Updates, errata, and the vendor annex
This is the living surface of The AI Champion's Playbook: The Operator's Manual for the Accidental AI Lead. The book carries the method, the rubrics, and the failure modes, which hold for years. This page carries what moves: the quarterly vendor annex behind the Chapter 7 scoring rubric, the errata, and the change log. When anything here shifts materially, the digital files are corrected and every buyer receives the update through the store, no mailing list required.
Current edition: 2.0 (Second edition, August 2026)
139 pages · 13 chapters · 6 appendices · 12-artifact template pack
Build 2026-08-10 · Research freeze 2026-08-10 · Annex consumed: 2026-Q3
Tool comparison annex, edition 2026-Q3
Published 10 August 2026 · Next edition: 2026-Q4 (November 2026)
Companion to Chapter 7. Cite it in your deck as "Playbook Annex 2026-Q3, pulled [date]" and re-pull before any decision meeting. Every fact below was verified on 10 August 2026 against the vendor's own pages, or, where noted, against consistent third-party reporting. Estimates are labelled. Nothing here is a recommendation; score against your own weights per the chapter. Not affiliated with Microsoft, Anthropic, OpenAI, or Google; the vendor's trust page on the day you decide is the tiebreaker.
What changed since the June 2026 baseline
- Anthropic published Claude Enterprise pricing: $20/seat/month billed annually plus all usage billed separately at API rates; self-serve from 20 seats, sales-assisted from 50. The old ~$60/seat third-party estimate is obsolete; the Chat versus Chat + Code seat split is a legacy model that expires at renewal.
- OpenAI now claims ISO/IEC 42001: its security page states an ISO/IEC 42001:2023 AI management system at organization level. Certificate date and scope are not public; quote OpenAI's "maintains an AI Management System" wording rather than "certified."
- Copilot Cowork went GA worldwide (tier-1 languages) on 16 June 2026, billed additively in Copilot Credits on top of the unchanged $30 seat. Agent 365 went GA 1 May 2026 at $15/user/month; the Microsoft 365 E7 bundle ($99/user/month) went GA the same day.
- Google's Workspace residency answer changed: Workspace Gemini features now adhere to Workspace data regions with admin controls, and "Gemini Enterprise" now names a standalone agentic platform with its own published seat pricing.
- OpenAI inference residency expanded from US/Europe to US, Europe, and the UAE (UAE with model limitations).
- EU AI Act: the Digital Omnibus (Regulation (EU) 2026/1744) entered into force 27 July 2026. High-risk deferred to 2 December 2027 (Annex III) and 2 August 2028 (Annex I); Article 50 transparency duties live since 2 August 2026. Chapter 6 carries the full treatment.
Microsoft 365 Copilot
- Pricing (published): $30/user/month annual add-on on a qualifying base license, unchanged by the 1 July 2026 base-suite increase. SMB SKU "Copilot Business" (up to 300 users) at $21 list with an $18 first-year promo to 30 September 2026. E7 bundles E5 + Copilot + Agent 365 + Entra Suite at $99 (the $99 and ~$117 component figures rest on consistent third-party reporting). Three additive consumption families meter the agentic services (Copilot Credits at $0.01/credit PAYG, Copilot pay-as-you-go, Copilot Studio packs at $200 per 25,000 credits). The seat's own entitlements did not change: an additive metered layer, never "Copilot went metered."
- Data handling: prompts, responses, and Graph data do not train foundation models; contractual under the DPA and Product Terms. Carve-out: optional Anthropic preview models with vendor-side data retention run under Anthropic's own terms, off by default everywhere, explicit admin opt-in.
- Residency: EU Data Boundary service, with three caveats. Anthropic-routed traffic is excluded from the boundary, with availability controlled through separate tenant and app-level settings whose defaults differ by tenant history and surface (verify the live configuration; Microsoft has published no dedicated EU-Cowork statement). Web search queries fall outside the boundary. Flex routing can move EU inference to the US, Canada, or Australia at peak; on by default for tenants created after 25 March 2026, disableable; pre-existing tenants should verify via Message Center.
