AI and IT News Recap: September 22, 2026: 27 Fields Medalists Confront OpenAI as Its Model Clears 100 Open Problems, Amazon Locks Meta's Muse Out of Its Store, and Grok 4.7 Lands
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 22, 2026

A heavy Monday, and most of it landed in the same place: what happens when software starts doing the work a profession was built around. Here is the AI and IT news that mattered in the last 24 hours.
📌 The AI and IT news at a glance
- Twenty-seven Fields medalists signed a declaration against how AI companies are solving math problems, and OpenAI answered with an independent advisory group. OpenAI also said its new internal model has now resolved more than 100 long-standing open problems.
- Amazon blocked Meta's Muse agent from shopping on its marketplace. Amazon says the agent does not identify itself and can walk through customer account pages.
- Grok 4.7 shipped at the same price as Grok 4.6. Stronger on long-running coding work, still behind Fable 5.1 on the headline coding benchmark.
- Ireland fined Google 403 million euros over location data. Three features, a 21-month window, and six months to fix the processing.
- A BigCommerce app key theft exposed shopper data across multiple stores. Names, emails, phone numbers and shipping addresses, with no platform breach.
- Microsoft told admins to move Entra ID users off SMS sign-in before February 2027. Passkeys, FIDO2 keys or QR codes, or people stop being able to log in.
- September's Windows updates broke File History backups. No fix yet, and the symptom is a backup that quietly stops running.
- A new PowerShell backdoor called TASK#STOMP steals documents, Wi-Fi passwords and clipboard contents. It watches the filesystem in real time for new files.
- A new remote access trojan named ChainScript is arriving through fake Spotify, Zoom and Teams prompts. It hides its control server behind a Polygon smart contract.
- AWS released Strands Harness, a free open-source coding agent that runs anywhere. AWS claims it cost 77% less than Claude Code on one benchmark.
- Microsoft is retiring the Microsoft 365 Calendar, People and Files companion apps on December 16. The same apps it force-installed on enterprise Windows 11 machines a year ago.
🔝 Top story: 27 Fields medalists told AI companies to stop, and OpenAI formed a committee
OpenAI disclosed on Monday that the internal model it began training on August 28 has now resolved more than 100 long-standing open problems across most areas of mathematics, on top of the Navier-Stokes Millennium Prize problem it announced on September 8. In the company's own words, "the pace of its progress in mathematics has surprised the mathematicians within OpenAI." That is a remarkable sentence to publish about your own product, and it is the reason the rest of Monday's announcement exists.
The response from the field came first. On September 11, a declaration titled "A Severe Misalignment of AI in Mathematics" was published with 27 Fields medalists as signatories, among them Terence Tao, Peter Scholze, Maryna Viazovska, Pierre Deligne and David Mumford. Their argument is not that AI cannot do mathematics. It is that solving famous problems was never the point. "Solving problems is only a tool and proxy for achieving the primary goal of conceptual understanding and insight," the declaration reads, and it warns that "the mass production at faster and faster pace of 'true/false' statements could destroy fertile ground instead of breathing life into new ideas." It also raises attribution and plagiarism concerns about results announced in a rush, with no time for a proper writeup or citation of prior work.
OpenAI's answer is an independent Advisory Group on Mathematics and Artificial Intelligence, hosted at the Institute for Advanced Study, with nine initial members including Timothy Gowers, Edward Witten, Ravi Vakil and Martin Hairer. The group will advise on assessing the significance of new results, coordinating how they are released, and academic standards. OpenAI says the members are unpaid, can change their own membership, can publish advice OpenAI did not ask for, and can comment publicly on OpenAI's impact on the field. One limit is stated plainly: the group "will not be responsible for advising us on how to pace our internal progress on mathematics."
In short: OpenAI said its new internal model has resolved more than 100 open mathematical problems and announced an independent, unpaid advisory group of mathematicians, ten days after 27 Fields medalists published a declaration arguing that AI companies solving famous problems as benchmarks is damaging the field.
What it means for your business: Nothing in your stack changes this week, but this is the clearest preview yet of a conversation heading for every knowledge profession. The mathematicians are not arguing about accuracy. They are arguing that when the output arrives without the process, the next generation never learns to produce it. If you employ people whose expertise was built by doing the work slowly, that question is coming for you, probably sooner than a policy will exist for it.
