Q3 opens with four items that are not on the horizon — they are active. Costs are locking in, inference capacity is unlocking, identity governance goes live in seven days, and a regulatory hard stop on new product launches is 32 days out.
Microsoft 365 Pricing Resets Today — Security Copilot Is Now in Every E5 Seat
The price and packaging changes announced by Microsoft in December 2025 took effect today. For enterprise buyers, the headline numbers are:
- Microsoft 365 E5: $57 to $60 per user per month. Every E5 tenant now receives an allocation of 400 Security Compute Units (SCUs) per 1,000 licensed users per month — the unit of consumption for Security Copilot, Microsoft's agentic security layer spanning Defender, Entra, Intune, and Purview. Intune Endpoint Privilege Management, Enterprise Application Management, and Cloud PKI are also bundled in.
- Microsoft 365 E3: $36 to $39 per user per month. The plan now includes Microsoft Defender for Office 365 Plan 1, adding anti-phishing protection and Safe Links that previously required a separate add-on purchase.
- Office 365 E3 standalone: $23 to $26 per user per month, a 13 percent increase with no material feature additions.
Existing customers pay current rates until their next renewal after today. New contracts or renewals signed on or after 1 July are subject to the new rates.
The operator implication runs deeper than the $3 per seat increment. Security Copilot is no longer something a security team argues to procure; it is already provisioned in every E5 tenant. The governance question has shifted from "should we use AI in security operations?" to "how do we govern the agents already running in our environment?" Any enterprise that has not yet set a policy on Security Copilot agent permissions and alert triage workflows now has a gap that is actively accumulating.
OpenAI Commits GPT-5.6 Sol to Cerebras Hardware — 750 Tokens per Second in July
When OpenAI previewed GPT-5.6 Sol on 26 June, the most significant detail was buried in a single line: the model will launch on Cerebras at up to 750 tokens per second in July. The current GPT-5.5 priority tier delivers roughly 50 tokens per second. The 15x difference is not a benchmark number; it reflects Cerebras's wafer-scale silicon architecture, which eliminates the memory-bandwidth bottleneck of multi-GPU serving by fitting an entire model on a single die.
For operators running latency-sensitive agentic workflows — real-time voice agents, streaming multi-step document processing, live code review — this matters in ways quality alone cannot. Most deployed agents today are not memory-bound or context-bound; they are throughput-bound, with perceptible pauses at each reasoning step. 750 tokens per second makes the wait imperceptible for most use cases.
Access remains gated to roughly 20 US-government-approved partners while the model sits under the voluntary 30-day review framework established by the June 2 White House executive order. No date has been given for broader commercial availability. GPT-5.6 also introduced explicit cache breakpoints with a 30-minute minimum cache life; cache writes now carry a 1.25x surcharge on the base input rate, while reads retain the 90 percent discount. For high-volume agentic pipelines, this changes prompt structure economics.
Anthropic's Biometric Gate Opens July 8 — Enterprise API Is Exempt
Anthropic's updated privacy policy takes effect on 8 July, introducing the right to require a government-issued photo ID, a live selfie, and a facial geometry scan from consumer-tier Claude users — Free, Pro, and Max plans — before granting or maintaining access. Commercial accounts (Team, Enterprise, and the Claude Platform API) are explicitly excluded from these provisions.
Fable 5 remains offline for all users as of today. Mythos 5 was restored on 27 June for roughly 100 vetted US institutions. The connection between the biometric gate and Fable 5 access is not incidental: app-layer strings in the Claude client link Fable 5 usage credits to identity verification, suggesting that verified US-citizen consumer accounts may unlock Fable 5 access without the Commerce Department formally lifting its 12 June export-control directive. That is the most plausible path to a consumer restoration in the coming weeks.
For enterprise operators: if your teams use Claude through the Team or Enterprise plan, or via the API, no action is required and no service change is anticipated on 8 July. If your organisation has consumer-plan accounts alongside enterprise credentials — common in firms that allow personal subscriptions — those consumer accounts may encounter the verification prompt. The distinction between tiers matters more than it did two weeks ago.
EU Article 50 — The No-Grace-Period Trap for New Products
The 2 August deadline for EU AI Act Article 50 has been in view for weeks. The detail that is less widely understood is the asymmetry in the transitional provisions: AI systems already on the market before 2 August have until 2 December 2026 to implement machine-readable marking of synthetic outputs. Systems entering the market on or after 2 August receive no grace period whatsoever — they must mark from day one of deployment.
The marking requirement applies across all modalities: text, images, audio, and video. Any team planning to launch a new AI-assisted product — or a material new feature using generative AI outputs — in August or later must have Article 50 compliance built into the product architecture before go-live, not scheduled as a follow-up sprint. The EU AI Office has published the technical standard for the marking format. July 1 is the last month in which this can still be treated as a forward obligation; from August 2 it becomes a day-one launch requirement for anything new.
The through-line across today's items is that each one is a decision that has already been made for you: Microsoft has deployed the agents, OpenAI has committed the infrastructure date, Anthropic has set the policy clock, and the EU has drawn the product-launch line. What remains is governance — deciding how your organisation responds to the new defaults rather than waiting to be told.