All episodes

AI & Tech Daily

Enterprise AI Has Scale. Now Comes the Hard Part

11:11

Microsoft’s latest results show enterprise AI demand operating at cloud scale, although paid seats still reveal little about actual use or customer returns. Frontier-lab employees want governments to prepare an international pacing mechanism, while US security controls expand into robots and power infrastructure. Also covered: China’s reported domestic lithography push, the Origin Energy breach, an AI-assisted zero-click Zimbra campaign, AWS service closures and the full retirement of GitHub Models.

Full transcript

Read the episode.

I'm Jesse Owen. This is AI and Tech Daily.

Microsoft’s AI Scale Test

Microsoft’s enterprise AI machine is now measured in tens of millions of paid seats. What it still can’t show is whether customers are getting their money’s worth.

This is the development worth sitting with, because Microsoft’s results put real scale behind the enterprise AI story. For its fiscal fourth quarter, reported on July 29, Microsoft recorded revenue of 90 billion US dollars. Azure and other cloud-services revenue rose 43 per cent year on year, while total Microsoft Cloud revenue reached 59.3 billion dollars, up 27 per cent.

The company also said annual Azure revenue had passed 100 billion dollars for the first time, and Microsoft 365 Copilot had exceeded 30 million paid seats. Those are company-reported figures, but they’re substantial evidence that organisations are buying AI through the cloud and productivity contracts they already use. This has moved well beyond a collection of small pilots.

There’s still a critical blank in the results. A paid Copilot seat doesn’t tell us whether somebody uses it regularly, whether it improves their work, or whether the improvement justifies the licence and integration costs. Microsoft didn’t disclose usage intensity or customer-level returns.

For organisations, my read is that buying enterprise AI is becoming easier while evaluating it properly is becoming more important. Microsoft has proved distribution and demand. Customers now need to prove value—and account for the deeper dependence that comes from concentrating cloud, productivity software and AI with the same platform provider.

A Call to Pace Frontier AI

That gap between scale and control takes us inside the frontier labs, where employees are asking governments to prepare before AI research accelerates further.

A cross-company statement launched on July 28 with more than 1,100 verified employees from frontier-AI companies. Its live count had reached 1,273 when checked, including senior figures associated with OpenAI, Anthropic, Google DeepMind and Meta AI.

The statement asks the US government to support an international effort to develop technical and governance tools for deliberately pacing automated frontier-AI development. The concern is that systems capable of automating AI research could accelerate capability gains faster than institutions can understand or control them.

This isn’t an agreed pause, a binding rule or even a specified enforcement system. It’s a request to build a coordination option, and personal comments from signatories don’t necessarily represent their employers.

The constructive part is that people inside competing laboratories are publicly naming a genuine collective-action problem before a crisis forces the issue. The weakness is just as important: there’s no implementation path, timetable, shared threshold or verification model. Until governments and companies work through those details—and secure meaningful international participation—the appeal creates pressure, but no operational brake.

Security Rules Reach Robots and Power

The security perimeter is also expanding beyond models and chips, into the machines and electrical systems that make automation possible.

On July 28, the US Federal Communications Commission added categories of foreign-produced advanced mobile robots and connected power inverters to its Covered List on national-security grounds. The robot category includes humanoid and quadruped systems. The inverter category reaches equipment used in renewable-energy installations, data centres and other connected infrastructure.

The immediate effect is an authorisation barrier for new equipment and models entering the US market. It doesn’t order people to stop using previously authorised devices, and the FCC can consider conditional approvals. So this isn’t a blanket prohibition on every foreign component or every robot already operating in the country.

Even with those limits, the scope is notable. Security policy is moving into embodied AI and the power-management layer beneath digital infrastructure. Manufacturers and importers will need to treat equipment authorisation and country of origin as product-design concerns, while infrastructure operators may face a narrower choice of new hardware.

How restrictive this becomes will depend on the FCC’s country-of-origin tests, its use of conditional approvals and the way future products are classified. For now, the sensible conclusion is that physical automation and connected energy equipment are becoming part of the same security contest already reshaping semiconductors and communications networks.

China’s Reported Lithography Step

There’s a related hardware story from China, although this one needs a particularly firm grip on the caveats.

Reuters reported on July 27, citing The Information and unnamed sources, that China had begun manufacturing a domestically developed immersion deep-ultraviolet lithography system. Initial deliveries to Chinese chipmakers are reportedly expected this year, with potential recipients including SMIC, Hua Hong Semiconductor and memory producer CXMT.

The unnamed manufacturer is said to expect production of roughly five machines in 2026 and about 20 in 2027. That would be a meaningful domestic step, but the reported tools remain behind established systems in performance and reliability. They also have to pass qualification inside fabs before they can support mass production.

China still can’t import the more advanced extreme-ultraviolet systems used for leading-edge chipmaking. And this report doesn’t demonstrate that the new machine matches an ASML production tool: the manufacturer hasn’t been named, the underlying sources are unidentified, ASML declined to comment, and independent performance data isn’t available.

