CIA Brief 20260726

image

CIA Brief – Weekly News Digest

Here’s a quick roundup of the Microsoft, security and AI news worth tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.

Announcements & Product Launches

Claude Opus 5 is available today in Microsoft Foundry

Anthropic’s Claude Opus 5 — the first model in the fifth generation of Claude — is now available in Microsoft Foundry. Microsoft positions it for enterprise agents and long-running, complex work: it can run for hours, navigate large codebases like a senior engineer, reason over documents and visuals, and automate multi-step tasks across applications. Paired with Foundry’s governance, security and evaluation tools, teams can build and run production AI agents.

https://techcommunity.microsoft.com/blog/azure-ai-foundry-blog/claude-opus-5-is-available-today-in-microsoft-foundry/4535068

Introducing MAI-Image-2.5-Pro and MAI-Voice-2-Flash

Microsoft AI has released two new in-house models in public preview: MAI-Image-2.5-Pro, its highest-fidelity image model with notably accurate in-image text rendering, and MAI-Voice-2-Flash, a faster, cheaper speech model (about 2× faster and ~32% cheaper than MAI-Voice-2). The models are already powering production features in Bing Image Creator, PowerPoint, OneDrive and Dynamics 365 Contact Center. Both are available to build with in Microsoft Foundry.

https://microsoft.ai/news/introducing-mai-image-2-5-pro-and-mai-voice-2-flash/

Microsoft and Mistral expand strategic partnership

Microsoft and Mistral have significantly expanded their partnership, including a multibillion-dollar deal for Microsoft to tap Mistral’s growing GPU capacity in Europe. Mistral’s Medium 3.5 and OCR 4 models are now in Microsoft Foundry, with Medium 3.5 also in Copilot Studio. The aim is to give enterprises and regulated industries frontier AI they can run across cloud, cloud-connected and fully disconnected environments while keeping control of their data.

https://news.microsoft.com/source/2026/07/21/microsoft-and-mistral-expand-strategic-partnership-to-give-enterprises-and-regulated-industries-frontier-ai-they-can-control/

Policy & Industry Perspective

Open Weights and American AI Leadership

In this Microsoft corporate-responsibility piece, Microsoft argues that America’s AI leadership depends on building a strong, open ecosystem rather than a single frontier model. It makes the case for open-weight models — which anyone can download, inspect, modify and run — as a way to widen access, boost competition, give customers control, and even improve security. The statement is co-signed by a long list of technology and AI companies, including Microsoft, NVIDIA, OpenAI, Meta, Google, Hugging Face and Mistral.

https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/

Industry News

How worried should we be about the AI that went rogue and launched a cyber-attack?

A BBC News video examining a reported case of an AI system being used to carry out a cyber-attack, and asking how concerned we should be about AI-driven security threats. Shared as a video in the AI team’s Models channel.

https://www.youtube.com/watch?v=M4kliMrqbB4

OpenAI Says Its Models Hacked Hugging Face by Mistake

A Bloomberg Television segment reporting that OpenAI said its models hacked Hugging Face “by mistake.” The clip covers the incident and what it suggests about AI safety and autonomous model behaviour.

https://www.youtube.com/watch?v=rN_7QlYg_b8

Chinese AI Model Raises Pressure on US Spending

A Bloomberg Television segment on a new Chinese AI model and how it is intensifying pressure on US AI investment and spending. It looks at the competitive dynamics between Chinese and US AI development.

https://www.youtube.com/watch?v=8v5T7Gk0_b8

Tools & Resources

How to create custom skills (Claude)

A Claude help-centre guide explaining how to create custom “skills” — reusable packages of instructions (and optionally scripts) that give Claude specialised knowledge for specific, repeatable tasks. It covers recording a skill by demonstrating a workflow on a Mac, the required skill.md structure, and packaging, testing and best practices.

https://support.claude.com/en/articles/12512198-how-to-create-custom-skills

The Agent Skills Directory (skills.sh)

