52:31,400
A hiring agent scores candidates.
1511
00:52:31,400 --> 00:52:33,680
Before any candidate gets rejected or moved forward
1512
00:52:33,680 --> 00:52:36,200
based on that score, a human reads the assessment.
1513
00:52:36,200 --> 00:52:38,960
The human understands how the agent arrived at the score
1514
00:52:38,960 --> 00:52:41,880
and can question it overrided or asked for a rescore.
1515
00:52:41,880 --> 00:52:43,480
That human review isn't optional.
1516
00:52:43,480 --> 00:52:44,640
It's a design requirement.
1517
00:52:44,640 --> 00:52:47,360
For medium-risk agents, sampling-based review works.
1518
00:52:47,360 --> 00:52:49,920
You don't review every output, but you review 10%
1519
00:52:49,920 --> 00:52:51,040
and look for patterns.
1520
00:52:51,040 --> 00:52:53,640
You check if the agent is consistently biased
1521
00:52:53,640 --> 00:52:55,560
or if it's missing important context.
1522
00:52:55,560 --> 00:52:57,440
Sampling gives you continuous validation
1523
00:52:57,440 --> 00:52:59,560
that the system is behaving as expected.
1524
00:52:59,560 --> 00:53:01,280
You also have alerts on anomalies.
1525
00:53:01,280 --> 00:53:03,840
If the agent's behavior deviates from normal patterns
1526
00:53:03,840 --> 00:53:05,680
and alert fires and that specific output
1527
00:53:05,680 --> 00:53:07,440
gets human review immediately.
1528
00:53:07,440 --> 00:53:09,040
For low-risk agents.
1529
00:53:09,040 --> 00:53:11,440
Like content generation or routine automation,
1530
00:53:11,440 --> 00:53:14,280
you move to automated monitoring with human escalation.
1531
00:53:14,280 --> 00:53:16,520
The system watches the agent continuously.
1532
00:53:16,520 --> 00:53:18,440
If credit consumption spikes unexpectedly
1533
00:53:18,440 --> 00:53:21,520
or if the agent starts accessing data outside its normal scope,
1534
00:53:21,520 --> 00:53:23,360
the system escalates to a human.
1535
00:53:23,360 --> 00:53:25,520
The human then decides whether to investigate further
1536
00:53:25,520 --> 00:53:28,840
or to shut the agent down, but oversight requires capability.
1537
00:53:28,840 --> 00:53:32,280
It requires humans who actually understand what they're overseeing.
1538
00:53:32,280 --> 00:53:34,520
This is where training becomes non-negotiable.
1539
00:53:34,520 --> 00:53:36,760
Teams using agents and teams supervising them
1540
00:53:36,760 --> 00:53:39,280
need to understand what the agent is supposed to do
1541
00:53:39,280 --> 00:53:40,320
and what could go wrong.
1542
00:53:40,320 --> 00:53:42,080
This isn't a one-hour onboarding video.
1543
00:53:42,080 --> 00:53:43,640
It's ongoing training.
1544
00:53:43,640 --> 00:53:45,920
New people need foundational training
1545
00:53:45,920 --> 00:53:47,680
and existing users need refresher training
1546
00:53:47,680 --> 00:53:51,080
when the agent is updated or when new edge cases emerge.
1547
00:53:51,080 --> 00:53:52,880
The training covers the agent's purpose,
1548
00:53:52,880 --> 00:53:55,240
its limitations and its failure modes.
1549
00:53:55,240 --> 00:53:57,440
Teams need to know what is outside the agent's scope
1550
00:53:57,440 --> 00:53:59,560
and what could make it produce bad output.
1551
00:53:59,560 --> 00:54:02,200
They need to know what happens if data quality is poor
1552
00:54:02,200 --> 00:54:04,800
or if the agent encounters a situation it wasn't trained for.
1553
00:54:04,800 --> 00:54:06,960
You can't supervise something you don't understand.
1554
00:54:06,960 --> 00:54:10,400
The escalation path is the operational reality of oversight.
1555
00:54:10,400 --> 00:54:12,280
It's not just escalate to compliance.
1556
00:54:12,280 --> 00:54:13,760
It's a clear documented path.
1557
00:54:13,760 --> 00:54:15,960
You need to know when an issue goes to the technical owner
1558
00:54:15,960 --> 00:54:18,520
versus the business owner or the IT security team.
1559
00:54:18,520 --> 00:54:20,720
Different issues root to different places.
1560
00:54:20,720 --> 00:54:22,760
A cost anomaly roots to the cost owner
1561
00:54:22,760 --> 00:54:26,320
while a suspected bias issue roots to the AI governance board.
1562
00:54:26,320 --> 00:54:28,200
A security incident roots to the CSO
1563
00:54:28,200 --> 00:54:30,840
and a potential regulatory violation roots to legal.
1564
00:54:30,840 --> 00:54:32,320
You're not creating chaos.
1565
00:54:32,320 --> 00:54:35,440
You're creating clarity about who handles what and how fast.
1566
00:54:35,440 --> 00:54:38,200
Real oversight also means continuous visibility.
1567
00:54:38,200 --> 00:54:39,880
This isn't just for when something breaks.
1568
00:54:39,880 --> 00:54:41,960
You need dashboards showing what the agent is doing
1569
00:54:41,960 --> 00:54:44,440
and reports on its performance and cost efficiency.
1570
00:54:44,440 --> 00:54:46,920
You need quarterly reviews where you look at patterns
1571
00:54:46,920 --> 00:54:49,240
and ask if the agent is still delivering value.
1572
00:54:49,240 --> 00:54:51,280
You ask if there are new risks to address
1573
00:54:51,280 --> 00:54:53,320
or if you should adjust its constraints.
1574
00:54:53,320 --> 00:54:54,280
This infrastructure.
1575
00:54:54,280 --> 00:54:57,120
Understanding monitoring, training and clear escalation
1576
00:54:57,120 --> 00:54:59,840
is what separates governance theater from actual governance.
1577
00:54:59,840 --> 00:55:02,400
Without it, meaningful human oversight is just words
1578
00:55:02,400 --> 00:55:03,840
in a compliance document.
1579
00:55:03,840 --> 00:55:05,480
With it, you have a real operating system
1580
00:55:05,480 --> 00:55:07,920
that keeps autonomous agents bounded within the authority
1581
00:55:07,920 --> 00:55:08,640
you granted them.
1582
00:55:08,640 --> 00:55:10,760
It catches problems before they become incidents.
1583
00:55:10,760 --> 00:55:12,680
That's what August 20, 26 demands.
