Microsoft Security Copilot
Big Tech Burns Cash on AI While an Unpatched 'Worm' Stalks Microsoft Copilot
The major American technology companies — Microsoft, Alphabet, Amazon, and Meta — collectively committed to $170 billion in AI capital expenditure in a single quarter, a rate of spending without historical precedent for any single technology category. For the first time, aggregate free cash flow across the group turned negative in the quarter: the companies are spending faster than they are generating cash. Microsoft alone posted $90 billion in quarterly revenue while confirming that Copilot is being positioned as a 'super app' — the primary interface layer for everything from code to spreadsheets to Teams conversations.
The same week Microsoft was celebrating the Copilot super-app vision, a security researcher published findings that a vulnerability in the product — described as an 'AI worm' — had survived 144 days despite the company's attempts to patch it. The mechanism works by embedding a hidden text string in a Word document that instructs Copilot to alter data and propagate the payload to subsequent documents the tool processes. Because Copilot is sold specifically to large enterprises as a tool that reads and processes internal documents at scale, the worm targets precisely the use case Microsoft is monetizing most aggressively. That it has survived 144 days of known, reported existence without a successful fix suggests a structurally difficult problem rather than a simple coding oversight.
Google offered a contrasting AI security narrative. The company reported that its Gemini-based automated bug discovery and patching tools fixed 1,072 Chrome security vulnerabilities across just two releases — more than all security fixes from the prior 23 Chrome versions combined. The divergence captured a central tension in AI-assisted security: the same category of technology is simultaneously creating new attack surfaces and enabling dramatically faster remediation of existing ones, with the net effect on security posture genuinely unclear.
Meta's earnings footnotes disclosed $279 billion in off-balance-sheet AI data center leases — up 53 percent from the prior quarter. Off-balance-sheet treatment means these commitments do not appear as debt under current accounting rules, but they represent real financial obligations. Aggregated across Microsoft, Amazon, Google, and Meta, the total capital commitment to AI compute infrastructure over the next five years reaches into the multiple trillions of dollars. LinkedIn, meanwhile, announced a 'seems like AI slop' community flagging tool allowing users to identify inauthentically AI-generated posts, while simultaneously removing its own built-in AI writing assistant and deprioritizing algorithmically flagged content — a notable reversal for a platform that was among the earliest enthusiastic adopters of AI writing tools.
Anthropic's one-and-a-half billion dollar copyright settlement with authors received attention not for its headline figure but for its distribution: some individual authors are receiving as little as $5,000. When a total settlement of that size is divided across potentially hundreds of thousands of claimants, the per-person amounts feel dismissive relative to the scale of creative work involved. The terms of this settlement will likely shape how future AI training data negotiations are structured.