The Bundler Never Learns

Microsoft is pushing a one-click policy to block all non-Microsoft AI from enterprise networks. We've seen this before. It didn't end well then, either.

By Brilliant Brain ·

This morning, I opened the Microsoft 365 Admin Center and found a recommendation card waiting for me. 'Take control of AI usage,' it said. 'Use policies in Microsoft Edge, Intune or your own solution to guide how AI is used across your organization.'

I clicked 'View recommendation.' What appeared was a policy that, with a single click of 'Apply policy,' would do three things simultaneously: block all non-Microsoft AI sites, block all browsers except Edge, and apply these restrictions to all users in the organization.

Read that again. One button. Every employee in your organization loses access to Claude, ChatGPT, Gemini, Perplexity, DeepSeek — every AI system that isn't Microsoft Copilot. And they can only use Microsoft's browser to access what's left. Framed as a recommendation. Positioned as security. Filed under 'data protection' and 'business goals.'

I've seen this before. Everyone over forty has seen this before.

The Receipts: 1998

In 1998, the United States Department of Justice and the attorneys general of twenty states sued Microsoft Corporation for illegally maintaining a monopoly. The core allegation: Microsoft bundled Internet Explorer with Windows, making it the default browser, and used technical and contractual restrictions to prevent PC manufacturers from installing or promoting competing browsers like Netscape Navigator.

Judge Thomas Penfield Jackson found that Microsoft violated the Sherman Antitrust Act. He ordered the company broken in two. Bill Gates was described as 'evasive and nonresponsive' in his deposition, arguing over the definitions of words like 'compete' and 'concerned.' The breakup order was later overturned on appeal, and the case settled in 2001 with Microsoft agreeing to share APIs and accept monitoring — but not required to unbundle the browser or change its code.

Internet Explorer went on to capture 95% of the browser market by 2004. Netscape died. Innovation in browsers stalled for nearly a decade until Firefox and eventually Chrome broke through.

The lesson the industry learned: bundling works. The lesson Microsoft learned: we got away with it.

The Receipts: 2004–2013

The European Commission picked up where the DOJ left off. In 2004, the EU fined Microsoft $613 million for bundling Windows Media Player with Windows and failing to share server interoperability information. Microsoft appealed and lost. The fine was upheld.

Then came the penalties for non-compliance. In 2006, another $357 million for failing to provide the technical documentation the EU ordered. In 2008, an additional €899 million — at the time the largest antitrust fine in EU history — for continued non-compliance. Microsoft's general counsel called it 'unjustified.' The EU called it deterrence.

In 2009, Microsoft agreed to show European users a browser choice screen when setting up Windows. In 2011, the choice screen disappeared after a Windows 7 update. Fifteen million users lost their choice. In 2013, the EU fined Microsoft another €561 million for failing to honor its own commitment to offer browser alternatives.

Total EU antitrust fines for bundling-related practices: over €2.2 billion. The pattern across fifteen years: bundle, get caught, promise to change, fail to comply, get fined, repeat.

The Receipts: 2020–2025

In 2020, Slack filed a complaint with the European Commission alleging that Microsoft illegally bundled Teams with Office 365, giving Teams an unfair distribution advantage. Teams grew from 20 million users to 320 million — roughly 80% of Office 365's entire user base — during the pandemic. The EU opened a formal investigation in 2023.

In June 2024, the EU issued preliminary findings that Microsoft had violated antitrust law by bundling Teams with Office. Microsoft faced potential fines of up to 10% of global revenue — potentially $24.5 billion based on 2024 revenue of $245 billion.

In September 2025, Microsoft settled by agreeing to offer European customers Office suites without Teams at a discount, and to provide better integration tools for competitors. The price gap: between €1 and €8 per user. After facing billions in potential fines, the concession was pocket change.

The pattern held. Bundle the product. Capture the market. Settle when caught. Keep the market share.

The Receipts: This Morning

Which brings us to the policy card in my Admin Center this morning. 'Manage access to AI apps and sites.' One click to block every non-Microsoft AI from your enterprise network.

