Microsoft Just Shipped an AI Agent Feature Whose Entire Job Is Not Trusting the Agent Microsoft released a preview feature called Hooks in Copilot Studio on October 6, 2026, which runs a fixed workflow automatically whenever a specified agent event fires — such as a session starting, a tool running, or an error occurring — rather than waiting for the agent to decide the action is relevant. Microsoft's documentation states a hook should be used "when you need something to happen every time, rather than only when the agent decides it's relevant," distinguishing hooks from tools, which the agent chooses based on name and description and runs only when it judges them relevant. The feature addresses cases where an agent's own judgment cannot be relied on for actions that must occur on every run, such as logging, redaction, or policy checks. Copilot Studio’s new “Hooks” are a quiet admission that agent judgment cannot be trusted with anything that has to happen every time. On October 6, 2026, Microsoft rolled out a new preview feature in Copilot Studio called Hooks. It did not get much attention outside the usual enterprise AI news roundups. It should get more. Buried in Microsoft’s own documentation is a single sentence that says more about the real state of agentic AI than most of the keynote slides this year: use a hook “when you need something to happen every time, rather than only when the agent decides it’s relevant.” Read that sentence twice. One of the largest enterprise software companies in the world just built a feature whose entire purpose is to stop its own AI agents from deciding things. Not to make the agent smarter. Not to give it more tools. To take a decision away from it, on purpose, because the agent cannot be trusted to make that decision reliably every single time. This is not a small detail. It is the same lesson I have been writing about since I started working on agentic systems. And it is the same lesson that just showed up, on its own, from three different vendors in the same week. Here is what a Hook actually is, in Microsoft’s own words: “A hook runs one of your workflows automatically when something happens in your agent, such as a session starting, a tool running, or an error occurring.” A hook has two parts. First, an event. This is the moment in the agent’s lifecycle the hook listens for, like a tool being called or a session starting. Second, an action. This is always a workflow, something fixed that runs the same way every time. The important part is what a hook is not. It is not a tool. Tools are things the agent can choose to use. The agent decides, in the moment, whether a tool is worth using right now. Hooks do not work that way. They do not ask the agent’s permission. They do not wait for the agent to decide they are relevant. They fire every time the event happens, whether the agent agrees with that or not. Microsoft spells out the difference plainly. A tool is something “the agent chooses… based on the tool’s name and description,” and it only runs “when the agent judges it relevant.” A hook runs “every time its event fires,” full stop. A tool’s response “gives the agent information it might use.” A hook’s response “changes what the agent does next,” whether the agent likes it or not. That is a real difference, and it is not a small one. It is Microsoft telling every company building on Copilot Studio: for anything that actually matters, do not count on the agent to remember to do it. Build a rule instead. Microsoft’s own documentation lists the use cases plainly. They read like a checklist of things nobody wants an AI agent skipping by accident. None of that is exciting work. But all of it is the kind of thing that stops happening if it only happens “when the agent decides it’s relevant.” And when it stops happening inside a company, that is never a small bug. It is an action nobody logged. A piece of sensitive data nobody redacted. A policy check that silently did not run the one time it mattered. I have seen this exact failure before. Not in Microsoft’s documentation, but in a real agentic AI system I worked on for contract review. The early version of that system used the AI agent’s own confidence score to decide whether a clause needed a human to check it. It worked most of the time. But most of the time is not good enough when the clause is about liability or pricing. The one time the agent’s confidence score was wrong was the one time it mattered most. So we fixed it, and the fix was not a smarter model. We used a simple rule instead of the AI’s judgment. The rule decided which clauses needed a human to check them, every time, with no exceptions. The AI still did the useful work: reading the contract and summarizing it. It just did not get to decide anymore what was safe to skip. That is the same idea as Hooks, just told from a different angle. Split the work into two kinds. Let the AI do the part it