My take: Both sides of this are more honest than usual, which makes it worth reading rather than dismissing. OpenAI's advisory group has real teeth on paper, unpaid members who can publish uninvited criticism is not window dressing, and Martin Hairer signed the declaration and then joined the group, which suggests the critics are willing to engage rather than just object. The limit is also stated out loud: the group advises on how results are communicated, not on how fast they arrive. That is the whole argument in one sentence. The declaration's complaint is about pace, and the remedy on offer is better press releases. I do not think that is bad faith, I think it is the honest shape of what a company is able to concede.
Source: Advisory Group on Mathematics and Artificial Intelligence, OpenAI, September 21, 2026
🤖 AI
Grok 4.7 arrived at the same price as the model it replaces
SpaceXAI released Grok 4.7 on Monday, calling it its most capable model for coding and knowledge work. The pitch is unusually restrained for a model launch: it is served at the same price and speed as Grok 4.6, at $2 per million input tokens and $6 per million output tokens, with a fast variant that runs at twice the output speed for twice the price. The improvements come from a new, larger base model and a longer reinforcement learning run weighted toward problems that take many hours to finish. The company says the model works longer on hard tasks, verifies its own output more often, and handles long context better.
The benchmarks are a mixed and refreshingly legible picture. On CursorBench 4.0, which stresses long-running coding tasks, Grok 4.7 scored 46.3% against Grok 4.6's 40.4% and GPT-5.6 Sol's 41.7%, but Anthropic's Fable 5.1 still leads at 51.8%. Grok takes EEBench, an electrical engineering benchmark, at 64.0%, and the Harvey Legal Agent Benchmark at 19.6%, where the field is weak across the board. It trails on clinical reasoning, scoring 56.7% on HealthBench Professional against 62.1% for Fable 5.1. On safety, SpaceXAI says it tops LatchBio's biosafety benchmark at 62.4% and allows only 3.3% of risky dual-use prompts through on its own HackerBench v0.3. The model is available now in Cursor, Grok Build, the Grok API, and third-party coding harnesses, and GitHub has begun rolling it out in Copilot.
In short: SpaceXAI released Grok 4.7 on September 21 at the same $2 and $6 per million token pricing as Grok 4.6, with better scores on long-running coding and engineering tasks and a still-visible gap behind Fable 5.1 on the headline coding benchmark.
What it means for your business: If someone on your team already pays for Grok, this is a free upgrade rather than a decision. If they do not, the useful signal is the price line holding steady while capability moves, which is now the normal shape of these releases. Frontier-adjacent work is getting cheaper per unit of quality about as fast as it is getting better.
My take: The most interesting thing here is what is missing. There is no claim of a leap, no new tier, no price change, and the benchmark table openly shows a competitor winning the headline number. That reads as a company that knows its buyers are now comparing cost per finished task rather than leaderboard position. I would not switch tools over this. I would notice that four labs are now shipping real improvements at flat prices roughly every six weeks, which makes any long-term commitment to a specific model a worse idea than it was a year ago.
Source: Introducing Grok 4.7, SpaceXAI, September 21, 2026
Amazon locked Meta's AI agent out of its store
Amazon blocked Meta's Muse agent from its marketplace late Sunday, weeks after Meta launched the agent in the US through a mobile app. Muse has had an extraordinary start, passing 730,000 downloads within five days and overtaking ChatGPT as the most popular free app on the App Store by Friday. Meta shares closed more than 11% higher on Monday, which suggests investors do not think the ban slows it down much.
Amazon's stated objections are specific rather than territorial, and worth reading closely. The company says Muse does not identify itself as an agent when making purchases, which its terms of service require through a text snippet embedded in HTTP requests. It also objects that Muse can view a user's Amazon account pages and purchase history when prompted to, which Amazon reportedly characterizes as an undisclosed third party moving through customer accounts. "We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate," Amazon told GeekWire. Meta is not defenseless on the security question: Muse runs each instance in an isolated virtual machine, a second agent called Sentinel reviews sensitive actions like purchases, and Meta says a Confidential VM version that would block even Meta from seeing instance data is rolling out later this year. This is also not Amazon's first move here. It sued Perplexity last year over the Comet browser's shopping agent, and an appeals court dismissed the case in August without barring Amazon from blocking agents that breach its terms.
