The Governed Path Is a Licensed Path
The case for governing the route to AI models is correct. This is its contractual cost, what can switch off the control plane, and what its own evidence proves.
Tags: Microsoft, Agent 365, Copilot, AI Governance, Software Licensing, Licensing Assurance
The security case for governing the route instead of the model is correct. This is the invoice attached to it: what the control plane costs, what can switch it off, and what its own evidence proves to somebody other than you.
In reply to
“How Microsoft Can Govern Claude, ChatGPT, Gemini, and Every Other AI Model”
· Quinton Barber · LinkedIn · 2026-08-12 ✓ canonical link verified 2026-08-20
From Deep Sight Consulting · independent consulting on software, services and AI licensing in the era of agentic AI
programming
Marks · ✓ verified against a primary source or contractual instrument · ◐ reported or self-reported · ◯ open, no
verifiable source
| Indicator | Reading |
|---|---|
| $15 | Agent 365, per human person per month, not per agent ✓ |
| E5 | prerequisite for new standalone Agent 365 since June 1, 2026 ✓ |
| Jul 1 | agent security capabilities deactivated without an eligible license from 2026 ✓ |
| 125% | of prepaid credit capacity: custom agents disabled, hard stop ✓ |
| 5 | credits per agent action, at $0.01 per credit ✓ |
| 1 year | term on both prepurchase plans, no cancellation, no exchange ✓ |
| 4 | benefits in a published precedence order; the broadest is consumed last ✓ |
In short
What does it cost to govern the path to AI models, and who can switch it off? The article this replies to argues that the enterprise does not need to govern every model, only the route to them, and it is right as security architecture. What it does not say is that the route is a purchase: it requires a license underneath it, it arrives with a meter already running, and it leaves a switch on the vendor’s side. That switch is contracted; it is not engineered.
01 — The agreement
Two disciplines, no contact between them, one border
The article’s thesis
The enterprise does not need to govern every model. It needs to govern the path to the model, because identity, device posture, data classification, policy evaluation and evidence all actually live on that path.
It is right, and that deserves saying without hedging: the licensing side reached the same border from the opposite direction, without the security vocabulary.
On July 1, 2026, alongside the announced pricing reset, Microsoft moved agentic enforcement from the invoice to the capacity. The Copilot Studio and Microsoft Foundry security capabilities that lived in Defender for Cloud were deactivated for tenants without an eligible Agent 365 license, and Copilot Cowork tenants without credit billing configured had access suspended the same day ✓. The verbatim line in Microsoft Learn says nothing about billing:
“Tenants currently configured to Block on existing Agent 365 rules will stop blocking on July 1, 2026.”
Microsoft Learn ✓ re-verified 2026-08-14
A security architect reads that ground and concludes the path must be governed. A licensing analyst reads it and concludes the path is now where contract enforcement lives. What follows is not a rebuttal: it is the part that belongs to a different contract.
02 — Price
The control plane is a licensed product with a prerequisite
“Standardize on a single control plane” is a purchasing decision before it is an architecture, and it has published numbers.
- Agent 365 costs $15 per user per month, and covers agent governance and security: registry, Entra Agent ID, compliance, observability ✓. What it does not cover is building and running the agent, which bills separately through Copilot Studio and Microsoft Foundry consumption ✓.
- The metric is per human person, not per agent: that $15 covers governance of every agent that person operates, administers or sponsors ✓.
- Microsoft 365 E5 became a prerequisite on June 1, 2026 for new standalone Agent 365 purchases in the enterprise segment ✓.
Entra Agent ID carries the identity half of the argument, and it arrives inside that chain. Priced honestly, the recommendation reads: an E5 base plus $15 per person per month, before governing a single third-party model and before measuring a single unit of consumption. In most 2026 budgets that line does not exist yet, because the work was planned as security architecture and not as licensing.
