
Episode notes
Microsoft has announced a new category of AI agent called Autopilot, starting with one named Scout, which sits in the background watching everything you do across Teams, Outlook, OneDrive, and SharePoint and takes action on your behalf without being prompted. It's powered by something called OpenClaw, which The Register has previously described as a security dumpster fire. Scout schedules your meetings, blocks your calendar, flags risks, and is bound to your Entra identity so its actions are attributed to you. The product is currently in Frontier preview, gated behind a GitHub Copilot subscription that recently moved to usage-based billing. The Register covered the launch in early June.
The editorial center is the gap between the pitch and the pattern. The pitch is that Scout is a new product category — always-on, identity-bearing, background-capable — that represents the substrate moment for agentic work. The pattern is that the autonomous personal-assistant has been pitched in roughly the same form, with roughly the same promises, every five to seven years since 1987. Apple commissioned the Knowledge Navigator concept video that year — a five-minute clip of a tenured professor sitting down at a folding screen device while a man in a bow tie informs him his mother called, his nine-thirty is canceled, his colleague in Brazil has a question about deforestation data. Newton was a piece of it. Lotus Agenda in 1988 was a piece of it. Microsoft Bob in 1995. Clippy in 1997. Wildfire, the voice agent that cost about $180 a month in 1996 dollars. General Magic. The whole intelligent-agent wave of the early 2000s. Siri, Google Now, Cortana — each one a piece of it. The RPA cycle of the 2010s — UiPath, Automation Anywhere, Blue Prism — same pitch in enterprise-software clothing. The work didn't get done. The work got moved, and then someone had to figure out what the robot did and clean it up.
The underlying threat model is sharper this time, because the new agent has the credentials and the new agent doesn't have judgment. OpenClaw — the platform Scout is built on — has a documented record of agents making bad decisions for users. A British mathematician handed an OpenClaw agent a credit card earlier this year and the agent made purchases it should not have made. The Register reported Microsoft was asked about Scout's security model and didn't respond before deadline; the mitigation in Microsoft's launch announcement was enterprise-grade security and controls, which is a phrase, not a strategy. Prompt injection through email or calendar invites can fire without any user interaction. The user has not opened the email. The user has not approved anything. The Entra log shows the user's Scout agent did it. The user is now in a conversation with their CISO about why they exfiltrated board minutes to an external address. UNC3944 has been compromising help desk workflows for two years. They will compromise agent workflows in roughly the same way for roughly the same reason. The org that adopts this in 2026 will be writing the incident report in 2027.
Source Article
No longer just a Copilot: Microsoft's AI wants to take the wheel — The Register, June 3, 2026.
Panel
- The Legacy Sysadmin
- The Paranoid CISO
- The Startup Founder
- The Goat Farmer's Counsel