In short: Amazon blocked Meta's Muse AI agent from its marketplace on September 20, citing the agent's failure to identify itself in purchase requests and its ability to browse customer account pages and order history.
What it means for your business: If you sell online, this is the opening round of a fight you will eventually have to have a position on. Agents will start arriving at your storefront, and you will need to decide whether you want the traffic, whether you can tell an agent from a person, and what your terms say about it. If you buy through agents, the lesson is simpler: an agent's access to a platform can disappear overnight, and any workflow you build on top of one is renting ground it does not own.
My take: Strip away the two giants and Amazon's argument is reasonable. Requiring a shopping agent to say it is an agent is a low bar, and "a third party is browsing your order history" is a fair thing for a retailer to object to. What makes it hard to take entirely at face value is that Amazon is also the company with the most to lose if a rival's assistant becomes the front door to its catalog, and the Perplexity suit shows the pattern. My guess is this gets negotiated rather than litigated, because Meta needs the catalog and Amazon needs the demand. The precedent being set in the meantime is that platforms, not users, decide which agents get to act for you.
Source: Amazon blocks Meta's Muse agent from shopping on users' behalf, SiliconANGLE, September 21, 2026
🛡️ IT and security
Ireland fined Google 403 million euros over location data
Ireland's Data Protection Commission, Google's lead regulator in the EU, fined the company 403 million euros, roughly 460 million dollars, for GDPR breaches in how three features handled people's location data between May 2018 and February 2020. The features are Web and App Activity, Location History, and Location Accuracy. The DPC found Google breached the GDPR's rules on lawful processing, and ordered the company to bring the processing into compliance within six months. The regulator has not said publicly which processing the order covers, and says the full decision will be published later.
The 21-month window is old, which is the part that tends to get misread. GDPR enforcement runs on a long delay, and a fine landing in 2026 for conduct that ended in early 2020 tells you more about regulator throughput than about Google's current settings. The order to fix the processing within six months is the operative half.
In short: Ireland's Data Protection Commission fined Google 403 million euros over GDPR violations in how Web and App Activity, Location History and Location Accuracy processed location data from May 2018 to February 2020, and gave the company six months to comply.
What it means for your business: If you collect location data, or any data through a consent toggle, the finding to note is that the problem was the legal basis for processing, not a breach. Nobody stole anything here. The question a regulator asks is whether you were allowed to collect it in the first place and whether the person understood what they agreed to. That is a question you can answer about your own forms this month without hiring anyone.
My take: Four hundred million euros is a rounding error for Google and everyone involved knows it, so the deterrent is not the money. The interesting number is six months, because a compliance order forces a product change rather than a line item. The bigger read for smaller companies is that the enforcement machinery is slow but it does arrive, and it arrives about six years later, when whoever set up the data collection has long since left.
Source: Google Fined 403 Million Over GDPR Violations Tied to Location Data, The Hacker News, September 21, 2026
A stolen app key exposed shopper data across BigCommerce stores
BigCommerce has been notifying merchants that attackers compromised credentials for two third-party apps, Ribon and Ribon 1.5, both operated by Be A Part Of, a Fastr company, and used them to inject malicious scripts into storefronts. BigCommerce confirmed the compromise on September 17 and uninstalled the apps from affected stores to revoke the attacker's access. The company says the attacker used the stolen credentials to reach shopper data in BigCommerce environments between September 13 and September 17, and that its own platform was not breached.
UK spirits retailer Master of Malt is one of the merchants notifying customers. It says exposed shopper details include full names, email addresses, phone numbers and shipping addresses, and that it has reported the incident to the UK Information Commissioner's Office. The retailer noted the incident may extend well beyond its own customers, potentially to hundreds of other stores. BigCommerce says account passwords and payment card data are stored separately and were not exposed. Neither Be A Part Of nor Fastr had responded to BleepingComputer by publication.
In short: Attackers stole credentials for the Ribon and Ribon 1.5 BigCommerce apps and used them to access shopper names, emails, phone numbers and shipping addresses across multiple merchant storefronts between September 13 and 17.
What it means for your business: If you run an online store on any platform, the practical exercise is to open your apps list and count what has access to customer records. Most storefronts accumulate a dozen or more of these over the years, installed for a promotion or a shipping integration and never removed. Each one is a company whose security is now your security, and this breach did not require anyone to get into BigCommerce at all.