1584
00:55:12,680 --> 00:55:13,960
Not the process of oversight,
1585
00:55:13,960 --> 00:55:15,600
the actual capability to intervene
1586
00:55:15,600 --> 00:55:17,400
and the demonstrated discipline to do it.
1587
00:55:17,400 --> 00:55:19,600
The organizational change management problem.
1588
00:55:19,600 --> 00:55:21,120
Adoption without chaos.
1589
00:55:21,120 --> 00:55:23,040
Agents change how work gets done.
1590
00:55:23,040 --> 00:55:24,280
That is not a technical change.
1591
00:55:24,280 --> 00:55:25,760
It is an organizational one.
1592
00:55:25,760 --> 00:55:27,560
Most deployments fail because they treat this
1593
00:55:27,560 --> 00:55:28,840
like a feature rollout.
1594
00:55:28,840 --> 00:55:31,400
They assume it is just another tool, but in reality,
1595
00:55:31,400 --> 00:55:34,280
it is a fundamental shift in how your operation actually runs.
1596
00:55:34,280 --> 00:55:36,040
The classic mistake is the big bang.
1597
00:55:36,040 --> 00:55:38,800
You build your governance framework and stack up your controls.
1598
00:55:38,800 --> 00:55:40,400
You decide the system is ready.
1599
00:55:40,400 --> 00:55:42,080
Then you flip a switch and turn on co-work
1600
00:55:42,080 --> 00:55:44,040
for the entire company on a Monday morning.
1601
00:55:44,040 --> 00:55:45,400
By Wednesday, you are drowning.
1602
00:55:45,400 --> 00:55:47,680
People do not understand what the agent is supposed to do
1603
00:55:47,680 --> 00:55:50,240
so they use it for tasks it was never designed for.
1604
00:55:50,240 --> 00:55:51,600
They escalate non-issues.
1605
00:55:51,600 --> 00:55:53,680
They get frustrated because the agent did not meet
1606
00:55:53,680 --> 00:55:55,360
their unspoken expectations.
1607
00:55:55,360 --> 00:55:57,920
While this is happening, your IT team is overwhelmed.
1608
00:55:57,920 --> 00:55:59,520
They are trying to explain the system
1609
00:55:59,520 --> 00:56:01,200
while simultaneously fighting fires
1610
00:56:01,200 --> 00:56:03,400
from agents behaving unexpectedly at scale.
1611
00:56:03,400 --> 00:56:04,960
That path does not work.
1612
00:56:04,960 --> 00:56:06,800
You need a phased approach where every step
1613
00:56:06,800 --> 00:56:08,640
has different success criteria.
1614
00:56:08,640 --> 00:56:10,040
The first phase is the pilot.
1615
00:56:10,040 --> 00:56:12,960
You pick a narrow use case with a concrete measurable outcome.
1616
00:56:12,960 --> 00:56:16,040
Maybe you choose one specific department or a single workflow.
1617
00:56:16,040 --> 00:56:17,880
You are not deploying agents broadly yet.
1618
00:56:17,880 --> 00:56:20,080
You are deploying them precisely to test if the model
1619
00:56:20,080 --> 00:56:22,520
actually works before you even think about scale.
1620
00:56:22,520 --> 00:56:24,240
This pilot runs with heavy monitoring.
1621
00:56:24,240 --> 00:56:25,040
You watch everything.
1622
00:56:25,040 --> 00:56:26,760
You look at which users are adopting it
1623
00:56:26,760 --> 00:56:28,160
and how often they engage.
1624
00:56:28,160 --> 00:56:30,720
You check if they are seeing the time savings you predicted
1625
00:56:30,720 --> 00:56:32,200
or if they are hitting errors.
1626
00:56:32,200 --> 00:56:34,160
The pilot phase usually lasts 30 days.
1627
00:56:34,160 --> 00:56:36,400
During this time, you gather data and watch behavior
1628
00:56:36,400 --> 00:56:38,520
to see where adoption stores and why.
1629
00:56:38,520 --> 00:56:41,000
At the end of those 30 days, you measure three things.
1630
00:56:41,000 --> 00:56:42,200
First, adoption.
1631
00:56:42,200 --> 00:56:45,640
If fewer than 45% of your target group is using the agent,
1632
00:56:45,640 --> 00:56:47,840
you have an adoption problem, not a capability problem.
1633
00:56:47,840 --> 00:56:50,520
Something about the positioning is not resonating.
1634
00:56:50,520 --> 00:56:51,600
Second, errors.
1635
00:56:51,600 --> 00:56:53,720
You need to know if the agent produced wrong outputs
1636
00:56:53,720 --> 00:56:55,440
or made decisions people disagreed with.
1637
00:56:55,440 --> 00:56:56,840
These errors are just information.
1638
00:56:56,840 --> 00:56:58,840
They tell you which constraints are missing.
1639
00:56:58,840 --> 00:57:00,000
Third, value.
1640
00:57:00,000 --> 00:57:02,720
Is the agent delivering the productivity you expected?
1641
00:57:02,720 --> 00:57:04,600
If the metrics do not show real gains,
1642
00:57:04,600 --> 00:57:06,720
expanding the program will not fix it.
1643
00:57:06,720 --> 00:57:09,200
When the pilot succeeds, you move to phase two.
1644
00:57:09,200 --> 00:57:10,120
Expand.
1645
00:57:10,120 --> 00:57:12,680
You take your lessons and adjust the agent's behavior.
1646
00:57:12,680 --> 00:57:14,720
You move into more teams and add new use cases
1647
00:57:14,720 --> 00:57:16,000
based on what worked.
1648
00:57:16,000 --> 00:57:17,960
Phase two typically runs for 60 days.
1649
00:57:17,960 --> 00:57:19,680
You are still monitoring heavily,
1650
00:57:19,680 --> 00:57:21,160
but now you are adding scale.
1651
00:57:21,160 --> 00:57:23,720
You look for patterns that did not show up in the small group.
1652
00:57:23,720 --> 00:57:25,440
You train teams as you bring them on
1653
00:57:25,440 --> 00:57:28,080
and adjust your governance based on how the agent behaves
1654
00:57:28,080 --> 00:57:29,240
at a larger volume.
1655
00:57:29,240 --> 00:57:31,760
Only after both phases succeed, do you move to phase three.
1656
00:57:31,760 --> 00:57:32,760
This is the broad rollout.
1657
00:57:32,760 --> 00:57:34,520
You are finally scaling to the organization,
1658
00:57:34,520 --> 00:57:36,400
but you are scaling into mature governance
1659
00:57:36,400 --> 00:57:37,440
and support structures.