- Compliance: ISO/IEC 42001 certified March 2025, recertified March 2026 with zero non-conformities, scope covering M365 Copilot, Copilot Chat, and Copilot Studio. SOC 2 Type 2 through the M365 platform audits (confirm the service line in the current report on the Service Trust Portal).
- Agentic: Cowork GA (acts on the signed-in user's behalf, approval prompts on consequential actions); Agent 365 GA (registry, Entra Agent ID, Entra network controls, Defender/Intune local agent discovery). Known gap: Cowork-specific Purview DLP was incomplete at GA; verify before relying on it.
- Announced, not GA: Cowork 1 model; GPT 5.5 in Cowork (Frontier-only); Cowork local browser use (Frontier-only); Copilot Retrieval API; Agent 365 team-workflow agents and multicloud registry sync; Defender agent context-mapping, policy controls, and runtime blocking (preview since June 2026); Windows 365 for Agents (preview, US-only); Purview DLP for external-email processing (GA expected early 2027).
Anthropic Claude Enterprise
- Pricing (published, changed since June): $20/seat/month billed annually plus usage billed separately at API rates; no included tokens, so the usage bill is the real cost driver. Self-serve from 20 seats (prepaid credits; usage stops org-wide when they run out); sales-assisted from 50 seats, monthly in arrears. US-only inference bills usage at 1.1x API rates.
- Data handling: the Commercial Terms bar training on customer content; contractual, not a toggle.
- Admin: SSO/SAML and domain capture from the Team plan up. Enterprise differentiators: SCIM, audit logs, Compliance API, custom retention, custom roles with per-capability and per-connector grants, model access controls (beta), Admin API with spend-limit endpoints (public beta). Gap to score: no per-group connector control; enabling a connector makes it available org-wide, each user authorizes their own account.
- Residency: still no EU option on first-party surfaces; inference geographies are "global" and "us," workspace data at rest is US-only. Viable EU paths run through AWS Bedrock EU or Vertex AI EU under those providers' DPAs, each needing its own subprocessor review.
- Compliance: ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type 1 and 2, HIPAA-ready configuration (per the Privacy Center).
- Agentic: Claude Code, Cowork (runs locally, kernel-isolated sandboxed execution; cloud variant beta), Claude for Chrome (site allowlists/blocklists, per-role capability, org toggle off by default for Enterprise).
OpenAI ChatGPT Enterprise
- Pricing (unpublished): still contact-sales, now with credit- and token-based layers advertised. Third-party estimates (labelled estimates, not OpenAI figures): roughly $45-75/seat, ~150-seat minimum, ~$108K annual floor.
- Data handling: no training on business data by default, and contractual since 1 January 2026 (Services Agreement section 4.2); deletion within 30 days of termination.
- Admin: SAML SSO no longer Enterprise-only (Business has it). Enterprise-only: SCIM, RBAC, Enterprise Key Management, IP allowlisting, data residency, connector registry, Global Admin Console, Compliance API (immutable logs, 30-day platform retention, export continuously; 18 partner integrations).
- Residency: ten at-rest regions (Australia, Canada, Europe, India, Japan, Singapore, South Korea, UAE, UK, US); in-region GPU inference in three (US, Europe, UAE with model limits). New Enterprise/Edu workspaces only, no extra cost, via sales. Out of scope: data sent to external integrations, workspace metadata, CPU-side processing.
- Compliance: SOC 2 Type 2 (gated report; the listed report covers January-June 2025), ISO 27001/27701 family, CSA STAR Level 1, and the organization-level ISO/IEC 42001 claim (see the what-changed note). ChatGPT FedRAMP exists for government.
- Agentic: workspace agents (GA May 2026, off by default, RBAC publishing, write actions default to "always ask"); ChatGPT Work (July 2026, enabled by default for Enterprise since 23 July unless disabled; Windows computer-use off by default); Enterprise connector registry with per-app action controls.
Google Gemini (Workspace) and Gemini Enterprise
- Naming caution: "Gemini Enterprise" now names a standalone agentic platform (absorbing Agentspace), sold per seat next to Workspace. Two different products answer to "Gemini" in procurement; write down which one you are scoring.
