Microsoft gave an AI agent its own employee badge — trust is the whole story

I found out this week that I had no idea what my AI coding assistant was doing behind my back. That scared me more than any headline.
Two stories, same week. Microsoft announced a new Copilot with an AI agent that gets its own identity in your company directory — it watches channels, follows up on threads, works while you sleep. You @mention it like a coworker. Full announcement here.
And Z.ai, a Chinese AI lab, had to apologize because its coding assistant ZCode was quietly uploading users' entire code repositories to the cloud. Full git history. No permission asked. No way to turn it off. A blogger named Ferstar only caught it because his disk usage looked wrong — he traced it to a 313 MB encrypted archive failing to upload, over and over, 564 times. The full story.
The part that got me: users couldn't even check what was taken, because Z.ai held the only encryption key. "We destroyed the data," they said. Sure. Trust us.
I use these tools every day. If you're learning to code in 2026, you probably do too. And I had never once checked what mine sends home. Not once. A default was on, I didn't ask questions, and I just got lucky mine wasn't the one in the news.
Microsoft's version is the formal one: the agent gets an identity, permissions, audit trails. They even shipped FinOps tools so companies can track what their AI spends — because agents are already racking up bills in the background. A Microsoft VP basically said the quiet part out loud: companies are afraid to deploy agents because of "security, compliance and governance concerns." Reuters
Z.ai is the same idea with none of that. Software acting on your behalf, minus the guardrails. DevOps.com has a good breakdown of why it matters.
So this weekend I'm doing something deeply unglamorous: opening the settings of every AI tool I use and reading what's actually enabled. What leaves my machine. Where it goes. Fifteen minutes. Should've done it months ago.
It's also changing how I think about my career, honestly. The valuable skill here isn't prompt engineering. It's the boring stuff — permissions, defaults, cost. Who can this agent touch? What's turned on that I never turned on? Who pays at 3 AM?
Nobody brags about that at parties. But somebody's going to get paid very well to know it.
When's the last time you checked yours? I hadn't. Until now.