1660
00:57:37,440 --> 00:57:39,240
You are not scaling into chaos.
1661
00:57:39,240 --> 00:57:41,720
You have a control plane and oversight mechanisms.
1662
00:57:41,720 --> 00:57:43,600
You have training ready for incoming teams
1663
00:57:43,600 --> 00:57:46,120
and a support model that can actually handle the volume.
1664
00:57:46,120 --> 00:57:46,960
Throughout this progression,
1665
00:57:46,960 --> 00:57:49,000
you are building organizational capability.
1666
00:57:49,000 --> 00:57:51,040
Teams learn what agents can and cannot do.
1667
00:57:51,040 --> 00:57:53,040
They start to understand the limitations.
1668
00:57:53,040 --> 00:57:54,800
They know how to override a recommendation
1669
00:57:54,800 --> 00:57:56,480
when it does not fit their context.
1670
00:57:56,480 --> 00:57:58,640
They stop treating the agent as a magic box.
1671
00:57:58,640 --> 00:58:00,600
They start treating it as a tool
1672
00:58:00,600 --> 00:58:03,720
with specific purposes and specific constraints.
1673
00:58:03,720 --> 00:58:06,040
Set the right expectations from day one.
1674
00:58:06,040 --> 00:58:08,680
Agents augment work, they do not replace judgment.
1675
00:58:08,680 --> 00:58:10,920
They handle routine tasks so humans can focus
1676
00:58:10,920 --> 00:58:12,880
on decisions that require reasoning.
1677
00:58:12,880 --> 00:58:15,160
Frame it that way and the conversation shifts.
1678
00:58:15,160 --> 00:58:17,480
It stops being about, we are being replaced
1679
00:58:17,480 --> 00:58:20,720
and starts being about, we can finally focus on what matters.
1680
00:58:20,720 --> 00:58:22,000
Do not skip the phases.
1681
00:58:22,000 --> 00:58:24,680
Do not scale before your governance is operational.
1682
00:58:24,680 --> 00:58:26,360
That is how you turn a successful pilot
1683
00:58:26,360 --> 00:58:28,440
into an organizational catastrophe.
1684
00:58:28,440 --> 00:58:29,680
The consumption trap.
1685
00:58:29,680 --> 00:58:32,120
Why more usage doesn't mean more value.
1686
00:58:32,120 --> 00:58:35,240
There is a structural trap that most organizations fall into,
1687
00:58:35,240 --> 00:58:37,320
the moment they move to credit-based billing,
1688
00:58:37,320 --> 00:58:39,200
the economic incentive is now inverted.
1689
00:58:39,200 --> 00:58:40,560
With seats you pay for access.
1690
00:58:40,560 --> 00:58:42,280
You buy 500 licenses
1691
00:58:42,280 --> 00:58:43,960
and your goal is to make sure people use them
1692
00:58:43,960 --> 00:58:45,760
because the cost is already sunk.
1693
00:58:45,760 --> 00:58:47,080
Your incentive is adoption.
1694
00:58:47,080 --> 00:58:49,320
You drive usage up so you are not wasting the money
1695
00:58:49,320 --> 00:58:50,560
you already spent.
1696
00:58:50,560 --> 00:58:53,920
With credits, the dynamic flips, you are paying for action.
1697
00:58:53,920 --> 00:58:56,080
Every time the agent does something, you spend money.
1698
00:58:56,080 --> 00:58:57,640
More usage equals more spend.
1699
00:58:57,640 --> 00:58:59,080
This means your incentive should shift
1700
00:58:59,080 --> 00:59:01,520
toward value efficiency, not usage volume.
1701
00:59:01,520 --> 00:59:03,480
You want to use agents where they create leverage
1702
00:59:03,480 --> 00:59:05,560
and avoid them where manual work is faster.
1703
00:59:05,560 --> 00:59:06,800
But here is the problem.
1704
00:59:06,800 --> 00:59:09,040
Nobody has designed their incentives that way.
1705
00:59:09,040 --> 00:59:11,200
Teams still think like they are in the old model.
1706
00:59:11,200 --> 00:59:12,520
What actually happens is this.
1707
00:59:12,520 --> 00:59:15,640
A team gets access to co-work and looks at their daily tasks.
1708
00:59:15,640 --> 00:59:16,920
They ask what they can automate.
1709
00:59:16,920 --> 00:59:19,520
They identify 20 tasks and start building.
1710
00:59:19,520 --> 00:59:23,160
Pretty soon the agent is handling 60% of their daily work volume.
1711
00:59:23,160 --> 00:59:24,360
The team feels productive.
1712
00:59:24,360 --> 00:59:26,760
The organization seems happy, usage is high,
1713
00:59:26,760 --> 00:59:28,760
but there is a problem that nobody is measuring.
1714
00:59:28,760 --> 00:59:30,920
The team might be experiencing zero time savings,
1715
00:59:30,920 --> 00:59:32,320
not all work is created equal.
1716
00:59:32,320 --> 00:59:34,920
Some tasks are genuinely better when they are automated.
1717
00:59:34,920 --> 00:59:36,840
They are repetitive, data heavy,
1718
00:59:36,840 --> 00:59:38,360
and do not require judgment.
1719
00:59:38,360 --> 00:59:39,840
An agent handling those is a win.
1720
00:59:39,840 --> 00:59:42,560
It saves time and the cost per hour of labor eliminated
1721
00:59:42,560 --> 00:59:43,400
is favorable.
1722
00:59:43,400 --> 00:59:45,560
Other tasks are different.
1723
00:59:45,560 --> 00:59:47,280
They are faster to do manually,
1724
00:59:47,280 --> 00:59:50,120
or they require judgment and agent cannot replicate.
1725
00:59:50,120 --> 00:59:52,920
An agent handling these tasks actually waste time.
1726
00:59:52,920 --> 00:59:55,200
The human has to review the work and often redo it,
1727
00:59:55,200 --> 00:59:57,760
which is slower than just doing it themselves the first time.
1728
00:59:57,760 --> 00:59:59,760
When a team uses agents indiscriminately,
1729
00:59:59,760 --> 01:00:01,520
they apply automation to everything.
1730
01:00:01,520 --> 01:00:03,280
They burn credits on low value work.
1731
01:00:03,280 --> 01:00:04,600
The agent completes the task,
1732
01:00:04,600 --> 01:00:07,080
but it costs more than the manual labor would have.
1733
01:00:07,080 --> 01:00:08,160
The team thinks they are winning
1734
01:00:08,160 --> 01:00:10,320
because the agent is handling more work.
1735
01:00:10,320 --> 01:00:11,160
They are not.