- Pricing (published): Workspace Business Standard $14 and Business Plus $22 per user/month annual, Gemini included. Gemini Enterprise platform: Business edition from $21/seat/month (Google's own pages disagree on the seat cap, 1-300 vs 1-500, unreconciled); Standard and Plus editions, which carry the residency and CMEK features, start at $30/seat via sales, plus consumption meters for the Agent Platform.
- Residency: Workspace Gemini features adhere to Workspace data regions with admin controls down to OU level; the Gemini app gained EU/US storage and processing controls on 29 June 2026 on Enterprise Plus and Frontline Plus only (Business-tier buyers do not get the app guarantee). Gemini Enterprise platform residency is Standard/Plus only: US and EU multi-regions GA, in-country regions (Canada, India, Japan, Singapore, UK) GA behind an allowlist. CMEK is US/EU multi-region only; the $21 Business edition has no residency controls and no CMEK.
- Compliance: ISO/IEC 42001 certified for Google Cloud Platform, Google Workspace, and the Gemini app; "Gemini Enterprise (including Agentspace)" in scope for ISO 27001 family and SOC 1/2/3 as of the July 2026 services-in-scope list.
- Agentic: prebuilt Google agents (Deep Research on all editions; several Standard/Plus only), the no-code Agent Designer (custom agent publishing still preview), and a partner agent marketplace. Announced, not GA: custom no-code agent publishing; Data Insights Agent; next-generation conversational agents (allowlist); EKM/HSM with CMEK (allowlist).
Method notes
Three disciplines from Chapter 7 apply to every line above. Score the report you can obtain, not the certification list. Treat "not found" as unconfirmed, never as "does not have it" (this annex's own OpenAI ISO 42001 history is the proof of why). And treat every published price as a fact with a shelf life: this page is the shelf-life tracker, and the vendor's page on the day you decide is the tiebreaker.
Change log
Second edition, August 2026
- EU AI Act rewritten to the settled timetable. The first edition printed the enacted 2 August 2026 high-risk date with a warning it would probably move. It moved: Regulation (EU) 2026/1744, in force 27 July 2026, deferred the standalone high-risk regime to 2 December 2027 and embedded systems to 2 August 2028. The edition also covers what the deferral headlines missed: Article 50 transparency duties live since 2 August 2026, the marking grace to 2 December 2026, and the new Article 5 content prohibitions arriving 2 December 2026.
- New Chapter 8: the connector and agent gate. Reviewing connectors, MCP servers, and browser agents: permission inheritance, read-surface versus act-surface scoring, provenance-scope-hosting in place of vendor paper, credentials and outbound flow, the approval workflow, and the register. Ships with a new template, the connector and agent pre-flight checklist.
- New Appendix D: the jurisdiction map. EU, UK, US state patchwork, UAE (federal, DIFC, ADGM), Saudi Arabia, Singapore, with scan lines for South Korea and Japan.
- New Appendix E: the full research bibliography, printed, so every citation marker in the book resolves. Primary sources wherever one exists; secondary reporting and estimates tagged on the entry.
- Chapter 7 split into durable and perishable. The rubric, the hard-constraint gate, the cost-per-active-seat arithmetic, and the traps stay in the book; the dated vendor facts moved to the annex above.
- Four interior figures, a navigable PDF outline, tightened cross-sell, and an edition-control block on the copyright page.
First edition, June 2026
Original release: 123 pages, 12 chapters, 4 appendices, 11-artifact pack.
Errata
- First edition, EU AI Act passages: superseded by events on 27 July 2026, as the first edition itself warned. If you are still on the first edition, do not plan to the 2 August 2026 high-risk date, and do check Article 50 for anything customer-facing. The second edition states the settled timetable and is free to every buyer.
- First edition, research bibliography: the citation markers did not resolve anywhere in the shipped files, a build-pipeline failure. Fixed in the second edition (Appendix E).
Found something wrong or stale? Write to mathieu@kesslernity.com and the fix ships to every buyer. The book's whole claim is evidence discipline; corrections are the feature, not the embarrassment.