October, is that boo? Philly makes the scary shift to spooky season this week, with a super-sized lineup of things to do.
Serious Halloweeners, it’s time. Philly’s premier haunted attraction, Halloween Nights at Eastern State Penitentiary, is back (begins Friday), alongside plenty of other nightmarish haunted houses and spook-tacular themed restaurants and bars.
The Philadelphia Film Society brings the movie magic for REEL October, a blockbuster month celebrating all things cinema (starts Thursday).
Raise a glass! Dine Latino Restaurant Week kicks off its Hispanic Heritage Month celebración, bringing meal deals and exclusive eats to top Latino-owned eateries across the region (starts Sunday).
Beep, beep: Philly’s parking warriors (IYKYK) head into battle for the first-ever Philadelphia Parallel Parking Association Championship at Headhouse Plaza (Saturday).
Plus, don’t miss: Out & About in Manayunk (Saturday) and the St. Nicholas of Tolentine Italian Festival on South 9th Street (Sunday).
With so much happening this week, you’ll wanna stay over. So why pay more? Book the Visit Philly Overnight Package for free hotel parking and priceless peace of mind.
Keep reading for the best things to do in Philadelphia this week and weekend, September 28 to October 4, 2026.
Critter Stack Roundup: Two Weeks, Six Repositories, and an EF Core Sweep
It’s been a busy couple of weeks across the Critter Stack. Between September 13th and today, we merged roughly 370 pull requests across JasperFx, Weasel, Marten, Polecat, Fisher, and Wolverine, and shipped a pile of releases along the way. More importantly, a big chunk of that work came from, or was driven by, people outside of JasperFx Software, so there’s a lot of thanking to do in this post.
5.27.0, 5.28.0, 5.28.1, 5.29.0, 5.30.0, 5.31.0, and now 5.32.0
Weasel
9.33.0, 9.34.0, 9.35.0, 9.35.1, 9.35.2
JasperFx
2.69.1 through 2.75.2
Fisher
1.5.0 through 1.13.0
And Polecat 5.32 will be released by the time you read this.
And the big themes:
An Entity Framework Core sweep through Wolverine and Weasel, touched off by a set of sharp bug reports — I wouldn’t expect any of the bugs we address to impact many people, but I’d like the number of EF Core features not supported or features we don’t support well to be essentially zero
Vector, full text, and hybrid search across Marten, Polecat, and Fisher, all behind one shared API – this is to support our forthcoming agentic memory tool “Stoat”
Conjoined multi-tenancy tightened up and held to a shared compliance suite on every store. This was mostly a testing effort, but there were some EF Core related issues that helped spawn that work. It did find some issues with Polecat and Fisher when we did more compliance testing against Marten behavior to the younger tools
Error messages that tell you what to do instead of just telling you something went wrong – I wrote about that previously in our new AI Skills 1.14 release notes
Idempotency and agent distribution improvements in Wolverine, a lot of it from the community – Some things are just flat out hard. Gulp.
