Skip to content
Home » Grok Enters Copilot, OpenAI Resets Government Pricing

Grok Enters Copilot, OpenAI Resets Government Pricing

THE MODEL IS NO LONGER THE PRODUCT — THE SEAT IS

Something shifted this week that deserves more attention than the headlines gave it. Microsoft announced that SpaceXAI’s Grok models are rolling out inside Copilot for Word, Excel, and PowerPoint — starting with Frontier program customers — the day after Grok Bot landed in Microsoft Teams with connectors to Salesforce, HubSpot, Gong, Clay, and Granola. Microsoft 365 on X (https://x.com/Microsoft365/status/2098791167185785301). Meanwhile, OpenAI cut its ChatGPT Enterprise license price to zero for roughly 23 million US public-sector employees. OpenAI OneGov 2.0 (https://openai.com/index/expanding-ai-access-us-government/).

Taken separately, each move looks like a product launch. Taken together, they reveal a race to own the seat — the place where a worker already sits — rather than win a head-to-head model comparison.

DISTRIBUTION BEATS CAPABILITY, FOR NOW

The distinction Microsoft drew matters. SpaceXAI had already shipped its own Grok add-ins for Word, Excel, PowerPoint, and Outlook in June and July, and Grok 4.6 has been available on Microsoft Azure Foundry since late August. But those are parallel installs. This week’s announcement puts Grok inside Copilot itself — as a model choice within the tool that is already open, not a separate application a user must seek out.

That framing — “expansion of model choices” — is the tell. Microsoft is positioning Copilot as the interface layer and every model, including Grok, as a pluggable option beneath it. The competitive question is no longer which model wins on benchmarks. It is which interface layer the worker never closes. The announcement specifies neither the Grok version involved, nor pricing, nor a timeline beyond the Frontier program.

OpenAI is playing the same game from a different angle. The OneGov 2.0 agreement with the federal General Services Administration runs 27 months, from October 1, 2026, through December 31, 2028. The per-user license drops from $15 per month to zero, with no minimum commitment. Model usage is billed at half the commercial rate. States, local governments, and tribal governments are eligible for the first time. Full terms, OpenAI (https://openai.com/index/expanding-ai-access-us-government/). At that price, the friction of switching to a competing model is almost entirely political rather than financial.

OPENAI’S REGULATORY PLAY IS NOT SEPARATE FROM ITS SALES PLAY

Two days before the GSA announcement, Chris Lehane, OpenAI’s Chief Global Affairs Officer, published an op-ed calling on Congress to pass mandatory, capability-based AI regulation before the end of its session. OpenAI policy op-ed (https://openai.com/index/ai-policy-window/). The obligations, he argued, should target the handful of labs developing the most capable systems — not startups, not open-weight models.

Read charitably, that is a principled safety argument. Read structurally, it is also a moat. Compliance costs fall hardest on the labs that can least absorb them. OpenAI also announced support for four California bills, including some it had not previously backed. Lehane wrote: “Some of these bills we did not endorse in the past, and are now supporting after reconsidering in light of the recent jump in capabilities we have seen.” The four bills are SB 813 (independent safety evaluations), AB 1405 (standards for AI auditors), SB 1119 (protection of minors using companion chatbots), and AB 1864 (safeguards against AI-enabled biological threats).

The credible counterpoint is that capability-based thresholds genuinely track risk better than blanket rules. A lab running recursive self-improvement experiments poses different hazards than one shipping a document summariser — and the op-ed explicitly states that fully autonomous recursive self-improvement is not happening today and should not be pursued until it can be done safely. So the policy direction is defensible on its merits. But operators should note that OpenAI is simultaneously the government’s zero-cost supplier and the loudest voice shaping the rules those suppliers will face. That dual role deserves scrutiny regardless of whether the policy positions are correct.

DEEPSEEK’S REVERSAL AND WHAT IT TELLS YOU ABOUT MODEL PRICING

On September 10, DeepSeek announced that V4 Pro would be redirected to V4.1-Flash starting September 14 at 04:00 UTC. By September 12, the documentation said the opposite: V4 Pro would continue at unchanged billing, because user demand warranted it. DeepSeek pricing page (https://api-docs.deepseek.com/quick_start/pricing/). The September 10 announcement post still shows the old schedule. Two contradictory versions remain online simultaneously.

The operational lesson is blunt. Depending on the billing line, V4 Pro costs between 3.3 and 7.3 times more than Flash. Users kept paying it anyway. That tells you something about how sticky a specific model’s output characteristics become once a production pipeline depends on them — and it tells you that the cheapest available model is not always the one your system will actually use when the moment arrives. A lower capture rate on cost savings is the realistic outcome when pipelines are tuned to a specific model’s behaviour.

For teams building on third-party APIs, the DeepSeek episode is a reminder to treat model availability as a variable, not a constant. Deprecation notices can reverse. Pricing can change without announcement. Building a hard dependency on a single model ID is a reliability risk even when the vendor appears committed.

APPROVAL PROMPTS ARE BECOMING A PRODUCT SURFACE, NOT A SAFETY FOOTNOTE

The week’s quietest thread may be the most operationally significant. Gemini CLI’s v0.61.0-nightly.20260912 now requires explicit confirmation before running a build or test command if a build file was modified during the session, or if command arguments came from untrusted external content — Google Docs, Buganizer, web fetch results, or MCP server responses. Gemini CLI nightly notes (https://github.com/google-gemini/gemini-cli/releases/tag/v0.61.0-nightly.20260912.g9c1b0a610). The sandbox is now isolated from the user’s credentials and home directory; on macOS, Seatbelt profiles prohibit writing to ~/.gemini and reading credential stores or hook definitions.

Vibe CLI 2.25.4 made approval mandatory for shell syntax that previously bypassed workspace controls, citing four CVEs (CVE-2026-87984 through CVE-2026-87987) and residual variants of CVE-2026-87988. The severity of these vulnerabilities is not specified in the release notes. Vibe CLI release notes (https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.4). Smart approve now asks for confirmation and displays the reason, rather than silently blocking.

Claude Code 2.1.270 illustrates the failure mode in the other direction. A regression in version 2.1.269 caused it to re-request authorization for simple read-only git commands after a certain amount of session time. Claude Code 2.1.270 release notes (https://github.com/anthropics/claude-code/releases/tag/v2.1.270). Fixing that regression is the entire changelog for that version. Between the vulnerability that lets something through and the prompt that appears too often, calibrating these approval gates is now visible product work — not a configuration detail buried in documentation.

WHAT OPERATORS SHOULD DO BEFORE NEXT WEEK

Four threads, one common implication: the decisions that used to sit with your IT procurement team are now being made by vendors before you are asked. Grok is in Copilot. ChatGPT is free for government employees. DeepSeek’s model availability changed twice in 48 hours. Your CLI agent’s approval logic shipped a regression and a patch in the same week.

This does not mean every change is harmful. But passive adoption — using whatever the platform defaults to — is now a deliberate choice with real consequences for cost, compliance, and control.

The single action worth taking this week: pull the list of model IDs your production pipelines are actually calling — not what your configuration files say they should call, but what the API logs show they are calling — and verify each one still resolves to the model you tested. If any are DeepSeek endpoints, check the API change log (https://api-docs.deepseek.com/updates/) directly rather than the September 10 announcement post; the two sources currently contradict each other, and only the change log reflects current behaviour.

— Eagentix


Eagentix helps growth-focused enterprises redesign and automate manual business processes. We combine executive strategy, implementation support, and managed services to build dependable operations across Southeast Asia.

Sources:

Leave a Reply

Your email address will not be published. Required fields are marked *