03 — Enforcement
The governed path has an off switch, and the licensor holds it
Two published mechanisms make the availability of these controls depend on licensing state rather than on engineering: the July 1 access lock already described, and the deactivation of custom agents at 125% of prepaid Copilot credit capacity, with a grace band up to 125% and a hard stop from there until capacity is bought or reallocated ✓.
The twin question
An enforcement point that is itself a licensed capability is an enforcement point with a single contractual point of failure. The board that is learning to ask “can we prove our controls operated when they should have?” needs the twin question taught in the same session: what happens to the controls at 126% of prepaid capacity, or on the first day of a lapsed entitlement? This is not hypothetical: it is documented product behaviour, with a date.
04 — Entitlement
A gateway concentrates evidence, not entitlement
The article’s second scenario
An API gateway brokers the approved paths to the model: it authenticates, authorizes, applies policy, evaluates prompts before execution, monitors token consumption and retains the evidence trail.
This is the correction that matters most, and the one that costs money when it is missed. Microsoft’s multiplexing definition is reprinted verbatim in Appendix A of the Copilot Studio Licensing Guide, inside the agent licensing guide itself—the June 16, 2026 and August 2026 editions were verified identical—and anchored to the primary guidance page captured on August 16, 2026 ✓:
“Multiplexing refers to hardware or software that a customer uses to: pool connections or reduce the number of Operating System Environments (OSEs), devices, or users a Product directly manages; reduce the number of devices or users that directly or indirectly access or use a Product; or access data a Product itself processes or generates. Multiplexing does not reduce the number of Licenses of any type that a Customer needs.”
Microsoft Licensing Guidance ✓ captured 2026-08-16
An API brokerage layer that pools every user’s request behind a single authenticated, policy-evaluated path is the first clause of that definition, stated as architecture. Three consequences follow, and the precision is the whole value.
- Scope. The gateway does not create Microsoft licensing exposure through a third-party model’s own consumption. Anthropic licenses Claude; Microsoft’s Product Terms count Microsoft products. Exposure falls on the Microsoft-licensed products the path traverses and reads in order to produce a useful answer. The worked examples in the guide itself are SQL Server, Project Server and Azure DevOps Server CALs, with the material nuance that per-core licensing removes the CAL requirement ✓.
- What was bought. The brokered path buys provability. It does not buy license reduction. The two get confused because a diagram that collapses two thousand users into one arrow looks like consolidation on the page. Under the licensor’s own sentence, it is not.
- What has to be planned. The telemetry that proves the controls operated is the same telemetry that documents the indirect-beneficiary population behind that arrow. The board’s question and the auditor’s question are answered by one artifact: the operator sees an agent, the auditor sees everyone behind it ✓.
Epistemic status of this section
[synthesis], resting on ◯. What is missing is not the logic, which is the primary text read plainly, but a published application of that language to an AI brokerage layer, or a documented audit where such telemetry served as proof of indirect access. It is cited as a reading of Microsoft’s text, never as Microsoft’s position. None of this argues against building the gateway: it argues against buying it as a licensing optimization, and in favour of doing the entitlement arithmetic before the diagram convinces a committee that consolidation happened.
05 — The meter
The token blind spot already has a meter, and it comes with the path
The article names token consumption as a governance blind spot. On the Microsoft path it is not blind: it is metered, and adopting the governed path means adopting the meter. Copilot credits, official rate table ✓: classic response 1, generative response 2, agent action 5, grounding on the tenant graph 10, voice at 10, 35 and 75 per minute for premium generative voice. Credit price $0.01 pay-as-you-go; a 25,000-credit pack at $200 per month, no rollover; the hard stop at 125% already described. Separately, the 5,000 seeded AI Builder credits retire on November 1, 2026 ✓.
Visibility is the gain. Measurement is the price. And the meter scales with the architecture, not with headcount: a single approved prompt that triggers a chain of agent actions and grounded retrievals bills against a rate card whose unit is the action, while the seat count sits still. Any consumption forecast built from number of users is measuring the wrong variable.