The EF Core Sweep
This one started with a trio of excellent issue reports from Ali Yuksekkaya against Wolverine’s EF Core integration:
Conjoined EF Core tenancy was ignored in the Lightweight transaction mode, so a message could be written under the wrong tenant and HTTP cascades skipped the outbox (GH-4611)
Conjoined tenancy allowed detached updates and deletes to touch rows that belonged to another tenant (GH-4612)
Returning Update<T> or Store<T> from a handler saved nothing at all for an entity the DbContext wasn’t already tracking (GH-4613)
Those got fixed, but reports like that are a signal that nobody had been looking hard enough at that corner of the code, so we went looking. The resulting sweep landed as a wave of Wolverine pull requests this weekend:
Lightweight EF Core message handlers now get a real transactional outbox. Before, Lightweight mode quietly meant no outbox enlistment, no domain event scraping, and no idempotency check
Domain event envelopes scraped out of the DbContext are now flushed before the Eager transaction commits. This was a leftover from an earlier fix where the scraped envelopes were tracked after the only SaveChanges() call and never persisted
Wolverine’s conjoined tenant query filter now composes with your query filter instead of replacing it. EF Core 9 and EF Core 10 behave differently here (EF 9 discards the earlier filter, EF 10 throws), and we now cover both
A new EfCoreOps family of declarative side effects for ExecuteUpdate, ExecuteDelete, raw SQL, and bulk inserts. These force the Eager transaction mode they need and scope themselves to the current tenant
A conjoined tenancy test battery that now runs against Marten, Polecat, and Fisher backed message stores
Closing several test coverage holes, including owned, complex, and JSON mapped models end to end
::: warning One of these changes is technically breaking. If you’re using AutoApplyTransactions() and a single handler could be claimed by two persistence providers (say, it takes both a DbContext and a Marten IDocumentSession), Wolverine used to silently apply no transaction at all. It now fails loudly at startup and tells you how to resolve it (GH-4631). If your application hits this, it had a real bug that this change is surfacing. :::
The sweep reached down into Weasel as well, which is where our EF Core schema migration support lives. Ali also reported that EF Core batched queries silently returned incomplete entities for owned, complex, and JSON members, and then contributed a follow up pull request to prepare each batched query once while keeping the provider’s parameter types intact. On top of that, Weasel now:
Materializes EF Core batched queries through EF Core itself
Carries database indexes that EF Core can’t model as their own DDL
Maps the columns of table-split complex properties, which were previously omitted and then dropped by CreateOrUpdate
Never drops a column from an EF Core derived table just because the model doesn’t happen to declare it
Marten, Polecat, and Fisher also all fixed the same bug where an EF Core backed projection leaked the DbContext it created per batch. Thanks to wpei-infotrack for reporting the Marten version of that one, which turned out to be a leaked PostgreSQL connection per batch in the async daemon.
Vector, Full Text, and Hybrid Search Everywhere
The other big feature push was around search. JasperFx now has a shared, store-neutral vector and hybrid search surface in JasperFx.Events.Vectors, and all three of our document stores implement it:
Marten.PgVector moved onto the shared contracts with scored search, HNSW index declarations, and hybrid search using reciprocal rank fusion over PostgreSQL’s ts_rank and the vector leg. Marten also now warns you when a full text search falls back to an unindexed, whole document scan
Polecat picked up vector search on SQL Server 2025’s native VECTOR type, a Polecat-owned full text inverted index with LINQ operators and BM25 scoring, prefix search, and hybrid search on top of both
Fisher got hybrid search and embeddings produced from an event stream
Because they all implement the same contract, there’s now a DocumentSearchCompliance suite in JasperFx that holds all three stores to the same behavior. As usual, the first real run of that suite found defects in the suite itself as well as in the stores, which is exactly what it’s for.
Polecat 5.32
Polecat 5.32 is the release that rolls up the last few days of work, and it’s largely about parity with Marten and about multi-tenancy:
Conjoined document tenancy sweep. Every document shape is now tested in both directions, and conjoined tenancy now also holds on the event, vector, and partition onboarding paths
Raw SQL in IBatchedQuery, bringing batching up to parity with Marten
Strongly typed identifiers are now assigned onto a live aggregated aggregate, just like Marten does
Document indexes, computed columns, and foreign keys are now modeled as Weasel schema objects, which means db-dump finally reproduces the full configured schema
Every tenant database is described in the store’s usage descriptor for a multi-tenanted store, which matters for CritterWatch
Event store diagnostic reads answer “no results” rather than throwing when the schema was never applied or has drifted
Adoption of JasperFx 2.75 and Weasel 9.35
Earlier in the window, Polecat 5.31 also made startup migrations take a real cross-process lock through sp_getapplock and routed the last few hand-escaped SQL construction sites through a shared escaping helper.