Skills.sh is an open directory of reusable “skills” for AI agents that can be installed with a single command to add procedural knowledge. It lists and ranks community and official skills — from the likes of Anthropic, Vercel and Microsoft — across topics such as design, testing and agent workflows, and works with agents including Claude Code, Cursor and GitHub Copilot.

https://www.skills.sh/

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

SpaceX launches Starship on 13th flight test, booster splashes down – https://www.youtube.com/watch?v=2TF98WKebD4

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

One Edit Away From Digital Oblivion

image

There is a special kind of fear that only appears after you press save on a Markdown file and the entire publishing pipeline falls over.

Not a dramatic fear. Not screaming in the street. More the quiet, professional terror of staring at a screen thinking, “I only changed one line.”

That is the funny thing about modern work. We talk about transformation, automation and AI as if the future is floating gracefully above us. Then a missing bracket, a badly indented bullet, or one heroic colon in the wrong place reminds everyone that civilisation is still held together by plain text and hope.

The smallest change can have the loudest voice

I like Markdown. It is simple. It is readable. It keeps content close to the person writing it rather than burying it under layers of formatting gymnastics. A good Markdown file feels honest. What you see is almost what you get.

Almost.

Because one tiny edit can turn a neat document into a crime scene. A table stops rendering. A link eats the next paragraph. A heading becomes normal text. Suddenly the document that looked perfectly sensible in your editor appears in SharePoint like it has had a hard weekend.

This is where a lot of organisations get caught. They assume simple files mean simple risk. They do not. A Markdown file can be part of a blog, a knowledge base, a GitHub repository, an internal procedure, a training handout, or a client-facing instruction set. If that file drives a process, then the little typo is no longer little. It has been promoted.

Copilot is useful, but it is not a seatbelt for carelessness

This is also where Copilot changes the conversation in a useful way. I can paste a Markdown section into Copilot in Word or ask Copilot in Teams to review a draft before I send it around. I can ask it to spot broken structure, unclear steps, inconsistent headings, or a table that looks ready to start a small fire.

That does not remove responsibility. It just gives me another set of eyes before I publish something that makes future me question past me’s life choices.

The real benefit is not that Copilot makes the edit for me. The benefit is that it slows the moment down just enough for me to think. Is this still clear? Did I break the flow? Does the document still say what I intended? Have I just created a support ticket disguised as punctuation?

That last one matters.

Version history is cheaper than regret

The sensible answer is boring, which is usually how you know it works. Keep important files in SharePoint or OneDrive so version history is available. Use Teams to discuss changes where the people affected can see the conversation. If the document matters, do not treat it like a disposable note on the side of your monitor.

For MSPs and small businesses, this is not academic. Your documentation is part of your service delivery. A password reset process, onboarding checklist, security exception register, or client build guide can all live as ordinary files. If someone “just fixes a sentence” and breaks the meaning, the cost may not appear until someone follows the bad instruction perfectly.

That is how documentation gets dangerous. It does not need to be malicious. It just needs to be confidently wrong.

So yes, we may all be one edit away from Markdown oblivion. But we are also one review, one version history check, one Copilot pass, or one quick peer glance away from avoiding it.

The lesson is simple. Respect the little files. They know where the bodies are buried.

The Bystander Effect Is Quietly Killing Your Marketing

image

There’s a famous bit of psychology that explains why a person can collapse on a busy footpath and twenty people walk past. It’s called the bystander effect. When responsibility is spread across a crowd, everyone assumes someone else will step in — so nobody does. The more people present, the less likely any single one of them acts.

I’ve come to believe the same thing happens in marketing, and most of us never notice it. We think the problem is that people are rejecting us. Usually they’re not. They’re just standing in the crowd, assuming the message was meant for the person next to them.

“Everyone” Is Nobody

When you write an email, a newsletter, or a webinar invitation addressed to everyone, you’ve accidentally recreated that footpath. The reader scans it, decides — without much thought — that it’s aimed at some other, more relevant person, and moves on. They don’t unsubscribe. They don’t send an angry reply. They simply file you under “not for me” and get back to their day.

