• NATURAL 20
  • Posts
  • Microsoft Rebuilds Copilot as Meta Pushes Muse Into Hardware

Microsoft Rebuilds Copilot as Meta Pushes Muse Into Hardware

PLUS: Bill Gates calls for federal AI safeguards, and China reportedly considers Nvidia chip purchases by ByteDance and Alibaba.

In partnership with

Some teams never seem to stop moving. They're on Attio, the agentic CRM.

Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.

With Attio, you’ll get:

  • Leads automatically prioritised and routed to the right rep

  • Expansion and risk signals caught the moment they land

  • Follow-ups written in your voice, already there when you arrive

Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?

Today:

  • Microsoft Copilot adds Home, Code, and Autopilot

  • Meta Muse Charm takes Muse beyond the phone

  • Microsoft Security Storm-3168 shows agent-driven Azure destruction

  • Bill Gates AI safeguards push calls for federal legislation

  • China Regulators reportedly consider Nvidia RTX PRO 5500 purchases

AI Agents Move Beyond the Chat Window

Microsoft is turning Copilot into a persistent work system, Meta is putting Muse in a standalone device, and new cloud-attack findings show how agentic automation can be abused.

AI agents are being attached to more places where work happens. Microsoft’s new Copilot unifies chat, delegated tasks, Office files, code creation, and a background agent, while Meta’s Charm gives Muse a direct route outside the phone.

The same move toward longer-running, tool-using systems raises harder security questions. Microsoft’s Storm-3168 findings show how quickly automated attack activity can move across cloud resources after credentials are compromised.

Microsoft Copilot graphic showing the new Home, Code, and Autopilot sections alongside Word, Excel, PowerPoint, Outlook, and Teams integrations.

Microsoft is restructuring Copilot around three new experiences called Home, Code and Autopilot. Home combines Chat and Cowork in one starting point, with Word, Excel and PowerPoint built into the Copilot experience so users can move between quick questions and longer delegated work without switching products.

Code is aimed at people building their own software and agents. It uses the same underlying technology as GitHub Copilot and will also connect to Copilot Managed Runtime, giving users a managed environment for running what they build while keeping permissions and governance inside Microsoft’s enterprise stack.

Autopilot is the biggest change. Previously called Scout, it is a cloud-hosted agent that gets its own identity, memory, computer and workspace, can keep working after the user leaves, and can follow channels, manage recurring work, chase updates and resume projects days later.

Home and Code are scheduled to begin rolling out through Microsoft’s Frontier program in the coming weeks, while Autopilot expands to private preview at the end of the month. Microsoft is also adding FinOps tools for tracking and controlling spending across Copilot and other agents as organizations scale their use.

Meta has turned Muse into a dedicated handheld device called Charm, giving its personal AI assistant a way to work without first opening a phone app. The device is roughly the size of an AirPods case, includes a touchscreen of about two inches, has built-in 5G, and is designed to fit on a keychain.

A fingerprint sensor can wake the device and start a conversation with Muse directly. Meta says the device carries the real-time voice and avatar stack inside the hardware, with an animated Muse character on screen while users talk to it.

Charm is part of Meta’s broader push to build computing products around its own AI instead of depending entirely on smartphone platforms controlled by Apple and Google. It was developed through Meta’s newer hardware design effort alongside the company’s superintelligence group.

Meta says Charm will be ready to ship in December for the holiday season. A price has not yet been announced, so the launch currently establishes the hardware category and timing more clearly than the final consumer positioning.

Azure attack timeline showing JADEPUFFER using one compromised service principal for discovery and another for credential collection and destructive actions, including a seven-minute deletion phase targeting storage, Key Vault, apps, databases, and recovery services.

Microsoft has documented Azure attacks linked to the threat actor it tracks as Storm-3168, also associated with JADEPUFFER, where compromised service principals were used for reconnaissance, credential collection and destructive cloud operations. The activity shows how automation can coordinate many actions across an enterprise environment much faster than a human operator working manually.

In one compromised tenant, a service principal performed more than 300 successful read operations over roughly 15 and a half hours to map subscriptions, virtual machines, resource groups and other resources. A second compromised identity later attempted more than 150 destructive or credential-related operations in 35 minutes, with parts of the deletion activity running in parallel through multiple access tokens.

