Week 29
Enterprise AI Weekly: July 13–18, 2026
A week where the competition between the AI vendors turned openly combative: Microsoft began replacing its own AI suppliers inside its Office apps and briefing salespeople on how to undercut them — even as an independent safety scorecard complicated the pitch. The more urgent operational story, though, was a run of actively exploited identity and edge-infrastructure flaws that landed on CISA’s catalog. And Anthropic kept expanding its enterprise footprint the practical way, by localizing Claude’s price for its second-largest market.
1. Microsoft Starts Replacing OpenAI and Anthropic Inside Its Own Office Apps
What happened: Microsoft is quietly swapping the models behind some of its most-used AI features. Bloomberg reported on July 7 that Excel and Outlook are now completing tens of thousands of AI prompts each week with Microsoft’s own in-house MAI models, work that previously leaned on OpenAI and Anthropic. Microsoft AI chief Mustafa Suleyman was blunt about the motivation: “We pay a lot of money to Anthropic — so our goal is to reduce and ultimately eliminate that cost.” The substitution is possible in part because Microsoft’s April amendment to its OpenAI partnership dropped the old exclusivity terms, freeing both sides to work around each other. Microsoft’s MAI models — the seven-model family unveiled at Build in June, one of which it says matches the coding ability of Anthropic’s still-popular Opus 4.6 at a lower cost — are also selectable inside GitHub Copilot.
The strategy went from plumbing to sales pitch a week later. At an internal meeting on Tuesday, July 15 — billed as a strategy session for the new fiscal year — Microsoft executives told salespeople to position the company’s in-house models directly against rivals on cost and integration. EVP Jay Parikh framed it as “Everyone else is selling parts — we’re selling the full end-to-end system.” Copilot EVP Jacob Andreou reportedly gave a presentation comparing Copilot to Anthropic’s Claude, arguing that inside Microsoft’s own applications the competing model was “slower and less accurate, and lacked the proper security integrations.”
Why it matters to sysadmins and IT decision-makers: The practical takeaway is that “which model is answering my Copilot prompt” is no longer a stable fact — and you probably won’t get a changelog when it shifts. If your organization has standardized on Copilot in Excel, Outlook, or GitHub, the model doing the work underneath can now change for commercial reasons that have nothing to do with your workload. That is not inherently bad; MAI models may well be cheaper and fast enough. But it means output quality, tone, and edge-case behavior can move without a version bump you control, so if you have prompts, macros, or agent flows tuned to a specific model’s behavior, build in a way to notice regressions rather than assuming continuity.
The sales angle deserves a healthy dose of salt. “Slower, less accurate, and lacking security integrations” is a vendor talking point delivered to a sales force, not a benchmark — and, as the fourth story this week shows, an independent safety review reached almost the opposite conclusion about which lab leads on security and governance. Treat every “our model is safer and cheaper than theirs” claim you hear this quarter, from any vendor, as a prompt to ask for the evidence: run your own evaluation on your own prompts and data, and price the total cost including the integration work, rather than taking the pitch at face value. The broader signal is that the hyperscaler-versus-model-lab relationships are becoming openly competitive, and multi-model flexibility — the ability to move a workload between providers without a rewrite — is now a procurement hedge worth designing for.
Read more: Bloomberg — Microsoft replaces OpenAI, Anthropic with own AI in some apps | TechCrunch — Microsoft is reportedly training salespeople to talk down OpenAI and Anthropic | American Bazaar — Microsoft replaces OpenAI, Anthropic models with its own AI | PYMNTS — Microsoft quietly shifts thousands of Office prompts to in-house AI
2. CISA Flags a Wave of Actively Exploited Identity and Edge-Infrastructure Flaws
What happened: The mid-week security news was a reminder that the boring attack surface is still the dangerous one. On July 14, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, followed by two more on July 15 — and the standouts were not AI tools but the identity, collaboration, and remote-access plumbing that runs most enterprises.