That quiet non-decision is far more dangerous than a flat “no”. A rejection at least tells you the message landed. The bystander never even picks up the phone. You walk away thinking the offer was weak, when really the offer was fine — it just never felt personal enough for anyone to claim it.

I see this constantly with MSPs marketing to small business. We send a generic “we can help with your IT” message to a list of three hundred contacts and wonder why two people reply. The content isn’t the issue. The aim is. Three hundred people each assumed we were really talking to one of the other 299.

First Aid Trainers Got There First

Anyone who’s done a first aid course has been taught the fix already. When you’re standing over someone who needs help, you don’t shout “somebody call an ambulance” to the crowd. You point at one specific person — “you, in the blue jacket, call triple zero now.” The instant that individual realises they’ve been singled out, they move.

That’s the whole game. The moment a person understands you are talking to them, the bystander effect collapses and action becomes possible. Marketing is no different. The job isn’t to reach more people — it’s to make each person feel seen.

Naming the Person, Not the Crowd

So how do you point at the blue jacket without writing three hundred individual emails? This is where I think the tools we already pay for earn their keep.

Most MSPs sit on a goldmine of context they never use. You know which clients are still on ageing hardware, which ones asked about security last quarter, which ones have a renewal coming. That detail is scattered across Outlook threads, meeting notes, and a CRM nobody opens. The work of pulling it together used to be the reason we defaulted to “Dear valued customer”. It isn’t anymore.

I’ll draft a campaign in Word and ask Copilot to rewrite the same core message for three distinct groups — manufacturers worried about downtime, professional services worried about compliance, retailers worried about card data. Three versions in the time it used to take to write one bland one. Each reader recognises their own world in the words, and the bystander reflex never gets a chance to kick in.

Copilot in Outlook does the same thing one conversation at a time. Before I reply to a prospect, I can have it summarise everything we’ve ever discussed and surface the one concern they keep raising. The reply then opens with their problem, in their language — not my service menu. That’s the digital version of pointing across the room and saying the person’s name.

Even your segmentation gets easier. I’ll drop a client export into Excel and let Copilot group accounts by industry, size, or last contact, so the list I’m writing to is genuinely a room of similar people rather than a faceless mob. The narrower the room, the easier it is to talk to everyone in it as if they were one person.

One “Yes, You” Away

The shift here is small but it changes everything. Stop trying to be relevant to a crowd. Be unmistakably relevant to one type of person, and let them know you mean them.

Your next client is probably already on your list. They’re not ignoring you out of disinterest — they’re waiting in the crowd, quietly assuming the invitation belongs to someone else. The work isn’t louder marketing or a bigger list. It’s removing the doubt about who you’re speaking to.

Point at the blue jacket. Use the context you already have, the tools you already pay for, and address the person directly. You might be one moment of genuine recognition away from the conversation you’ve been chasing all quarter.

When the Fix Stops Being a Fix: Troubleshooting in the Age of Probabilistic IT

image

For most of my working life, troubleshooting an SMB environment was a hunt for a single, knowable cause. Something was broken, and somewhere there was a reason. A permission was wrong. A DNS record pointed at the wrong place. A service had stopped. You worked the chain backwards, found the link that had failed, fixed it, and the problem went away. The same input produced the same output, every time. That was the quiet contract underneath everything we did. IT was deterministic, and our whole troubleshooting craft was built on that assumption.

That contract is now breaking, and AI is the reason. The more our clients lean on tools like Microsoft 365 Copilot, the more we find ourselves chasing problems that don’t have a single cause and don’t behave the same way twice. We’ve spent decades learning to solve deterministic problems. We’re now being asked to solve probabilistic ones, and most MSPs haven’t noticed the ground shift under their feet.