Operational warning
The Microsoft 365 admin center shows only the credits from the Copilot credit prepurchase plan, and if the subscription also carries the agent plan, “the system uses the Agent P3 credits first” ✓. What the dashboard does not show is precisely what gets consumed first, silently. Anyone measuring adoption against that dashboard is reading the wrong balance.
06 — Open terms
Four things to get in writing while nobody has published the answer
The article’s subject is governing third-party models. On that exact question the record is open ◯, and open questions are negotiated until they stop being open.
- Registration scope for non-Microsoft agents. Whether Agent 365 governance reaches agents running on foreign stacks, and whether such an agent must register an Entra Agent ID to function inside the ecosystem, is not resolved in the available sources. It is the premise of the whole architecture, and the first clause to ask for.
- The commitment instruments exist; the rate card does not. Rewritten in edition 2: edition 1 said variable cost could not be modelled from published terms, and that no longer holds. Two prepurchase instruments are published, described below. What remains open is narrower and more useful: unit cost beyond the base allocations is still unpublished, and the instruments buy discount, not a ceiling; whether buying a plan counts toward an Azure consumption commitment is stated on no published page; and what happens to the 125% hard stop when live prepaid units exist.
- Liability and service levels for autonomous agent errors.
- Forward pricing for an identity class that does not exist yet. There is no “Agentic Users” category in general availability. Microsoft confirmed those identities will require their own license and published no price, no metric and no date.
Each one is a gap today and a term-sheet point tomorrow. The negotiating room closes the day the official terms are published, not the day the organization remembers to ask.
07 — Concentration
The sentence the article does not write
There is a structural cost to concentrating every prompt, every policy decision, every trace and every correction in a single control plane, and it is not a security cost.
Satya Nadella’s own essay locates the transfer of enterprise knowledge not in model training but in what he names exhaust: prompts, agent tool use and, above all, human corrections, “trace by trace, correction by correction, eval by eval” ✓. His first stated principle is Control: private evals, ownership of memory, traces and outputs. Read economically, a brokered path that retains prompts, decisions and telemetry inside the tenant is the enterprise keeping its own exhaust, which makes this architecture a stronger idea than its security framing claims.
But his third principle is Choice: orchestration decoupled from any single model ✓. A control plane sold by a vendor that also sells models concentrates the record of how the organization thinks in one counterparty. It is governance gain and counterparty concentration at the same time, and the two do not cancel out.
The practical shape of the objection
It is not “don’t standardize.” It is: make the evidence portable. Retention format, export rights, and the ability to run the same policy through a different intermediary go into the contract, at the same moment the architecture is approved and for the same reason it is approved.
A structural note, about the category and not about any author: when the party recommending a control plane is also the party implementing it, the recommendation and the commercial interest point the same way. This corpus carries a verified case in the adjacent market, where assessments offered at no cost by the implementation channel function as pre-audits with an upsell incentive ✓. That is reason to read the licensing terms independently. It is not reason to dismiss the architecture, which is sound.
08 — Purchase construct
The purchase construct sets the price before the discount does
Everything above prices the governed path in two units: the seat and the credit. A third is missing, and it is the one that decides the invoice. For the same capability, Microsoft sells more than one purchase construct, and they do not cost the same.
There are two prepurchase instruments, and they are not the same ✓
The Microsoft Agent Prepurchase Plan covers consumption of Microsoft Foundry, Copilot Studio, Microsoft Fabric and GitHub. It is bought in Agent Commit Units, and one ACU equals one dollar and one hundred credits. Its written scope is the “Copilot Credits-enabled agentic services: Microsoft Copilot Studio, Dynamics 365 first-party agents, and Copilot”, and Microsoft reserves the right to update which products are eligible.
The Copilot Credit Pre-Purchase Plan covers Copilot credit consumption only, and is bought in its own unit.
That Fabric and GitHub enter through the same instrument is not an administrative detail. It is confirmation, on the purchasing paper itself, that the agentic licensing question can no longer be separated from the data layer or the development layer.