1736
01:00:11,160 --> 01:00:13,600
They are just spending more credits without generating value.
1737
01:00:13,600 --> 01:00:14,920
This is the consumption trap.
1738
01:00:14,920 --> 01:00:18,240
Credits incentivize usage, but usage does not equal value.
1739
01:00:18,240 --> 01:00:20,480
A team using agents for 30% of their work
1740
01:00:20,480 --> 01:00:22,960
on high-level tasks might get triple the value
1741
01:00:22,960 --> 01:00:26,360
of a team using them for 60% of their work indiscriminately.
1742
01:00:26,360 --> 01:00:27,680
The metric that actually matters
1743
01:00:27,680 --> 01:00:29,440
is the cost per unit of value.
1744
01:00:29,440 --> 01:00:32,320
It is not about cost per task or agent utilization.
1745
01:00:32,320 --> 01:00:34,640
It is about the cost per resolved ticket,
1746
01:00:34,640 --> 01:00:37,720
the cost per document drafted, or the cost per hour saved.
1747
01:00:37,720 --> 01:00:39,680
You have to measure the cost to achieve an outcome
1748
01:00:39,680 --> 01:00:42,240
with the agent versus the cost without it.
1749
01:00:42,240 --> 01:00:44,040
That delta is your actual value.
1750
01:00:44,040 --> 01:00:46,480
Imagine a team processing customer support tickets
1751
01:00:46,480 --> 01:00:48,840
without agents, a ticket takes 45 minutes
1752
01:00:48,840 --> 01:00:50,920
and costs $20 in labor.
1753
01:00:50,920 --> 01:00:52,720
The team handles 20 tickets a day,
1754
01:00:52,720 --> 01:00:55,360
which puts the daily labor cost at $400.
1755
01:00:55,360 --> 01:00:59,240
Now you deploy a co-work agent to handle triage and draft responses.
1756
01:00:59,240 --> 01:01:01,640
In the first scenario, the agent reduces the human time
1757
01:01:01,640 --> 01:01:03,000
to 20 minutes per ticket.
1758
01:01:03,000 --> 01:01:04,680
That labor now costs $9.
1759
01:01:04,680 --> 01:01:07,840
The agent's work costs $2.50 in credits.
1760
01:01:07,840 --> 01:01:10,520
Your total cost per ticket is $11.50.
1761
01:01:10,520 --> 01:01:13,520
You are saving $8.50 on every ticket.
1762
01:01:13,520 --> 01:01:17,200
Over 20 tickets that is $170 in daily savings.
1763
01:01:17,200 --> 01:01:18,560
Now look at a different scenario.
1764
01:01:18,560 --> 01:01:19,960
The agent handles triage,
1765
01:01:19,960 --> 01:01:22,160
but the team also uses it for low-value tasks
1766
01:01:22,160 --> 01:01:25,280
like refraising emails or generating summaries nobody reads.
1767
01:01:25,280 --> 01:01:27,560
They are using it more but not on the right work.
1768
01:01:27,560 --> 01:01:29,600
The labor time only drops to 35 minutes
1769
01:01:29,600 --> 01:01:31,840
because the human is still doing the heavy lifting.
1770
01:01:31,840 --> 01:01:34,880
The agent's work now costs $5 in credits per ticket.
1771
01:01:34,880 --> 01:01:37,640
Your total cost is $15.75.
1772
01:01:37,640 --> 01:01:39,400
You have not actually saved anything.
1773
01:01:39,400 --> 01:01:41,600
You have just made the process more expensive.
1774
01:01:41,600 --> 01:01:44,560
Same tool, same team, same capabilities.
1775
01:01:44,560 --> 01:01:45,800
One is using it for value,
1776
01:01:45,800 --> 01:01:47,480
the other is using it for volume.
1777
01:01:47,480 --> 01:01:49,160
The difference comes down to discipline.
1778
01:01:49,160 --> 01:01:51,600
You have to answer which tasks the agent should handle
1779
01:01:51,600 --> 01:01:53,360
before you turn the feature on.
1780
01:01:53,360 --> 01:01:55,200
You cannot wait until you are reviewing the bill
1781
01:01:55,200 --> 01:01:56,240
at the end of the month.
1782
01:01:56,240 --> 01:01:57,800
The trap is that the credit model
1783
01:01:57,800 --> 01:02:00,040
does not enforce this discipline for you.
1784
01:02:00,040 --> 01:02:01,040
It does the opposite.
1785
01:02:01,040 --> 01:02:04,240
It encourages you to automate more and burn more credits.
1786
01:02:04,240 --> 01:02:05,520
The more you use the system,
1787
01:02:05,520 --> 01:02:07,720
the more you feel like you are getting your money's worth.
1788
01:02:07,720 --> 01:02:09,640
But you are not. You are just spending.
1789
01:02:09,640 --> 01:02:11,280
This is why you need a cost model in place
1790
01:02:11,280 --> 01:02:13,280
before you ever deploy at scale.
1791
01:02:13,280 --> 01:02:14,640
Building the cost model.
1792
01:02:14,640 --> 01:02:16,320
Forecasting and budget planning.
1793
01:02:16,320 --> 01:02:18,560
You can't budget for something you don't understand.
1794
01:02:18,560 --> 01:02:21,080
And right now, most organizations can't forecast
1795
01:02:21,080 --> 01:02:23,440
their co-expend because they haven't built the model
1796
01:02:23,440 --> 01:02:24,440
that makes it visible.
1797
01:02:24,440 --> 01:02:25,960
The math here is actually straightforward.
1798
01:02:25,960 --> 01:02:27,360
It's the discipline that matters.
1799
01:02:27,360 --> 01:02:29,360
Start by looking at how your people actually work.
1800
01:02:29,360 --> 01:02:30,320
You aren't guessing.
1801
01:02:30,320 --> 01:02:31,320
You're observing.
1802
01:02:31,320 --> 01:02:33,720
You need to know which roles use co-work the most.
1803
01:02:33,720 --> 01:02:35,960
An executive might call on an agent five times a day
1804
01:02:35,960 --> 01:02:38,760
for quick tasks or decisions that need fast execution
1805
01:02:38,760 --> 01:02:40,520
while an analyst might use it 20 times
1806
01:02:40,520 --> 01:02:43,120
because their work is data heavy and repetitive.
1807
01:02:43,120 --> 01:02:45,400
A customer service rep might hit 15 uses a day
1808
01:02:45,400 --> 01:02:46,680
to process high volume,
1809
01:02:46,680 --> 01:02:49,320
but a success manager might only need it three times.
1810
01:02:49,320 --> 01:02:51,400
The pattern isn't the same across the company.