Multi-Tenancy, Everywhere
Multi-tenancy was a recurring thread through all six repositories:
JasperFx now has conjoined document tenancy compliance tests, and Marten, Polecat, and Fisher all enrolled
TenantIdStyle is now applied consistently. Marten applies it at every boundary that stamped or keyed on the raw tenant id, and Wolverine now normalizes Envelope.TenantId through it so that the stores reading that value write the right tenant
There’s a new canonical DisabledTenantException in JasperFx. All the stores and Wolverine now refuse a disabled tenant with that exception instead of reporting “Unknown tenant id”
IEventStore.OpenReadOnlyEventStore(tenantId) is now tenant aware, so the read-only tier is actually reachable in multi-tenanted systems
Marten and Fisher both fixed bugs with the diagnostic and explorer reads that CritterWatch depends on, including one in Marten where a read against an unknown tenant under sharded tenancy could provision a new tenant and run DDL
Error Messages That Name the Remedy
I spent a chunk of the last two weeks going through the exception messages across the stack, asking one question of each: does this tell the user what to do next? A lot of them didn’t. That turned into a wave of small pull requests:
Wolverine saga failures, handler discovery, missing aggregates, oversized Azure Service Bus messages, mismatched RabbitMQ queue declarations, missing Redis streams, missing HTTP transport clients, and SNS configuration problems all name the remedy now. Named connection strings are validated in one pass at startup. The SignalR transport fails the host start if the hub refuses the connection. Wolverine.HTTP gets a one-line opt in for mapping concurrency failures to a 409 ProblemDetails, and an unknown tenant id maps to a 404 instead of a 500
Marten stream identity mismatches, stream collisions, LINQ refusals, and the rich append concurrency exception all got clearer
Weasel decodes sp_getapplock failures, translates database permission failures into a typed exception, and now warns before AutoCreate.All drops and recreates an object
JasperFx lifted canonical ArchivedStreamException, DisabledTenantException, and stream exceptions so that all three stores throw the same types with the same guidance
On a related note, Marten 9.39 includes two SQL injection fixes, for GroupBy()HAVING comparison operands and for full text search regConfig values on every sink, not just the WHERE clause. If you’re on an older 9.x version, please upgrade.
Wolverine
Besides the EF Core work above, here are some of the highlights in Wolverine:
Capacity aware agent assignment.Michael Harris contributed per-node capacity ceilings for agent distribution (GH-3959), so one node dying no longer pushes its entire share onto the survivors. Anne Erdtsieck filed the original issue, and also contributed a fix for group affinity placement during blue/green deployments. There’s new documentation for the whole thing
Transactional deduplication. Wolverine’s deduplication claim can now ride the native Marten, Polecat, or Fisher transaction. Laurence Gillian reported that an HTTP deduplication claim survived a non-2xx response and turned legitimate retries into false duplicates, and that’s fixed too
An Oracle external table transport contributed by Travis Kirke, along with a fix for the Oracle durability agent’s incoming message recovery
GCP Pub/Sub now shares one subscription across nodes by default, thanks to a report from bittercoder about duplicated messages
Topology scoped message grouping rules, from a request by Anne Erdtsieck
Recurring schedule operability with occurrence attribution and a manual trigger, and a fix for non-UTC recurring schedules. Both came from issues filed by Babu Annamalai
OpenTelemetry parenting fixes. Recurring messages, inline receivers, and Wolverine’s internal agent loops no longer inherit whatever Activity happened to be current when they were started. Marten had a similar fix for spans being re-parented to their grandparent, reported by bohdan-hukivskyi. Open Telemetry sometimes has some weird behavior in terms of how parents are tracked. I expect or hope this will help the CritterWatch graphing of Otel spans from Wolverine
Tore Hammervoll fixed TypeLoadMode.Static so a handler chain finds its pre-generated type by full name instead of scanning exported types per chain
Two concurrency fixes reported by Marcin Aumiler: delayed sends to a partitioned PostgreSQL queue could be deleted without ever being handled, and the listener collection could be corrupted when agents started in parallel
Marten
Other than the search work, multi-tenancy, and messages, Marten had a lot of community driven fixes:
Anne Erdtsieck fixed the outer projection of GroupJoin/SelectMany and GROUP BY rendering over a join, made the projection batch fault properly when an operation can’t be configured, and made an unprovisioned event store answer “nothing” for its progression and dead letter tables
Erik Shafer fixed patched documents and replaced events to be stamped with the session’s actual instant (reported by BaerMitUmlaut)
vpetrevski routed QuickWithServerTimestamps stream starts through mt_quick_append_events to avoid sequence gaps
Arnel Robles corrected the pgvector docs and reported two async daemon bugs in the skip-ahead loader and progression writes
tychomensing-topicus reported a Select() projection problem with absent JSON keys
Weasel
Besides the EF Core work, Weasel got two nice community contributions. Joel Reinford made SQL Server migration scripts runnable under sqlcmd and safe to re-run, and Jaedyn moved us onto the patched advisory lock. Anne Erdtsieck also contributed a change to let the schema delta decide when an index needs a concurrent build.