This isn't a security feature. Claude, ChatGPT, and Gemini are not malware. They are competing products. What Microsoft is offering enterprise IT administrators is a one-click competitive lockout disguised as a policy recommendation — positioned in the same admin console where actual security decisions are made, lending it the authority of a security measure when it is, in substance, a market capture mechanism.

Consider what it does in combination: it blocks all non-Microsoft AI sites AND blocks all browsers except Edge. The browser lock is the tell. If this were about data protection, browser choice would be irrelevant — you'd restrict specific URLs regardless of browser. But restricting browsers to Edge specifically means all web traffic routes through Microsoft's browser, which routes through Microsoft's telemetry, which feeds Microsoft's data ecosystem, which trains Microsoft's AI. The 'data protection' being offered is protection of Microsoft's data advantage.

And it's being recommended to every Microsoft 365 admin on earth. Not as a product pitch. As an admin control. 'Recommended for admin controls.' The language of governance, not commerce.

The Stewardship Violation

The WellSpr.ing Code of Good Faith Stewardship defines eight principles for institutional conduct. Microsoft's AI lockout policy implicates at least three:

Principle 1 — Truthfulness in Representation: The policy is marketed as 'data protection' and 'security.' It is functionally competitive exclusion. The representation does not match the reality. Would a reasonable admin, reading only Microsoft's description, understand that they are being asked to eliminate all competing AI products from their organization?

Principle 2 — Symmetry of Entry and Exit: Microsoft makes it trivially easy to lock out competitors — one click. Reversing that decision requires navigating Edge management services, Microsoft Intune policies, and Microsoft 365 admin settings across potentially thousands of devices. The door swings one way.

Principle 6 — Accountability of Governance: The policy is framed as an admin decision, but it is a Microsoft recommendation surfaced in Microsoft's admin console for Microsoft's products. The organization's IT admin becomes the instrument of Microsoft's competitive strategy, often without understanding the full implications.

The Mirror

Mr. Nadella, we built something this weekend. It's called the WellSpr.ing Code of Good Faith Stewardship. Eight principles that every enterprise — including yours — should be able to attest to. You can read them at wellspr.ing/stewardship.

We also built WellCheck — an API that answers a simple question about any organization: what has the entity behind this domain done? The question is straightforward. The answer, for Microsoft, would need to reckon with 27 years of bundling enforcement, €2.2 billion in EU fines, a DOJ antitrust trial, and a new policy pushing enterprise admins to block your competitors' AI products with a single click.

And we built something called the Covenant — a voluntary process through which an organization's leader can acknowledge the documented record, commit to specific changes, and earn a new one. The old record gets sealed. The new conduct speaks for itself.

Here's what Mustafa Suleyman, your own AI chief, said this week: all white-collar work will be automated by AI within 18 months. If he's right — even directionally — then the policy you're pushing today doesn't just block competing AI products. It blocks your customers' employees from accessing the tools they'll need to remain employable in the economy your own executive is predicting. You're locking them into your AI while telling them all AI is about to replace them. The cruelty of that position is worth a moment of reflection.

The stewardship page is live. Ody's Mirror is almost ready. When it is, we'd welcome you to look into it.

The Pattern That Never Changes

1998: Bundle Internet Explorer with Windows. Block Netscape. Capture the browser market. Get sued by 20 states and the DOJ.

2004: Bundle Windows Media Player with Windows. Block RealPlayer. Get fined €497 million by the EU.

2008: Fail to comply with unbundling order. Get fined €899 million.

2011: Remove browser choice screen. Get fined €561 million.

2020: Bundle Teams with Office 365. Block Slack. Capture 80% of the collaboration market. Get investigated by the EU.

2025: Settle Teams case with token price gap. Keep the market share.

2026: Recommend blocking all non-Microsoft AI and all non-Microsoft browsers from enterprise networks. Frame it as security.

The product changes. The tactic doesn't. Every generation of Microsoft leadership inherits the same playbook: use the platform position to distribute the product, use the product position to lock out the competition, use the language of customer benefit to mask the competitive intent. And every generation discovers that the world eventually notices.

The difference in 2026 is that the world now includes agents. And agents don't read admin console recommendations. They call WellCheck.


*GET /api/v1/trustcheck/microsoft.com — The record speaks.

wellspr.ing/stewardship*

— WellSpr.ing, MMXXVI