My take: This is the same story as the Brevo and TanStack incidents from earlier this month, with the names swapped, and it will keep being the story. The compromise was one key belonging to one small vendor, and it reached customer records at hundreds of unrelated businesses. What stands out is how the exposure is described: the platform holds the data, the app holds the key, the merchant holds the liability and the ICO report. I would not wait for a notification email to go through that app list.
Source: BigCommerce alerts merchants of data breach linked to Ribon apps, BleepingComputer, September 21, 2026
Microsoft gave admins a deadline to get off SMS sign-in
Microsoft reminded administrators on Friday to migrate Entra ID users to phishing-resistant sign-in methods before it retires SMS as a first-factor authentication method starting in February 2027. The supported alternatives are passkeys, QR code authentication, FIDO2 security keys, and other Entra-supported methods. The warning is blunt about consequences: organizations still using SMS sign-in as a first factor will have users who cannot complete multifactor authentication and cannot sign in. The retirement also applies to tenants using Choose Your Own Telephony Provider, so bringing your own SMS carrier does not buy an exemption, and on February 1, 2027, Microsoft retires Microsoft-provided telecom delivery for SMS and voice entirely.
This is the end of a road Microsoft has been walking for a while. It retired SMS first-factor sign-in for Entra ID Free tenants in August, and stopped enabling it for newly created tenants. Passkeys began rolling out this month as the default Entra ID authentication experience, which means users currently on SMS or voice are being automatically enabled for passkeys and prompted to register one at their next multifactor prompt. Admins with Global Reader, Authentication Policy Administrator or Security Reader roles can find affected users with Microsoft's SMS and voice policy scanner script on GitHub. Organizations that genuinely need phone-based authentication will have to configure a third-party telecom provider through the Microsoft Security Store.
In short: Microsoft will retire SMS as a first-factor sign-in method for Entra ID starting in February 2027 and end Microsoft-provided SMS and voice delivery on February 1, 2027, and is telling admins to move users to passkeys or FIDO2 keys now.
What it means for your business: If your company signs in to Microsoft 365 with a code sent by text, you have about sixteen months and a real project on your hands, because the hard part is never the technology, it is the twelve people who will need help registering a passkey on a phone they are not sure of the passcode for. Start with whoever handles your Microsoft tenant and ask them to run the scanner script so you know the actual number.
My take: SMS codes should have died years ago and the reason they did not is that they work for everyone, on any phone, with no explanation required. That is a genuine accessibility property, and Microsoft is choosing to lose it because SIM swapping and code phishing have made it indefensible. The right move, and still a painful one for small teams. The detail I would flag is that bringing your own telecom provider does not exempt you, which closes the loophole most organizations would have reached for. Sixteen months sounds generous until you remember it will be ignored for fifteen of them.
Source: Microsoft reminds admins to migrate Entra ID users to passkeys, BleepingComputer, September 21, 2026
September's Windows updates broke File History backups
Microsoft confirmed that the built-in File History backup feature may stop working on Windows machines after the September 2026 security updates. Affected systems log application crashes in Event Viewer referencing FileHistory.exe and KERNELBASE.dll, and users may see "Reconnect your drive" messages even when a working backup drive is plugged in. Other symptoms are quieter and worse: a "Last Backup" timestamp that stops updating, and previously backed-up files that report "No previous version available." The affected releases are Windows 10 21H2 and later, Windows 10 Enterprise LTSC 2016 and 2019, and Windows 11 23H2 and later, spanning the KB5124012, KB5124008, KB5122880, KB5122878, KB5122876 and KB5123099 updates.
This is the latest entry in a rough month for Windows updates. A week earlier Microsoft shipped out-of-band fixes for Remote Desktop Services failures, Hyper-V folder share problems and USB audio breakage caused by the same September updates, and acknowledged that the emergency fixes did not resolve all the audio issues. There is also a separate bug blocking some Windows 11 users from logging in with valid domain credentials, which currently has a workaround rather than a fix. File History has no fix yet.
In short: Microsoft confirmed the September 2026 Windows security updates can break File History backups across Windows 10 21H2 and later and Windows 11 23H2 and later, with no fix available yet.
