Hanso Heartbeat Hanso Heartbeat
Microsoft launched a $2.5 billion forward-deployed engineering unit to embed AI engineers inside enterprise customers; Z.ai's GLM-5.2 is growing 80x faster than Anthropic on Vercel; and the SharePoint KEV patch deadline passed on 4 July.

Issue 27

4 July 2026

Hi there,

Microsoft Frontier Company is the most interesting thing Microsoft announced this week, and it got less attention than it deserved. The idea is simple: take 6,000 engineers, embed them directly inside enterprise customers, and charge for successful AI deployments rather than seats. It’s the forward-deployed engineering model that Palantir built its reputation on, applied to Copilot and Azure at scale. Amazon announced a $1 billion version two days earlier. OpenAI and Anthropic did theirs in May. The whole AI industry is quietly converging on "sell outcomes, not subscriptions" as the model for enterprise – which is a very different sales motion than anything the software industry has run for the last twenty years.

The other thing worth noting: Z.ai’s GLM-5.2 is growing 80 times faster than Anthropic on Vercel’s infrastructure, at roughly a fifth of the cost, and it’s within a percentage point on the agentic benchmarks that matter. The "what model are we actually using" conversation has an answer now that isn’t always a US lab, and that answer is increasingly Chinese.

Industry

1. Microsoft launches Frontier Company – $2.5B, 6,000 engineers, embedded inside customers

Microsoft Frontier Company is a new operating business backed by $2.5 billion and staffed with 6,000 industry and engineering experts, led by Rodrigo Kede Lima (currently running Microsoft’s Asia business). The model is forward-deployed engineering: Microsoft’s people work inside the customer, designing, deploying and managing AI systems tailored to their operations. Early partners include the London Stock Exchange Group, Unilever, Land O’Lakes and Accenture. Amazon announced a $1 billion version two days earlier; OpenAI and Anthropic launched similar units in May. The entire AI industry is converging on the same realisation: the bottleneck is no longer the model, it’s making enterprise customers actually succeed with it. Hanso is a Microsoft partner, so "Microsoft now sells forward-deployed AI engineering" is less background noise and more something to understand clearly.

2. Chinese AI keeps taking market share on price

Z.ai’s GLM-5.2 grew token volume 27x and customer count 80x in its first full week on Vercel – the fastest adoption curve Vercel has tracked. It lands within a percentage point of Anthropic’s Opus 4.8 on leading agentic benchmarks at roughly a fifth of the cost. On OpenRouter, Chinese models now account for more than 30% of weekly token volume, touching 46% at peak; a year ago the figure was 4.5%. DeepSeek V4-Pro outputs a million tokens for $3.48 against Anthropic’s $25 for the same. The enterprise AI supply chain is quietly reorganising around price, and the default is no longer automatically a US lab.

StreetComplete: fixing the map, one quest at a time
StreetComplete — aerial city view with OpenStreetMap quest pins

StreetComplete hit the top of Hacker News this week, and earned it. It's an Android app that turns OpenStreetMap contribution into a series of small quests: walk past a building, answer "what are the opening hours?" or "is there a ramp here?" The answers go straight into OSM. No GIS knowledge required. You just walk around and answer questions.

It's the second most-used OSM editor by user count, and it's a smartphone app. Worth knowing about against the backdrop of the ongoing concern about AI-generated OSM edits flooding the database with plausible-sounding but unverified data. Humans, walking, answering questions they can verify: still the most reliable way to get accurate ground-truth map data.

Infrastructure

3. The EU’s Cloud and AI Development Act takes shape

The European Commission formally proposed the Cloud and AI Development Act this month – scaled capital investment, protected data residency requirements, and a framework to build out a more resilient sovereign computational ecosystem across member states. It arrives in the same quarter as the AI Act’s high-risk provisions take full effect (17 July). Europe is building the regulatory and infrastructure stack for AI simultaneously, which is either impressively coherent or dangerously slow depending on your read of the timeline.

Microsoft

4. SharePoint CVE-2026-45659 KEV deadline passed today

The CISA Known Exploited Vulnerabilities deadline for CVE-2026-45659 – the SharePoint deserialization RCE (CVSS 8.8) – was today, 4 July, giving federal agencies three days from the KEV listing to patch. Exploitable by any authenticated user with Site Member permissions, no interaction required. Microsoft patched it in May and originally rated exploitation as "less likely." CISA’s addition means exploitation is confirmed. If you run on-prem SharePoint and haven’t applied the May update, the federal deadline has passed. The practical standard is the same regardless of whether you’re a federal agency.

5. Microsoft 365 with Copilot becomes a permanent SKU

From 1 July, Microsoft 365 Business Standard with Copilot and Microsoft 365 Business Premium with Copilot are permanent SKUs rather than add-ons. The bundling move is part of the broader Copilot consolidation announced at Build – one product, one price, one inbox. Whether that makes it easier or harder to justify the spend depends on whether you were going to buy Copilot anyway.

Development

6. npm v12 is here – and it broke some pipelines

npm v12 shipped this week as signalled. Install scripts in dependencies now require explicit approval; Git and remote-URL dependencies are blocked by default. Teams that ran the npm 11.16.0 warnings got here cleanly. Teams that didn’t are fixing CI pipelines today. The supply-chain rationale is sound – this year’s run of npm attacks (Miasma, Red Hat namespace, Azure Durable Task) made opt-in execution the right default. The migration cost is real but bounded: npm approve-scripts, review what runs, commit the result.

Information Security

7. The Azure CLI ROPC password spray: 81 million attempts, MFA bypassed

Between 12 and 26 June, attackers ran 81 million login attempts against Microsoft 365 accounts via Azure CLI, compromising at least 78 accounts across 64 organisations – including shops with MFA enabled. The bypass used the ROPC OAuth flow (deprecated in OAuth 2.1), which exchanges credentials at the token endpoint without triggering an interactive auth step. Conditional Access policies enforcing MFA at the authorisation endpoint don’t catch it. Eight of the affected organisations had no MFA at all. The fix: enforce Conditional Access across all cloud apps, block legacy auth flows, treat Azure CLI as the same authentication surface as the browser. The ROPC gap has been documented for years. Still open at a lot of organisations.

Coming up

Thu 17 Jul: EU AI Act high-risk provisions take full effect. Grace period ends.

Thu 31 Jul: curl reopens its vulnerability inbox after its AI-spam-induced summer closure.

Aug: Apple Foundation Models framework open-source release expected.

Oct: Anthropic IPO window opens.

Until next week, Julian

How this is made

Throughout the week I stumble across a mildly unreasonable number of interesting things, and I forward them instantly to the friend or colleague I think might care – sometimes to their delight, sometimes to their annoyance, and often with no context at all. Heartbeat is the attempt to do that a little better.

Every Friday a small agent I built, Honoka, looks through the places where those links tend to leak out: my private email, work email, Matrix, Mastodon, WhatsApp, Apple Messages, Signal, and the faint imprints on the platen of my Olympia typewriter (still not an API, tragically). It sorts, filters, groups and summarises the week, then hands me a draft.

Honoka is guided by a private corpus of things I have written over the last fifteen years, so it can get closer to how I sound in more-or-less official emails and public notes. I still take a pass by hand: remove things, change sentences, check links, argue with the judgement. Whether that is enough is, frankly, the experiment. Every issue has one item written entirely by hand. If you can reliably spot it, hit reply and judge.

Hanso Hanso
Hanso Pte Ltd · 1 Phillip Street #08-00, Singapore 048692
www.hanso.group