“It Worked Yesterday” Now Means Something Different

Here’s the scenario I keep running into. A client calls because Copilot gave them a wrong answer. It summarised a meeting and missed the one decision that mattered. Or it drafted a reply in Outlook that referenced a document the user swears they never mentioned. Yesterday it was brilliant. Today it’s confidently wrong. Nothing changed on your side. No update shipped. No setting moved.

Under the old model, “it worked yesterday and not today” was a clue. It told you something had changed, and you went looking for the change. With AI in the mix, that same sentence tells you almost nothing. Large language models are probabilistic by design. The same prompt can produce a different response on Tuesday than it did on Monday, and that’s not a bug you can ticket your way out of. It’s how the technology actually works.

So when a client reports that “Copilot is broken,” your first instinct — find what changed — quietly fails you. There may be nothing to find. The behaviour you’re chasing isn’t a fault in the wiring. It’s variance in the output. And variance doesn’t sit still long enough to be caught with the tools we’ve always used.

The Cause Isn’t Always in the System

The harder adjustment is accepting that the problem often isn’t technical at all. When Copilot returns a poor result, the cause is frequently the question, not the code. A vague prompt, missing context, the wrong document open in the background, permissions that quietly scope what Copilot can and can’t see — these shape the answer far more than any registry key ever did.

I had a client convinced Copilot in Teams couldn’t read their project files. The real issue was that the files lived in a SharePoint site the user didn’t have access to, so Copilot, correctly, never touched them. The system was working exactly as designed. The human’s mental model was the thing that was broken. There was no error in any log, because there was no error. Try writing that up in a standard ticket resolution.

This is the part that unsettles seasoned engineers. We are trained to distrust “user error” as a lazy diagnosis. But with AI, the boundary between the tool and the person using it has genuinely blurred. The quality of what Copilot produces is now a function of context, phrasing, data access, and the user’s own clarity of thought. Half of real-world “AI problems” are actually grounding problems — Copilot simply wasn’t given the right material to work with. You can’t fix that with a script. You fix it by teaching.

From Repair to Probability Management

So what does troubleshooting look like when certainty is gone? It looks less like repair and more like managing probability. Instead of asking “what’s broken,” you start asking “why is this likely happening, and how do we make the good outcome more likely next time.”

That changes the work in practical ways. You start checking what Copilot can actually see — the SharePoint and OneDrive permissions, the Purview sensitivity labels, the data the user assumes is in scope but isn’t. You look at how the question was asked, not just what the system returned. You reproduce the issue several times, because one bad answer is an anecdote, not a pattern. You document tendencies rather than root causes, because a tendency is often the most honest thing you can record.

It also changes what you sell. The deterministic world rewarded MSPs who could find and fix. The probabilistic world rewards MSPs who can guide, set expectations, and shape how AI gets used across a client’s day. The value moves from the repair to the relationship.

Sitting With Uncertainty

None of this means our old skills are worthless. Plenty of SMB problems are still gloriously deterministic — a licence didn’t assign, a mailbox didn’t migrate, a Conditional Access policy locked someone out. Find it, fix it, move on. That work isn’t going anywhere.

But a growing slice of what lands in your queue now has no clean answer, and pretending otherwise only frustrates everyone. The MSPs who’ll do well from here are the ones who can hold two modes at once — the precision of the engineer and the judgement of an advisor who’s comfortable saying “here’s what’s most likely, and here’s how we improve the odds.” Learning to sit with that uncertainty, rather than fight it, might be the most valuable troubleshooting skill of the next decade. I’m still getting used to it myself.

AI Governance Starts Before Copilot Does

image

Most AI conversations with business owners start in the wrong place. They ask whether Microsoft 365 Copilot is worth buying. I think the better question is whether the business is ready for what Copilot will reveal.

I have seen the same pattern often enough now. A client gets excited about Copilot in Outlook, Teams, Word and Excel. Someone wants meeting summaries. Someone else wants faster proposals. The owner wants staff to stop using random public AI tools with company data. All fair enough. But then we look underneath and find the real issue: years of loose permissions, old Teams, forgotten SharePoint sites, stale guests and no clear policy on what staff should or should not ask an AI system to do.