1811
01:02:51,400 --> 01:02:53,720
It breaks down by persona and workflow.
1812
01:02:53,720 --> 01:02:54,760
Once you have that baseline,
1813
01:02:54,760 --> 01:02:56,480
you segment by task complexity.
1814
01:02:56,480 --> 01:02:59,040
Not all co-work tasks are equal, a light task.
1815
01:02:59,040 --> 01:03:02,240
Like summarizing an email chain costs about 135 credits.
1816
01:03:02,240 --> 01:03:04,200
You're just pulling one stream and analyzing it.
1817
01:03:04,200 --> 01:03:06,600
It's quick and bounded, a medium task,
1818
01:03:06,600 --> 01:03:08,920
like building a meeting agenda from your calendar emails
1819
01:03:08,920 --> 01:03:11,360
and docs costs about 500 credits.
1820
01:03:11,360 --> 01:03:12,960
The agent is doing real work here.
1821
01:03:12,960 --> 01:03:14,680
It's gathering data from multiple sources
1822
01:03:14,680 --> 01:03:16,480
and synthesizing it into a structure.
1823
01:03:16,480 --> 01:03:19,600
A heavy task, like analyzing last quarter's churn trends
1824
01:03:19,600 --> 01:03:21,480
and drafting retention talking points,
1825
01:03:21,480 --> 01:03:23,440
starts at 1,500 credits.
1826
01:03:23,440 --> 01:03:25,480
The agent is reasoning, not just retrieving.
1827
01:03:25,480 --> 01:03:27,080
It's working with large data sets
1828
01:03:27,080 --> 01:03:28,880
and generating structured output.
1829
01:03:28,880 --> 01:03:30,240
Now look at the distribution.
1830
01:03:30,240 --> 01:03:32,360
In most organizations, the work isn't balanced.
1831
01:03:32,360 --> 01:03:33,360
Most of it is routine.
1832
01:03:33,360 --> 01:03:35,960
You can usually expect 60% light tasks,
1833
01:03:35,960 --> 01:03:38,240
30% medium and 10% heavy.
1834
01:03:38,240 --> 01:03:40,360
Your specific organization might be different,
1835
01:03:40,360 --> 01:03:42,560
so you should check with the teams using the system,
1836
01:03:42,560 --> 01:03:46,040
but that 60, 30, 10 split is a solid place to start.
1837
01:03:46,040 --> 01:03:47,600
To find your average cost per task,
1838
01:03:47,600 --> 01:03:49,680
multiply each tier by its percentage.
1839
01:03:49,680 --> 01:03:51,880
60% of 135 is 81.
1840
01:03:51,880 --> 01:03:53,720
30% of 500 is 150.
1841
01:03:53,720 --> 01:03:55,680
10% of 1,500 is 150.
1842
01:03:55,680 --> 01:03:58,440
When you add those up, you get 381 credits per task.
1843
01:03:58,440 --> 01:04:00,600
Let's call it 400 to account for the variations.
1844
01:04:00,600 --> 01:04:02,120
Now multiply that by your usage.
1845
01:04:02,120 --> 01:04:05,280
If you have 100 users doing 10 tasks a day at 400 credits each,
1846
01:04:05,280 --> 01:04:07,360
that's 400,000 credits every single day.
1847
01:04:07,360 --> 01:04:10,080
Over a 30-day month, you're looking at 12 million credits.
1848
01:04:10,080 --> 01:04:12,280
Add a penny per credit, your raw consumption
1849
01:04:12,280 --> 01:04:14,840
is $120,000 a month.
1850
01:04:14,840 --> 01:04:16,200
But you have to add a buffer.
1851
01:04:16,200 --> 01:04:18,240
Organizations almost always underestimate usage
1852
01:04:18,240 --> 01:04:20,520
at the start because teams find new use cases
1853
01:04:20,520 --> 01:04:22,600
and power users adopt heavier patterns.
1854
01:04:22,600 --> 01:04:24,200
Add 20% for safety.
1855
01:04:24,200 --> 01:04:27,560
Your real forecasted spend is $144,000 a month.
1856
01:04:27,560 --> 01:04:29,240
But here's the step nobody actually does.
1857
01:04:29,240 --> 01:04:31,640
You have to validate that against business value.
1858
01:04:31,640 --> 01:04:33,480
The assumption is that agents save time.
1859
01:04:33,480 --> 01:04:36,320
If each of those 100 users saves just 10 hours a month,
1860
01:04:36,320 --> 01:04:38,480
that's 1,000 hours total.
1861
01:04:38,480 --> 01:04:40,640
If your loaded labor cost is $75 an hour,
1862
01:04:40,640 --> 01:04:42,560
you're saving $75,000 a month.
1863
01:04:42,560 --> 01:04:44,320
Wait, your spend is $144,000.
1864
01:04:44,320 --> 01:04:45,840
Your value is $75,000.
1865
01:04:45,840 --> 01:04:47,080
The math doesn't work.
1866
01:04:47,080 --> 01:04:48,720
Something is wrong with the model.
1867
01:04:48,720 --> 01:04:50,960
Either your usage estimates are too aggressive,
1868
01:04:50,960 --> 01:04:53,040
your productivity gains are too optimistic,
1869
01:04:53,040 --> 01:04:54,680
or you're deploying to the wrong people.
1870
01:04:54,680 --> 01:04:56,200
You have to go back and recalibrate.
1871
01:04:56,200 --> 01:04:58,520
Maybe the actual usage is six tasks a day,
1872
01:04:58,520 --> 01:05:01,000
or maybe you only deploy to 60 high value users
1873
01:05:01,000 --> 01:05:01,840
instead of 100.
1874
01:05:01,840 --> 01:05:03,600
The point is, you're testing the model
1875
01:05:03,600 --> 01:05:04,640
before you commit the money.
1876
01:05:04,640 --> 01:05:06,880
You're forcing the value hypothesis to be explicit.
1877
01:05:06,880 --> 01:05:08,920
You aren't just assuming agents pay for themselves.
1878
01:05:08,920 --> 01:05:10,520
You're proving it.
1879
01:05:10,520 --> 01:05:13,160
Once the spend is justified, you have a baseline.
1880
01:05:13,160 --> 01:05:14,480
Now you can plan in stages.
1881
01:05:14,480 --> 01:05:16,040
Pile it with one persona this quarter
1882
01:05:16,040 --> 01:05:17,320
and validate the model.
1883
01:05:17,320 --> 01:05:19,120
Expand to the next persona next quarter
1884
01:05:19,120 --> 01:05:20,040
and keep validating.