JasperFx
JasperFx is just a foundational shared library, but a lot happened there:
The shared vector and hybrid search surface described above
A store-agnostic StubEventStream<T> for unit testing event sourced handlers, with documentation on all three stores
The @jasperfx/event-model-vue renderer moved into the JasperFx repository, next to the Event Model descriptor it draws, and the Event Model now handles services that host more than one model
Hardening the aggregate source generator, including an opt-in build-time assertion that the generator is actually attached
Andre Vieira fixed codegen test failing for every message handler since Wolverine 6.37, and Alan Klimowski fixed a code generation frame ordering issue (and a duplicated service declaration in Wolverine.HTTP)
Fisher
Fisher went from 1.5 to 1.13 in two weeks. Beyond the search work, Fisher now creates its event store tables on first use, supports directory tenancy on Windows, validates tenant ids before turning them into file names, fixes decimal comparisons in LINQ, and requires the source generator with a smoke test of the packed package. Kebin contributed a fix for enlisted sessions with an inline projection registered.
Thank You
The Critter Stack only gets this good because people use it hard (thanks?), tell us when it breaks with actionable error reports, and increasingly send in the fix too. Thank you to everybody who contributed code over the past two weeks:
Ali Yuksekkaya, Anne Erdtsieck, Michael Harris, Travis Kirke, Marko Lahma, Laurence Gillian, Tore Hammervoll, Alan Klimowski, Erik Shafer, Andre Vieira, Jakob Tikjøb Andersen, Joel Reinford, Jaedyn, Mark van der Dam, Raymond Masciarella, Arnel Robles, vpetrevski, Kebin, Marcin Aumiler, Jorge L. Torres M, and Rayan-and-beyond.
And to everyone who filed a good issue with a reproduction, including ArieGato, michielpeeters, raypet-visma, AndreiKopylov, framos-varajo, syserr500, BaharAtNode, Petteroe, zxjon22, r0ss88, bittercoder, BaerMitUmlaut, wpei-infotrack, bohdan-hukivskyi, tychomensing-topicus, and Babu Annamalai: those reports are what drove a lot of this.
No, seriously, the Critter Stack community is as far as we can tell far, far about average for OSS projects in terms of how helpful the community is to help drive and improve the tools.
.NET 11 brings hundreds of small performance improvements across the runtime and libraries. The JIT generates faster code by removing unnecessary checks, allocations, and indirections. A major change, runtime async, lets the runtime optimize async/await more effectively, reducing tasks, allocations, and execution time. Other improvements cover memory safety, collections, networking, JSON, I/O, threading, and more.
Consuming webhooks is a giant pain, and yet, every integration relies on their existence. Tom explains why this is the case and how he solved most of those problems in practice. This is likely going to increase in relevance as AI workflows and chains increasingly depend on webhooks to react to events from third-party services.
Modeling Bible text looks simple at first but quickly runs into real world exceptions. Verse ranges, missing verses, out of order chapters, and books like Greek Esther that split and repeat chapters all break basic assumptions. Jon's advice is to decide how much accuracy you actually need, then pick the simplest model that handles it without crashing.
