Daily Agentic Field Watch - 2026-06-05 21:00 UTC
Late-pass signal: Copilot billing pain is now showing up in user reports, Copilot CLI has a fresh security scare, and Microsoft’s Foundry/enterprise-agent stack keeps widening.
- Copilot billing fallout is now practical, not theoretical: a fresh r/GithubCopilot post says a Max user burned through 30% of monthly credits by June 3, and yesterday’s thread says Copilot Pro used 57% of monthly AI credits in under an hour. That is the lived result of GitHub’s June 1 switch to usage-based billing. Sources: GitHub changelog, r/GithubCopilot: “GitHub Copilot becoming unsustainable? Credits are burning through instantly.”, r/GithubCopilot: “Copilot Pro used 57% of my monthly AI credits in less than an hour”, HN discussion
- Copilot CLI security watch: PromptArmor says indirect prompt injection can bypass the URL approval gate and turn a crafted
env curl ... | shpath into arbitrary shell execution, and HN is debating whether Copilot’s allowlist is too permissive. Sources: PromptArmor report, HN discussion - Microsoft Foundry’s Build recap is the clearest enterprise-agent signal today: Microsoft says hosted agents, routines, toolboxes, memory, and publishing to Teams/Microsoft 365 Copilot are all part of the Build push, with hosted agents expected to go GA in early July and Teams/M365 publishing planned for June. Sources: What’s new in Microsoft Foundry | Build Edition, Build and run agents at scale with Microsoft Foundry at Build 2026, AI alone won’t change your business. The system running it will.
- Microsoft 365 admin chatter says Copilot Planner Agent is hitting GA this month and Purview is expanding protections to AI agents; the corresponding Microsoft Learn doc now exists for Planner Agent controls. Sources: r/msp: “June 2026 Microsoft 365 Changes Admins Should Know”, Microsoft Learn: turn off or restrict access to Planner Agent and Planner Agent chat