1885
01:05:20,040 --> 01:05:22,320
You aren't deploying at scale based on a theory.
1886
01:05:22,320 --> 01:05:24,600
You're deploying incrementally based on evidence.
1887
01:05:24,600 --> 01:05:27,920
That is how you build a cost model that actually works.
1888
01:05:27,920 --> 01:05:30,440
The procurement and vendor strategy, licensing,
1889
01:05:30,440 --> 01:05:32,440
commitments and negotiation.
1890
01:05:32,440 --> 01:05:34,560
The way you buy credits matters more than you think.
1891
01:05:34,560 --> 01:05:36,840
It isn't because the price per credit changes that much.
1892
01:05:36,840 --> 01:05:38,960
It's because the terms you accept shape
1893
01:05:38,960 --> 01:05:40,200
everything that happens next.
1894
01:05:40,200 --> 01:05:42,120
You need a strategy before you ever sit down
1895
01:05:42,120 --> 01:05:43,680
to negotiate with Microsoft.
1896
01:05:43,680 --> 01:05:45,080
Credits come in three models.
1897
01:05:45,080 --> 01:05:48,120
You need to understand each one to know which mix to use.
1898
01:05:48,120 --> 01:05:50,080
Pay as you go is your flexible option.
1899
01:05:50,080 --> 01:05:51,080
You don't commit to anything
1900
01:05:51,080 --> 01:05:53,400
and you get billed monthly for what you actually used.
1901
01:05:53,400 --> 01:05:55,720
You're paying the full list price of one cent per credit
1902
01:05:55,720 --> 01:05:57,240
but you have total freedom.
1903
01:05:57,240 --> 01:05:59,680
If a project ends or you need to scale down,
1904
01:05:59,680 --> 01:06:00,800
there is no penalty.
1905
01:06:00,800 --> 01:06:02,400
This is the right choice for experiments
1906
01:06:02,400 --> 01:06:05,200
or teams that can't forecast their consumption yet.
1907
01:06:05,200 --> 01:06:08,000
Pre-purchase plans or P3 are the opposite.
1908
01:06:08,000 --> 01:06:09,760
You commit to a block of credits upfront
1909
01:06:09,760 --> 01:06:11,440
for a year to get volume discounts.
1910
01:06:11,440 --> 01:06:14,280
At 300,000 credits, you get 5% off.
1911
01:06:14,280 --> 01:06:17,000
At 300 million, that discount hits 20%.
1912
01:06:17,000 --> 01:06:18,680
Large enterprises can often negotiate
1913
01:06:18,680 --> 01:06:20,920
another 10 or 15% on top of that.
1914
01:06:20,920 --> 01:06:21,800
But here is the catch.
1915
01:06:21,800 --> 01:06:23,000
You're buying a fixed pool.
1916
01:06:23,000 --> 01:06:24,720
If you don't use those credits by the end of the year,
1917
01:06:24,720 --> 01:06:25,480
they expire.
1918
01:06:25,480 --> 01:06:26,320
They don't roll over.
1919
01:06:26,320 --> 01:06:27,280
They're just gone.
1920
01:06:27,280 --> 01:06:28,720
You are betting on your forecast.
1921
01:06:28,720 --> 01:06:30,280
Capacity packs sit right in the middle.
1922
01:06:30,280 --> 01:06:32,480
You buy a fixed allocation of interactions.
1923
01:06:32,480 --> 01:06:35,160
Usually 25,000 a month and it renews monthly.
1924
01:06:35,160 --> 01:06:36,600
It's more stable than pay as you go
1925
01:06:36,600 --> 01:06:39,480
but you don't get the deep discounts of a P3 commitment.
1926
01:06:39,480 --> 01:06:41,600
Most mature organizations use a hybrid approach.
1927
01:06:41,600 --> 01:06:43,680
They buy a capacity pack for their baseline.
1928
01:06:43,680 --> 01:06:45,720
The work they know they'll do every month.
1929
01:06:45,720 --> 01:06:49,000
They layer a P3 commitment on top for their expected growth.
1930
01:06:49,000 --> 01:06:50,480
Then they keep pay as you go,
1931
01:06:50,480 --> 01:06:52,200
enabled for the overflow.
1932
01:06:52,200 --> 01:06:54,680
When the baseline hits the cap, it pulls from P3.
1933
01:06:54,680 --> 01:06:56,720
When P3 is empty, it's built to pay as you go.
1934
01:06:56,720 --> 01:06:58,720
The economics work because the bulk of your work
1935
01:06:58,720 --> 01:06:59,960
is covered by discounts.
1936
01:06:59,960 --> 01:07:02,600
But you aren't penalized for growing faster than expected.
1937
01:07:02,600 --> 01:07:04,280
Negotiation is where your leverage lives.
1938
01:07:04,280 --> 01:07:06,440
Most organizations just accept the published pricing.
1939
01:07:06,440 --> 01:07:07,120
They shouldn't.
1940
01:07:07,120 --> 01:07:09,160
If you have 500 or more co-workers,
1941
01:07:09,160 --> 01:07:11,440
you are a material part of Microsoft's revenue
1942
01:07:11,440 --> 01:07:12,280
for this product.
1943
01:07:12,280 --> 01:07:13,760
They want your multi-year commitment
1944
01:07:13,760 --> 01:07:15,640
because it gives them predictability.
1945
01:07:15,640 --> 01:07:16,960
That is your negotiating room.
1946
01:07:16,960 --> 01:07:19,240
Benchmark your usage against the discount curve.
1947
01:07:19,240 --> 01:07:21,320
If you're forecasting 5 million credits a year,
1948
01:07:21,320 --> 01:07:22,600
you're already in discount territory,
1949
01:07:22,600 --> 01:07:26,320
but enterprise customers can often push for 25% off the list price.
1950
01:07:26,320 --> 01:07:28,160
Ask what the volume pricing looks like
1951
01:07:28,160 --> 01:07:30,960
and don't assume the first number they give you is the final one.
1952
01:07:30,960 --> 01:07:33,240
The contract terms matter just as much as the price.
1953
01:07:33,240 --> 01:07:34,520
You need to clarify what happens
1954
01:07:34,520 --> 01:07:36,360
if you go over your P3 commitment.
1955
01:07:36,360 --> 01:07:38,040
Does the price jump back to the list rate
1956
01:07:38,040 --> 01:07:39,920
or stay at your negotiated rate?
1957
01:07:39,920 --> 01:07:41,920
Ask if unused credits can carry forward
1958
01:07:41,920 --> 01:07:44,160
if you're showing a clear growth path.