The two discount curves do not match, and that is the lever ◐
The tiers rise with committed volume, and they do not rise the same way in the two plans. At the same committed amount, around one hundred thousand dollars, the agent plan yields on the order of 10% and the credit plan on the order of 7%. The lever is not asking for a discount: it is choosing the construct, and that comparison is almost never run because almost nobody publishes it.
What is verified, and what is not
This is the most quotable figure in the section and the easiest to overstate, so precision is warranted. That both instruments exist, that they are bought in different units, and that their curves differ is ✓. The specific tiers and the delta at a point are ◐: they come from the private corpus, and of the ladder only two rungs are corroborated against public documentation, which further publishes the full table only as a portal screenshot, not as text, with percentages drawn from examples it marks as hypothetical itself. There is no citable Microsoft rate card. Before putting a number in a recommendation, redo it against the portal, with a date.
The purchase terms are harder than the consumption terms ✓
“All purchases are final.”
Microsoft Learn · Agent Prepurchase Plan and Copilot Credit P3 · read 2026-08-19
Both plans run one year, with auto-renewal on by default. They cannot be split or merged, and they allow no cancellation and no exchange. The purchase bills as a separate line. Read alongside the eligibility reservation cited above: one party commits for twelve months with no exit, and the other reserves the right to change which products that commitment covers. That asymmetry is a term-sheet point, not a fact of nature, and it gets negotiated before signature or it never gets negotiated.
The precedence order is already written, and it is not negotiable ✓
“Reservations always apply before prepurchase plans.”
Microsoft Learn · Agent Prepurchase Plan · upd. 2026-07-17
In Azure: Foundry PTU reservation, then Fabric capacity reservation, then the credit plan, and the agent plan last. In the Microsoft 365 admin center the order is capacity packs, prepurchase and pay-as-you-go, and prepurchase is not an alternative route: “P3 is layered on top of pay-as-you-go.” The practical consequence is that the broadest instrument is consumed last, meaning a badly built portfolio leaves the most expensive discount unused and burns the cheapest first. The modelling is done in layers, in that order, or it is not worth doing.
Three things that only appear in the fine print, and all three bite in operation ✓
- The dashboard does not show what gets spent first. Already described under the meter.
- A spending policy’s billing method is immutable. Once the policy is created, changing it means deleting and recreating it. An allocation decision made quickly at kickoff becomes a migration.
- Capacity is contended across boundaries. Capacity assigned to environments from the Power Platform admin center reduces what is available to Cowork and the Work IQ API. Two teams that never speak share one balance without seeing it, and whoever allocates first takes it.
And the Azure commitment already signed ✓ ◯
Eligible Copilot consumption does apply against an Azure consumption commitment, but only if the subscription is tied to the billing account that holds the commitment. With a different one, in the documentation’s own words, “you still pay for consumption, but it might not count toward your MACC”. It is a configuration step with a contractual consequence, and it gets verified before enabling the service, not after.
What should not be said yet
Whether buying the plan counts against that commitment is not resolved ◯. What is published says the purchase bills as a separate line and is not drawn from the Azure Prepayment, which is a different construct from the MACC. Until that is clarified in writing, a prepurchase plan should not be sold as a way to burn a MACC. It is exactly the kind of claim that sounds good in a meeting and does not survive the invoice.
09 — Close
Intake first, then the board
This section’s order changed in edition 2. The earlier version opened with the board question. A review against channel field practice made clear that the question arrives too late: before answering it you have to know what is being discussed and under which paper it is bought.
- Which Copilot? It is not one product, it is several with the same name. Microsoft 365 Copilot, GitHub Copilot, Copilot Studio and the Dynamics first-party copilots share no meter, no license prerequisite and no prepurchase instrument. All the arithmetic in this text belongs to one of those routes, not to all of them. Answering “Copilot” is not an answer.