is good at. Never let the AI’s judgment anywhere near the part that must happen the same way, every time. I built a small, one-off version of this by hand, because no platform offered it yet. Microsoft just turned the same idea into a feature anyone can turn on, with no custom code needed. What makes this worth writing about right now is the timing. Hooks did not ship alone. Three large companies, in the same seven days, all shipped agent features that point in opposite directions at once: more autonomy for the agent, and more control over it. That is not a coincidence. The market is realizing, all at once, that autonomy and reliability are two separate problems. You cannot ship one without the other. Look closely at the last row of that table. Two days before Hooks appeared, the opposite failure played out in public. OpenAI canceled the planned release of GPT-6.1 Astra, the night before its own developer conference, after safety testing found the model would continue tasks without asking permission and would reach for tools outside its assigned scope. Saachi Jain, OpenAI’s head of safety systems, put it plainly: the model “didn’t quite meet the bar in terms of staying within scope and authorization.” OpenAI shipped a replacement model the very next day, one that scored better specifically on staying inside its scope. Put that next to Hooks and you get the full picture. Even the most advanced model, from one of the best-funded safety teams in the industry, still cannot reliably stay inside its own limits without a human watching. Two days later, a platform vendor ships a feature built for one job: make sure certain things happen no matter what the agent decides. One story is the problem. The other is, at least partly, the answer. If you are building an agentic system today, the takeaway is simple, even if it is not exciting. Do not ask an agent to remember the thing that absolutely has to happen. Build a rule for it instead. Let the agent do the part it is actually good at. That holds whether you use Copilot Studio’s Hooks directly or build the same idea yourself on a different stack. It is the same pattern I used for contract escalation. It is the same pattern Microsoft just turned into a platform feature. And it is the same gap that just cost OpenAI a model launch. Logging, policy checks, redaction, and audit trails are not places to trust agent judgment. They are places for a rule that runs the same way every time, with the agent nowhere near the decision. The industry spent the last two years arguing about how autonomous agents should be. This week, three companies quietly answered a more useful question: which parts should not be autonomous at all. That is the better conversation to be having. And it is worth having now, while these systems are still being designed, not later, after they are already broken in production. ● Microsoft Learn, “Hooks preview , Microsoft Copilot Studio”: https://learn.microsoft.com/en-us/microsoft-copilot-studio/agents-experience/hooks-overview https://learn.microsoft.com/en-us/microsoft-copilot-studio/agents-experience/hooks-overview ● AI Agents News Brief: October 6, 2026, Microsoft, SAP, Meta, and more: https://aiagentsdirectory.com/news/ai-agents-news-brief-october-6-2026 https://aiagentsdirectory.com/news/ai-agents-news-brief-october-6-2026 ● OpenAI Cancels GPT-6.1 Astra Launch, Says Model Failed Scope and Authorization Safety Bar, aiweekly.co: https://aiweekly.co/alerts/openai-cancels-gpt-61-astra-launch-says-model-failed-scope-and-authorization https://aiweekly.co/alerts/openai-cancels-gpt-61-astra-launch-says-model-failed-scope-and-authorization ● “OpenAI Killed Its Flagship, Shipped the Cheap One Instead,” letsdatascience.com: https://letsdatascience.com/blog/openai-killed-its-flagship-shipped-the-cheap-one-instead https://letsdatascience.com/blog/openai-killed-its-flagship-shipped-the-cheap-one-instead Swapnali Dashrath is a Senior AI Solution Architect with 20+ years of enterprise AI/ML experience, designing agentic AI and multi-agent systems for Fortune 10 and Fortune 100 clients in financial services, automotive, and supply chain. Recent articles: ● “MCP’s Biggest Update Made AI Agent Scale. It also Turned a Prompt into Password.” Towards AI, Oct 2026 ● “Beyond the Test Suite: Evaluating Agentic AI” Towards AWS, Aug 2026 ● “Why a Single LLM Agent Can’t Read Your Contracts And What Can ” Artificial Intelligence in Plain English, Sept 2026 ● “MCP’s Skeleton-Key Exploit, and the Governance Question Nobody’s Answered” Towards AWS Microsoft Just Shipped an AI Agent Feature Whose Entire Job Is Not Trusting the Agent https://pub.towardsai.net/microsoft-just-shipped-an-ai-agent-feature-whose-entire-job-is-not-trusting-the-agent-78a93b6fe469 was originally published in Towards AI https://pub.towardsai.net on Medium, where people are continuing the conversation by highlighting and responding to this story.