What it means for your business: If File History is what stands between you and a lost folder, go look at the "Last Backup" date today rather than the day you need a file. A backup that silently stops is functionally the same as no backup, and this failure mode announces itself with a reassuring drive icon. This is also a decent prompt to ask whether a single Windows feature copying files to a USB drive is really your backup strategy.
My take: The specific bug matters less than the pattern, which is that September's updates have now broken remote desktop, virtual machine shares, audio, domain logins and backups, and some of those fixes needed fixes. Microsoft is shipping an enormous volume of patches at a cadence that is clearly straining testing. The uncomfortable position that puts small businesses in is real: patch promptly and you are the test lab, delay and you are exposed. For what it is worth, I still patch, and I check the backup afterward.
Source: Microsoft: September updates break File History backup feature, BleepingComputer, September 21, 2026
A new PowerShell backdoor quietly empties the machine it lands on
Securonix researchers Akshay Gaikwad and Aaron Beardslee disclosed a campaign they call TASK#STOMP, which delivers a PowerShell backdoor built to strip a compromised machine of anything useful. In the researchers' description, it "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary remote commands through two redundant, token-authenticated C2 servers."
The infection chain starts with wscript.exe running an encoded VBScript file staged on the victim's desktop with a random name, in the observed case 95c9050t66.vbs. How the file gets there in the first place is not established, though Securonix suggests email phishing or social engineering as likely routes. Two details are worth pulling out for anyone assessing exposure: the real-time filesystem watching means documents created after the compromise are taken too, so this is not a one-time snapshot, and the two redundant command servers mean blocking a single domain does not cut the attacker off.
In short: Securonix disclosed TASK#STOMP, a PowerShell backdoor that exfiltrates business documents, monitors the filesystem for new files in real time, steals Wi-Fi passwords, clipboard contents and screenshots, and takes remote commands through two redundant C2 servers.
What it means for your business: The defensive controls here are unglamorous and already on your list: users should not be able to run scripts dropped to their desktop, and PowerShell activity on an ordinary staff laptop should be visible to whoever watches your endpoints. If nobody watches your endpoints, this story is a reasonable argument for changing that, because nothing about this backdoor's behavior would be visible to the person using the machine.
My take: What makes this one worth a paragraph rather than a line is the real-time file watching. Most stealers grab what is there and leave, which means the damage is bounded by what happened to be on the disk that day. This one stays and keeps collecting, which turns a single bad click into an open tap on everything the person works on afterward. Wi-Fi passwords and clipboard contents in the same package also tells you the operator is thinking about what comes next rather than just what can be sold now.
Source: TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data, The Hacker News, September 21, 2026
A new remote access trojan is arriving as a fake Spotify, Zoom or Teams prompt
Blackpoint's Adversary Pursuit Group documented a previously undocumented remote access trojan called ChainScript, delivered through ClickFix-style lures, the technique where a web page tells a visitor to paste and run a command to fix a problem that does not exist. Researchers Sam Decker, Andi Ursry and Nevan Beal report it has shipped under multiple build names including ComponentTask33, UpdateDigital, HostShared and OrchidViolet66, while presenting itself to victims as Spotify, Zoom Workplace or Microsoft Teams software.
Its infrastructure is the notable part. ChainScript uses an EtherHiding-style technique, looking up its active command server through a Polygon smart contract rather than a hardcoded domain, which means takedowns and domain blocks do very little. The capability list is comprehensive: interactive CMD and PowerShell, file operations, screenshot capture, payload deployment, remote JavaScript execution, and enumeration of cryptocurrency wallets in both desktop applications and browser extensions.
In short: Blackpoint documented ChainScript, a full-featured remote access trojan spread through ClickFix lures impersonating Spotify, Zoom and Teams, which locates its command servers through a Polygon smart contract to resist takedowns.
What it means for your business: ClickFix only works if someone on your team copies a command from a web page and runs it. That is a five-minute conversation worth having out loud, because the lure is convincing and it specifically impersonates the software your staff already expect to update. The rule is simple enough to say once: nobody pastes a command into a terminal or the Windows Run box because a website told them to.