For semiconductor planners, the useful signals will come later—fab qualification, production yields, reliability and continued dependence on foreign components. The reported start of manufacturing suggests incremental progress towards reducing import dependence. It doesn’t establish semiconductor self-sufficiency.

Origin’s 900,000-Record Breach

Back in Australia, the risk is much more immediate and personal.

Origin Energy said its initial review found that information belonging to approximately 900,000 current and former customers had been accessed in a data-security incident. Potentially affected fields include names, addresses, dates of birth, phone numbers and account information.

Some records also contained the last four digits of a credit card or the last three digits of a bank account. Origin says those fragments can’t, by themselves, be used to make purchases or access an account. That’s reassuring in a narrow sense, but it doesn’t remove the larger risk created by combining accurate identity, contact and account details.

Origin is notifying affected customers and offering identity and cyber-support services. Its investigation remains active, and the company hasn’t publicly detailed the exact combination of information exposed for each person or the complete intrusion path.

For affected customers, the most credible danger is convincing impersonation rather than someone spending directly with a partial card number. A scammer who knows your address, provider and account details can make a fraudulent call, message or email sound legitimate. That makes unexpected contact claiming to be from Origin—or from a bank or support service in response to the breach—more difficult to judge and potentially more effective.

Zero-Click Attacks on Zimbra

A separate cyber campaign shows why user caution can’t compensate for vulnerable server software.

Cybersecurity agencies from 15 countries, including Australia, disclosed a Russian state-supported campaign targeting vulnerable Zimbra Collaboration Suite installations. The campaign has operated against Western government and commercial organisations since at least July 2025 and is attributed to the group commonly called Laundry Bear.

The attack uses malicious emails, but it doesn’t depend on somebody clicking a link or opening an attachment. On a vulnerable Zimbra webmail installation, simply viewing a crafted message can be enough to trigger exploitation. That’s the important meaning of zero-click here: phishing awareness alone can’t close the opening.

The joint advisory says technical analysis indicates AI assisted development of a relatively simple codebase. It doesn’t claim AI created the underlying vulnerability or transformed the campaign into something unprecedented, and it doesn’t quantify how much of the tooling was AI-generated.

For organisations running Zimbra, the priority is therefore conventional but urgent: apply current patches and inspect systems and network activity for the advisory’s indicators. AI may have lowered the attacker’s implementation effort. The decisive weakness was still unpatched, internet-facing software.

What Changes for You

For developers, two hosted AI doors close today, and both are a useful warning about provider lifecycle risk.

From July 30, AWS no longer accepts new customers for a collection of AI and cloud offerings. The group includes Bedrock Agents Classic, Amazon Q Business, Amazon Kendra, and SageMaker AI features including Clarify, Ground Truth, Model Monitor and Studio Lab. Existing customers retain access and AWS says it will continue operating and supporting the services.

That means new projects must choose other services now. Existing deployments can keep running, but they’ve entered a maintenance path that belongs in migration and architecture planning. AWS hasn’t provided one universal shutdown date or a one-for-one replacement for every product, which leaves teams with some uncertainty about how long each transition will last.

GitHub Models has gone further. Its July 30 retirement ends access for every customer, including active users, across the playground, model catalogue, inference API and bring-your-own-key endpoints. Applications, tests and internal workflows calling that inference API now need another model-access provider.

GitHub points users towards Microsoft Foundry for model access and GitHub Copilot for GitHub workflows, but those aren’t promised as equivalent replacements. Pricing, authentication and platform dependence can all change in the move. For builders, the practical lesson is to keep a portable provider boundary around hosted inference wherever the extra engineering is justified; a convenient prototyping surface can disappear while the code depending on it remains.

You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.

Sources

Reporting behind this episode.

  1. microsoft.com/en-us/Investor/earnings/FY-2026-Q4/press-release-webcast
  2. pacingthefrontier.com
  3. axios.com/2026/07/29/anthropic-claude-open-models-ban-china
  4. fcc.gov/document/fcc-adds-foreign-produced-power-inverters-and-robots-covered-list-0
  5. apnews.com/article/china-us-humanoid-robots-ban-tech-c9f5e3c94d91d00eff3b61b141fab366
  6. investing.com/news/stock-market-news/china-begins-making-homegrown-duv-chipmaking-tools-the-information-reports-4814529
  7. theguardian.com/australia-news/2026/jul/28/about-900000-origin-energy-customers-affected-by-hack-as-company-admits-it-was-warned-weeks-before-public-told
  8. originenergy.com.au/about/investors-media/update-on-data-security-incident
  9. ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign
  10. media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
  11. aws.amazon.com/about-aws/whats-new/2026/06/aws-service-availability
  12. github.blog/changelog/2026-07-01-github-models-is-being-fully-retired-on-july-30-2026