Microsoft Build ran on June 2 and 3, 2026 in San Francisco, and the through-line across the keynotes was unusually consistent. Where the previous two years framed AI as an assistant that responds to a person, this year framed it as an agent that executes work across systems. The distinction is not marketing. It changes what has to be governed, what has to be licensed, and what has to be architected.
What was announced
Microsoft IQ was introduced as an intelligence layer intended to give AI better context, combining organizational data, web content and business systems so that Copilot responses reflect how a specific company actually works rather than generic knowledge. This is the layer that determines whether an agent's output is useful or merely fluent, and it makes the quality of your underlying data estate the primary determinant of AI value — a point we have made repeatedly and that the platform is now enforcing structurally.
The MAI model family is Microsoft's own set of proprietary models spanning reasoning, coding, voice, transcription and image generation. Strategically this reduces Microsoft's exposure to a single external model provider and gives customers first-party options inside the stack they already license.
Project Solara was presented as a platform architected for agent-first computing, where agents rather than applications become the primary way work moves through systems. Microsoft characterised it as early-stage, and it should be read as a direction of travel rather than something to plan a 2026 project around.
New AI security controls covered protected execution environments and data governance frameworks for agent deployment. This was the most immediately practical announcement of the event, because it acknowledges the problem every organization running agents has already discovered: an agent with credentials is an identity, and identities need boundaries.
What actually changes for a mid-market IT function
Three things, none of which require waiting for Project Solara.
The first is identity. An autonomous agent that reads mail, updates records and calls APIs needs a principal, permissions and an audit trail. Organizations that have not resolved their service account and workload identity position — and most have not — will find that agent deployment surfaces that debt immediately and at scale. The identity work described in our earlier coverage of workload identity migration is the prerequisite for agents, not a parallel project.
The second is data readiness. Microsoft IQ's value depends on what it can see, which means oversharing in SharePoint and Teams becomes an AI problem rather than merely a governance one. A site with broken permission inheritance was a latent risk when only its members could find it; it is an active risk when an agent with a user's context can surface it in a chat response. Sensitivity labelling, site access reviews and removal of organization-wide sharing links are the unglamorous work that determines whether an AI deployment is safe.
The third is cost architecture. Microsoft's agent economics are moving toward consumption rather than per-seat subscription, with Copilot Credits emerging as the unit of account across Copilot Cowork, Work IQ and Copilot Studio. Consumption pricing without governance produces surprises. Budgets, alerts and ownership of the pay-as-you-go billing configuration need to exist before the first agent reaches production, not after the first invoice.
The honest assessment
Very little of what was announced at Build 2026 is production-ready for a mid-market organization this quarter. Project Solara is early. The MAI models will take time to prove out against the workloads customers actually run. Microsoft IQ's practical value is unproven outside Microsoft's own demonstrations.
What is real is the direction, and the direction has prerequisites that take longer to build than the platform will take to arrive. Identity hygiene, data governance and consumption cost control are all six-to-twelve-month programmes in a typical estate. Organizations that start them now will be able to adopt agents when the platform matures. Organizations that wait for the platform will then need a year of remediation before they can use it safely.
How Lorexus engages
We run AI readiness assessments that measure the three prerequisites directly: workload identity posture, oversharing exposure across SharePoint and Teams, and consumption governance for Copilot Credits. The output is a prioritised remediation plan with effort estimates, not a strategy deck. Book a free 15-minute call with our senior engineers.