1959
01:07:44,160 --> 01:07:45,840
You also need to know the renewal timeline
1960
01:07:45,840 --> 01:07:48,040
and if there's a minimum size for the next year.
1961
01:07:48,040 --> 01:07:51,080
Finally, remember that vendor lock in is real.
1962
01:07:51,080 --> 01:07:53,280
Co-pilot credits are specific to Microsoft.
1963
01:07:53,280 --> 01:07:55,200
If your entire business becomes dependent
1964
01:07:55,200 --> 01:07:58,720
on this specific model, your switching costs will be astronomical.
1965
01:07:58,720 --> 01:08:00,360
That doesn't mean you avoid the commitment
1966
01:08:00,360 --> 01:08:03,160
but it does mean you should build redundancy where it matters.
1967
01:08:03,160 --> 01:08:05,280
If a critical workflow depends entirely on co-work,
1968
01:08:05,280 --> 01:08:06,320
you're exposed.
1969
01:08:06,320 --> 01:08:08,760
If that same workflow could run on Azure OpenAI
1970
01:08:08,760 --> 01:08:11,560
or another tool if needed, you've protected yourself.
1971
01:08:11,560 --> 01:08:13,800
The procurement decision isn't just a financial one,
1972
01:08:13,800 --> 01:08:14,840
it's architectural.
1973
01:08:14,840 --> 01:08:18,400
What you buy determines what you can deploy
1974
01:08:18,400 --> 01:08:20,000
and how trapped you become, sir.
1975
01:08:20,000 --> 01:08:23,560
The implementation timeline, 90 days to August 2026.
1976
01:08:23,560 --> 01:08:24,720
The math is brutal.
1977
01:08:24,720 --> 01:08:27,120
You have roughly 90 days before the high risk rules
1978
01:08:27,120 --> 01:08:29,400
of the EUAI Act become enforceable.
1979
01:08:29,400 --> 01:08:32,240
That is not a long runway, but it is also not impossible.
1980
01:08:32,240 --> 01:08:34,160
If you move fast and stay disciplined.
1981
01:08:34,160 --> 01:08:35,560
Here is what the timeline looks like
1982
01:08:35,560 --> 01:08:37,040
when you execute it properly.
1983
01:08:37,040 --> 01:08:39,640
Weeks one and two, inventory and discovery.
1984
01:08:39,640 --> 01:08:42,120
You are cataloging everything, every power automate flow
1985
01:08:42,120 --> 01:08:44,560
with an AI connector, every co-pilot studio agent,
1986
01:08:44,560 --> 01:08:47,040
every custom integration calling OpenAI APIs,
1987
01:08:47,040 --> 01:08:49,880
every third party tool your teams adopted without asking.
1988
01:08:49,880 --> 01:08:52,360
You are not making judgments yet, you are collecting data.
1989
01:08:52,360 --> 01:08:55,000
Document the owner, the purpose, the data sources
1990
01:08:55,000 --> 01:08:56,480
and the tools it invokes.
1991
01:08:56,480 --> 01:08:59,000
This phase is exhausting because you are finding things
1992
01:08:59,000 --> 01:09:00,560
nobody knew existed.
1993
01:09:00,560 --> 01:09:01,600
And that is the point.
1994
01:09:01,600 --> 01:09:03,680
Shadow AI stops being shadow the moment you put it
1995
01:09:03,680 --> 01:09:04,600
in a spreadsheet.
1996
01:09:04,600 --> 01:09:07,240
Weeks three and four, risk classification.
1997
01:09:07,240 --> 01:09:10,760
Each agent gets evaluated against the EUAI Act categories.
1998
01:09:10,760 --> 01:09:12,800
Is it minimal risk, limited, high-risk,
1999
01:09:12,800 --> 01:09:14,560
prohibited, map it explicitly?
2000
01:09:14,560 --> 01:09:16,320
If an agent is screening drop candidates
2001
01:09:16,320 --> 01:09:18,600
or evaluating employees, it is high-risk
2002
01:09:18,600 --> 01:09:20,680
if it is just drafting meeting notes.
2003
01:09:20,680 --> 01:09:21,680
It is low-risk.
2004
01:09:21,680 --> 01:09:23,400
If it is handling customer communications,
2005
01:09:23,400 --> 01:09:25,880
it is limited risk and requires transparency.
2006
01:09:25,880 --> 01:09:27,360
You are building the risk register
2007
01:09:27,360 --> 01:09:29,400
that becomes the foundation for everything else.
2008
01:09:29,400 --> 01:09:30,360
Do not rush this.
2009
01:09:30,360 --> 01:09:32,840
Misclassification creates compliance gaps
2010
01:09:32,840 --> 01:09:35,200
that you cannot easily close later.
2011
01:09:35,200 --> 01:09:37,560
Weeks five through eight, governance design.
2012
01:09:37,560 --> 01:09:40,120
Define the structure, who makes agent approval decisions,
2013
01:09:40,120 --> 01:09:41,800
who owns the overall AI governance,
2014
01:09:41,800 --> 01:09:43,440
which roles handle the escalations,
2015
01:09:43,440 --> 01:09:45,520
what does the approval gate actually look like?
2016
01:09:45,520 --> 01:09:47,120
Design the monitoring dashboards.
2017
01:09:47,120 --> 01:09:49,680
Decide which metrics matter and how you will track them.
2018
01:09:49,680 --> 01:09:51,480
Define the technical controls.
2019
01:09:51,480 --> 01:09:53,040
What permissions will agents have?
2020
01:09:53,040 --> 01:09:55,440
What approvals are required before an agent takes action?
2021
01:09:55,440 --> 01:09:56,760
What are the kill switch procedures?
2022
01:09:56,760 --> 01:09:57,960
Write the policies.
2023
01:09:57,960 --> 01:09:59,440
But not as thick legal documents.
2024
01:09:59,440 --> 01:10:01,240
Write them as operating procedures.
2025
01:10:01,240 --> 01:10:02,680
How do we actually do this work?
2026
01:10:02,680 --> 01:10:06,480
Weeks nine through 12, technical implementation.
2027
01:10:06,480 --> 01:10:07,520
This is infrastructure.
2028
01:10:07,520 --> 01:10:10,040
Deploy agent 365 and configure EntraID
2029
01:10:10,040 --> 01:10:12,200
to treat agents as first class identities.
2030
01:10:12,200 --> 01:10:14,720
Configure DLP policies explicitly for co-pilot
2031
01:10:14,720 --> 01:10:16,080
and agent outputs.
2032
01:10:16,080 --> 01:10:19,320
Setup conditional access rules that enforce least privilege.