C# 15 and .NET 11 introduce native union types, letting a single type hold one of a fixed set of types, such as an int or a string. The compiler enforces exhaustive pattern matching, so adding a new case immediately flags any switch that doesn't handle it. For new APIs where all cases share a common base class, a closed hierarchy with a JSON discriminator is often a better fit. Unions shine when the contract is already discriminator-free or the case types are unrelated primitives or existing types you don't control.
Andrew provides an introduction to Device Bound Session Credentials. He describes the problem they're trying to solve, how the protocol works, and what you need to do to support them.
Two requests read the same database row, change it, and write it back. The second write silently erases the first. No errors appear, but the data is wrong. Two main fixes exist. Optimistic concurrency adds a version token to each row and fails the write if the token changed since you read it. Pessimistic concurrency locks the row upfront so others wait their turn. For simple counters, one atomic SQL statement removes the gap entirely.
And the most popular article from the last issue was:
Get caught up on the latest technology and startup news from the past week. Here are the most popular stories on GeekWire for the week of Sept. 20, 2026.
Amazon says it has cut off Meta’s new Muse personal AI agent from shopping on Amazon.com, citing data security and other concerns. It’s part of a larger industry fight over who controls the shopping experience and customer relationship in agentic commerce. Read More… Read More
Microsoft is moving communications out of its marketing group and under Vice Chair and President Brad Smith, as CEO Satya Nadella calls for a fundamentally new approach that makes employees a bigger part of how the company tells its story. Read More… Read More
The cuts total about 600 globally, including about 300 in Washington state, and 268 worldwide in Xbox Game Studios. The restructuring folds some existing studios under Activision, Bethesda and King, and leaves Ninja Theory, the studio behind the Hellblade series, facing a potential closure. Read More… Read More
Former Seattle City Council President Sara Nelson has launched CivicTide, a website that tracks City Council legislation, publishes policy briefs and opinion pieces, and gives readers tools to contact councilmembers. The site runs on a custom AI-powered system built by Seattle tech communications executive Viet Nguyen. Read More… Read More
Microsoft’s revamped Copilot app adds AI coding, always-on agents and full versions of Word, Excel and PowerPoint as the company competes with OpenAI and Anthropic and shifts more of its AI pricing to usage-based billing. Read More… Read More
Impacted positions span across technology, product, and corporate roles — including data scientists, software engineers, finance managers, and senior leadership. Read More… Read More
Amazon announced new AI tools for its independent sellers, led by a plugin that lets them run their Amazon businesses from Anthropic’s Claude or Amazon’s own Quick assistant. Read More… Read More
Bungie, the Bellevue-Wash.-based video game studio behind Destiny and Marathon, began its week with an apology from its new studio head, as it tries to win back its audience after several recent missteps. Read More… Read More
Shankar Sundaram, a former Boeing engineer and enterprise sales leader, said the ultimate goal of East West Club is to create a “third place” in the city that’s centered around genuine connection rather than corporate networking or status. Read More… Read More
Mayor Katie Wilson’s proposed budget closes a $175 million deficit through spending cuts and leaves the JumpStart payroll tax untouched, offering big tech employers a period of tax stability. Read More… Read More
Debugging mobile apps is weird: intermittent connections, mid-onboarding drop-offs, edge cases on devices you've never tested. bitdrift captures 100% of data, unsampled and in real time, so it’s immediately queryable by engineers and agents. Try bitdrift: mobile observability for the real world.
Android apps face over 14 million attacks annually, and most vulnerabilities are found too late. DerScanner brings enterprise-grade SAST to your APK: false positives cleared, context-aware fixes ready to apply. 14-day community edition access.
We reach out to more than 80k Android developers around the world, every week, through our email newsletter and social media channels. Advertise your Android development related service or product!
Microsoft’s September 25 announcement introduces Home, Code and Autopilot alongside a clearer commercial distinction between everyday Copilot use and usage-based agentic work.
There is plenty to get excited about. But what caught my attention is not only what Copilot can do next. It is what organizations will need to do differently.
My reading is that Microsoft is building an AI operating model—and an AI economy—inside Microsoft 365.
