
4,000. That's how many Copilot Credits each member of staff can spend a month by default from 1 December, on top of the licence you already pay for.
Three stories this week, one message. AI that does the work for you is arriving inside software you already pay for. It comes with a meter, it comes with access to your data and in California it now comes with a legal duty. Someone in your business needs to own all three.
1. Microsoft Copilot moves agent work onto a pay-as-you-go meter
On 25 September Microsoft relaunched Copilot. Everyday Copilot chat stays on the per-user licence. The new features that do the work for you, Cowork, Code and Autopilot, "all run on UBB", Microsoft's shorthand for usage-based billing. Autopilot is an agent Microsoft says "keeps working even when you're not". Most of it is still in preview.
On 1 October Microsoft told its partners that from 1 December 2026 pay-as-you-go will be switched on by default for new Copilot Business licences bought through a Microsoft partner. The default limit is 4,000 Copilot Credits per user per month. Microsoft's own example is 100 users spending up to 400,000 credits a month. New services are added to your spending policy automatically unless an admin changes that setting. A handful of countries including Germany, France and Australia are excluded at first. The UK and US are not.
Why it matters: the seat price is no longer the whole bill. Neither announcement puts a price on a credit, so what you pay depends on what your people ask agents to do. And 4,000 credits a head is a ceiling Microsoft chose for you, not one you chose.
Practical takeaway:
- Find out how you buy Copilot. If it's through your IT provider, ask them before 1 December what the default will be on your account.
- Set the cap per person yourself. Start low for most staff and raise it for the few who need more.
- Turn off auto-apply for new services until you've decided which agents belong in the budget. If you run an IT services firm your clients will be asking about this, and our AI for MSPs page shows where we help.
2. ChatGPT gets always-on agents and Word is switched on by default

On 29 September OpenAI launched dots, "always-on agents" that each get their own cloud computer and can connect to over 4,000 apps. You reach them through ChatGPT, Slack or Teams. They're rolling out to Business Premium seats, which cost $100 per user per month billed annually. The first dot is included at no extra cost. More will cost extra later.
You choose how much freedom each one has: act without asking, act if pre-approved, ask first or hand it back to you. The line that matters is in OpenAI's help page: "Disconnecting an app does not delete information your dot has already obtained from it." To remove that data you delete the dot.
Separately, ChatGPT for Word has been switched on by default for ChatGPT Business since 1 October. It's billed on usage at API rates and comes out of your shared allowance.
Why it matters: an agent with access to your inbox, CRM and accounts is only as safe as the rules you give it. Unplugging a tool doesn't make the agent forget what it saw. And a default-on add-in is a new route for client documents into a metered service that nobody in your business decided to switch on.
Practical takeaway:
- Decide what an agent may connect to before anyone connects one. Client data and finance systems last, not first.
- Start every agent on "ask first". Loosen the rules once you've watched what it does.
- Check the Word setting this week if you pay for ChatGPT Business. It's in the admin console.
3. California says a person must sign off AI decisions about staff

On 30 September California signed SB 947. From 1 July 2027 employers can't "rely solely" on an automated decision system to discipline or dismiss someone. If they rely mainly on its output, a person has to corroborate it and the worker gets a written notice at the time. A second law, SB 951, says layoff notices caused in whole or in substantial part by AI must list the job functions being automated.
Why it matters: this is one US state, but it's the direction of travel. The EU AI Act already lists AI used to hire, promote or dismiss staff as high-risk. If you have sites or staff in California it applies to you directly. If you don't, it's still the right design rule for any AI that touches people's jobs.
Practical takeaway:
- List every tool that scores, ranks or flags staff. Include the ones built into rota, HR and performance software. Multi-site operators usually find more than they expect. Our AI for franchises page covers how we approach it.
- Build the human check in now and write down who does it.
- Keep a record of the decision and the review. If you can't show the check happened, it didn't.
What this week means for your business
One more on the same theme. On 1 October Google updated its guidance on AI content to say it is "critical to manually factcheck and review all AI-generated content" before publishing. Same rule, applied to your website.
AI agents are now a line on the bill and a set of permissions, not a demo. The businesses that get real value from them will be the ones that set the caps, the connections and the human checks before switching them on, not after the first invoice.
That's the work we do. We build production AI with limits and approvals designed in, and we run it so those controls don't drift. The AI Readiness Diagnostic is free and no-obligation. You keep the statement of work, the wireframe and the ROI case whether or not we build anything.
Questions business owners are asking
Will Microsoft Copilot cost more from December 2026?
The per-user licence for everyday Copilot doesn't change. From 1 December 2026, new Copilot Business licences bought through a Microsoft partner get pay-as-you-go billing switched on by default for agent features such as Cowork, Code and Autopilot. The default limit is 4,000 Copilot Credits per user per month and admins can lower it.
Is it safe to connect ChatGPT agents to my business apps?
It can be, with rules in place first. OpenAI's dots let you require approval before an agent acts. Disconnecting an app doesn't delete what the agent already pulled from it, so decide what it may see before connecting anything and keep client and finance data off-limits until you've tested it.
Can AI decide to dismiss an employee?
Not on its own in California from 1 July 2027. SB 947 stops employers relying solely on an automated system to discipline or dismiss, and requires a person to corroborate the output when it's the main basis. In the EU, AI used for these decisions is classed as high-risk under the AI Act.