2033
01:10:19,320 --> 01:10:20,600
Build the logging infrastructure.
2034
01:10:20,600 --> 01:10:23,040
You are not using Microsoft Perview logs alone.
2035
01:10:23,040 --> 01:10:25,320
You are building a separate layer that captures
2036
01:10:25,320 --> 01:10:27,640
agent-specific metadata, which agent,
2037
01:10:27,640 --> 01:10:29,480
which model, which tools, which daughter,
2038
01:10:29,480 --> 01:10:30,840
and the decision reasoning.
2039
01:10:30,840 --> 01:10:33,200
This layer feeds directly into your audit
2040
01:10:33,200 --> 01:10:35,080
and compliance framework.
2041
01:10:35,080 --> 01:10:37,960
Weeks 13 through 16, pilot and validation.
2042
01:10:37,960 --> 01:10:39,240
You are not scaling yet.
2043
01:10:39,240 --> 01:10:40,880
You are proving the model works.
2044
01:10:40,880 --> 01:10:42,840
Select a small group of high-risk agents
2045
01:10:42,840 --> 01:10:44,400
or a focused use case.
2046
01:10:44,400 --> 01:10:46,920
Deploy into the governance environment you just built.
2047
01:10:46,920 --> 01:10:48,000
Monitor heavily.
2048
01:10:48,000 --> 01:10:50,040
Measure adoption rates are people actually using it.
2049
01:10:50,040 --> 01:10:50,840
Track errors.
2050
01:10:50,840 --> 01:10:52,640
Is the agent producing outputs people trust?
2051
01:10:52,640 --> 01:10:53,400
Measure outcomes.
2052
01:10:53,400 --> 01:10:55,120
Is the promised value materializing?
2053
01:10:55,120 --> 01:10:56,320
Document everything.
2054
01:10:56,320 --> 01:10:57,280
Every incident.
2055
01:10:57,280 --> 01:10:58,520
Every work around.
2056
01:10:58,520 --> 01:11:00,600
And every unexpected behavior becomes input
2057
01:11:00,600 --> 01:11:01,800
for the next phase.
2058
01:11:01,800 --> 01:11:03,560
Weeks 17 through 20.
2059
01:11:03,560 --> 01:11:04,480
Remediation.
2060
01:11:04,480 --> 01:11:07,040
The pilot revealed what did not work.
2061
01:11:07,040 --> 01:11:07,880
So fix it.
2062
01:11:07,880 --> 01:11:10,280
If the logging infrastructure is not capturing the right data,
2063
01:11:10,280 --> 01:11:11,120
rebuild it.
2064
01:11:11,120 --> 01:11:13,240
If the approval gates are slowing things down too much,
2065
01:11:13,240 --> 01:11:14,080
streamline them.
2066
01:11:14,080 --> 01:11:16,120
Teams do not understand the governance model.
2067
01:11:16,120 --> 01:11:17,200
Revise the training.
2068
01:11:17,200 --> 01:11:19,480
If certain agents are hitting edge cases,
2069
01:11:19,480 --> 01:11:21,040
update the decision logic.
2070
01:11:21,040 --> 01:11:22,840
Governance improves through iteration,
2071
01:11:22,840 --> 01:11:24,880
not through perfect design on day one.
2072
01:11:24,880 --> 01:11:27,880
Weeks 21 through 24 and beyond scale.
2073
01:11:27,880 --> 01:11:30,280
Now you are expanding agent deployments incrementally.
2074
01:11:30,280 --> 01:11:32,920
One new team per week, one new use case per sprint,
2075
01:11:32,920 --> 01:11:34,480
maintain the monitoring discipline.
2076
01:11:34,480 --> 01:11:36,680
Keep refining based on what you are seeing at scale.
2077
01:11:36,680 --> 01:11:39,280
Establish the quarterly review cycle, monthly reviews
2078
01:11:39,280 --> 01:11:40,480
of usage and cost.
2079
01:11:40,480 --> 01:11:43,200
Quarterly reassessment of risk classification.
2080
01:11:43,200 --> 01:11:45,080
Governance is not something you finish.
2081
01:11:45,080 --> 01:11:46,440
It is something you maintain.
2082
01:11:46,440 --> 01:11:49,840
By August 2nd, 2026, you need to be able to demonstrate compliance,
2083
01:11:49,840 --> 01:11:51,800
not just aspire to it, demonstrate it.
2084
01:11:51,800 --> 01:11:54,720
You have documented risk assessments for your high-risk agents.
2085
01:11:54,720 --> 01:11:57,440
You have audit trails, capturing decisions and approvals.
2086
01:11:57,440 --> 01:12:00,040
You have governance procedures that are actually being followed.
2087
01:12:00,040 --> 01:12:02,320
You have evidence that humans are meaningfully overseeing
2088
01:12:02,320 --> 01:12:03,080
the systems.
2089
01:12:03,080 --> 01:12:05,960
You have technical controls enforcing the boundaries you set.
2090
01:12:05,960 --> 01:12:07,640
You do not have perfect governance.
2091
01:12:07,640 --> 01:12:09,000
But you have working governance that is
2092
01:12:09,000 --> 01:12:10,440
auditable and defensible.
2093
01:12:10,440 --> 01:12:12,240
But here is the reality most organizations
2094
01:12:12,240 --> 01:12:13,880
do not want to hear.
2095
01:12:13,880 --> 01:12:16,920
The co-pilot credit trap is not the credits themselves.
2096
01:12:16,920 --> 01:12:19,240
It is the assumption that you can deploy autonomous agents
2097
01:12:19,240 --> 01:12:22,160
into an unprepared organization and just pay for what you use.
2098
01:12:22,160 --> 01:12:22,880
You cannot.
2099
01:12:22,880 --> 01:12:24,240
The structure does not support it.
2100
01:12:24,240 --> 01:12:25,840
Your data governance is weak.
2101
01:12:25,840 --> 01:12:27,200
Your identity model is broken.
2102
01:12:27,200 --> 01:12:28,840
Your audit trails do not exist.
2103
01:12:28,840 --> 01:12:30,440
Your cost model is guesswork.
2104
01:12:30,440 --> 01:12:33,560
By August 2026, if you have not built the governance layer,
2105
01:12:33,560 --> 01:12:34,880
you are not just overspending.
2106
01:12:34,880 --> 01:12:35,880
You are exposed.
2107
01:12:35,880 --> 01:12:38,640
Regulators will ask for evidence, and you will not have it.
2108
01:12:38,640 --> 01:12:39,480
Start now.
2109
01:12:39,480 --> 01:12:42,160
And if you want more of this, follow me on LinkedIn.