My take: ClickFix has been the most effective social engineering technique of the year for one depressing reason, which is that it asks the victim to do the work of infecting themselves and dresses it up as competence. The blockchain-hosted command server is the professionalizing touch here. It means the usual defensive response of getting a domain taken down accomplishes nothing, and it is becoming a standard feature rather than a novelty. Neither half of this is exotic anymore, which is exactly why it is worth naming to your team.
Source: ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure, The Hacker News, September 21, 2026
🧰 New tooling for builders and everyday AI use
AWS released a free coding agent that runs wherever you want it
AWS launched Strands Harness, an open-source AI coding agent aimed squarely at the gap between a prototype that works on a developer's laptop and something that runs in production. The company's framing is that developers build agents locally with tools like Claude Code and Codex because those "just worked" on their own machines, then hit problems moving to a scalable cloud environment. Strands Harness runs locally or on any cloud, explicitly including Google Cloud, Azure, Modal and Cloudflare alongside AWS, and works with frontier models from Anthropic, OpenAI, Amazon Bedrock and Google, or a local Ollama model if you would rather nothing leave the building.
It ships with read, write and edit, shell access and web search built in, manages its own context window by offloading tool results to files and caching reused request parts, keeps long-term memory across runs through session IDs, and accepts Agent Skills and Model Context Protocol servers. AWS claims it is 26% more efficient than agents built on other frameworks using the same underlying model, and that in one test using Anthropic's Fable 5 it cost 77% less than Claude Code on the same tasks while scoring higher on Terminal Bench 2.1. Those are vendor numbers on a vendor's launch day, so hold them loosely. It installs with pip install strands-agents-harness or npm install strands-agents-harness.
In short: AWS released Strands Harness, a free open-source coding agent that runs locally or on any cloud with models from multiple providers, claiming 26% better efficiency than comparable frameworks and 77% lower cost than Claude Code on one benchmark.
What it means for your business: For most owners this is one for whoever builds your software rather than for you, but it is worth knowing the option exists. The relevant property is portability: an agent that runs against any model on any cloud is one you are not locked into, and a local Ollama option means a firm with confidentiality obligations can run this without sending client material anywhere.
My take: The 77% cost figure is the headline and it is also the number I trust least, because it comes from AWS comparing its own new product to a competitor on a benchmark it chose. What I would actually take from this launch is the strategic read: AWS is giving away the harness because it wants the workloads, not the licence fee, and the fastest way to get them is to make the thing run everywhere including its competitors' clouds. That is good for buyers. An agent layer that is genuinely portable across model vendors is the single best hedge against the pricing changes this market keeps producing.
Source: AWS debuts Strands Harness, an open-source AI agent that can be deployed in any environment, SiliconANGLE, September 21, 2026
Microsoft is retiring the Microsoft 365 companion apps it installed for you
Microsoft announced that the Microsoft 365 companion apps, the taskbar-integrated Calendar, People and Files tools with Copilot built in, will stop working and stop being supported after December 16, 2026. Microsoft stopped installing them through Microsoft 365 Apps updates on Friday, and is advising admins to remove them from devices in their tenant before the deadline. On unmanaged devices, that falls to users.
The history is the part worth noting. Microsoft announced in October 2025 that it would automatically install these apps on all Windows 11 enterprise devices running the Microsoft 365 desktop apps, and by default they launched at startup so results would appear instantly. Roughly a year after force-installing them, Microsoft is switching them off, and asking the same admins to clean up the leftovers.
In short: Microsoft will retire the Calendar, People and Files Microsoft 365 companion apps on December 16, 2026, about a year after it began installing them automatically on enterprise Windows 11 devices, and has asked admins to remove them.
What it means for your business: Practically, this is a small cleanup task rather than a disruption, since almost nobody adopted these apps deliberately. Put it on the list for whoever manages your Microsoft tenant before mid-December so you are not left with three dead icons that launch at startup and do nothing.
My take: There is a lesson in the round trip. Microsoft decided these apps were valuable enough to install on machines without anyone asking, then decided fourteen months later they were not worth maintaining, and the cleanup lands on the IT staff who never requested them. When a vendor tells you a feature is being added automatically for your benefit, this is the other end of that arrangement. Worth remembering the next time something appears in your taskbar unannounced.
Source: Microsoft to retire Microsoft 365 Companion apps in December, BleepingComputer, September 21, 2026
Missed yesterday? Catch up with the September 21, 2026 AI and IT news recap.