May 2026 marked the most aggressive month of AI product announcements in industry history. While regulators delayed deadlines and litigated state laws, the major AI companies shipped products that fundamentally change how AI operates in organisations. Understanding what was announced, what it means, and what governance implications it creates is essential for any organisation that will inevitably encounter these tools, whether through deliberate adoption, employee usage, or vendor integration. The 2025 AI governance policy that your organisation may have spent six months developing is already obsolete in important ways.
Microsoft Agent 365 (May 2026)
Microsoft Agent 365 reached general availability on 1 May 2026. It is not an autonomous workforce in itself: Microsoft describes Agent 365 as the control plane for AI agents, built around a registry of every agent operating in the organisation, access control through Microsoft Entra Agent ID, visualisation, interoperability and security. It governs agents built with Copilot Studio and Foundry, agents inside Microsoft 365 and Teams, local agents on Windows endpoints, SaaS agents, and agents imported from AWS Bedrock and Google Cloud. Standalone pricing is US$15 per user per month, and it is also bundled in the Microsoft 365 E7 suite. Separately, Microsoft guided on its 29 April 2026 earnings call to roughly $190 billion of calendar 2026 capital expenditure, then restated that as about $175 billion on 29 July 2026 after extending the assumed useful life of data centres and buildings to 25 years and reclassifying more future leases as operating leases, with underlying build plans unchanged. The governance implications: organisations using Microsoft 365 will encounter agents by default, whether or not they license Agent 365, which is a paid add-on rather than something switched on automatically. Agent 365 is the surface Microsoft expects administrators to discover and govern those agents from, including the ones it classes as shadow AI, so an AI inventory that does not reconcile with what Agent 365 discovers will be incomplete. Data classification policies need to address what data agents can access and what actions they can take.
OpenAI GPT-5.5 Instant and the move to AI-first devices
OpenAI shipped GPT-5.5 Instant on 5 May 2026 as the new default model in ChatGPT and was reported at roughly $25 billion in annualised revenue at the time. On 8 June 2026 OpenAI confirmed it had confidentially submitted a draft Form S-1 to the SEC, while saying it had not decided on timing, and subsequent reporting points to a listing in 2027 rather than late 2026 (Anthropic overtook OpenAI on annualised revenue in April 2026 at a reported $30 billion run rate, disclosed a $47 billion run rate on 28 May 2026, and third-party estimates put it near $69 billion by early July 2026). Reports also indicate OpenAI is exploring AI-first hardware devices that could displace traditional smartphone apps. The governance implications: rapid model iteration means organisations need processes for evaluating new model versions before adoption, not just initial vendor selection. The shift to AI-first devices creates entirely new categories of AI exposure that current governance frameworks don't address.
Anthropic Project Glasswing
Anthropic announced Project Glasswing on 7 April 2026, a controlled initiative giving named partners (Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks) plus more than 40 further organisations that build or maintain critical software infrastructure early access to Claude Mythos Preview to find and fix critical software vulnerabilities before malicious actors exploit them. In its first public update on 22 May 2026, Anthropic reported that participants had identified more than 10,000 high or critical severity vulnerabilities. Mythos reportedly excels at identifying weaknesses in software at a level that concerned US government officials. Anthropic's annualised revenue overtook OpenAI's in April 2026 at a reported $30 billion run rate, and Anthropic disclosed with its Series H announcement on 28 May 2026 that run-rate revenue had crossed $47 billion; higher mid-2026 figures near $69 billion are third-party estimates the company has not confirmed. The governance implications: AI systems capable of identifying software vulnerabilities are dual-use, useful for defence, equally useful for attack. The Five Eyes agentic AI guidance (May 2026) becomes more relevant as these capabilities become more accessible.
Google Gemini Spark and Search Agents (Google I/O 2026)
At I/O 2026, Google announced Gemini Spark, autonomous agents that work in the background on recurring long-term tasks across Gmail, Google Docs, Slides, and third-party apps. The search bar was redesigned to accommodate conversational queries and create monitoring agents. Google reportedly shut down its internal "Mariner" project ahead of I/O to focus execution. Gemini now has over 900 million active users. Google's 2026 AI infrastructure spend: $180-190 billion. The governance implications: search-embedded agents change content discovery, verified, structured content from authoritative sources gets cited; thin or unverified content gets skipped.