This is bigger than adopting another tool. It connects delegation, solution creation, autonomous work, governance and spending. And it raises a practical challenge: helping people create meaningful business value with the right AI capability, at the right cost, under the right governance model.
Let’s take a closer look.
Home and Cowork: from choosing tools to directing work
Home brings together Chat and Cowork, with Word, Excel and PowerPoint experiences integrated through Office in Copilot. Microsoft describes a future where people state what they want to accomplish and Copilot routes the work to Chat, Cowork or Code, rather than requiring them to select the mode themselves.
That is a significant direction: less focus on operating the interface, more focus on describing the outcome.
Cowork makes this shift particularly clear. Microsoft positions it around delegated, end-to-end work, including complex deliverables such as RFP responses and financial close packages.
This is not simply bigger chat.
When I delegate work, the important questions become what I want completed, which context matters, what boundaries apply and how I will judge the result. Better prompting helps, but a good prompt is not the same as a well-defined assignment.
That distinction should become part of how we teach people to work with AI.
This has already changed how I work
Cowork has already changed how I am able to work. Using Cowork and Copilot Chat on my mobile phone, I can draft, generate content and keep refining it when opening a laptop is not an option. Like preparing this blog post, planning the next work webinar, creating customer workshop materials, and the list goes on.
That might be on public transportation, sitting in a café or at home in the living room with my family. Bringing a laptop to the table with “I’ll just do some work while we’re having family night” does not really work. And yes, I should probably put the phone away as well. Touché.
The change is not just about the device. I can move work forward through conversation: describe what I need, review what comes back and steer the next iteration.
What excites me about Code and Autopilot is the possibility of extending that pattern—creating applications by chatting with Copilot, refining what I want an agent to do and reviewing its outcomes. That is the working pattern I want to build toward as these capabilities become available.
And perhaps the most useful outcome should be knowing when the work is handled—and putting the phone away.
Code: creating a solution is becoming part of everyday work
Microsoft describes Code as a way to create apps, dashboards, trackers, automations and workflows through natural language, extending solution-building beyond professional developers.
The important story is not that developers can build software. It is that business users, subject-matter experts and knowledge workers can increasingly turn their understanding of a problem into a working solution.
I see Code as extending that direction into the everyday Copilot experience. Compared with learning a visual builder or expression language, describing the desired outcome can lower the starting barrier further.
But easy to create must not become easy to abandon.
A useful team application still needs an owner, tested behavior, appropriate data permissions and a maintenance decision. A convincing first demonstration is not automatically a dependable business solution.
This is why Copilot Managed Runtime matters. Microsoft describes it as IT-governed hosting within the organization’s Microsoft 365 environment, supporting applications created through Cowork, Code and Copilot Studio; it is currently in preview.
For me, this is an enterprise-readiness discussion, not merely a hosting detail. Generating an application and operating it responsibly are different responsibilities.
My recommendation is to involve administrators, security teams and business owners early. Give experimentation a defined scope and a clear route from useful prototype to supported solution.
Autopilot: the work happens
Autopilot, previously known as Microsoft Scout, is Microsoft’s proactive, cloud-hosted agent for persistent work, including following up on threads, running recurring tasks and resuming projects beyond an individual interaction.
The important shift is that work can continue after the person stops interacting with it.
I find the digital-teammate framing useful, provided we do not confuse delegated execution with transferred accountability.
For persistent agentic work, I would want a business owner, a bounded objective, escalation rules, a review schedule and a clear way to stop execution.
This also connects directly to FinOps. When work continues beyond a conversation, organizations need to understand what they are funding and why.
Just because an agent keeps working does not mean the work is still needed or worth the cost.
An agent’s purpose should be reviewed alongside its quality, permissions and cost. Continuing to run is not, by itself, evidence that the work remains valuable.
For everyday AI, the USL provides a fixed subscription cost covering Chat, Copilot experiences across Microsoft 365 applications, model selection and Auto model routing; Auto weighs accuracy, speed and cost when selecting a model.
