Microsoft folds coding and always-on agents into one Copilot app
Microsoft finally shipped the consolidated Copilot it promised in June — and the surprise is that an app sold to knowledge workers now writes and hosts internal apps. Two other stories worth your time: ICLR's second anonymity incident in two cycles, and Berlin's AI street cameras, which are not judging anything yet.
Microsoft unveiled the Copilot "super app" it has been teasing since June: one app with three tabs — Home, Code and Autopilot — that merges Copilot Chat with Cowork and rebrands the desktop assistant Scout as Autopilot. The Code tab is the surprise addition, because it puts app-building inside an app sold to knowledge workers. Anyone can create an app, tracker, dashboard or automation and share it with colleagues as a cloud-hosted internal app; Microsoft says it runs sandboxed inside the customer's own tenant on the same underlying technology as GitHub Copilot. Autopilot is the cloud version of a product Microsoft shipped as a desktop assistant, and it gets its own identity, memory, computer and workspace inside the tenant, shows up in Teams, Outlook, chats and documents where you can mention it like a colleague, and keeps working while you are asleep.
Pricing is where the strategy shows. The plain Copilot licence — $30 per user per month commercially — still covers Chat plus Word, Excel, PowerPoint, Outlook and Teams, but Cowork, Code and Autopilot are billed by usage, and Microsoft is steering IT admins toward new "FinOps for AI" tooling to stop agent spend running away. It is chasing a customer base that has not yet bought in: CNBC reports that of more than 450 million commercial Office 365 seats worldwide, fewer than 7 percent carry a licence for the AI addition. Jacob Andreou, Microsoft's executive vice president for Copilot, told CNBC that adding coding to the app is a case of the company playing catch-up, and that "the problem is that these agents have been almost impossible to bring into the enterprise." The Home tab still routes work to OpenAI and Anthropic models — Microsoft's own model is only selectable in Code.
Microsoft is also not pretending this is a consumer play. Its pitch is "the AI built for work," with marketing chief Jared Spataro arguing that "just as Office defined work for the PC era, the new Copilot is built to define it for the AI era" — a comparison that lands differently when the company's shares are up 3 percent this year against a Nasdaq that has done better. Home and Code reach Frontier-program customers in the coming weeks, Autopilot goes into private preview by the end of September, and Code reaches Microsoft 365 Premium and Pro subscribers later this year. This is the second stage of a consolidation we covered in August — Microsoft starts merging Copilot apps into a super app — and the open question is whether packaging fixes an adoption problem that is really a trust-and-habit problem.
An error in a newly introduced OpenReview feature let ICLR 2027 program-committee members see which authors had submitted which papers, and the platform shut the entire submission site down to patch it. OpenReview's own accounting is unusually precise: submissions went to reviewers and area chairs at 8:15am on 23 September, a staff member saw a social-media post about the leak at 10:20am, the bug was reproduced ten minutes later, and OpenReview hit its per-venue emergency stop at 10:33am — leaving a window of roughly two hours and twenty minutes. The fix was deployed at 11:35am and the stop lifted at 11:42am. The scope was narrow but not trivial: 770 committee members — 704 reviewers and 66 area chairs, under 2 percent of the total — looked at at least one ICLR author's profile, and those profiles listed 12,230 submissions, about 20 percent of what was sent out. One account probed 796 papers.
The context is what makes it land: this is ICLR's second anonymity incident in two cycles. Last November an API flaw in the same platform let anyone scrape author and reviewer names for more than 10,000 ICLR 2026 papers — roughly 45 percent of the cycle — pushed ICLR to revert every review, and put reviewer names for about 600 papers into public comments. That the emergency button existed and worked this time is real progress; that a profile page could link an author to a submission at all, in a system whose entire value rests on double-blind review, is the part that has not been explained.
Berlin police began setting up AI camera surveillance at Kottbusser Tor on 24 September, and the correction worth keeping is that nothing is being judged yet: the roughly 30 cameras go through about four weeks of technical calibration before test operation begins. The software, supplied by Adesso with Staige, does what police call semantic and spatial analysis — it flags patterns such as someone falling, a fight, a kick or a drawn knife rather than identifying people. Berlin's data protection commissioner, Meike Kamp, says the enabling law excludes biometric remote identification such as facial or gait recognition and bars automated action without a human decision, while warning that large parts of the city centre could end up barely crossable unobserved. The state has budgeted more than 16 million euros for AI cameras and software across its pilot sites; netzpolitik puts the Kottbusser Tor installation at 1.89 million euros plus 349,000 euros a year to run.
The politics are already in court. Die Linke and the Greens filed a constitutional challenge on 28 August against the police law that authorizes the system, arguing it risks "a huge super-database" that oversteps the bounds of the rule of law, and no ruling has been issued. Expanding AI surveillance to measuring how crowds move — while a court weighs whether the law permits it — is the honest version of this story, and it is more interesting than the wire's "cameras switched on."
What to watch: whether Microsoft publishes seat numbers for the new tabs rather than licence percentages, and whether Berlin's calibration phase produces any independent evaluation before the roll-out to Alexanderplatz and Görlitzer Park.
Does bundling chat, code and agents into one app fix enterprise AI adoption — or just move the same licence problem into a bigger window? Tell us in the comments.
Sources: The Verge · CNBC · Techmeme · OpenReview statement on ICLR 2027 submission exposure · ICLR 2026 response to security incident · r/MachineLearning discussion · rbb24 · Tagesspiegel · netzpolitik.org