Microsoft is remaking its own stack for the AI era, on both offence and defence. This week it moved on two fronts. It began pulling OpenAI’s models out of its most-used apps to cut costs. And it set a date to kill the text-message login, blaming a wave of AI-powered phishing.
The two announcements look nothing alike, yet they share a driver.
Swapping OpenAI out
Microsoft is replacing OpenAI’s image-generating models with its own technology in PowerPoint and Bing, Bloomberg reported. “It’s faster, it’s cheaper, it’s higher quality, it drives better retention,” Microsoft’s AI chief Mustafa Suleyman said.
The decisive word is cheaper. Suleyman said the company’s own MAI models run about 85% cheaper than OpenAI’s in PowerPoint.
Microsoft still gets OpenAI’s models free under their partnership. But it pays to run them, and that compute bill is enormous. It began replacing OpenAI and Anthropic text models in its office apps earlier this month, matching GPT-5.6 on common Excel tasks at lower cost.
Images are next. MAI models now run in more than half of all Microsoft products, and the company is testing them in every one. T-Mobile and Britain’s EasyJet are already using its voice models in their call centres.
The subtext is independence.
Suleyman, the DeepMind co-founder hired last year to run its own AI push, was brought in to loosen the reliance on OpenAI. Microsoft has poured more than $100 billion into that partnership. Every app it moves in-house makes OpenAI look a little less like a partner, and a little more like a vendor.
The death of the SMS login
The second move is defensive. From 1 September, passkeys become the default sign-in for Entra ID, Microsoft’s business identity service. From 1 February 2027, the company will stop sending its own SMS and voice-call codes altogether. Windows Hello and FIDO2 security keys stay.
The humble text-message code is being shown the door.
The reason is AI. “The AI era demands stronger, phishing-resistant authentication,” Microsoft said. Its own figures explain why. AI-assisted phishing emails get a 54% click-through rate, against 12% for conventional ones.
AI has made scams far more convincing, so the weakest login method has to go. Passkeys help because an attacker would need the victim’s actual device, not just a stolen code.
Neither move is as clean as it sounds. Microsoft frames its models as matching OpenAI only on “common” tasks, and much of the rollout is still in testing. Passkeys are no silver bullet either, which is why biometrics and hardware keys remain.
Still, the through-line is plain. AI is both the thing Microsoft wants to run more cheaply, and the reason it has to lock its doors differently. Even Google now lets you sign in with a selfie. The password’s long goodbye is speeding up.
Get the TNW newsletter
Get the most important tech news in your inbox each week.