- What purchase construct do you hold with Microsoft, and did you compare the two plans at the amount you intend to commit? Together with the question that always accompanies it: what is licensed today, with Microsoft and with other publishers.
Neither is answered by a formula. They are answered case by case, and there is no single correct way to assemble the package.
The board question, widened
“Can we prove our AI controls operated when they should have?” is the right question and it is incomplete. The complete version has four parts, and the last three are contractual.
- Can we prove the controls operated? Evidence, retention, later reconstruction.
- What entitlement keeps them operating, and what is the documented behaviour when it lapses or when prepaid capacity is exceeded?
- What does the evidence we are generating prove to somebody who is not us? Specifically: to a licensor that counts indirect access to the products sitting behind the path.
- Can the evidence leave? Format, export rights, and whether the same policy can be applied through a different intermediary.
Governance becomes real when intent is translated into technical controls that produce evidence. That is the original article’s closing claim and it holds. What gets added is that those controls are contracted, that the evidence they produce is legible to more than one party, and that both are decided at signature and not during the incident. And that the paper they are bought under moves the price before the negotiation begins.
Source register
What each claim rests on
| Key | Source | Class |
|---|---|---|
| Barber 08-12 | “How Microsoft Can Govern Claude, ChatGPT, Gemini, and Every Other AI Model”, Quinton Barber, LinkedIn Pulse, 2026-08-12. Published on LinkedIn only. | ✓ authorship, title and date checked against the canonical link on 2026-08-20 |
| 07-24 | Licensing policy verification 2026-07-24: Agent 365 scope and metric, E5 prerequisite, the July 1 lock, Cowork GA, AI Builder retirement. | ✓ |
| 08-14 | 3x Paradox verification 2026-08-14, re-verified live against Microsoft Learn: Foundry naming, credit table, the 125% stop, the Defender for Cloud Apps nuance. | ✓ |
| Multiplexing | Microsoft Licensing Guidance, captured 2026-08-16, and Copilot Studio Licensing Guide Appendix A, the 2026-06-16 and 2026-08 editions verified identical. | ✓ |
| Nadella 07-12 | Essay “Reverse Information Paradox”, post on X 2026-07-12, first-hand verbatim in the corpus. | ✓ |
| Channel SAM | Conflict of interest in the channel’s free assessment; the figures are the sources’ own. | ✓ pattern · ◐ figures |
| § Entitlement | Gateway as a multiplexing pattern, formed 2026-08-18; no source asserts it. | [synthesis] ◯ |
| Agent P3 08-19 | Microsoft Agent Prepurchase Plan, updated 2026-07-17, read 2026-08-19: coverage, unit, term, purchase finality, precedence, invoice line. | ✓ |
| Copilot Credit P3 08-19 | Copilot Credit Pre-Purchase Plan, updated 2026-07-17, read 2026-08-19. | ✓ |
| Usage-based billing 08-19 | Manage Copilot credits, updated 2026-08-18, read 2026-08-19: M365 precedence, balance visibility, billing-method immutability, Power Platform contention, MACC. | ✓ |
| Ladders | Private corpus 2026-07-26, three vault files. Two rungs corroborated against public documentation; the rest of the curves and the delta at $100,000, not. | ◐ |
| Peer review 08-19 | Review against Microsoft channel field practice in LATAM. Source anonymous by the operator’s decision; it contributed search direction, not evidence. | ◐ |
The figures and terms cited come from a licensing corpus with per-claim traceability. This is commercial and contractual analysis, not legal advice. Where this text differs from the original article it differs in scope, not in accuracy: nothing in the source was contradicted by the verified record.
A live piece: this is edition 3. Whatever the earlier editions stated differently has been corrected inside the text itself, at the point where each correction applies, and it is said there with its mark ✓. No separate changelog is kept: a correction you have to go and look for somewhere else is not corrected.
Deep Sight Consulting · Calado class · edition 3 · 2026-08-20 · ver profundo · deepsightconsulting.com