Government oversight is formalising
The US Commerce Department's Center for AI Standards and Innovation (CAISI) now has pre-deployment evaluation agreements with Microsoft, Google DeepMind, xAI, OpenAI, and Anthropic. CAISI evaluates frontier AI models for hacking capabilities, military misuse, and unexpected behaviours before public deployment. This builds on the AI Safety Institute network that includes the UK AISI, the Australia AISI (launched early 2026 with A$29.9M funding), and similar institutes in Canada, Japan, and South Korea. The governance implications: government pre-deployment testing means certain AI capabilities will be flagged before they reach commercial customers, but it also means commercial customers cannot assume that a publicly available model has been comprehensively safety-tested for their specific use case.
Microsoft's A$25B Australia commitment
On 23 April 2026, Microsoft committed A$25 billion (US$18 billion) by the end of 2029 to expand Azure cloud and AI compute infrastructure in Australia, strengthen cybersecurity partnerships with government agencies, and upskill 3 million Australians in AI by 2028. It follows AWS's A$20 billion Australian data centre commitment covering 2025 to 2029, announced in June 2025, and the A$7 billion Sydney AI campus that NEXTDC is developing at its S7 site under a non-binding memorandum of understanding with OpenAI, announced alongside Australia's National AI Plan in December 2025. The governance implications: Australian organisations will have significantly more access to enterprise-grade AI services. The APRA (Australian Prudential Regulation Authority), ASIC (Australian Securities and Investments Commission), and OAIC (Office of the Australian Information Commissioner) supervisory expectations from April-May 2026 are timely, the infrastructure for widespread AI adoption is being built simultaneously with the regulatory framework.
How innovation is changing how we work
The cumulative effect of these announcements is a fundamental change in how AI integrates with work. AI is moving from a tool that humans use (ChatGPT, Copilot as separate applications) to an autonomous layer that operates continuously across applications (Agent 365, Gemini Spark, Anthropic agents). Tasks that previously required human attention, monitoring inboxes, tracking topics, coordinating across tools, are increasingly delegated to AI agents that operate in the background. This creates productivity gains and governance challenges simultaneously. The productivity gains are real. The governance challenges include: agent access controls (what can the agent see and do?), accountability (who is responsible when the agent makes a mistake?), audit trails (can you reconstruct what the agent did and why?), and shadow AI (employees adopting agents independently without IT or risk awareness).
For every organisation, the practical implication is that AI governance must now address autonomous agents specifically, not just AI as a tool, but AI as an autonomous actor operating across systems. The Five Eyes agentic AI guidance (May 2026), APRA's industry letter (April 2026), and the EU AI Act's GPAI transparency and copyright obligations (applicable since 2 August 2025, with European Commission enforcement powers starting 2 August 2026 and full compliance for pre-existing models required by 2 August 2027) all become more relevant as these capabilities become standard rather than experimental.
Sources: Microsoft, Agent 365 now generally available (1 May 2026) | Anthropic, Project Glasswing | Anthropic, Series H announcement (28 May 2026) | Google, I/O 2026: Welcome to the agentic Gemini era | Microsoft, A$25 billion Australia investment (23 April 2026) | CNBC, CAISI Agreements with Major AI Companies | Five Eyes Agentic AI Guidance
Related reading
- AI Search Agents Are Here: What Google Gemini Spark, OpenAI, and Autonomous Search Mean for AI Governance
- AI Agents and GRC: The 2026 Guide to Governance, Risk, and Compliance for Autonomous AI
- Choosing AI Tools for Your Organisation: A Practical Comparison of Microsoft Copilot, ChatGPT Enterprise, Claude, and Google Workspace AI
- Agentic AI Governance: How to Govern AI That Takes Actions in the World