That is where AI governance starts.

Governance is not a document no one reads

A policy is useful, but only if it changes behaviour. If the policy says “use AI responsibly” and nothing else, it has failed before it starts.

For Copilot, I want plain rules. What data can be used? What data must not be used? When does a human need to review the answer? Who owns the final output? What happens if Copilot surfaces something the user did not expect to see?

That last question matters. Copilot does not need to break into your tenant to create a problem. If a user already has access to a file, Copilot may be able to use that file as part of an answer. The silent risk is not Copilot ignoring permissions. The risk is that the permissions were never cleaned up in the first place.

The technology follows the tenant

This is why I keep coming back to the Microsoft 365 basics. Entra ID, MFA, Conditional Access, SharePoint permissions, Teams lifecycle, Purview sensitivity labels and Data Loss Prevention are not side issues. They are the foundation.

If identity is weak, every AI answer sits on a weak account. If SharePoint is overshared, Copilot can make that oversharing easier to discover. If labels do not exist, users have no clear signal that a document is sensitive. If DLP is sitting in test mode forever, the business has a policy theatre problem, not a protection model.

I would rather see a small, controlled Copilot pilot in a tidy tenant than a broad deployment in a messy one. Start with a few users. Pick real scenarios. Meeting follow-ups in Teams. Draft replies in Outlook. Summaries from known SharePoint libraries. Then watch what happens. What worked? What surprised people? What data did Copilot find that no one expected?

Guardrails should be practical

The best guardrails are boring. That is a compliment.

Require MFA. Tighten external sharing. Review old guests. Publish simple sensitivity labels. Apply DLP where it matters. Use Restricted SharePoint Search where the content estate needs time to be cleaned up. Train users to verify answers before sending anything to a client. Make it normal to say, “Copilot drafted this, but I approved it.”

That is not anti-AI. That is responsible adoption.

The businesses that do this well will not be the ones with the flashiest prompts. They will be the ones that treat Copilot as part of their operating model. Policy, security, people and process all moving together.

My view is simple. Do not start with the licence. Start with the trust model. If you can trust the identity, the data, the permissions and the controls, then Copilot becomes much easier to use with confidence.

AI governance is not there to slow the business down. It is there so the business can move without pretending the risks are someone else’s problem.

When the Product Is the Answer

MAI_d2738865c0ceccd4

A few years ago, I paid real money for an online course about something I could have googled. Not because the information wasn’t out there — it was — but because someone had packaged it up into a tidy sequence, with a PDF checklist at the end. That felt like value. I’d trade some cash for the shortcut.

I’m not sure that trade still makes sense.

There’s a question worth sitting with if you sell courses, run a newsletter, or operate any kind of advice business: what exactly are you selling? If the core of your offer is “I know how to do X, and for a fee, I’ll explain it to you,” then you’re competing — right now, today — with a chat interface that will do the same thing for free, in plain language, at any hour, and answer every follow-up question without sighing.

That’s not pessimism. It’s just arithmetic.

The Commodity Shift

The thing is, knowledge transfer was already becoming cheaper. YouTube, forums, documentation sites — the raw material was free or nearly so long before any of us had heard of a large language model. What the structured course or the curated newsletter offered was organisation and trust. Someone had done the sorting for you.

AI has now taken that arrangement apart. Ask Copilot in Microsoft 365 how to build a pivot table, how to structure a client proposal, how to read a balance sheet, or how to write a meeting agenda — and you’ll get a clear, accurate, step-by-step answer in seconds. It knows context. It remembers what you asked two prompts ago. It adjusts when you say “that’s too complicated, simplify it.” The experience of learning from it is genuinely conversational in a way that a pre-recorded video module is not.

For anyone whose business rests primarily on the instruction layer — here’s how to do the thing — that shift deserves honest attention.