Two of the entries are SonicWall SMA1000 zero-days that Rapid7’s managed detection team caught being exploited in the wild. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery flaw that an unauthenticated attacker can hit on the appliance’s Work Place interface; CVE-2026-15410 is a post-authentication code-injection bug (CVSS 7.2) that lets an administrator run arbitrary OS commands. In observed attacks the two are chained: attackers use them for stealthy initial access, then extract credentials, active session databases, and TOTP multi-factor seed configurations to keep a foothold. SonicWall says the flaws affect SMA1000 models 6210, 7210, and 8200v, with fixes in hotfix releases 12.4.3-03453 and 12.5.0-02835. The same July 14 batch added CVE-2026-56155, an Active Directory Federation Services access-control flaw allowing local privilege escalation, and CVE-2026-56164, a missing-authentication flaw in Microsoft SharePoint Server that lets an unauthorized attacker elevate privileges over the network — the second SharePoint flaw to hit the KEV catalog in two weeks. July 15 added an Oracle E-Business Suite privilege-management bug (CVE-2026-46817). Federal remediation deadlines under Binding Operational Directive 26-04 ran July 17 for the SonicWall and SharePoint entries and July 28 for the ADFS flaw.
Why it matters to sysadmins and IT decision-makers: This is exactly the pattern the Five Eyes advisory two weeks ago warned about, made concrete: internet-reachable appliances and identity infrastructure, exploited as zero-days, with a federal patch clock measured in days rather than weeks. The SonicWall pair is the urgent one — a remote-access appliance is by definition exposed, the SSRF half needs no authentication, and the attackers are going straight for session tokens and MFA seeds, which means a successful compromise can survive a password reset. If you run SMA1000 appliances, apply the hotfixes now and treat any unpatched exposure window as a credential-theft incident: rotate secrets and invalidate active sessions, don’t just patch and move on.
The ADFS and SharePoint entries are the quieter risk. Federation and on-prem SharePoint are the kind of long-lived, deeply integrated systems that get patched on a slower cadence precisely because they are load-bearing — and both flaws are privilege-escalation paths in your identity and collaboration core, with SharePoint back on the catalog for the second time this month. If your patch SLA for internet-facing and identity-adjacent systems is still measured in weeks, this week is the argument for shortening it. Prioritize the edge and identity tier ahead of the general server fleet, and make sure remote-access appliances, ADFS, and SharePoint are on the short list you patch first when CISA sets a same-week deadline.
Read more: CISA — four known exploited vulnerabilities added July 14 | BleepingComputer — SonicWall warns of SMA1000 flaws exploited in zero-day attacks | The Hacker News — two SonicWall SMA 1000 zero-days exploited | CISA — two known exploited vulnerabilities added July 15
3. Anthropic Localizes Claude Pricing for India, Its Second-Largest Market
What happened: On July 13, Anthropic began showing India-specific, rupee-denominated pricing for Claude on its website and mobile apps — its first real localization push beyond the US. India now accounts for 5.8% of global Claude usage, making it the company’s second-largest market. The new tiers price Claude Pro at ₹2,000 per month on annual billing (₹2,399 month-to-month), Claude Max 5x at ₹11,999 per month, and Max 20x at ₹23,999 per month, with GST already included so the displayed price is what subscribers actually pay. In dollar terms the tiers sit modestly above US pricing, but denominating in rupees with tax baked in removes the currency-conversion and checkout friction that suppresses paid conversion in price-sensitive markets.
The move is the consumer-facing edge of a broader enterprise build-out. Anthropic opened a Bengaluru office in February and, in January, appointed former Microsoft India managing director Irina Ghose to run its business in the country; it has also signed partnerships with Indian IT-services giants Infosys and Tata Consultancy Services to route Claude into large corporate deployments through their existing delivery arms. One notable gap: Anthropic has not yet enabled payments through UPI, India’s dominant instant-payment rail, so users are still limited to card or app-store billing — a friction point OpenAI has already cleared for ChatGPT.
Why it matters to sysadmins and IT decision-makers: For most IT leaders outside India this is a market-strategy story, but it carries two practical signals. First, the frontier labs are now competing on localized commercial terms — local currency, local tax handling, local payment rails, local systems-integrator partners — not just on model benchmarks. If your organization operates in India or runs delivery centers there, Claude just got materially easier to procure and expense through local billing, and the Infosys and TCS tie-ups mean it will increasingly show up inside SI-led engagements. That is worth knowing before it arrives as a fait accompli in a project your integrator is running.
Second, the details are a reminder to read the fine print on how AI subscriptions actually bill in each region you operate. GST-inclusive pricing, annual-versus-monthly gaps, and the absence of a payment method your finance team relies on (UPI here) are exactly the kind of operational specifics that determine whether a rollout is smooth or stalls at expense-approval. As the labs localize, expect per-region pricing and payment differences to become a standard part of AI procurement — the same way you already track them for every other SaaS contract.