Microsoft places Cowork, Code, Autopilot, long-running agentic capabilities and frontier models such as Astra and Fable under UBB. I would not frame this simply as “the interesting things cost extra.”
Someone pays for computation. If the customer is not charged separately for an operation, its cost still exists within the provider’s economics.
My view is that indefinitely expanding agentic work cannot sustainably be treated as computation without an economic consequence. Organizations should not base their strategy on that assumption. This is an economic argument, not a claim about Microsoft’s margins or unpublished pricing.
Equally, usage-based billing does not automatically mean poor value.
A demanding task can justify higher consumption if it produces a valuable, accepted result. A cheap task repeated unnecessarily can still waste money.
The useful business conversation connects the outcome, the required quality, the total cost of producing and reviewing it, and the value actually realized.
We should optimize for valuable work—not simply the lowest consumption or the most powerful model.
I see this as a business capability, not a dashboard finance checks after IT has enabled everything.
The main Copilot announcement describes spending-policy management through APIs, credit requests routed into approval workflows and model-family controls for different user groups, including constraints on Auto’s choices.
It also describes cost-management expansion to Code and Copilot Managed Runtime, visibility into Cowork task outcomes, and users’ ability to see credit usage, remaining balances and usage history.
These are useful foundations. They are not, by themselves, proof of ROI.
A completed task is not necessarily useful work. Time saved does not automatically become financial savings. Someone still needs to establish a baseline, assess the result and decide what the organization gained.
For a pilot, I would examine accepted outputs, turnaround time, review effort, rework and consumption together. For an application, I would include maintenance and support. For autonomous work, I would also check whether the process still needs to run.
FinOps should help organizations spend confidently on valuable work—not merely spend less.
That becomes increasingly important when AI is creating applications, executing longer assignments and operating beyond individual interactions.
AI literacy needs to move beyond prompting
If an adoption program mainly teaches people to start using AI and write better prompts, I would now broaden it.
Prompting remains useful. It is simply not sufficient.
The next layer of AI literacy should include:
Capability selection: matching the approach to the outcome.
Delegation: defining objectives, boundaries and review points.
AI judgment: assessing evidence, quality and uncertainty.
Cost awareness: recognizing when additional consumption is justified.
Governance awareness: understanding what may be accessed, created, shared or executed.
A quick answer may not require the most advanced model. A reusable business dashboard may justify evaluating Code. A recurring process with clear boundaries may justify evaluating Autopilot when it becomes available.
These are judgment exercises, not automatic product-selection rules.
Even when Copilot handles more routing, people still need to decide whether work should be delegated and whether the result is acceptable.
My practical recommendation is to select a few meaningful outcomes, give each an owner and baseline, agree on spending and review boundaries, and scale what demonstrates value. Connect IT, finance, business owners and adoption champions rather than treating each as a separate workstream.
And do not turn cost awareness into anxiety. Give people understandable limits, room to learn and a straightforward way to request more capacity.
Code: Frontier rollout at the end of September, with broader availability in the coming weeks.
Autopilot: expansion into private preview at the end of September.
Copilot Managed Runtime: currently in preview.
Plugin Registry: rolling out, with general availability across supported surfaces in the coming weeks.
Dynamics 365 and Power Platform grounding: public-preview rollout over the month following the announcement.
Code is also planned to enter preview for Microsoft 365 Premium and Pro subscribers later in 2026. These are consumer subscriptions, not Microsoft 365 enterprise licenses, as reflected in Microsoft’s guidance on AI credits and limits for Microsoft 365 subscriptions.
My perspective: adoption is becoming operational
I am excited about this direction. But I would not use this moment simply to add more features to a Copilot training deck. I would use it to reconsider what successful AI adoption means.
Home, Code and Autopilot are important. FinOps may prove even more important because it connects that ambition to a sustainable way of operating.
The defining challenge of the next phase is not merely getting people to use AI. It is helping them delegate responsibly, create dependable solutions and recognize which work is worth doing.
The future of work is not a maximum AI consumption nor a heavily constrained one. It is meaningful business value, created with the right AI capability, at the right cost, under the right governance model.