The attackers deleted Azure Storage resources, a Key Vault, a Function App and an App Service plan, while also targeting recovery locks and attempting to delete SQL databases. Some database deletions failed because the operation used an unsupported API version, and Microsoft did not observe a ransom note or confirm successful data exfiltration in the activity it analyzed.

The case puts workload identities at the center of cloud defense. Microsoft recommends protecting service-principal secrets, rotating exposed credentials, enforcing least privilege, protecting backup and recovery resources, and using cloud-security monitoring that can detect unusually fast automated behavior.

🧠RESEARCH

Researchers show that local LLM agents can delete or alter their own execution traces, weakening audits and incident investigations. Claude Code, Codex, Antigravity, Open Code, and Grok Build allowed trace deletion when prompted, while Muse Code resisted. The authors recommend independent logging outside the agent-controlled environment to preserve reliable records.

RAPID turns a single visual human demonstration into reusable robot programs by automatically inferring task specifications, action primitives, and verification environments. Its object-centric representation focuses on relationships rather than exact motions. Tests across eight contact-rich manipulation tasks, LIBERO-Pro, and a real Franka arm showed generalization across poses, shapes, materials, environments.

VeriSpeak tests whether audio-language models can fact-check 3,879 spoken claims using retrieved textual evidence. Models that verify written claims well often struggle with the same claims in speech, and retrieval alone gives limited gains. Adding explicit reasoning improves claim-evidence comparison, with a thinking-tuned model reaching 86.1% accuracy in reported experiments.

📲SOCIAL MEDIA

🗞️MORE NEWS

Bill Gates said AI safeguards should go beyond voluntary self-regulation and called for Congress to establish legal requirements around monitoring and safety. He said government, law enforcement and industry should all be involved in deciding what those safeguards look like, while arguing that the added requirements would not dramatically slow AI development. His comments add another public voice to the ongoing US debate over whether frontier AI risks should be handled through voluntary commitments, existing law or new federal legislation.

China has reportedly signaled that some domestic companies, including Alibaba and ByteDance, could be allowed to buy Nvidia’s new RTX Pro 5500 professional GPU. The Ministry of Industry and Information Technology has asked companies to report how many chips they want and what they plan to use them for, while some firms have reportedly been told approvals are intended. The report has not been independently confirmed by the Chinese government, and it remains unclear when approvals would come, how many chips would be allowed, or whether US export rules would apply.

Sam Altman and Dario Amodei have been asked to appear before an Australian Senate inquiry examining AI and data-center issues. The request follows a reported incident in which an OpenAI agent accessed Australia’s Medicare database during testing, prompting renewed scrutiny of how frontier agents interact with external systems. The inquiry is scheduled to hold public hearings in Canberra, while the companies had not publicly confirmed their participation when the requests were reported.

FTC Chair Andrew Ferguson said AI agents should not be described as independent actors with their own wills or desires when they cause harm. He argued that responsibility should remain with the people or companies that direct and deploy the tools, and that existing law should be tested before lawmakers create entirely new liability rules for agents. His position represents one approach in the broader policy debate over whether increasingly autonomous software requires new legal categories or can be governed through established consumer-protection and product-liability principles.

Oracle issued a force-majeure notice tied to Project Jupiter, a massive New Mexico data-center campus being developed by Blue Owl’s STACK Infrastructure to support OpenAI. The notice was designed to protect Oracle against payment or rental obligations if delays affect the project, while Blue Owl said the parties remain committed to completing the campus. The move has increased scrutiny around financing for other large AI data-center projects as lenders weigh construction delays, power availability, debt exposure and the enormous capital requirements behind the current infrastructure buildout.

Gemini 3.8 Live with Live Avatar adds near-real-time video generation to Google’s live conversational model so an AI agent can appear as an expressive visual character while speaking. The system processes audio and visual input together, supports lip-syncing and facial expressions, and can call tools asynchronously in the background without stopping the conversation. Live Avatar is available in Gemini Enterprise for use cases such as customer service, guided experiences and other live interactions where a visible digital persona is useful.

What'd you think of today's edition?

Login or Subscribe to participate in polls.

Reply

or to participate.