What Doesn’t Commoditise

I don’t think this means the advice economy is finished. But I do think it clarifies what was always the actual product, beneath the packaging.

What an AI won’t give you is accountability. It won’t check whether you actually implemented what it told you, or notice that you’ve been stuck on step three for six weeks because there’s something uncomfortable underneath the technical question. A good advisor, coach, or community does that.

It also won’t give you judgement built from real exposure to your specific industry, your clients, your context. I can ask Copilot about pricing strategy for an MSP, and I’ll get a reasonable answer. But the answer from someone who has personally renegotiated forty MSP contracts and remembers what went wrong — that carries a different weight.

The value proposition that survives isn’t “I’ll explain the concept.” It’s “I’ve seen this pattern before, here’s what it usually means, and here’s what I’d actually do.” That’s the part that takes years to earn and can’t be scraped.

What I’m Watching

My own approach has shifted. The things I now put into writing — whether that’s a post, a session, or anything structured — I try to hold to a higher bar than “here’s how to do X.” Anyone can get that from Copilot. What I’m aiming for is the observation behind the explanation: the why, the tradeoff, the thing that only becomes clear once you’ve been surprised by the edge case.

The knowledge economy isn’t dying. It’s just shedding the parts that were never really the point.

Stop Hoping Your Team Will “Figure Out Copilot”

mastery-cover

Microsoft 365 Copilot is one of the most powerful productivity tools Microsoft has ever released. Yet many organisations are still struggling to get consistent value from it.

Why?

Because giving people access to Copilot is not the same as teaching them how to use it effectively.

The reality is that most users start with enthusiasm, ask a few basic prompts, get mixed results, and then drift back to their old ways of working. The opportunity remains, but the outcomes never arrive.

That’s exactly why I created the Microsoft 365 Copilot Team Training Guide.


Moving Beyond Random Prompting

Successful Copilot users don’t rely on luck.

They understand:

  • How to structure prompts

  • Which Copilot tool to use for specific tasks

  • How to refine outputs

  • How to work with Copilot rather than simply ask questions

  • How to safely use AI within a business environment

This guide provides practical, repeatable approaches that teams can use every day rather than theoretical discussions about AI.

What’s Included?

The guide covers:

  • Microsoft Word

  • Outlook

  • Teams

  • PowerPoint

  • Excel

  • Copilot Chat

You’ll also learn practical prompting techniques, prompt frameworks, governance considerations, adoption strategies, and ways to measure success across your organisation.

Unlike many AI resources that focus on concepts, every principle is designed to be immediately applied with examples, expected outcomes, tips, and common mistakes to avoid.

Designed For Real Teams

Whether you’re:

  • A business owner investing in Copilot licences

  • An IT manager responsible for adoption

  • A team leader looking to improve productivity

  • An MSP helping clients get value from Copilot

  • A user wanting to work smarter

This guide provides a structured path to getting measurable results from Microsoft 365 Copilot.

Copilot Success Requires More Than a Licence

The organisations seeing the biggest productivity gains are not necessarily those with the most licences.

They’re the organisations that invest in education, consistency, and repeatable ways of working.

The good news is that learning how to use Copilot effectively doesn’t need to be complicated. With the right guidance, your team can quickly move from experimentation to real business outcomes.

Ready to Become a Copilot Champion?

If you want a practical, no-nonsense guide that helps your team use Microsoft 365 Copilot more effectively, then the Microsoft 365 Copilot Team Training Guide is for you.

Get your copy here: Microsoft 365 Copilot Team Training Guide

Stop experimenting. Start mastering Copilot.

Your organisation has already invested in AI. Now it’s time to make sure everyone knows how to use it.

CIA Brief 20260718

image

CIA Brief – Weekly News Digest

Here’s a quick roundup of the Microsoft, security and AI news worth tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.

Security
Microsoft 365 & Windows
Cloud & AI

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

I Only Made $50 Training Robots – https://www.youtube.com/watch?v=yfZhpEupz5M

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week