Read more: TechCrunch — Anthropic starts localizing Claude pricing for India | Business Today — Anthropic introduces India pricing for Claude plans | Business Standard — Anthropic introduces India pricing for Claude subscription plans
4. No AI Lab Scores Above a C+ on the Latest Independent Safety Index
What happened: The Future of Life Institute published its Summer 2026 AI Safety Index earlier this month, scoring nine frontier labs across six domains — Risk Assessment, Current Harms, Safety Frameworks, Existential Safety, Governance & Accountability, and Information Sharing — using 37 indicators with data collected through early June. The headline finding is that the best grade any lab earned was a C+. Anthropic took the top spot at C+ (2.66 out of ~4.0), leading five of the six domains; OpenAI followed at C (2.28), leading on Risk Assessment; and Google DeepMind placed third at C (2.01). Meta landed at D+ (1.32), Z.ai and Alibaba Cloud at D− (0.88 and 0.87), and xAI (0.65), DeepSeek (0.47), and Mistral (0.33) received failing grades.
The panel’s most pointed criticism was aimed at the leaders. It found that Anthropic, OpenAI, Google DeepMind, and Meta had all weakened or voided earlier commitments to pause development if their systems approached defined risk thresholds — some citing “competitor-contingent” conditions — behavior the reviewers called “moving goalpost” and said had “undermined safety frameworks across the board.” No company scored above C− on existential safety. An enterprise-focused readout of the index made the buyer-relevant caveat explicit: these are lab-level policy grades, not product certifications — “a lab-level C+ is not a safety certificate for the particular model version, API configuration, fine-tune, and contract terms your team is actually evaluating.”
Why it matters to sysadmins and IT decision-makers: The index is a useful, vendor-neutral input for AI due diligence — and a well-timed counterweight to this week’s marketing. When one vendor’s sales deck tells you a competitor’s model “lacks the proper security integrations,” an independent panel scoring the same field ranked that competitor highest on safety and governance overall. The lesson is not that any single scorecard is decisive, but that “trust us, we’re safer” claims from any vendor should be checked against outside assessment and your own testing rather than accepted from a sales conversation.
The practical way to use it is as a tiering tool, not a verdict. Let a lab’s governance grade set how deep your review goes — a lighter touch where governance is strong, more scrutiny and red-teaming where it is weak — but do the deployment-level work regardless: verify the filtering, monitoring, and guardrails on the specific model and configuration you will actually run, and negotiate concrete safety and data-handling commitments into the contract instead of relying on a published policy that, as the “moving goalpost” finding shows, the vendor may quietly revise. In a quarter where the providers are competing loudly on who is safest and cheapest, an independent grade you can point to is exactly the kind of evidence to demand before you standardize on anyone.
Read more: Future of Life Institute — AI Safety Index Summer 2026 | TIME — the latest AI safety rankings are in, nobody gets an A | Digital Applied — FLI AI Safety Index 2026 enterprise buyer readout | MIT Sloan Management Review ME — Anthropic tops 2026 AI Safety Index
The Week in Summary
The through-line this week is that the AI market has entered its openly competitive phase, and IT buyers are the ones who have to keep the marketing honest. Microsoft is now displacing its own suppliers inside Excel and Outlook and coaching its sales force to argue that its rivals are slower and less secure — while an independent safety index published the same month ranked one of those rivals highest on exactly those dimensions. Neither the vendor pitch nor the scorecard is the last word; the point is that “our model is safer and cheaper” is now a claim you will hear constantly, from every direction, and the only reliable response is your own evaluation on your own data.
The security story is the reminder that the models are not where this week’s actual risk lived. Actively exploited zero-days in SonicWall remote-access appliances, plus fresh privilege-escalation flaws in ADFS and SharePoint, are the same lesson the Five Eyes agencies spelled out a fortnight ago: the attack surface is your internet-facing and identity infrastructure, and the time you have to patch it is shrinking. Anthropic’s India localization, meanwhile, is the quiet structural story — the frontier labs are now competing on local currency, tax, and integrator partnerships, not just benchmarks.
Three things worth doing before next week: confirm you can detect a behavior change if a vendor swaps the model under one of your AI features; patch any exposed SonicWall SMA1000 appliances immediately and rotate the credentials and sessions they held; and add an independent safety or governance reference to your AI vendor due-diligence checklist so the next “trust us” pitch meets some outside evidence.
Next edition publishes July 25.
More Enterprise AI Weekly coverage:
- Enterprise AI Weekly: June 29 – July 4, 2026 — Week 27
- Enterprise AI Weekly: July 6–11, 2026 — Week 28
- Enterprise AI Weekly: July 20–25, 2026 — Week 30